arrow_back Back

shield Privacy Policy

Last updated: 1 May 2026

Note: This is a courtesy translation. The legally binding version of this document is the Spanish original at /privacy.

1. Data controller

Personal data collected through FacturaOk is processed by:

2. Data we process

CategoryDataPurpose
Sign-upName, email, password (hash)Create and manage your account
InvoicingTax ID, legal name, tax address, invoice dataIssuing invoices and tax compliance
TechnicalIP, user-agent, access logsSecurity, fraud prevention, performance
PaymentBilling email (Stripe handles card data)Subscription management

We never collect biometric, genetic, health, sexual orientation or political/union affiliation data.

3. Legal basis for processing (GDPR Art. 6)

4. Data retention

5. Recipients and processors

ProviderPurposeLocationSafeguards
Amazon Web Services EMEA SARL (AWS)Cloud infrastructure, storage (S3), database (RDS), KMSEU (eu-west-1, Ireland)AWS DPA, ISO 27001/27017/27018, SOC 2, standard contractual clauses
Amazon SES (AWS)Transactional email deliveryEU (eu-west-1, Ireland)AWS DPA
Stripe Payments Europe Ltd.Payment and subscription processingEU (Ireland) with processing by Stripe Inc. in the USAPCI-DSS Level 1, Stripe DPA, EU-US Data Privacy Framework
Anthropic, PBCOCR of received invoices (Claude Vision): the user may upload a PDF/image and the bytes are sent to Anthropic for data extractionUSAAnthropic Commercial Terms and DPA, EU-US Data Privacy Framework. Anthropic does not train models on data submitted via API.
AEAT (Spanish Tax Agency)Reporting of VeriFactu invoicing records (when the user enables live mode)SpainLegal obligation (RD 1007/2023, Order HAC/1177/2024)
FACe / public B2B platformSubmission of invoices to the Spanish Public Administration when requested by the userSpainLegal obligation (Law 25/2013, Law 18/2022)

We do not sell or share personal data with third parties for advertising purposes. The OCR feature with Anthropic is opt-in: if you do not upload invoices to the expenses module, no data is transferred to Anthropic.

6. International transfers

Primary processing and storage take place on AWS servers in the European Union (Ireland, eu-west-1). International transfers to the United States occur in the following cases:

You may exercise your rights regarding these transfers or request a copy of the safeguards by writing to dpo@facturaok.es.

7. User rights (GDPR Arts. 15–22)

You may exercise the following rights at any time:

To exercise any of these rights, write to privacidad@facturaok.es. We will respond within 30 days.

You may also lodge a complaint with the Spanish Data Protection Agency (AEPD).

8. Security measures

9. Cookies

FacturaOk uses only essential technical cookies. See our Cookie Policy for details.

10. Contact