Privacy Policy
Last updated: August 2026
1. Data Controller
OFFITIA (hereinafter, "the provider") provides users with this Privacy Policy to inform about how personal data of website users and users of the services offered through it are collected, processed, and protected.
Identity: OFFITIA
Contact email: support@offitia.io
2. Data we collect
When you use our services, we may collect the following categories of data:
- Identification data: name, email address, phone number, tax ID
- Billing data: tax address, bank details
- Client data that you enter into the system (names, emails, addresses, tax IDs)
- Browsing data: IP address, browser type, visited pages
- Usage data: quotes, invoices, and documents created through the platform
3. Purpose of processing
We process your personal data for the following purposes:
- To manage your user account and contracted services
- To process and store quotes, invoices, and created documents
- To send service-related communications (notifications, reminders)
- To improve our platform and user experience
- To comply with legal and tax obligations, including Veri*Factu regulations (RD 1007/2023) for NIF registration and submission of invoice records to the AEAT
4. Use of artificial intelligence
OFFITIA uses third-party artificial intelligence services (such as Groq, Together AI, or OpenAI) for the following features:
- Text generation: to process job descriptions and generate automatic quotes. Text data is sent securely (HTTPS), is not used to train models, and is not retained once processing is complete.
- Ticket OCR: when you upload a photo of a purchase receipt, the image is sent to OpenAI (GPT-4o Vision) to extract product lines. The image is stored in your account so you can view and delete it at any time.
5. Legal basis for processing
The legal basis for processing your data is:
- Performance of the service contract you accept when registering
- Your express consent, which you may withdraw at any time
- Compliance with applicable legal obligations (especially tax and accounting, including Veri*Factu regulations RD 1007/2023)
6. Data retention
We retain your personal data for as long as necessary to fulfill the purposes described in this policy, or while you maintain an active account. Once you delete your account, operational data (profile, clients, quotes, materials, ticket images) will be retained for 30 days in read-only mode to allow export, after which it will be securely deleted. Billing and accounting data (issued invoices) will be retained for the legally established period (5 years) to comply with tax obligations.
7. User rights
You may exercise the following rights at any time:
- Access: know what data of yours we are processing
- Rectification: request correction of inaccurate data
- Erasure: request deletion of your data
- Restriction: request restriction of processing
- Portability: receive your data in a structured format
- Objection: object to the processing of your data
To exercise these rights, send an email to support@offitia.io. You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD).
8. Security
We implement technical and organizational security measures to protect your personal data against unauthorized access, loss, or alteration. We use encryption in transit (HTTPS/TLS) and at rest in the database (Supabase). However, no system is completely secure, and we cannot guarantee absolute data security.
Security Measures for Access Data: In compliance with current regulations (Art. 32 GDPR), we implement robust technical measures to protect your access data. Passwords are stored using advanced encryption protocols. Additionally, the system incorporates active protection mechanisms, such as password complexity validation and technical limits on login attempts (rate limiting), ensuring the protection of your information by design and by default.
9. Third Parties and International Data Transfers
We may share data with essential third-party service providers required for platform operation:
- Vercel / Supabase: web hosting, SQL database, and cloud servers located within the European Union (Frankfurt, Germany)
- OpenAI LLC / Groq / Together AI: intelligent document processing and receipt OCR
- Stripe Payments Europe Ltd. / Stripe Inc.: secure payment and subscription processing
- Google Workspace / Gmail API: OAuth authentication and document transmission from the user's email account
- Microsoft Azure AD / Office 365 API: OAuth authentication and email integration
- VeriFacti.com (Verifacti SL): Veri*Factu statutory compliance, NIF validation, and invoice logs submission to the AEAT
- Functional Software, Inc. (Sentry): real-time technical error monitoring, telemetry, and platform performance tracking to guarantee service security and availability (Art. 32 GDPR). Processing in servers located in the European Union (Frankfurt, Germany) and US transfers under the Data Privacy Framework (DPF). Retention period: 30-90 days.
- Umami Software, Inc. (Umami Analytics): aggregated and anonymous measurement of traffic metrics and platform usage to optimize website performance and user experience, grounded in our legitimate interest (Art. 6.1.f GDPR). It operates without cookies (cookie-less), avoids individual profiling, and processes/stores data exclusively on servers within the European Union under a Data Processing Agreement (DPA). Users may exercise their right to object by contacting us. Learn more at umami.is/privacy.
International Transfer Safeguards & AI Zero Training Guarantee: Where US-based auxiliary providers are engaged (OpenAI, Stripe), transfers operate under the European Commission's EU-US Data Privacy Framework (DPF). Specifically for Artificial Intelligence, OFFITIA configures official enterprise APIs to guarantee that user data and documents are never used to train third-party AI models.
Google User Data Policy (Google API Services User Data Policy)
When utilizing Google OAuth authentication or integrations (such as sending invoices via Gmail API), OFFITIA accesses only basic profile information (email, name) and permissions strictly required to transmit the requested documents.
Google Limited Use Disclosure: OFFITIA's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Data obtained through Google APIs is never used to train Artificial Intelligence (AI) models, is never shared with third parties for advertising, and is not retained beyond what is required to execute user-requested tasks.
10. Account Deletion, Right to be Forgotten, and Data Retention
In compliance with the General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD), you may request account deletion at any time.
How to request deletion
- From the platform: Go to Settings → Delete account in your dashboard. The process is immediate without requiring manual verification.
- By email: Send a message to support@offitia.io from your registered email address. We will process your request within 10 business days.
Two-Phase Post-Contractual Protocol
- Immediate cancellation of any active Stripe subscription.
- Phase 1 (Portability - 30 Calendar Days): Your account remains in read-only and download mode so you can log in and export your complete history (clients, quotes, invoices, materials, and fiscal year-end ZIP packages) pursuant to Art. 20 GDPR and National Court jurisprudence (SAN 706:2025).
- Phase 2 (Legal Data Blocking - 5 Years): After 30 days, user login access is disabled. In compliance with statutory tax and invoicing requirements under the Spanish General Tax Law and Veri*Factu (RD 1007/2023), tax records and issued invoices will remain duly blocked pursuant to Art. 32 LOPDGDD and Resolution 33/2026. Any exceptional access prompted by a formal AEAT or judicial authority order will be recorded in an immutable traceability Audit Log with timestamp and legal justification.
Legal blocking consists of identifying and reserving encrypted data to prevent ordinary or commercial processing, remaining available exclusively to the Tax Agency (AEAT), judges, and courts to address potential liabilities during statutory limitation periods. Following the 5-year statutory period, data is permanently and securely destroyed.
11. Changes to this policy
We reserve the right to modify this policy to adapt to legislative changes or platform updates. We will notify you of significant changes through the website or by email.