Privacy Policy
Last updated: March 27, 2026
Introduction
[YOUR_COMPANY_NAME] ("we", "our", or "us") operates ImmiDesk, a cloud-based immigration case management platform (the "Service"). This Privacy Policy explains how we collect, use, store, and protect your personal data when you visit our website, create an account, or use our Service.
We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, and applicable Spanish data protection legislation (LOPDGDD, Ley Organica 3/2018).
By accessing or using our Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.
Data Controller
The data controller responsible for your personal data is:
[YOUR_COMPANY_NAME]
[YOUR_ADDRESS]
Email: [YOUR_EMAIL]
Data We Collect
Information You Provide
- Account Information: Name, email address, and password when you create an account.
- Profile Information: Professional details such as your company name, role, and contact information.
- Client Data: Information you enter about your immigration clients, including names, nationalities, case details, and document references. You are the data controller for your client data; we process it on your behalf.
- Communications: Messages you send to us via email or through the Service.
- Payment Information: Billing details processed through our payment provider. We do not store full credit card numbers.
Information Collected Automatically
- Usage Data: Pages visited, features used, interaction patterns, and session duration.
- Device Information: Browser type, operating system, device identifiers, and screen resolution.
- Log Data: IP addresses, access times, referring URLs, and error logs.
- Cookies and Similar Technologies: As described in our Cookie Policy.
How We Use Your Data
We use your personal data for the following purposes:
- To provide, maintain, and improve the Service.
- To create and manage your account.
- To process payments and manage your subscription.
- To send transactional communications (e.g., password resets, billing receipts).
- To send marketing communications, where you have opted in. You can unsubscribe at any time.
- To analyze usage patterns and improve user experience.
- To detect, prevent, and address technical issues and security threats.
- To comply with legal obligations.
Legal Basis for Processing
Under the GDPR, we process your personal data on the following legal bases:
- Contract Performance (Art. 6(1)(b)): Processing necessary to provide the Service you have subscribed to.
- Legitimate Interest (Art. 6(1)(f)): Analytics, fraud prevention, service improvement, and direct marketing to existing customers.
- Consent (Art. 6(1)(a)): Marketing communications, non-essential cookies, and analytics tracking.
- Legal Obligation (Art. 6(1)(c)): Compliance with tax, accounting, and regulatory requirements.
Third-Party Processors
We share your personal data with the following categories of third-party service providers who process data on our behalf:
- Clerk (Authentication): Manages user authentication, session tokens, and account security. Clerk processes your email, name, and authentication credentials.
Clerk Privacy Policy - PostHog (Analytics): Collects usage data and product analytics to help us understand how the Service is used and to improve features. PostHog processes usage events, device information, and IP addresses (which are anonymized).
PostHog Privacy Policy - Cloudflare (Hosting & CDN): Provides hosting infrastructure, content delivery, and DDoS protection. Cloudflare processes IP addresses and request metadata.
Cloudflare Privacy Policy
All third-party processors are bound by data processing agreements and are required to process your data in accordance with the GDPR.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Account Data: Retained for the duration of your account and for up to 30 days after account deletion.
- Client Data: Retained for the duration of your subscription. Upon cancellation, your data is available for export for 30 days, after which it is permanently deleted.
- Billing Data: Retained for the period required by applicable tax and accounting laws (typically 5-7 years in Spain).
- Usage & Analytics Data: Retained in anonymized form for up to 24 months.
- Log Data: Retained for up to 90 days for security and troubleshooting purposes.
Your Rights
Under the GDPR, you have the following rights regarding your personal data. To exercise any of these rights, contact us at [YOUR_EMAIL].
- Right of Access (Art. 15): You have the right to request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): You have the right to request correction of inaccurate or incomplete personal data.
- Right to Erasure (Art. 17): You have the right to request deletion of your personal data, subject to legal retention obligations.
- Right to Data Portability (Art. 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Restriction (Art. 18): You have the right to request restriction of processing in certain circumstances.
- Right to Object (Art. 21): You have the right to object to processing based on legitimate interest, including profiling and direct marketing.
We will respond to your request within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Espanola de Proteccion de Datos, AEPD) at www.aepd.es.
International Data Transfers
Some of our third-party service providers may process your data outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy decisions by the European Commission (e.g., the EU-U.S. Data Privacy Framework).
- Binding Corporate Rules where applicable.
You may request a copy of the safeguards in place by contacting us at [YOUR_EMAIL].
Children's Privacy
The Service is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without parental consent, we will take steps to delete that information promptly. If you believe we have collected data from a child, please contact us at [YOUR_EMAIL].
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. For significant changes, we may also send you an email notification.
We encourage you to review this policy periodically.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
[YOUR_COMPANY_NAME]
Email: [YOUR_EMAIL]
Address: [YOUR_ADDRESS]