comp1ex studios

Privacy Policy

Last updated: March 2026

1. Data controller

The data controller for your personal data is comp1ex studios (hereinafter, "the Controller"), with registered address in Spain.

Contact email: comp1exstudio@gmail.com

The Controller processes your data in accordance with Regulation (EU) 2016/679 General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018, of December 5, on Personal Data Protection and Digital Rights Guarantee (LOPD-GDD).

2. Personal data we collect

Identification data: name, surname, tax ID (DNI/NIE/CIF), company name.

Contact data: email address, phone number, postal address.

Access data: email and password (encrypted) for dashboard access.

Billing data: tax information required for invoice issuance under Spanish regulations (Royal Decree 1619/2012 and Royal Decree 1007/2023).

Usage data: activity logs within the platform, IP address, browser type, pages visited and usage patterns for analytical purposes.

3. Purpose and legal basis

Contractual performance (Art. 6.1.b GDPR): manage your account, provide contracted services (POSRetail, POS, QR Web, Commander, Kiosk, KDS), process orders and issue invoices.

Legal obligation (Art. 6.1.c GDPR): comply with tax and accounting obligations, including generating invoicing records under the VeriFactu system (Royal Decree 1007/2023) and communication with the Spanish Tax Agency (AEAT).

Legitimate interest (Art. 6.1.f GDPR): improve our services, perform anonymized statistical analysis and prevent fraud.

Consent (Art. 6.1.a GDPR): sending commercial communications about our products and services, always revocable.

4. Data retention period

Data will be retained while the contractual relationship is maintained. After termination, data will be blocked during the applicable legal limitation periods.

Invoicing records will be kept for a minimum of 4 years in accordance with Article 29.2.e) of the General Tax Law (Law 58/2003) and Article 25 of Royal Decree 1007/2023.

VeriFactu system records and the invoice chaining will be preserved in their entirety and unaltered throughout the legally required period.

5. Data recipients

Supabase Inc. (data processor): database hosting in the EU region (eu-west-3). Operates under Standard Contractual Clauses (SCCs) for international transfers.

Spanish Tax Agency (AEAT): communication of invoicing records in compliance with the VeriFactu system when the licensee has enabled automatic submission.

Vercel Inc.: web application hosting. Data processed under their Data Processing Agreement.

Data will not be shared with third parties except when legally required or with the express consent of the user.

6. Data subject rights

In accordance with Articles 15 to 22 of the GDPR and Articles 12 to 18 of the LOPD-GDD, you have the right to:

Access: obtain confirmation of whether your data is being processed and access it.

Rectification: request the correction of inaccurate or incomplete data.

Erasure: request the deletion of your data when it is no longer necessary for the purpose for which it was collected.

Restriction: request the restriction of processing in certain circumstances.

Portability: receive your data in a structured, commonly used and machine-readable format.

Objection: object to the processing of your data on grounds relating to your particular situation.

7. Exercising your rights

To exercise any of these rights, contact comp1exstudio@gmail.com with a copy of your identity document. Your request will be addressed within a maximum of one month.

If you believe the processing of your data violates regulations, you may file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.

8. Security measures

We implement appropriate technical and organizational measures to ensure the security of your data, including encryption in transit (TLS) and at rest, role-based access control (RBAC), Row Level Security (RLS) at the database level and audit logs.

The invoicing system implements integrity controls through cryptographic chaining (hash) of records as established in Royal Decree 1007/2023.

9. International transfers

Data may be transferred to providers located outside the European Economic Area (EEA) when they have the appropriate safeguards provided for in Chapter V of the GDPR, such as Standard Contractual Clauses approved by the European Commission.

In particular, Supabase Inc. and Vercel Inc. (United States) operate under Standard Contractual Clauses (SCCs) that guarantee an adequate level of data protection.

10. Modifications

The Controller reserves the right to modify this policy to adapt it to legislative or jurisprudential developments. Any changes will be notified to registered users by email.

The current version will always be available on this page.