Privacy and Data Protection Policy
Version 2.4 · Last updated: August 2026 · Versión en español
This English translation is provided for convenience. In case of any discrepancy, the Spanish version at /legal/privacy prevails.
1. Data controller
The controller of the personal data collected through the Embiral platform (the "Service") is EMBIRAL SOLUTIONS, S.L. ("Embiral"), Spanish tax ID (NIF) B93774693, registered office at Calle Juan de Juanes 8, Esc. Der., 3.º D, 28933 Móstoles, Madrid (Spain). For any question about this Policy or your rights, write to privacidad@embiral.com.
Embiral has carried out the assessment required by Article 37 GDPR and concluded that, in its current configuration, it is not required to appoint a Data Protection Officer (DPO), since the processing does not meet any of the conditions of Art. 37.1 GDPR. If that assessment changes, the DPO's name and contact details will be published on this page.
2. Categories of data we process
- Account data: name, email address, password in encrypted form (bcrypt hash) and, if you sign in with Google or Microsoft, OAuth identifiers and the public avatar provided by those providers.
- Usage data: activity logs (login, sync, queries, chatbot creation, report generation), source IP address, browser and operating system, timestamps, and account/workspace audit events.
- User Content: documents, metadata and conversations the User uploads or syncs to manage with the Service. This content is processed only to provide the Service (indexing, vectorisation, search, answer and report generation) and is never used to train our own or third-party AI models.
- Third-party provider credentials: OAuth tokens and credentials of connected storage services, stored encrypted at rest (AES-256-GCM) and used exclusively to access the User's resources at those providers.
- Billing data: on paid plans, the identification and tax data needed to issue invoices and meet accounting and tax obligations.
- Legal acceptances: version and timestamp of the acceptance of the Terms and of this Policy, as required by the accountability principle of Regulation (EU) 2016/679 (GDPR).
3. Purposes and legal bases
- Providing the Service (account creation and management, storage sync, indexing, search, chatbots, reports): performance of a contract (Art. 6.1.b GDPR).
- Operational communications (email verification, password recovery, security notices, substantial changes to these legal texts): performance of a contract and legal obligation (Art. 6.1.b and 6.1.c GDPR).
- Security and fraud prevention (auditing, abuse detection, rate limiting, credential encryption): Embiral's legitimate interest in protecting the Service and its users (Art. 6.1.f GDPR).
- Compliance with legal obligations (accounting, tax, requests from competent authorities): legal obligation (Art. 6.1.c GDPR).
- Service improvement through aggregated, anonymous metrics (visit and performance analytics): legitimate interest, without the analytics allowing individuals to be identified.
- Experience personalisation (adapting features to the User's usage behaviour, where applicable): Embiral's legitimate interest, provided the User's rights and interests do not prevail (Art. 6.1.f GDPR). The User may object to this processing at any time as described in section 8.
- Non-operational commercial communications (if offered): will require prior, express consent, revocable at any time via the link included in each communication.
4. Retention periods
- Account data and User Content: while the account is active. After deletion, data is erased or anonymised within a maximum of thirty (30) days, except in automated backups, where erasure completes on the next scheduled rotation cycle, and except as indicated below.
- Audit logs: up to twenty-four (24) months from the event, for security and incident resolution.
- Accounting and tax data: for the applicable legal periods (generally up to six (6) years under the Spanish Commercial Code).
- Legal acceptances (Terms and Policy): for the duration of the contractual relationship and up to four (4) more years, to evidence compliance.
5. Processors and sub-processors
To provide the Service, Embiral relies on technology providers acting as processors under Article 28 GDPR, subject to a data processing agreement or to the standard clauses published by those providers. The current ones are, subject to reasonable updates:
- Vercel Inc. (hosting and CDN, USA/EU) — Privacy policy: vercel.com/legal/privacy-policy.
- Neon Inc. (managed PostgreSQL database) — Privacy policy: neon.tech/privacy-policy.
- Resend, Inc. (transactional email) — Privacy policy: resend.com/legal/privacy-policy.
- OpenAI, L.L.C. (language models, when the User uses them in their workspace; OpenAI states that API inputs are not used to train its models) — Privacy policy: openai.com/policies/privacy-policy.
- Storage providers connected by the User (Google LLC, Microsoft Corporation, Dropbox, Amazon Web Services, Microsoft Azure, Google Cloud), where the User Content resides and which Embiral only accesses with the credentials the User has authorised.
The list above is kept up to date on this page. Embiral will give reasonable advance notice of any relevant new sub-processor, offering the User the possibility to object on legitimate grounds.
6. International transfers
Some of the above providers may process data outside the European Economic Area. In those cases, Embiral ensures an adequate level of protection through (i) European Commission adequacy decisions, (ii) the Standard Contractual Clauses (SCC) adopted by the Commission (available on the European Commission's website) or (iii) any other valid mechanism under Articles 44 et seq. GDPR. You may request a copy of the safeguards at privacidad@embiral.com.
7. Automated decisions and artificial intelligence
The Service uses language models to extract metadata, answer in chatbots and draft reports. These functions are automated assistance: they produce suggestions or drafts that the User reviews and validates. No automated decisions with legal effects on the User, or that similarly significantly affect them within the meaning of Article 22 GDPR, are taken through the Service.
Pursuant to Article 13.2.f GDPR, the logic of the automated processing is based on: (i) semantic vectorisation of the User Content to enable similarity search; (ii) answer generation by large language models (LLMs) that receive as context fragments of the User Content automatically selected by relevance; and (iii) metadata extraction through automatic classification. These operations may produce inaccurate or biased results, whose review is the User's responsibility.
The Service's language model provider is OpenAI (through its API platform, whose terms exclude the use of inputs to train its models). The specific models are determined by Embiral as operator of the Service; Users cannot connect their own AI providers. Model outputs may be inaccurate; the responsibility to review them lies with the User, as developed in the Terms and Conditions.
7 bis. Limited Use of Google API data
Embiral's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, user data obtained through Google Workspace APIs — raw, aggregated, anonymised or derived — is not used, transferred or sold to create, train or improve generalised machine learning or artificial intelligence models, whether our own or third parties'. The model providers Embiral uses are accessed exclusively through APIs whose terms exclude the use of inputs for training.
For the avoidance of doubt: Google user data is used solely to provide and improve the user-facing functionality of the Service (sync, indexing, search, preview, and the chatbots and reports requested by the User). It is never used for advertising, commercial communications, market analysis or any other purpose; the purposes in section 3 concerning metrics, personalisation or commercial communications refer exclusively to account and platform usage data, never to data obtained from Google APIs. Google user data is not transferred to third parties except to the processors strictly necessary to provide the Service (section 5), where required by law, or with the User's express consent; and no human reads it except with the User's consent, for security purposes, or to comply with a legal obligation.
8. Your rights
As a data subject, you may exercise the following rights at any time:
- Access to your personal data and information about its processing.
- Rectification of inaccurate data.
- Erasure of data when no longer necessary or on any other legally established ground ("right to be forgotten").
- Restriction of processing in the cases of Article 18 GDPR.
- Objection to processing based on legitimate interest, save compelling grounds on our side.
- Portability of the data provided, in a structured, commonly used, machine-readable format.
- Withdrawal of consent given, without affecting the lawfulness of processing based on consent before its withdrawal.
- Not to be subject to automated decisions with legal effects (Art. 22 GDPR): as stated in section 7, the Service takes no such decisions, so this right does not apply in its current configuration. If such functions were implemented in the future, this Policy will be updated and the corresponding objection mechanism enabled.
To exercise any of these rights, use the rights request form or write to privacidad@embiral.com stating the right you wish to exercise and attaching, where necessary, documentation proving your identity. We will handle the request within the legal deadlines (one month, extendable by two more in complex cases). If you consider the processing does not comply with the law, you may lodge a complaint with the Spanish Data Protection Agency (aepd.es).
9. Security measures
Embiral applies technical and organisational measures reasonable and proportionate to the risk, including without limitation:
- Encryption in transit (TLS 1.2+) of all communications.
- Encryption at rest (AES-256-GCM) of connected-provider credentials and sensitive tokens.
- Password hashing with bcrypt and token rotation after credential changes.
- Role-based access control and resource-level permissions (RBAC).
- Application-level immutable audit logs and error monitoring.
- Rate limiting on sensitive endpoints to prevent credential abuse.
- Periodic dependency review and security patching.
- An internal security-incident management and response procedure covering identification, containment, analysis and breach notification.
Despite these measures, no platform is absolutely invulnerable. If a security breach affecting personal data is detected, Embiral will notify the Spanish Data Protection Agency within 72 hours and, where applicable, inform the affected individuals, in accordance with Articles 33 and 34 GDPR.
10. Minors
The Service is not directed at minors under 14 or under the minimum age required in their jurisdiction. Embiral does not knowingly collect or process personal data of minors below that age. If we become aware that data of a minor has been collected without the required authorisation, we will delete it without delay.
11. Cookies and similar technologies
The Service uses cookies and local-storage technologies strictly necessary for operation (session, theme preferences, persistence of the connection form during OAuth) and, where applicable, aggregated analytics that are technically anonymous and irreversible at the individual level (Vercel Analytics), based on legitimate interest. Embiral has verified that the Vercel Analytics configuration does not allow individuals to be identified or cross-site tracking, which permits its use without prior consent under EDPB and AEPD criteria; should that configuration change, a prior-consent mechanism will be implemented. No advertising or cross-site tracking cookies are used.
12. Changes to this Policy
Embiral may update this Policy to reflect legal changes or Service improvements. Any substantive change will be notified by email and/or within the Service at least thirty (30) days in advance, unless imposed by mandatory law. Where a change materially affects the legal basis, purpose or categories of data processed, Embiral may require the User's active acceptance or, failing that, offer the possibility to close the account before the change takes effect. The version and date of the last update appear at the top of this document.
13. Contact
For any question about this Policy, write to privacidad@embiral.com or use the contact form available in the Service's sidebar.