← Back to home

Privacy Policy

Version 1 · in force since July 22, 2026

⚠️ Provisional version — under legal review. This document will be finalised before launch.

Effective date: {{EFFECTIVE_DATE}}

1. Who is responsible for your data

The data controller is {{COMPANY_LEGAL_NAME}} ({{COMPANY_LEGAL_FORM}}), NIF {{COMPANY_NIF}}, registered office at {{REGISTERED_ADDRESS}}, entered in the {{MERCANTILE_REGISTRY}}. For any privacy matter you can write to {{PRIVACY_EMAIL}}.

We have appointed a Data Protection Officer (DPO): {{DPO_NAME}}, reachable at {{DPO_EMAIL}}.

Octo Services is an intermediary marketplace: we connect clients who need a service with vetted professional providers across Spanish destinations. We never process the payment for the service itself between a client and a provider.

2. What data we process and why (purposes and lawful bases)

Processing activityLawful basis (GDPR Art. 6)
Account creation, request matching, lead delivery, chat, quotes and engagementsPerformance of a contract — Art. 6(1)(b)
Provider document verification, invoicing and Spanish tax (IVA) obligationsLegal obligation — Art. 6(1)(c) (with contract)
Anti-abuse, fraud prevention and security audit loggingLegitimate interest — Art. 6(1)(f)
Marketing emails and product updatesConsent — Art. 6(1)(a), opt-in and withdrawable
Provider identity and insurance documentsContract + legal obligation; treated as access-restricted sensitive data

Consent for marketing is unchecked by default and can be withdrawn at any time without affecting the lawfulness of prior processing.

3. Categories of data and data subjects

  • Clients: identity and contact details, the content of service requests and dynamic form answers, estimates, messages, reviews.
  • Providers: identity and contact details, business information, coverage zones and availability, identity and insurance/registration documents, lead purchases, quotes, subscription and billing data.
  • All users: authentication data, consent records, device/technical data, and audit logs.

Client contact details are gated: a provider cannot see how to contact a client until the lead-unlock fee has been paid.

4. Recipients and sub-processors

We rely on the following processors, all hosting personal data within the EU/EEA: Supabase (database, EU region), Vercel (hosting/functions, EU region), Cloudflare R2 (document storage, EU bucket), Brevo (transactional email, EU), Stripe Payments Europe (payments, Ireland) and Inngest (background jobs).

International transfer: our estimation feature uses OpenAI (United States) to read uploaded quote documents. This is a transfer to a third country, covered by a Data Processing Agreement and, where applicable, the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses, with data minimisation: only the quote image and the extracted numeric values are sent — never client names, contact details or identity documents.

We do not sell your personal data.

5. How long we keep your data

We keep personal data only as long as necessary for the purpose. Messages, notifications, push tokens and sessions are deleted when no longer needed. Identity and insurance documents are deleted when their purpose ends. Financial records (invoices, lead purchases, commissions) are anonymised and retained — we sever the link to you but keep the amounts and tax fields — to comply with Spanish tax and accounting law. Reviews are kept but the author is de-identified; audit logs are kept in pseudonymised form for security.

6. Automated processing and provider scoring

To match a request to providers we compute a composite score (rating, acceptance/response rate, premium boost, fairness/rotation, seniority) using weights set by our administrators. This ranks and shortlists providers; it does not produce a decision with legal or similarly significant effect on you, and a human remains in the loop. Providers may request an explanation of the criteria used.

7. Your rights

You may exercise the rights of access, portability (data export), rectification, erasure, restriction, objection, and withdrawal of consent at any time — from your account settings or by writing to {{PRIVACY_EMAIL}} or the DPO at {{DPO_EMAIL}}. Erasure is honoured by deleting free-standing personal data and anonymising records we must retain by law.

If you believe your rights have not been respected, you may lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es).

8. Changes

We may update this policy; versions are dated and archived, and material changes are notified. This provisional version is effective from {{EFFECTIVE_DATE}}.