Skip to content
VerifactuCloud
Billing App Partner API Regulation Pricing Status API docs Facturas app Dashboard partners
Español English

Privacy policy

Draft pending legal review. Not to be treated as final.

Data controller

CONSULTORIA SEPULVEDA LACHMANN S.L.UNIPERSONAL — CIF B75670182, Calle Azul 2, 03170 Rojales (Alicante), España. hola@verifactucloud.com

What data this website processes

The public pages of this website are static: they carry no forms, no analytics and no trackers. If you email us, we process your address and the content of your message solely in order to reply, on the basis of our legitimate interest in answering your enquiry.

The partner dashboard

The dashboard, at /dashboard, does carry forms. When you create an account we process your company name, your email address and a password. The password itself is not stored: what is kept is an argon2id digest of it, which cannot be reversed. The legal basis is performance of the contract, or the pre-contractual steps you have asked for (GDPR art. 6.1.b).

If you register obligados, we process their NIF and registered name on your behalf: for that data you are the controller and we are the processor.

The dashboard uses a single session cookie, technical and necessary, described in the cookie policy. The public pages never receive it.

The authorisation to file on your behalf

Before we submit records on a taxpayer's behalf we need their express authorisation before the tax agency: the modelo de otorgamiento de la representación required by the Convenio de Colaboración Social. We keep it because we are the party the tax agency would ask for it.

For this particular processing we are the controller, not you. It is the exception to what is said above: invoicing data we process on the taxpayer's behalf, but the authorisation we keep because the agreement we signed obliges us to, and that obligation is ours.

What we keep from that authorisation

  • The exact text that was accepted, its version and its hash, so it can be compared against the current model.
  • The email address of whoever granted it, and the date and time they did.
  • The IP address and browser it was granted from, as corroboration. Deleted after four years.
  • The signed document, whether signed electronically or printed, signed by hand and scanned.
  • A copy of the signer's identity document — DNI, NIE or passport — only if they sign on paper: when signing with a certificate, the certificate already identifies them and we do not ask for it. Deleted after four years.

The purpose is set by the tax agency's own model: “the application of the tax and customs system”. The legal basis is compliance with a legal obligation (GDPR art. 6.1.c). The model also obliges us to give you this information, which is why this section exists.

We keep the authorisation for as long as it may be demanded of us: it is the evidence the tax agency can require, and the model puts no date on that requirement, so we set no period and would rather say so than invent one. What accompanies it does have one. The IP address, the browser and the copy of the identity document delete themselves four years after the authorisation was granted: that is the limitation period in article 66 of the Ley General Tributaria, after which the assessment they would help defend can no longer be raised. The signed document, the text that was accepted, the date and the email of whoever granted it stay.

The authorisation is deleted when somebody deletes it, and you can ask for that by exercising your right to erasure. The database refuses a deletion unless it is asked for explicitly in that same operation: a defence against accidentally erasing every authorisation at once, never against your request. Changing one is not possible at all — a correction is a new authorisation, not an edit of the old one.

This authorisation is not sent anywhere. The model says so expressly: it is produced to the tax administration only when the administration asks for it.

If the signer is not you — the company's administrator, say — this information is addressed to that person too, even though they have no account with us, and they can exercise their rights by writing to the address above.

Processors and sub-processors

To run the service we use two providers that may process personal data on our behalf, both as sub-processors and under a data processing agreement:

  • Cloudflare — website delivery and encrypted backups (Cloudflare R2). The transfer relies on their processing agreement and the standard contractual clauses.
  • Scaleway (France) — sending all of our email: the verification message for partner accounts, and the internal report generated when an authorisation is completed. That report carries the signed document as an attachment, and the copy of the identity document where there is one. The data does not leave the European Union.

Everything else stays on our own hardware, in Rojales (Alicante).

The deletion periods on this page describe the database. The encrypted backups are kept for 90 days and rotate on their own, so a deleted item can remain in them for up to 90 days longer. They are not read except to restore the service.

Your rights

You may exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to the email address above. You may also lodge a complaint with the Spanish Data Protection Agency.

CONSULTORIA SEPULVEDA LACHMANN S.L.UNIPERSONAL — CIF B75670182
Calle Azul 2, 03170 Rojales (Alicante), España
Inscrita en el Registro Mercantil de Alicante
hola@verifactucloud.com

VerifactuCloud is not affiliated with or endorsed by the Agencia Estatal de Administración Tributaria. References to VERI*FACTU and to the AEAT refer to the relevant regulation and public body.

This page contains general information about Spanish invoicing regulation, not tax or legal advice.

Legal notice Privacy Cookies