Privacy policy
Translation. This text is a translation provided for convenience. The Spanish version is the authoritative one and prevails in case of any discrepancy (https://atrazos.app/privacidad?lang=es)
This policy explains what personal data is processed in A Trazos (the app for workshops and the website https://atrazos.app), who decides about it, what it is used for and how you can exercise your rights, in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR) and Ley Orgánica 3/2018 de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD, the Spanish data protection act).
1. Who the controller is
| Item | Details |
|---|---|
| Controller | [TITULAR: nombre y apellidos o razón social] |
| Tax ID (NIF) | [NIF] |
| Address | [DOMICILIO] |
| Privacy contact | privacidad@atrazos.app |
We have not appointed a data protection officer because our activity does not require one (article 37 of the GDPR and article 34 of the LOPDGDD). For any privacy matter, write to privacidad@atrazos.app.
2. Two different roles: controller and processor
There are two kinds of data in A Trazos, and the law allocates responsibilities differently in each case:
- Data of workshops and their team (the people who register in the app), of website visitors and of people who send us a notice: here we are the controller. Sections 3 and 4 explain this processing.
- Data of a workshop’s customers (what the workshop records in the app about its customers and what a customer sends from a showcase or from their order page): here the controller is the workshop, which decides for what purposes and how the data is used, and we are its processor (article 28 of the GDPR). We process this data only to provide the service to the workshop and following its instructions, under the data processing agreement that forms part of the Terms and conditions (https://atrazos.app/terminos). Section 5 explains this.
If you are a customer of a workshop, send your questions about your order and your requests to exercise your rights to the workshop: its contact details are in its showcase or in its terms. If you write to us, we will pass your request on to the workshop and help it to reply to you.
3. Data of workshops and their team
| Data | What for | Legal basis |
|---|---|---|
| First name and surname, email address, password (stored encrypted by our authentication provider), language and, if you add them, phone number and profile photo | To create and manage your account and your team’s accounts | Performance of the contract (art. 6(1)(b) GDPR) |
| Identifier and email address that Apple or Google give us if you sign in with them | To sign in | Performance of the contract (art. 6(1)(b)) |
| Date of birth and country of residence | To check the minimum age and to know which data protection authority is competent for you | Performance of the contract and legal obligation (art. 6(1)(b) and 6(1)(c)) |
| Workshop data: name, showcase address, contact details, catalogue, prices, capacity, terms, photos and orders | To provide the service | Performance of the contract (art. 6(1)(b)) |
| Acceptances and consents: which version you accepted, when and from which device | To be able to prove that you accepted the terms and what you consented to | Legal obligation (art. 6(1)(c) and art. 7(1) GDPR) |
| The device’s notification token | To send you alerts about your orders, if you allow them | Performance of the contract (art. 6(1)(b)) |
| Technical error reports from the app (without your name or your email address) | To detect and fix faults | Legitimate interest in the service working properly (art. 6(1)(f)) |
| Suggestions and reports you send from the app, with their attachments | To deal with them and improve the service | Legitimate interest (art. 6(1)(f)) |
| Your name in the release notes, if you give us permission | To thank you publicly for your suggestion | Consent (art. 6(1)(a)), which can be withdrawn |
| Commercial communications | To tell you about what is new in A Trazos | Consent (art. 6(1)(a)), which can be withdrawn at any time |
| Notices about your content, our decisions and the reasons for them | To comply with the Digital Services Act and to defend ourselves against claims | Legal obligation (art. 6(1)(c)) and legitimate interest (art. 6(1)(f)) |
If your workshop is a sole trader business (autónomo), some of the workshop’s data is also your personal data; we process it in the same way.
4. Data of website visitors and of people who send a notice
Visiting the website. The website does not use its own cookies, analytics, advertising or trackers. To serve you the pages and protect them against attacks, our web delivery and security provider processes your IP address and technical data about your browser. The photos in the showcases are loaded from the storage of our hosting provider. Legal basis: legitimate interest in providing and protecting the website (art. 6(1)(f)). The Cookie policy (https://atrazos.app/cookies) explains what is stored in your browser.
Sending a request from a showcase. The data you enter goes to the workshop, which is the controller (section 5). To prevent automated submissions and abuse, in addition: the form runs a security check by our web security provider, which uses technical data about your browser and your IP address to check that you are not a robot; and we store your IP address only after transforming it into an irreversible code, which we use to limit the number of submissions. Legal basis: legitimate interest in protecting the service and the workshops against abuse (art. 6(1)(f)).
Sending a notice of illegal content (https://atrazos.app/denunciar). We process what you send us (the address of the content, your explanation, your name and your email address, which you may leave out if the notice concerns child sexual abuse, and your statement of good faith) and your IP address transformed into an irreversible code, in order to handle the notice, take a decision and tell you about it. The form uses the same security check as the request form. Legal basis: legal obligation (art. 16 of Regulation (EU) 2022/2065, in conjunction with art. 6(1)(c) GDPR) and legitimate interest in keeping the service free of illegal content (art. 6(1)(f)). We do not disclose your identity to the workshop concerned, unless it is strictly necessary (for example, in an intellectual property claim that requires knowing who the rights holder is) and, in that case, we will tell you beforehand.
Writing to us by email. We use your data to reply to you. Legal basis: legitimate interest (art. 6(1)(f)) or, if you are exercising a right, legal obligation (art. 6(1)(c)).
5. Data of workshops’ customers (we are the processor)
A workshop’s customers do not register or install anything: they use the website. When a customer sends a request from a showcase, confirms an order, approves a design or leaves their delivery address on their order page, and when the workshop records an order in the app, the following data may be processed: name, phone number, Instagram or other social network username, email address, province or region, delivery address, the date by which the order is needed, comments, order details, designs and photos of the pieces, payments recorded by the workshop and acceptance of its terms.
The workshop decides what the data is used for (normally, to answer the request, prepare and deliver the order and meet its legal obligations) and must inform its customers. We store the data, display it on the workshop’s pages and on the order pages, notify the workshop of what its customer does and, when the workshop uses the artificial intelligence features, process the data for that purpose. We do not use it for our own purposes: we do not sell it, we do not use it for advertising and we do not create profiles. We only process on our own account what is strictly necessary to protect the service against abuse (section 4) and to comply with the law, for example if some content is the subject of a notice.
The link to each order page is personal: anyone who has it can access the order. Do not share it.
6. Who we share data with
We do not sell data to anyone. We rely on providers in the categories below, which process data on our behalf (and, with regard to customers’ data, as sub-processors of the workshop) under a data processing agreement. If you want to know which specific companies they are, ask us at privacidad@atrazos.app.
| Type of provider | What for | Where and with what safeguards |
|---|---|---|
| Hosting and data storage | Storing the service’s data and photos, and managing accounts and sign-in | Servers in the European Union; US company (standard contractual clauses) |
| Content delivery network and web security | Serving the website, protecting it against attacks and abuse (including checking that you are not a robot) and resizing images | Global network; EU-US Data Privacy Framework and standard contractual clauses |
| Artificial intelligence | Artificial intelligence features: summaries, suggested replies and search in the order history | US; EU-US Data Privacy Framework and standard contractual clauses |
| Notifications and app updates | Delivery of notifications to the phone and app updates | US; standard contractual clauses |
| Apple and Google | Sign in with Apple or Google (if you choose it) and delivery of notifications | Under their own terms; EU-US Data Privacy Framework |
| Error monitoring | Technical error reports from the app | US; EU-US Data Privacy Framework and standard contractual clauses |
| Internal support tools | Internal technical alerts when something fails, and management of the suggestions and bug reports you send from the app | US; EU-US Data Privacy Framework |
We send the artificial intelligence provider only what is necessary for the feature the workshop is using. Under its contractual terms for businesses, that provider does not use the data we send it to train its models.
We will also disclose data to judges, prosecutors, law enforcement and authorities when a law or an order requires us to.
WhatsApp receives nothing from us: when you tap a WhatsApp button, it is you who opens the conversation, and Meta processes that data under its own terms.
7. Transfers outside the European Economic Area
Some providers are in the United States or may access the data from there. In those cases the transfer is based on the European Commission’s adequacy decision on the EU-US Data Privacy Framework (Decision (EU) 2023/1795), where the provider has signed up to it, or on the standard contractual clauses approved by the Commission (Decision (EU) 2021/914). You can ask us for a copy of these safeguards, and for the identity of the providers, at privacidad@atrazos.app.
8. How long we keep data
| Data | Period |
|---|---|
| Workshop account and its data | For as long as the account is active. If you ask for it to be deleted, we deactivate it and delete it after 30 days (during that period you can change your mind by signing in again) |
| Data of a workshop’s customers | As long as the workshop decides while its account is active (it can delete or anonymise a customer from the app); when the account is closed, the data is deleted with it |
| Requests sent from a showcase | For as long as the workshop needs them to manage the request and the order; they are deleted when the workshop’s account is closed |
| Record of acceptances and consents | For as long as the account exists and, after that, until the limitation period expires for any legal actions in which it might be needed as evidence |
| Content notices and moderation decisions | For as long as needed to handle them and deal with any complaints, and for no more than three years |
| Error reports and providers’ technical logs | Each provider’s retention periods, normally a few weeks |
Where a law requires us to keep some data for longer, we will keep it blocked (available only to judges and authorities) until that period ends (article 32 of the LOPDGDD).
9. Your rights
You can ask us for access to your data, its rectification or erasure, restriction of processing, portability of the data you gave us, and you can object to processing based on legitimate interest. If you gave your consent to something, you can withdraw it whenever you want, without this affecting what has already been done.
- In the app you can correct your data and delete your account.
- For everything else, write to privacidad@atrazos.app stating which right you are exercising. If we cannot tell that the request comes from you, we will ask you to prove it.
- We will reply within one month, which may be extended by two further months in complex cases, and we will let you know if that happens.
If you are a customer of a workshop, exercise your rights with the workshop; we will help it to deal with them.
If you believe we have not handled your data properly, you can lodge a complaint with the Agencia Española de Protección de Datos, the Spanish data protection authority (https://www.aepd.es) or with the authority of your country of residence (Agencia Española de Protección de Datos (AEPD), www.aepd.es).
The heirs of a deceased person, or people linked to them, may request access to, rectification or erasure of that person’s data under the terms of article 3 of the LOPDGDD.
10. Minimum age
A Trazos is a professional tool. To open a workshop account you must be of legal age. People whom a workshop invites to its team must be at least the minimum age their country requires to consent on their own to the processing of their data (14 in Spain), which the app checks at registration. We do not knowingly process data of minors below that age; if we find any, we delete it.
11. Automated decisions and artificial intelligence
We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (article 22 of the GDPR). The artificial intelligence features only propose texts (a summary, a suggested reply) that a person from the workshop reviews before using them. In accordance with Regulation (EU) 2024/1689 (Artificial Intelligence Act), we tell you which content is generated by artificial intelligence.
Notices of illegal content are always reviewed by a person; we do not use automated means to decide on them.
12. Security
All communications are encrypted. Each workshop can access only its own data. We apply access control, backups and other technical and organisational measures appropriate to the risk. Order pages can only be opened with a secret link. If a security breach occurred that put your data at risk, we would notify the supervisory authority and, where appropriate, the people affected, in accordance with articles 33 and 34 of the GDPR.
13. Changes to this policy
If we change this policy, we will publish the new version here and in the app. If the change is significant, we will let you know in the app before it takes effect and, where necessary, we will ask you to accept it again.