Skip to content
Constaia

Privacy policy

Updated 29 September 2026

Draft pending legal review. Items marked [COMPLETAR: …] must be filled in before publication.

This is a translation. In case of discrepancy, the Spanish version prevails.

1. Controller

ItemValue
ControllerAdd On Dev Solutions S.L. ("Constaia", "we")
Tax ID (NIF)B22654610
AddressCalle Espronceda, nº 2, planta 1, puerta C, 21001 Huelva (Huelva), Spain
Privacy contactcontacto@addon-sport.com
Data protection officer[COMPLETAR: state whether a DPO has been appointed and their contact, or remove this row]

2. Scope: controller and processor

2.1. This policy covers the data we process as controller: visitors to constaia.com, people who write to us, and customer users and accounts of the dashboard (app.constaia.com) and the API.

2.2. We process the documents customers send to the API for analysis (and the data they contain: ID cards, passports, certificates, receipts, etc.) on behalf of the customer, as processor (Art. 28 GDPR). The customer is the controller and decides what they are used for. That processing is governed by the Data processing agreement (DPA), not by this policy.

2.3. If you are the person whose document a Constaia customer analysed, please address your requests to that organisation. If they reach us, we will forward them.

3. Data we process

CategoryDataSource
Website visitorsCookieless aggregate analytics: page views, referrer, country, device type and browser. No personal identifiers are stored.Your browser
Technical dataIP address, user agent, date and time of requests in server and API logsYour browser or your integration
Account and usersName, email, company, password (stored only as a hash), role, language, invited membersYou, when signing up or inviting others
API keysKey name, prefix and last 4 characters; the full key only as a SHA-256 hashGenerated in the dashboard
BillingAccount tax details, credit purchases, invoices, usageYou and Stripe
Service usageNumber of analyses, credits, document types, audit log (who, IP, action, changes)Use of the dashboard and the API
CommunicationsContent of your support or contact messages and emailsYou

You enter card details directly in Stripe Checkout; we do not receive or store them.

To show you the right market, the website derives your country from your IP address using a local database (DB-IP Lite, CC BY 4.0 licence) on our own server, without storing the IP for this purpose and without involving third parties. IP geolocation by DB-IP.

PurposeLegal basis (Art. 6(1) GDPR)
Creating and managing your account, providing the service, authenticating access and keysPerformance of the contract (b)
Charging for credits, issuing invoices and meeting accounting and tax obligationsPerformance of the contract (b) and legal obligation (c)
Transactional emails (verification, sign-in, low-balance alerts, service changes)Performance of the contract (b)
Security, abuse and fraud prevention, audit logLegitimate interest (f) in protecting the service and customers
Cookieless aggregate website analytics, without personal identifiersLegitimate interest (f) in understanding website use
Answering contact and support requestsLegitimate interest (f) or pre-contractual steps (b)
Marketing communications about ConstaiaConsent (a) or, for customers, Art. 21(2) LSSI-CE, with an opt-out in every message [COMPLETAR: confirm whether they will be sent]

We do not take decisions based solely on automated processing that produce legal effects on you as a customer.

5. Retention periods

DataPeriod
Account and usersWhile the account is active. After closure, blocked for the limitation periods of potential liabilities and then deleted. [COMPLETAR: specific period after closure]
Billing and accounting6 years (Art. 30 of the Spanish Commercial Code) and the periods required by tax law
Technical and audit logs[COMPLETAR: retention period for logs and audit_log]
Website analyticsAggregate data only, no personal data
Contact requestsAs long as needed to handle them and [COMPLETAR: period] afterwards

Retention of analysed documents is decided by the customer through the storage, ttl_hours and keep_results options (see the DPA).

6. Recipients and providers

We do not sell data. We share it only with providers that render services to us under a processing agreement, or where required by law (authorities, courts).

ProviderFunctionLocation
Hetzner Online GmbHInfrastructure, databases and storageGermany (EU)
Stripe Payments Europe Ltd.Payments, taxes and invoicesIreland (EU); see section 7
[COMPLETAR: transactional email provider, e.g. Amazon SES]Sending transactional emails[COMPLETAR]
[COMPLETAR: error monitoring provider, if used]Error logging[COMPLETAR]

Website analytics use Plausible self-hosted on our own infrastructure, with no data shared with third parties.

The providers that process analysed documents (OCR and AI models) are listed in the DPA.

7. International transfers

We host and process data in the European Union. Stripe belongs to a group headquartered in the USA; using Stripe may involve international transfers of billing data, which take place with the appropriate safeguards provided for in the GDPR (for example, the European Commission's standard contractual clauses or the EU-US Data Privacy Framework). You can check the specific safeguards in Stripe's privacy policy or ask us at contacto@addon-sport.com.

8. Your rights

You may exercise the rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw consent at any time without affecting the lawfulness of prior processing. Write to contacto@addon-sport.com stating which right you are exercising. If we cannot identify you with your account data, we may ask for additional information.

We will reply within one month, extendable by two further months in complex cases (Art. 12(3) GDPR).

If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD), www.aepd.es.

9. Security

We apply technical and organisational measures appropriate to the risk: encryption in transit (TLS), encryption of files at rest, passwords and API keys stored only as hashes, role-based access control and an audit log. The measures applied to analysed documents are detailed in the DPA.

10. Changes

We may update this policy. We will publish the new version with its date and, if the change is significant, notify you by email or in the dashboard.