Privacy and Data Protection Policy

Version 2.4 · Last updated: August 2026 · Versión en español

This English translation is provided for convenience. In case of any discrepancy, the Spanish version at /legal/privacy prevails.

1. Data controller

The controller of the personal data collected through the Embiral platform (the "Service") is EMBIRAL SOLUTIONS, S.L. ("Embiral"), Spanish tax ID (NIF) B93774693, registered office at Calle Juan de Juanes 8, Esc. Der., 3.º D, 28933 Móstoles, Madrid (Spain). For any question about this Policy or your rights, write to privacidad@embiral.com.

Embiral has carried out the assessment required by Article 37 GDPR and concluded that, in its current configuration, it is not required to appoint a Data Protection Officer (DPO), since the processing does not meet any of the conditions of Art. 37.1 GDPR. If that assessment changes, the DPO's name and contact details will be published on this page.

2. Categories of data we process

3. Purposes and legal bases

4. Retention periods

5. Processors and sub-processors

To provide the Service, Embiral relies on technology providers acting as processors under Article 28 GDPR, subject to a data processing agreement or to the standard clauses published by those providers. The current ones are, subject to reasonable updates:

The list above is kept up to date on this page. Embiral will give reasonable advance notice of any relevant new sub-processor, offering the User the possibility to object on legitimate grounds.

6. International transfers

Some of the above providers may process data outside the European Economic Area. In those cases, Embiral ensures an adequate level of protection through (i) European Commission adequacy decisions, (ii) the Standard Contractual Clauses (SCC) adopted by the Commission (available on the European Commission's website) or (iii) any other valid mechanism under Articles 44 et seq. GDPR. You may request a copy of the safeguards at privacidad@embiral.com.

7. Automated decisions and artificial intelligence

The Service uses language models to extract metadata, answer in chatbots and draft reports. These functions are automated assistance: they produce suggestions or drafts that the User reviews and validates. No automated decisions with legal effects on the User, or that similarly significantly affect them within the meaning of Article 22 GDPR, are taken through the Service.

Pursuant to Article 13.2.f GDPR, the logic of the automated processing is based on: (i) semantic vectorisation of the User Content to enable similarity search; (ii) answer generation by large language models (LLMs) that receive as context fragments of the User Content automatically selected by relevance; and (iii) metadata extraction through automatic classification. These operations may produce inaccurate or biased results, whose review is the User's responsibility.

The Service's language model provider is OpenAI (through its API platform, whose terms exclude the use of inputs to train its models). The specific models are determined by Embiral as operator of the Service; Users cannot connect their own AI providers. Model outputs may be inaccurate; the responsibility to review them lies with the User, as developed in the Terms and Conditions.

7 bis. Limited Use of Google API data

Embiral's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, user data obtained through Google Workspace APIs — raw, aggregated, anonymised or derived — is not used, transferred or sold to create, train or improve generalised machine learning or artificial intelligence models, whether our own or third parties'. The model providers Embiral uses are accessed exclusively through APIs whose terms exclude the use of inputs for training.

For the avoidance of doubt: Google user data is used solely to provide and improve the user-facing functionality of the Service (sync, indexing, search, preview, and the chatbots and reports requested by the User). It is never used for advertising, commercial communications, market analysis or any other purpose; the purposes in section 3 concerning metrics, personalisation or commercial communications refer exclusively to account and platform usage data, never to data obtained from Google APIs. Google user data is not transferred to third parties except to the processors strictly necessary to provide the Service (section 5), where required by law, or with the User's express consent; and no human reads it except with the User's consent, for security purposes, or to comply with a legal obligation.

8. Your rights

As a data subject, you may exercise the following rights at any time:

To exercise any of these rights, use the rights request form or write to privacidad@embiral.com stating the right you wish to exercise and attaching, where necessary, documentation proving your identity. We will handle the request within the legal deadlines (one month, extendable by two more in complex cases). If you consider the processing does not comply with the law, you may lodge a complaint with the Spanish Data Protection Agency (aepd.es).

9. Security measures

Embiral applies technical and organisational measures reasonable and proportionate to the risk, including without limitation:

Despite these measures, no platform is absolutely invulnerable. If a security breach affecting personal data is detected, Embiral will notify the Spanish Data Protection Agency within 72 hours and, where applicable, inform the affected individuals, in accordance with Articles 33 and 34 GDPR.

10. Minors

The Service is not directed at minors under 14 or under the minimum age required in their jurisdiction. Embiral does not knowingly collect or process personal data of minors below that age. If we become aware that data of a minor has been collected without the required authorisation, we will delete it without delay.

11. Cookies and similar technologies

The Service uses cookies and local-storage technologies strictly necessary for operation (session, theme preferences, persistence of the connection form during OAuth) and, where applicable, aggregated analytics that are technically anonymous and irreversible at the individual level (Vercel Analytics), based on legitimate interest. Embiral has verified that the Vercel Analytics configuration does not allow individuals to be identified or cross-site tracking, which permits its use without prior consent under EDPB and AEPD criteria; should that configuration change, a prior-consent mechanism will be implemented. No advertising or cross-site tracking cookies are used.

12. Changes to this Policy

Embiral may update this Policy to reflect legal changes or Service improvements. Any substantive change will be notified by email and/or within the Service at least thirty (30) days in advance, unless imposed by mandatory law. Where a change materially affects the legal basis, purpose or categories of data processed, Embiral may require the User's active acceptance or, failing that, offer the possibility to close the account before the change takes effect. The version and date of the last update appear at the top of this document.

13. Contact

For any question about this Policy, write to privacidad@embiral.com or use the contact form available in the Service's sidebar.