DRAFT · Pending approval by the owner and review by a lawyer. This is not yet a final text.
Privacy policy
Last updated: 07/10/2026
Here is everything the law requires us to tell you when you give us your data: who processes it, why, on what basis, who it is shared with, how long it is kept and what rights you have. It covers the website (including the «Book a demo» form), the demo and the panel.
Law: article 13 of the General Data Protection Regulation (EU) 2016/679 (GDPR) and article 11 of Spanish Organic Law 3/2018 (LOPDGDD), which allows the information to be given in two layers: a summary next to the form and this page.
1. Who the controller is
- Controller: [PENDING: full name or company name], tax ID [PENDING: NIF], with address at [PENDING: address].
- Email for anything to do with your data: [PENDING: privacy email].
- Data protection officer: [PENDING: state whether there is one and their contact, or that it is not mandatory].
Bildeit processes data in two different roles:
- Controller of the data of people who ask for a demo and of the login accounts (the people who use the panel).
- Processor of the personal data each client company enters in Bildeit: its clients, suppliers, projects, invoices and team members. There the client company is the controller, and Bildeit only processes that data to provide the service and following its instructions, under a processing agreement signed before the service is used with real data ([PENDING: draft the processing agreement]).
Laws: articles 4, 13.1.a, 13.1.b and 28 of the GDPR; article 33 of the LOPDGDD (processor).
2. What data we process, why and on what legal basis
| Data | Why | Legal basis |
|---|---|---|
| From the «Book a demo» form: name, email, phone (if you give it), company, number of projects and what you tell us | To answer you and show you the product. Nothing else: we do not send you advertising | Your consent, given by ticking the box and sending (art. 6.1.a). You can withdraw it at any time, without affecting what was done before |
| From the account: email, name and password (stored encrypted) | To create your login, protect it and let you in | The service contract (art. 6.1.b) |
| From the client company: company name, tax ID, province of the tax address, address and what it enters in the panel | To provide the service: projects, budgets, certificates, invoices, record books and forms | The contract (art. 6.1.b); for invoicing records, also a legal obligation (art. 6.1.c) |
| Photos or PDFs of supplier invoices you upload to be read | To fill in the supplier invoice for you | The contract (art. 6.1.b) |
| Technical access logs (date, time, IP address) | To protect the service and detect abuse | Legitimate interest in the security of the service (art. 6.1.f) |
The form fields marked as mandatory (name and email) are needed to answer you; without them, we can't. We make no automated decisions with legal effects on you, we do not sell data and we do not use it for advertising.
Laws: articles 6.1 and 13.1.c, 13.2.c, 13.2.e and 13.2.f of the GDPR; article 6 of the LOPDGDD (consent).
3. How long we keep it
- Demo requests: as long as needed to answer you and, at most, 12 months from the last time we spoke, unless you become a client.
- Account data: while the account is active.
- Invoices, record books and invoicing records: the periods set by law. A business's books and supporting documents are kept for six years; the Tax Agency can review for four. A Verifactu record cannot be deleted or changed.
- Afterwards, whatever the law requires us to keep is blocked (nobody uses it) until liabilities expire, and then deleted.
- The panel demo creates a sample company with made-up data, which deletes itself after 24 hours.
Laws: article 13.2.a of the GDPR; article 32 of the LOPDGDD (blocking); article 30 of the Spanish Commercial Code (six years); article 66 of Law 58/2003, General Tax Law (four years); Royal Decree 1619/2012 (invoicing) and Royal Decree 1007/2023 (invoicing records).
4. Who it is shared with (providers)
We do not hand your data over to anyone. We do use providers that process it on our behalf, with a contract and safeguards:
- Supabase: the database and the login accounts. Project region: [PENDING: confirm it is the European Union].
- Cloudflare: hosts and serves the website and the panel.
- Anthropic: only when you scan a supplier invoice, that file (the photo or the PDF) is sent to it to read its data. What is read is not saved until you review and confirm it. [PENDING: verify its data processing agreement with an official source before using reading with real data].
Some of these providers are in the United States. The transfer relies on the EU-US Data Privacy Framework (if the provider is certified) or on the European Commission's standard contractual clauses. [PENDING: verify provider by provider]
Laws: articles 13.1.e, 13.1.f, 28 and 44 to 46 of the GDPR.
5. Your rights
You can ask for access to your data, its rectification or erasure, restriction of processing, portability, and object to processing, and withdraw your consent at any time. Write to the privacy email above; we reply within one month at most. It is free.
If you think we have not handled your data properly, you can complain to the Spanish Data Protection Agency (AEPD).
Laws: articles 12, 13.2.b, 13.2.c, 13.2.d, 15 to 22 and 77 of the GDPR; articles 12 to 18 of the LOPDGDD.
6. Security
Each company can only read its own data, and the database enforces this row by row (row-level security), not just the screen. Passwords are not stored in plain text. Connections are encrypted.
Law: article 32 of the GDPR (security of processing).