Privacy policy
Updated 29 September 2026
Draft pending legal review. Items marked [COMPLETAR: …] must be filled in before publication.
This is a translation. In case of discrepancy, the Spanish version prevails.
1. Controller
| Item | Value |
|---|---|
| Controller | Add On Dev Solutions S.L. ("Constaia", "we") |
| Tax ID (NIF) | B22654610 |
| Address | Calle Espronceda, nº 2, planta 1, puerta C, 21001 Huelva (Huelva), Spain |
| Privacy contact | contacto@addon-sport.com |
| Data protection officer | [COMPLETAR: state whether a DPO has been appointed and their contact, or remove this row] |
2. Scope: controller and processor
2.1. This policy covers the data we process as controller: visitors to constaia.com, people who write to us, and customer users and accounts of the dashboard (app.constaia.com) and the API.
2.2. We process the documents customers send to the API for analysis (and the data they contain: ID cards, passports, certificates, receipts, etc.) on behalf of the customer, as processor (Art. 28 GDPR). The customer is the controller and decides what they are used for. That processing is governed by the Data processing agreement (DPA), not by this policy.
2.3. If you are the person whose document a Constaia customer analysed, please address your requests to that organisation. If they reach us, we will forward them.
3. Data we process
| Category | Data | Source |
|---|---|---|
| Website visitors | Cookieless aggregate analytics: page views, referrer, country, device type and browser. No personal identifiers are stored. | Your browser |
| Technical data | IP address, user agent, date and time of requests in server and API logs | Your browser or your integration |
| Account and users | Name, email, company, password (stored only as a hash), role, language, invited members | You, when signing up or inviting others |
| API keys | Key name, prefix and last 4 characters; the full key only as a SHA-256 hash | Generated in the dashboard |
| Billing | Account tax details, credit purchases, invoices, usage | You and Stripe |
| Service usage | Number of analyses, credits, document types, audit log (who, IP, action, changes) | Use of the dashboard and the API |
| Communications | Content of your support or contact messages and emails | You |
You enter card details directly in Stripe Checkout; we do not receive or store them.
To show you the right market, the website derives your country from your IP address using a local database (DB-IP Lite, CC BY 4.0 licence) on our own server, without storing the IP for this purpose and without involving third parties. IP geolocation by DB-IP.
4. Purposes and legal bases
| Purpose | Legal basis (Art. 6(1) GDPR) |
|---|---|
| Creating and managing your account, providing the service, authenticating access and keys | Performance of the contract (b) |
| Charging for credits, issuing invoices and meeting accounting and tax obligations | Performance of the contract (b) and legal obligation (c) |
| Transactional emails (verification, sign-in, low-balance alerts, service changes) | Performance of the contract (b) |
| Security, abuse and fraud prevention, audit log | Legitimate interest (f) in protecting the service and customers |
| Cookieless aggregate website analytics, without personal identifiers | Legitimate interest (f) in understanding website use |
| Answering contact and support requests | Legitimate interest (f) or pre-contractual steps (b) |
| Marketing communications about Constaia | Consent (a) or, for customers, Art. 21(2) LSSI-CE, with an opt-out in every message [COMPLETAR: confirm whether they will be sent] |
We do not take decisions based solely on automated processing that produce legal effects on you as a customer.
5. Retention periods
| Data | Period |
|---|---|
| Account and users | While the account is active. After closure, blocked for the limitation periods of potential liabilities and then deleted. [COMPLETAR: specific period after closure] |
| Billing and accounting | 6 years (Art. 30 of the Spanish Commercial Code) and the periods required by tax law |
| Technical and audit logs | [COMPLETAR: retention period for logs and audit_log] |
| Website analytics | Aggregate data only, no personal data |
| Contact requests | As long as needed to handle them and [COMPLETAR: period] afterwards |
Retention of analysed documents is decided by the customer through the storage, ttl_hours and keep_results options (see the DPA).
6. Recipients and providers
We do not sell data. We share it only with providers that render services to us under a processing agreement, or where required by law (authorities, courts).
| Provider | Function | Location |
|---|---|---|
| Hetzner Online GmbH | Infrastructure, databases and storage | Germany (EU) |
| Stripe Payments Europe Ltd. | Payments, taxes and invoices | Ireland (EU); see section 7 |
[COMPLETAR: transactional email provider, e.g. Amazon SES] | Sending transactional emails | [COMPLETAR] |
[COMPLETAR: error monitoring provider, if used] | Error logging | [COMPLETAR] |
Website analytics use Plausible self-hosted on our own infrastructure, with no data shared with third parties.
The providers that process analysed documents (OCR and AI models) are listed in the DPA.
7. International transfers
We host and process data in the European Union. Stripe belongs to a group headquartered in the USA; using Stripe may involve international transfers of billing data, which take place with the appropriate safeguards provided for in the GDPR (for example, the European Commission's standard contractual clauses or the EU-US Data Privacy Framework). You can check the specific safeguards in Stripe's privacy policy or ask us at contacto@addon-sport.com.
8. Your rights
You may exercise the rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw consent at any time without affecting the lawfulness of prior processing. Write to contacto@addon-sport.com stating which right you are exercising. If we cannot identify you with your account data, we may ask for additional information.
We will reply within one month, extendable by two further months in complex cases (Art. 12(3) GDPR).
If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD), www.aepd.es.
9. Security
We apply technical and organisational measures appropriate to the risk: encryption in transit (TLS), encryption of files at rest, passwords and API keys stored only as hashes, role-based access control and an audit log. The measures applied to analysed documents are detailed in the DPA.
10. Changes
We may update this policy. We will publish the new version with its date and, if the change is significant, notify you by email or in the dashboard.