Privacy Policy
What data we process, why, who we share it with, and how to exercise your rights.
Last updated: October 8, 2026
This policy explains how [RAZÓN SOCIAL, S.L.] ("Abastecia", "we", "us") processes personal data when you visit abastecia.com, create an account, or use the Abastecia application (the "Service"). We have written it to be easy to understand; if anything is unclear, email us at [email protected].
1. Who the controller is
- Controller: [RAZÓN SOCIAL, S.L.]
- NIF (Spanish tax ID): [NIF]
- Address: [DOMICILIO SOCIAL, CÓDIGO POSTAL, CIUDAD, ESPAÑA]
- Privacy contact: [email protected]
2. Two different roles: controller and processor
- We are the controller of the data of the people who use the Service: users' names and email addresses, the company account data, billing, and support conversations. This policy covers that data.
- We are a processor of the data your company uploads to the Service (sales, products, suppliers, stock, and orders). That data belongs to your company, and we process it only on your company's instructions, in accordance with the Data Processing Annex of the Terms of Use. It does not normally contain personal data; if it does, your company is the controller of that data.
3. What data we process and why
| Data | Purpose | Legal basis |
|---|---|---|
| User's name, email, password (stored as an irreversible cryptographic hash), language, and role | Creating and maintaining your account, identifying you, and sending you the emails required by the Service, such as the password change email | Performance of a contract |
| Company name, country, plan, and account status | Providing the Service under the subscribed plan | Performance of a contract |
| Activity log: sign-ins, password changes, uploaded files, and logged orders, with date and user | Account security, investigating incidents, and preventing abuse | Legitimate interest in protecting the Service and its users |
| Technical connection data (IP address, browser, date and time) recorded in our server logs | Operation, security, and attack detection | Legitimate interest |
| Billing and payment data | Charging for the Service and complying with tax and accounting obligations. Card data is processed directly by the payment provider: we do not see or store it | Performance of a contract and legal obligation |
| Messages you send us by email, chat, or WhatsApp | Responding to your inquiries | Performance of a contract or, if you are not yet a customer, your request |
| Questions you type into the support assistant and, if you are signed in, your account's name, plan, country, and usage | Answering you right away. We don't store conversations: they live only in your browser tab | Performance of a contract or, if you are not yet a customer, your request |
| Data you send us when requesting a trial through the website (business name, country, number of stores, WhatsApp) | Responding to your request and giving you access | Taking steps at your request prior to entering into a contract |
We do not use your data to make automated decisions that produce legal effects concerning you, nor to build marketing profiles. We do not sell personal data or business data.
The support assistant answers automatically and can make mistakes; don't use it to type passwords or other people's personal data. If you need a person, the assistant itself offers to write to us by WhatsApp or email with the conversation copied in.
We will only send you marketing communications if you give us your consent or if you are a customer and they relate to products similar to those you have subscribed to; you can unsubscribe in every email.
4. Who we share data with
We use providers that process data on our behalf (processors), under contracts and data protection safeguards:
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud (Google LLC / Google Ireland) | Hosting of the application and database, backups | United States |
| Cloudflare, Inc. | Domain, DNS, website hosting, attack protection, and forwarding of contact emails | Global network |
| Postmark (ActiveCampaign, LLC) | Sending the Service's emails | United States |
| Anthropic, PBC | Generating the support assistant's answers. Under its commercial terms, it does not use this data to train its models | United States |
| Stripe and dLocal (once we enable online payments) | Collecting subscription payments | Depending on the country of payment |
We will also disclose data to authorities and courts when required by law.
5. International transfers
Some providers process data outside the European Economic Area, mainly in the United States. We do so with the safeguards of the General Data Protection Regulation: providers certified under the EU-U.S. Data Privacy Framework or, failing that, Standard Contractual Clauses approved by the European Commission. You can ask us for a copy of these safeguards.
6. How long we keep data
- Account data and business data: for as long as the account is active. If you cancel the Service, we delete it within 30 days at most, unless you ask us for a copy beforehand. Backups are overwritten within a further 30 days at most.
- Free trial that does not continue: if you do not choose a plan, we keep the account for 90 days in case you decide to continue, and then delete it.
- Activity log and technical logs: up to 12 months.
- Invoices and accounting data: for the period required by law (in Spain, up to 6 years).
- Trial requests from the website: up to 12 months if you do not go on to create an account.
7. Your rights
You may at any time exercise your rights of access, rectification, erasure, objection, restriction of processing, and data portability, and withdraw any consent you have given us, by emailing [email protected]. We will respond within one month. If we need to in order to protect your account, we will ask you to confirm your identity.
If you believe we have not handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency (AEPD) (aepd.es) or with the data protection authority of your country.
If you are in Latin America: we also recognize the rights granted to you by the law of your country, for example Brazil's General Data Protection Law (LGPD) or Colombia's Law 1581 of 2012, and we handle them through the same channel.
8. Security
All data is encrypted in transit (HTTPS). Passwords are stored as an irreversible cryptographic hash. Each company can only see its own data. We make daily backups, log access, and restrict internal access to the people who need it to provide you with support.
If a security breach affecting your data occurs, we will notify the authority and, where applicable, the affected individuals, within the time limits set by law.
9. Cookies and browser storage
- The abastecia.com website does not use advertising or analytics cookies. Cloudflare may use strictly necessary technical cookies to protect the website against attacks.
- The application stores in your browser, using local storage, only what it needs to work: your signed-in session, your chosen language, and your display preferences. This information is not used to track you. The session is deleted when you sign out, and the rest when you clear your browser data.
- Fonts are served from our own servers, without connecting to third-party services.
Because we only use strictly necessary storage, we do not ask for your consent. If we add analytics or advertising cookies in the future, we will ask for your permission first.
10. Minors
The Service is intended for businesses and professionals. It is not intended for anyone under 18, and we do not knowingly process their data.
11. Changes to this policy
If we make material changes to this policy, we will notify you by email or within the application before the change takes effect. The date of the last update appears at the top.