Privacy policy · version 2026-09
What we do with the data, keeping yours apart from your customers'
There are two kinds of data and they cannot be mixed: the data you give us when you sign up, which we answer for; and your customers' data, which you answer for and which we only handle on your instructions. This policy keeps them apart because the law does too — Regulation (EU) 2016/679 (GDPR) and Spanish Act 3/2018 (LOPDGDD, the Spanish data protection act).
1. Controller
Flexibles y Accesorios Gobe, S.L. · Tax ID (CIF) B56727993
Calle Roger de Llúria, 54, Principal 1ª B, 08009 Barcelona, Spain
Registered at the Registro Mercantil de Barcelona (Barcelona companies register), Volume 49059, Folio 216, Sheet B-606144
Email: comercial@flexigobe.com · Phone: +34 616 809 504
“Operaria” and “FlexigoTech” are trading names of this company. The company that invoices you, that answers for your data and that you complain to is always the same one: the one above.
We are not required to appoint a data protection officer. For anything to do with your data, write to the address above with “Data” in the subject line.
2. Your data: the data of whoever uses the site and signs up
| What | What for | Legal basis | How long |
|---|---|---|---|
| What you write when you tell us about your process: business name, sector, figures, your name, email and phone number | Preparing your process spec and getting back to you | Pre-contractual steps at your request (Art. 6(1)(b)) | Up to 12 months if you do not sign up; you can ask us to delete it sooner |
| Your email, your name and your billing details | Providing the service, charging for it and meeting Spanish tax obligations | Performance of the contract (6(1)(b)) and legal obligation (6(1)(c)) | For as long as the contract lasts and the tax retention periods (up to 6 years for invoices) |
| What you accepted, with version, date and IP address | Being able to prove that you accepted it (Art. 5(2) and 7(1)) | Legal obligation (6(1)(c)) | For as long as the contract lasts, plus 5 years |
| Emails we send you and whether they arrived | Knowing that we told you when we had to tell you | Legitimate interest (6(1)(f)) | 12 months |
We do not use your data for third-party advertising and we do not sell it. We write to you about what is happening with your service; if we ever wanted to send you anything else, we would ask you first.
3. Your customers' data: you answer for it, we carry it out
When your process reads your calendar or writes to your customers, it handles the data of people who are your customers. For that data you are the controller and we are the processor (Article 28). When you sign up you accept the processing agreement, which in short says:
- We handle that data only to run your processes and only on your instructions (the spec you approve).
- We do not use it for anything of ours, we do not pass it on and we do not sell it.
- We do not handle health data or other special categories. If your process needed them, we would not build it.
- We respect opt-outs: anyone who asks you not to be messaged again is not messaged again. It is your obligation and we meet it for you.
- We store it encrypted, on servers in the European Union, with restricted access.
- We tell you without delay if we detect a breach, and we help you deal with the rights your customers exercise against you.
- When you leave, we delete it after 30 days, or sooner if you ask, and we give you back whatever is yours.
- We only use the sub-processors listed below, and we will tell you if that changes.
4. Who else is involved
| Who | What for | Where |
|---|---|---|
| netcup GmbH | The server everything lives on | Germany |
| Brevo (Sendinblue SAS) | Sending the service emails | France |
| Stripe Payments Europe | Taking the fee; it never sees your customers' data | Ireland, as a controller in its own right |
| Your calendar or your spreadsheet, which you share with our address. The data stays in your Google account, under your contract with Google | Depends on your account; Google relies on the EU-US Data Privacy Framework | |
| Meta (WhatsApp Business) | Messages go out through your WhatsApp Business account, under your contract with Meta | Depends on your account; Meta relies on the EU-US Data Privacy Framework |
| Anthropic | Only when we write your spec from what you tell us. It never sees your customers' data and plays no part in running the process | United States, under standard contractual clauses |
5. Artificial intelligence, put plainly
The day-to-day processes, the automatic repairs and the reports never go near a language model: they are code that always does the same thing, which is why they can be rehearsed beforehand. A model does one job only: helping us draft your spec from what you write about your business. Your customers' data is never sent to any model, and there is a check when the server starts that prevents it. Every message that goes out automatically says so, as the EU AI Act (Regulation (EU) 2024/1689) requires.
6. Cookies
This site uses no tracking or advertising cookies. Your dashboard stores a single technical cookie, the one that keeps you signed in without having to open the link again; without it the dashboard does not work, so it needs no consent.
7. Your rights
You can ask us for access, rectification, erasure, objection, restriction and portability by writing to comercial@flexigobe.com. We reply within a month. If you are not happy with the answer, you can complain to the Agencia Española de Protección de Datos (the Spanish data protection authority, aepd.es).
If we change this policy, we will tell you by email before it affects you. The version you accepted is kept on file with its date.