Privacy Policy
Last updated: March 2026
1. Data controller
The data controller for your personal data is comp1ex studios (hereinafter, "the Controller"), with registered address in Spain.
Contact email: comp1exstudio@gmail.com
The Controller processes your data in accordance with Regulation (EU) 2016/679 General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018, of December 5, on Personal Data Protection and Digital Rights Guarantee (LOPD-GDD).
2. Personal data we collect
Identification data: name, surname, tax ID (DNI/NIE/CIF), company name.
Contact data: email address, phone number, postal address.
Access data: email and password (encrypted) for dashboard access.
Billing data: tax information required for invoice issuance under Spanish regulations (Royal Decree 1619/2012 and Royal Decree 1007/2023).
Usage data: activity logs within the platform, IP address, browser type, pages visited and usage patterns for analytical purposes.
3. Purpose and legal basis
Contractual performance (Art. 6.1.b GDPR): manage your account, provide contracted services (POSRetail, POS, QR Web, Commander, Kiosk, KDS), process orders and issue invoices.
Legal obligation (Art. 6.1.c GDPR): comply with tax and accounting obligations, including generating invoicing records under the VeriFactu system (Royal Decree 1007/2023) and communication with the Spanish Tax Agency (AEAT).
Legitimate interest (Art. 6.1.f GDPR): improve our services, perform anonymized statistical analysis and prevent fraud.
Consent (Art. 6.1.a GDPR): sending commercial communications about our products and services, always revocable.
4. Data retention period
Data will be retained while the contractual relationship is maintained. After termination, data will be blocked during the applicable legal limitation periods.
Invoicing records will be kept for a minimum of 4 years in accordance with Article 29.2.e) of the General Tax Law (Law 58/2003) and Article 25 of Royal Decree 1007/2023.
VeriFactu system records and the invoice chaining will be preserved in their entirety and unaltered throughout the legally required period.
5. Data recipients
Supabase Inc. (data processor): database hosting in the EU region (eu-west-3). Operates under Standard Contractual Clauses (SCCs) for international transfers.
Spanish Tax Agency (AEAT): communication of invoicing records in compliance with the VeriFactu system when the licensee has enabled automatic submission.
Vercel Inc.: web application hosting. Data processed under their Data Processing Agreement.
Data will not be shared with third parties except when legally required or with the express consent of the user.
6. Data subject rights
In accordance with Articles 15 to 22 of the GDPR and Articles 12 to 18 of the LOPD-GDD, you have the right to:
Access: obtain confirmation of whether your data is being processed and access it.
Rectification: request the correction of inaccurate or incomplete data.
Erasure: request the deletion of your data when it is no longer necessary for the purpose for which it was collected.
Restriction: request the restriction of processing in certain circumstances.
Portability: receive your data in a structured, commonly used and machine-readable format.
Objection: object to the processing of your data on grounds relating to your particular situation.
7. Exercising your rights
To exercise any of these rights, contact comp1exstudio@gmail.com with a copy of your identity document. Your request will be addressed within a maximum of one month.
If you believe the processing of your data violates regulations, you may file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.
8. Security measures
We implement appropriate technical and organizational measures to ensure the security of your data, including encryption in transit (TLS) and at rest, role-based access control (RBAC), Row Level Security (RLS) at the database level and audit logs.
The invoicing system implements integrity controls through cryptographic chaining (hash) of records as established in Royal Decree 1007/2023.
9. International transfers
Data may be transferred to providers located outside the European Economic Area (EEA) when they have the appropriate safeguards provided for in Chapter V of the GDPR, such as Standard Contractual Clauses approved by the European Commission.
In particular, Supabase Inc. and Vercel Inc. (United States) operate under Standard Contractual Clauses (SCCs) that guarantee an adequate level of data protection.
10. Modifications
The Controller reserves the right to modify this policy to adapt it to legislative or jurisprudential developments. Any changes will be notified to registered users by email.
The current version will always be available on this page.
