Privacy Policy
Quién es responsable
The data controller for this site and the application accounts isSenda. You can write to info@senda.eus or call 623 78 81 26.
To request full tax details—the holder's name or company name, TIN and address for legal purposes—please contact us by email or telephone. We provide these details for invoices and contracts, and in response to requests from the tax authority or another authority.
Qué datos tratamos y para qué
If you subscribe to a plan
- Identification and contact details.: name, email address and telephone number. To create your account, grant you access and communicate with you. Legal basis: performance of the contract.
- Billing details: registered company name, tax identification number, tax address and country. To issue the invoice and calculate the applicable tax. Legal basis: legal obligation and performance of the contract.
- Payment details: you enter them directly into the gateway. Your card number neither passes through our servers nor is stored here.
If you use the
- Content you upload: contracts, documents and evidence, together with anything they contain. They are stored in encrypted form in your organisation's tenant. Senda and Administration staff cannot list or open them. They are used to provide the service you use: viewing and downloading them and, at your request, extracting obligations from them.
- Activity log: who does what and when, in an immutable record. It forms part of the contracted service—a compliance system without an audit trail is of no use—and also enables us to meet our obligation to demonstrate the security of processing.
- Technical session data: a first-party cookie that keeps you signed in while you work. It is essential for the application to function, so we do not ask for consent to use it. We do not use advertising cookies or third-party analytics cookies. Further details are available in the cookie policy.
Con quién se comparten
we do not sell data or disclose it to third parties for their own purposes. We rely on these providers to operate, each under a data processing agreement:
- Stripe, — collecting subscription payments and issuing invoices. It receives your billing and payment details.
- OVH — outgoing mail server. The notifications we send you are routed through it.
- Anthropic y OpenAI — analysis of contract wording to suggest obligations. We explain this separately below because it warrants more detail.
The application and database servers are located in Europe. Some of these providers are US-based, and their use may involve an international data transfer covered by the European Commission's standard contractual clauses or the applicable adequacy framework.
Lo que se envía a los sistemas de inteligencia artificial
The original remains in your tenant. Senda's administrators do not open it. If the contract is processed to suggest obligations—either when it is indexed or at your request—the text is sent to an artificial intelligence provider.
- Before the document is sent, any credentials and keys it may contain are removed, and identity documents, account numbers, card numbers and personal telephone numbers are masked.
- The rest of the contract text is sent, including the names of the companies and individuals named in the clauses. This is what enables the obligations to be identified, and there is no way to identify them without reading the document.
- The providers are contracted on terms under which the content is not used to train their models.
- It can be disabled. When the artificial intelligence feature is turned off, extraction is handled by an in-house parser that does not send anything externally. The trade-off is that it detects less and its suggestions are more limited.
Under no circumstances does a proposal generated in this way have any effect on its own.
Cuánto tiempo se conservan
- While the account remains active,, the data are retained to provide the service.
- On cancellation, the data remain available for a grace period in case you wish to retrieve them or return, after which they are deleted.
- Billing. is retained for the period required by tax and commercial law, namely six years.
- The audit log is retained for the duration of the relationship and the subsequent limitation period, precisely so that it can later serve as evidence of what happened.
Qué derechos tiene
You may request access to, rectification or erasure of your data, restriction of or objection to its processing, and data portability. Simply write to info@senda.eus, stating which right you are exercising. We will respond within one month.
If you are an employee, supplier or contact of an organisation that uses Senda, that organisation processes your data and you must contact it directly. If you write to us, we will put you in touch with that organisation.
If you believe that we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (aepd.es).
Seguridad
Each organisation's data is isolated within the database using policies that prevent queries from returning rows belonging to another organisation. This isolation is verified by automated tests whenever a change is made. Passwords are stored using one-way encryption. Traffic is encrypted in transit. The activity log is cryptographically chained, making any subsequent tampering detectable.
If a security breach occurs that poses a risk to your rights, we will inform you and notify the supervisory authority within the statutory time limits.
Last updated:28 de septiembre de 2026.