Cairos
Invoicing
Invoicing softwareQuotesRecurring invoicesExpenses and suppliersReceipts and cash flow
Accounting and tax
AccountingAEAT tax formsRecord booksFixed assetsIGIC and the Canary Islands
Operations
Inventory and warehousesCRMTime trackingProjectsGrants and funding
Compliance
VeriFactuTicketBAIElectronic invoicingAll the regulationsSecurity and data
By type of business
Self-employedSmall businessesAccountants and tax advisersForeigners in SpainStartupsRetail and shops
By sector
Hospitality and restaurantsConstruction and renovationProfessional servicesE-commerceAll sectors
By legal structure
AssociationsFoundationsCooperativesSports clubsAll legal structures
Switching software
ComparisonsAn alternative to HoldedMigrating your data
Free tools
Invoice templateVAT calculatorIRPF calculatorAll the tools
Learn
GuidesGlossaryTax calendarBlog
Developers
API and documentationGet started in five minutesResource referenceWebhooks
Help
Help centreContact
Pricing
Start for free Log in
Legal

Privacy policy

What data we process, what for, on what legal basis, how long we keep it and what you can require of us. And the distinction that is most often misread: when the controller is you.

Pending legal reviewNo invented details

Document pending legal review

This text has been drafted but it is not the final version yet. The details of the company that owns Cairos are missing — name, NIF, address and register entries — and so is a lawyer's review. The gaps you see like this are exactly that: gaps. We would rather show them than fill them with invented details. In the meantime, any question about how your data is handled is answered by writing to hola@cairos.es.

1. Who processes your data

  • Controller: [Registered company name]
  • NIF: [NIF]
  • Address: [Full registered address]
  • Contact email for data matters: hola@cairos.es
  • Data Protection Officer: [Name and contact details of the Data Protection Officer, or a note that none has been appointed because none is required]

This policy applies to the website https://cairos.es and to the management program hosted at https://erp.cairos.es.

2. Two different roles: controller and processor

It is the most important distinction in the whole document, and the one that determines who to take each thing up with.

Cairos is the controller of the data of its own users and customers: anyone who creates an account, subscribes to a plan or writes in asking for information. For that data, Cairos decides the purposes and the means.

Cairos is the processor of the data that you, as a customer, enter into the program: your customers, your suppliers, your members, your donors and your employees. You collect that data, you decide what it is used for, and you answer to the people it concerns. Cairos processes it solely on your behalf, following your instructions and only in order to provide you with the service, subject to the obligations in article 28 of the General Data Protection Regulation. The processing agreement forms part of the terms of service.

In practice: if one of your customers wants their data erased, they ask you and you do it from the program. Cairos does not erase or hand over data from your account at a third party's request.

3. What data we process and where it comes from

  • From your visit to the website: your IP address and the technical data the server records when it serves a page. This website carries no analytics, no advertising and no social media buttons that spy on you: what is stored is the server's own log.
  • From your account: name, email address, encrypted password and the details of the company you register.
  • From your subscription: your billing details and payment history. Cairos does not store card details: they are handled directly by the payment gateway [Payment provider].
  • From your use of the program: the activity log — who did what and when — and the technical logs needed to provide support and detect incidents.
  • From your communications with us: the content of the emails you send us and whatever is needed to answer them.

All the data comes from you. No files are bought, no profiles are enriched from outside sources, and there is no profiling and no automated decision-making with legal effects on anyone.

4. What we process it for, and on what legal basis

This policy is governed by Regulation (EU) 2016/679 (GDPR) and by Ley Orgánica 3/2018, of 5 December, on the protection of personal data and the guarantee of digital rights. Each purpose relies on a basis under article 6 of the Regulation:

  • To give you the service you subscribed to — creating the account, storing your data, issuing your invoices, calculating your modelos. Basis: performance of the contract, article 6(1)(b).
  • To charge and invoice you for the subscription. Basis: performance of the contract and, for retaining the invoices, a legal obligation, article 6(1)(c).
  • To answer your questions and give you support. Basis: performance of the contract or, if you are not yet a customer, steps taken at your request prior to entering into a contract, article 6(1)(b).
  • To tell you about significant changes to the service, security incidents or amendments to these policies. Basis: legal obligation, article 6(1)(c), and legitimate interests, article 6(1)(f). The specific legitimate interest is keeping anyone who has subscribed to the service informed about its terms, which is something you reasonably expect of us.
  • To maintain security, prevent abuse and keep the activity log. Basis: legitimate interests, article 6(1)(f). The specific legitimate interest is protecting the integrity of the service and every user's data against improper access and fraudulent use.
  • To send you marketing communications, if you subscribe. Basis: your consent, article 6(1)(a), which you can withdraw at any time and without explanation. If you are already a customer, also article 21.2 of Ley 34/2002 for products similar to those you have already subscribed to, with the same right to object in every message.
  • To comply with requests from courts or public authorities. Basis: legal obligation, article 6(1)(c).

Where the basis is legitimate interests, you can object to the processing by explaining your particular situation, and we will consider it. We have carried out the balancing test between that interest and your rights, and we can show it to you if you ask.

Do you have to give us this data? The fields marked as required when you create an account or subscribe are necessary in order to provide you with the service: without them we cannot register you or invoice you, and there would be no contract. The rest are voluntary and there is no consequence if you do not provide them. Subscribing to marketing communications is always optional and affects nothing.

5. How long we keep it

  • Account data: for as long as the account is active. If you close it, the data is erased or anonymised except for anything that has to be kept under a legal obligation.
  • Invoicing and accounting: the periods the law sets. For reference, four years of tax limitation (article 66 of the General Tax Act) and six years for keeping commercial books and records (article 30 of the Commercial Code).
  • Support emails: for as long as is needed to resolve the query and to evidence how it was resolved.
  • Activity log and technical logs: [Log retention period].
  • Data you enter into the program: we keep it for as long as your contract lasts. When it ends, it is returned or erased as you direct, on the terms of the processing agreement.

6. Who we disclose it to

No data is sold or handed to anyone. The only third parties who access it are the providers needed for the service to work, each with a signed processing agreement:

  • Hosting and infrastructure: [Hosting provider and country]
  • Email delivery: [Email provider, once one is engaged]
  • Payment gateway: [Payment provider]
  • Other sub-processors: [Up-to-date list of sub-processors]

Data will also be disclosed to courts, tribunals or public authorities where there is a legal obligation to do so.

International transfers: the servers and the backups are inside the European Union, as explained on the security page. There is one exception that is better said than hidden: this website's typefaces are loaded from Google Fonts, and in order to serve the file Google receives your IP address and the details of the request, with possible processing in the United States. Google LLC is certified under the EU–US Data Privacy Framework, which is covered by an adequacy decision of the European Commission, and that transfer relies on our legitimate interest in serving the site in a legible typeface. If you would rather avoid it, a content blocker prevents it and the site still reads. We say so in the cookie policy as well.

If at any other point it becomes necessary to use a provider outside the European Economic Area, it will be done under an adequacy decision or with standard contractual clauses, and it will be recorded here: [Other international transfers, if there ever are any].

7. Your rights

You may at any time exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw any consent you have given, without that withdrawal affecting the lawfulness of the processing carried out beforehand.

The way to do it is to write to hola@cairos.es stating which right you are exercising. We reply within one month at most, extendable to two if the request is complex, and we may ask you to prove your identity if there is reasonable doubt about who is asking.

Some rights you can exercise yourself, directly from the program: portability is covered by the export of all your data to CSV and Excel, available in your account and with no permission needed.

If you consider that the processing does not comply with the rules, you can complain to the Agencia Española de Protección de Datos, the Spanish data protection authority and the competent supervisory authority: C/ Jorge Juan 6, 28001 Madrid, with its electronic office at www.aepd.es. We would be grateful if you told us first, but it is not a requirement and it does not affect your right to complain.

8. Security of the data

The technical and organisational measures are described in detail, shortcomings included, on the security page: servers and backups inside the European Union, a daily backup, encryption in transit, access control by user and role, and an activity log.

In the event of a personal data breach posing a risk to the rights of the people concerned, the Agencia Española de Protección de Datos will be notified within 72 hours and, where the risk is high, so will the people concerned.

9. Changes to this policy

This policy may change if the rules, the providers or the service itself change. Significant changes are notified by email to registered users with sufficient notice. The version in force is always the one published here.

Last updated: [Date of the final version].

To exercise any right or ask anything about this document: hola@cairos.es.

About the language of this document. This text is published in Spanish, Catalan, Galician, Basque and English. The translations are there so you can read it comfortably, but the Spanish version is the only one that prevails: if a translation says something different, the original governs, and you can read it at cairos.es/legal/privacidad/.

Support