Introduction
Welcome to TaxFactory. We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your information when you use our website or request our advisory services.
This policy applies to people who visit the TaxFactory website, contact our team, or use our tax, accounting, employment, legal, or financial advisory services.
Data Controller
The data controller responsible for your personal data is:
TAX FACTORY S.L.
Email: cuentanos@taxfactory.es
For any questions regarding your personal data, please contact us at the email address above.
Data We Collect
We collect the following categories of personal data:
Contact and Client Information
- Name and contact details you provide
- Business, freelancer, or company information
- Preferred contact channel
- Service needs or consultation details
- Information needed to assess your request
Website and Service Interaction Data
- Contact form submissions and service requests
- Messages, emails, or consultation notes you send us
- Website usage data needed for security and improvement
- Pages or resources you interact with
- Communication history related to your request
- Documents or information you choose to share
Preferences
- Service interests and communication preferences
- Language preference
- Scheduling or contact preferences
Technical Data
- Browser and device information
- IP address and approximate location data
- Security and diagnostic logs
Billing and Service Data
When you become a client, we may process billing, invoicing, and service records needed to provide the agreed advisory services and comply with legal obligations.
How We Use Your Data
We use your personal data for the following purposes:
- To provide and maintain the TaxFactory service
- To respond to your enquiries and prepare advisory proposals
- To manage tax, accounting, employment, legal, or financial work
- To keep records required for service delivery and compliance
- To send service communications when appropriate
- To improve our website, processes, and client support
- To coordinate with service providers when needed for your request
Legal Basis for Processing
Under GDPR, we process your data based on the following legal grounds:
Consent
For optional communications or processing activities that require your permission. You can withdraw consent at any time.
Contract Performance
To respond to your requests and provide the TaxFactory advisory services you have agreed with us.
Legitimate Interest
For technical data collection necessary to keep the website secure, respond to enquiries, and improve our service.
International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). Supabase operates data centers in various locations. When data is transferred outside the EEA, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission
- Data processing agreements with all service providers
- Encryption of data in transit and at rest
Data Retention
We retain your personal data for as long as your account is active and you continue to use TaxFactory.
Upon account deletion request, we will delete or anonymize your personal data within 30 days, except where we are legally required to retain certain information.
Billing, service, and compliance records may be retained for the period required by applicable law.
Your Rights
Under GDPR, you have the following rights regarding your personal data:
Right of Access
You can request a copy of all personal data we hold about you.
Right to Rectification
You can request correction of inaccurate or incomplete data.
Right to Erasure
You can request deletion of your personal data ("right to be forgotten").
Right to Data Portability
You can request your data in a structured, machine-readable format.
Right to Object
You can object to processing based on legitimate interests.
Right to Withdraw Consent
Where processing is based on consent, you can withdraw it at any time.
Right to Lodge a Complaint
You have the right to lodge a complaint with your local data protection authority.
To exercise any of these rights, please contact us at cuentanos@taxfactory.es. We will respond within 30 days.
External Data and Documents
To provide advisory services, TaxFactory may need information or documents from you or from authorized third-party sources. We only request information relevant to the service.
Information We May Receive
- Tax, accounting, payroll, or legal documents you provide
- Business and identification details needed for your request
- Information from authorized providers when you ask us to coordinate with them
Records We May Create
- Consultation notes and service history
- Documents, filings, or reports prepared for your case
- Administrative records needed to manage the service
External Data Privacy
- We only process external data when it is relevant to your request or required by law
- We limit access to the team members who need it
- We do not use client documents for advertising
- You can contact us to update permissions or ask questions
AI-Assisted Features
TaxFactory may use AI-assisted tools to help organize information, draft internal materials, or improve service workflows.
When a third-party AI provider is used, we aim to limit the information shared to what is necessary for the specific workflow.
Data used with AI-assisted workflows may include:
- Information you submit in an enquiry
- Service context needed to prepare a response or document
- Questions or instructions you ask us to process
We do not use AI-assisted tools as a substitute for professional review of advisory work.
For questions about how AI-assisted processing may apply to your case, contact us at cuentanos@taxfactory.es.
Data Security
We implement appropriate technical and organizational measures to protect your personal data:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure authentication and access controls
- Regular security assessments of our infrastructure
- Limited access to personal data on a need-to-know basis
- Supabase's enterprise-grade security infrastructure
Children's Privacy
TaxFactory is designed for users aged 16 and older. We do not knowingly collect personal data from children under 16. If we discover that we have collected data from a child under 16, we will delete it promptly.
If you believe a child has provided us with personal data, please contact us at cuentanos@taxfactory.es.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will notify you through appropriate means.
We encourage you to review this policy periodically. The "Last updated" date at the top indicates when the policy was last revised.
Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
Email: cuentanos@taxfactory.es
We will respond to your request within 30 days, as required by GDPR.