1. Data Controller
Sübelo (hereinafter, "the Controller") is responsible for the processing of personal data collected through this website and our services.
DPO Contact: [email protected]
The identification data of the holder is available to any interested party who requests it at [email protected], in compliance with Article 10 of the LSSI.
2. Data We Collect
We collect the following personal data:
- Contact Data: name, email address
- Billing Data: payment information (processed by Gumroad Inc. as merchant of record)
- Product Data: information about the products you provide to generate files
- Technical Data: IP address, browser type, essential cookies
3. Purpose of Processing
We use your data to:
- Provide the file generation service
- Manage your account and access to the service
- Send communications related to the service
- Process payments and billing
- Improve our services through anonymous analysis
4. Legal Basis (GDPR)
The processing of your data is based on:
- Contract Execution: to provide the contracted service (Art. 6.1.b GDPR)
- Consent: for marketing communications (Art. 6.1.a GDPR)
- Legitimate Interest: to improve our services (Art. 6.1.f GDPR)
- Legal Obligation: to comply with tax requirements (Art. 6.1.c GDPR)
5. Data Retention
We retain your data for:
- Account Data: as long as you maintain the relationship with us
- Billing Data: 6 years (legal obligation, art. 30 Commercial Code)
- Product Data: 1 year after service cancellation
6. Your Rights (GDPR)
As a user, you have the right to:
- Access: request a copy of your data (Art. 15)
- Rectification: correct inaccurate data (Art. 16)
- Erasure: "right to be forgotten" (Art. 17)
- Objection: to processing based on legitimate interest (Art. 21)
- Portability: receive data in a structured format (Art. 20)
- Restriction: restrict processing (Art. 18)
To exercise these rights, contact: [email protected]
7. Security
We implement technical and organizational security measures:
- TLS 1.3 encryption for data in transit
- Storage on EU servers (AWS eu-west-1)
- Restricted access to authorized personnel
- Periodic security audits
- Daily backups
8. Third Parties (Data Processors)
We share data with:
- Gumroad Inc. (USA): payment processing as merchant of record. International transfer covered by the EU-U.S. Privacy Shield. https://gumroad.com/privacy
- Google LLC (USA) — Google Forms and Google Sheets: temporary receipt and storage of order data sent by customers. EU-U.S. Privacy Shield. https://policies.google.com/privacy
- Notion: storage of generated files
- AWS: hosting and infrastructure (eu-west-1)
- Cloudflare: CDN and security
All processors comply with the GDPR and have their DPAs (Data Processing Agreements) signed.
9. Cookies
We only use essential cookies for the functioning of the site. We do not use third-party cookies for advertising or tracking.
See full policy: Cookie Policy
10. Changes to this Policy
We may update this policy occasionally. We will notify you of significant changes via email or notice on the website.
11. Supervisory Authority
If you believe that the processing of your data infringes the GDPR, you can file a complaint with the Spanish Data Protection Agency (AEPD): www.aepd.es