Last drafted: 22 September 2026
1. Data controller
The controller is the owner of Rechnia (hereinafter, «the provider»), with tax ID 48244334V and registered address at Vilafranca del Penedès (Barcelona), 08720. Their full identification details appear on the invoices they issue and are provided to anyone who requests them at rechnia@rechnia.com. Contact e-mail for data protection matters: rechnia@rechnia.com.
This policy concerns the data the provider processes as controller: that of the people who request access, contract the service, hold an access account or communicate with the provider. The data that the company contracting the service (hereinafter, «the customer») enters in the application about its own business, staff and contacts is governed by the data processing agreement, under which the provider acts as processor on the customer's behalf.
2. What data is processed and where it comes from
Access request (public form): company name, contact person's name, e-mail address, telephone number if provided, plan of interest and any free text written, together with the version of the legal texts accepted and the date and time of acceptance. Provided by the interested person themselves.
Company registration: company name, legal form, tax ID, activity, company telephone and e-mail; tax address, VAT regime and registry details; representative's name, surname, tax ID and position; delivery address with its contact person, telephone and e-mail; chosen plan and the version of the legal texts accepted, with the registration completion date.
Access accounts: name, position, e-mail address, role, start and end dates, telephone and profile photo if filled in, and language and appearance preferences. The password itself is not stored: only an irreversible hash of it (calculated with scrypt and salt), from which not even the provider can recover the original password.
Open session: while an account has a session open, a random identifier, a generic label of the browser and system (for example, «Chrome on Windows»), the start time and the time of last use are stored. This allows each account to be open in only one place at a time and indicates where it is open when someone tries to log in from elsewhere. Neither the IP address nor the full browser identifier is stored.
Failed login attempts and submission limits: for each e-mail address used in an unsuccessful login attempt, together with the IP address it is attempted from, the number of consecutive attempts and the date of the last one are counted, in order to temporarily block login after five failures; they are also counted per origin so that a third party cannot lock someone out by mistyping their e-mail. The same counter, with the IP address only, limits repeated submission of the public access request form, and, with the e-mail only, requests for password reset links. Each failed attempt is also recorded, with the e-mail typed and the time —without the IP address—, in the server's general log, which is not visible from the application.
Password reset: when someone requests a reset from the login screen and the e-mail corresponds to an account, the application sends to that e-mail —never to another— a single-use link and stores an irreversible hash of the link (not the link itself), the account it belongs to, the language in which it was requested, the creation time, the expiry time (one hour later) and, if used, the time of use.
Activity log: the application records in a file-based log, separated by company, logins and logouts (with the account name), relevant save actions and errors, with date and time. Failed login attempts (with the e-mail typed), password reset requests (with the e-mail typed or the account name) and VIN decodings (with the VIN and, if obtained, the make and model) are recorded in the server's general log, not the company's. Neither log records the IP address or the browser.
Communications: the messages the customer sends to the provider from the application's support section (subject, text, urgency and the reply), with the name of the account and company sending them.
E-mail: the messages anyone sends to rechnia@rechnia.com or to any other address on the rechnia.com domain (sender, content and attachments) and the provider's replies. Provided by whoever writes. The e-mails the application sends by itself come from an unmonitored address (noreply@rechnia.com); anything replied to that address is discarded unopened, which is why each one says in its footer how to write to the provider (rechnia@rechnia.com and the website's contact form).
E-mails sent by the application: in addition to the reset link, the application sends the invitation link to complete registration (to the address given in the access request, which does not yet belong to any account) and a welcome e-mail once registration is complete (to the address of the first account, with the person's name, the company's name and the chosen plan). For every e-mail it sends, whether or not it goes out, the application records the recipient, the subject, the date and the outcome of the sending —never the content— in a log that only the provider sees, so that delivery can be checked.
Minors. The service is aimed at companies and professionals and is not intended for children under fourteen (14): no data of minors is requested or knowingly processed. The data of the people a customer gives access to is that of its staff, who are adults. If the provider became aware of having collected data of a child under fourteen without parental or guardian consent, it would delete it; any question may be sent to rechnia@rechnia.com.
3. Purposes and legal basis
Handling and assessing access requests, and contacting whoever sends them. Basis: pre-contractual measures requested by the data subject (art. 6(1)(b) GDPR).
Completing registration, providing the contracted service, managing access accounts and giving support. Basis: performance of the contract (art. 6(1)(b) GDPR).
Invoicing and keeping supporting documents. Basis: legal obligation (art. 6(1)(c) GDPR).
Keeping the service secure: a single open session per account, blocking after failed attempts, limits on repeated form submissions, single-use password reset links and the activity log. Basis: the provider's legitimate interest in protecting the service and customers' data against use contrary to what was contracted (art. 6(1)(f) GDPR). The minimum possible data is processed for this. The IP address is used only in the attempt and submission counters described in section 2 and is not recorded in the activity logs; the hosting provider also collects it in its technical access logs in accordance with its own policy.
Recording which version of the legal texts each customer accepted and when, as evidence of the conclusion of the contract. Basis: performance of the contract and defence against claims (arts. 6(1)(b) and 6(1)(f) GDPR).
No automated decisions with legal effects are taken and no profiling is carried out.
4. How long data is kept
Access requests that do not result in registration: up to twelve (12) months from the last communication; the provider then deletes them.
Data of active customers and their access accounts: for as long as the contractual relationship lasts. Access accounts the customer deactivates are kept as part of the company's history for as long as the relationship lasts.
After the customer's termination (the end of the service, under the terms and conditions): thirty (30) calendar days so that they can request a copy of their data; the provider then deletes the company's data, except for data that must be kept by legal obligation —mainly tax and accounting documentation and the record of acceptance of the conditions— for the periods set by law.
Open session: the record is replaced on each new login and deleted on logout, when the person is removed or when their access is withdrawn. If the session expires without being closed, the entry —with no data other than the browser label and the times— remains until the next login attempt with that account.
Failed login attempts and submission limits: each counter ceases to have effect fifteen minutes after the last attempt; the counter entries (e-mail, IP address or both, number of attempts and date of the last one) and the general log entries corresponding to e-mails that never log in are deleted by the provider within the following twelve (12) months.
Password reset links: each link expires one hour after being requested and is cancelled when used or when another is requested; its entry is kept with the company's data and deleted with it.
Activity log and support messages: for as long as the contractual relationship lasts; the provider deletes them together with the rest of the company's data.
Log of e-mails sent by the application: twelve (12) months from sending; entries addressed to a company's accounts are deleted earlier if that company's data is deleted.
E-mail correspondence: that of customers, for as long as the contractual relationship lasts and until their company's data is deleted; that of anyone who does not become a customer, up to twelve (12) months from the last communication; in both cases except for what must be kept by legal obligation.
5. Who else may access the data
Hosting and infrastructure provider: Render Services, Inc. (a United States company; servers in Frankfurt, European Union), which hosts the application, the database, uploaded files and backups. The provider has a data processing agreement with it.
E-mail provider: Zoho Corporation B.V. (Netherlands), Zoho Mail service contracted in its European version, with mailboxes hosted in European Union data centres. It receives and stores e-mail correspondence with the provider (access requests, support, invoicing and anything written to rechnia@rechnia.com or to another address on the rechnia.com domain) and is also the means by which the application sends the e-mails it sends by itself: the link to reset a forgotten password (to the account's e-mail), the invitation link to complete registration (to the address given in the request, which is not yet any customer's) and the welcome e-mail once registration is complete. It acts as processor in accordance with its data processing agreement, and states in its terms that it does not use the content of e-mails for its own purposes.
Built-in help provider: Groq, Inc. (United States; or Mistral AI, France, should the provider switch), which receives only what the person types in the question field and the previous turns of that conversation, under the terms of section 6 and with the transfer safeguards in section 7.
Payment provider: Stripe Payments Europe, Ltd. (Ireland), when the customer pays by card. Card details are entered in a Stripe form embedded in the application —a frame the customer's browser loads from Stripe's domain— or, where applicable, on Stripe's payment page; in both cases they travel from the customer's browser to Stripe and never pass through the provider's servers; the provider shares the customer company's name, tax ID, address and billing email with Stripe in order to issue invoices, and Stripe processes payment data as an independent controller in accordance with its own privacy policy. When payment is by transfer, bank details are processed only by each party's financial institutions.
Public authorities, courts and financial institutions, where there is a legal obligation.
No disclosures other than the above are made. The other external services, those in the following section, receive only what is indicated there, and only when the customer uses the corresponding feature.
6. External services the application queries
While logged in, the application queries third-party services to obtain information linked to what the customer does: sometimes when a button is pressed (decoding a VIN, asking the help), other times when a screen that needs the data is opened (placing an address on a map, calculating the kilometres of a route). These queries are made by the provider's server and do not include access account data. None of these features is necessary for the basic operation of the program. VIN decoding and route calculation with Google have a monthly quota depending on the plan; the built-in help has a rate limit of twelve questions every five minutes per person; the others have no quota.
Vincario (api.vincario.com): decoding of vehicle identification numbers (VIN) when the person presses the corresponding button while registering a vehicle. The VIN is sent. The reply is stored in the application, separated by company, so that it need not be queried again.
Google Routes (Google, routes.googleapis.com): calculation of road distances between the vehicle's location and the customer's delivery address, when the import calculator or an import file is opened. The two postal addresses are sent as text. If there is no quota or the service fails, the calculation is done with OpenStreetMap. The distance obtained is stored together with the two addresses in a results table shared by all customers, without indicating which company or vehicle it comes from, so that the query is not repeated; no company can see its content: only the server reads it to reuse a distance already calculated.
OpenStreetMap: Nominatim (nominatim.openstreetmap.org) converts postal addresses into coordinates to place them on a map and to calculate routes; it receives the address as text, also while it is being typed in the vehicle registration and delivery address forms. OSRM (router.project-osrm.org) calculates distances and receives only pairs of coordinates. A postal address may be personal data when it belongs to a private individual.
Embedded map: on screens that show a map (home, vehicle record and registration, delivery address, tax details and calculator), the viewer's browser loads the map frame directly from Google Maps —or from OpenStreetMap if the provider has not configured Google—. In that load the map provider receives the coordinates of the point, the browser's IP address and the site origin (rechnia.com), not the specific page being viewed. It is a browser connection, separate from the queries above, and the map provider may set its own cookies in accordance with its policy; see the cookie policy.
calendariosnacionales.com: official public holiday calendars by autonomous community for the application's calendar. The year and the community code are sent; no customer data. The reply is stored in the application.
Help with artificial intelligence: the built-in help answers from the user guide by means of an external language model provider, currently Groq, Inc. (api.groq.com, United States); the application is prepared to use Mistral AI (api.mistral.ai, France) instead, and if the provider switched it would update this policy and give notice in accordance with the data processing agreement. The user guide, the text of the question and the last turns of that conversation are sent. The application does not send any data about the company, its vehicles, its employees or its customers on its own: what travels is what the person types, which is why the field itself warns not to type customer data or registration plates. The conversation is not stored on the provider's server: only the number of questions per company and month is counted and, for the rate limit, when each person asked in the last five minutes. If the provider returns an error, a fragment of its error response is kept in the server's technical log for diagnosis. The provider states in its terms that it does not use data sent via API to train its models.
Uploaded documents: invoices, receipts and staff documents are read **on the server itself**. Their text is extracted by the program using a library installed there, and the file is not sent to any external service — not to the artificial-intelligence help provider of the previous paragraph either.
The tables of municipalities and official average prices used by the application are built into it; no external service is queried for them.
7. International transfers
Google LLC (routes and map) and Render Services, Inc. (hosting; servers in Frankfurt, European Union) are United States companies included in the EU-US Data Privacy Framework list, which is the safeguard covering transfers to them.
Groq, Inc. (help with artificial intelligence) is not on that list: the transfer of the text of help questions is covered by the standard contractual clauses approved by the European Commission incorporated into the terms of Groq's API service.
The OpenStreetMap services (Nominatim and the fallback map frame) are operated by the OpenStreetMap Foundation, based in the United Kingdom, a country with an adequacy decision from the European Commission. OSRM is a separate community project, with no contract or location guarantee, to which only pairs of coordinates are sent.
Vincario is sent only the vehicle identification number, with no data about the owner, seller or buyer, and has no access to anything else stored in the application. calendariosnacionales.com receives no personal data.
The provider's e-mail (Zoho Corporation B.V., Netherlands) is hosted in European Union data centres. Zoho states that, in order to provide technical support, staff of its subsidiary Zoho Corporation Pvt. Ltd. (India) may access the data, and that this access is covered by the standard contractual clauses approved by the European Commission signed between the two companies.
Information about the safeguards applied may be requested by writing to rechnia@rechnia.com.
8. Your rights and how to exercise them
Anyone may request access to their personal data, its rectification or erasure, the restriction of or objection to its processing, and the portability of the data they have provided.
To exercise them, simply write to rechnia@rechnia.com, stating the right being exercised. Proof of identity may be requested where necessary to prevent a third party from exercising rights on someone else's behalf. Where the data was entered by a customer company about its staff or contacts, the provider will forward the request to that company, which is the controller, and assist it in handling it.
If the response is unsatisfactory, a complaint may be lodged with the Spanish Data Protection Agency (www.aepd.es).
9. Security
To use the application you must identify yourself with e-mail and password, and the whole application sits behind that door. Without a session, only the public presentation pages, the access request form, the legal texts, the registration screen reached through an invitation link, and the two screens for requesting and using the password reset link are accessible.
There is one more case: the subscription link to the company calendar (arrivals, expiries, events and who is absent and when, without the reason). It is personal to each person and protected by a random code, but anyone who receives it can read that calendar without logging in; it should therefore not be shared.
Passwords are stored as explained in section 2 and must be at least eight characters long with upper and lower case letters, numbers and symbols. After five consecutive failed attempts, login with that e-mail from that origin is blocked for fifteen minutes. A forgotten password is reset with a single-use link that the application sends to the account's e-mail, valid for one hour; the screen requesting it responds the same whether or not the account exists, so as not to reveal to a stranger which e-mails have one, and using the link closes any sessions that account had open. Sessions expire after thirty minutes of inactivity and, in any case, thirty days after starting.
Each customer company's data is separated from the rest: no account can read or modify another company's information, and automated tests check this on every change to the program. Within each company, the invoicing, accounting, staff and subscription screens are reserved for the administrator role, and each person sees only their own personal documents.
Communication with the application is encrypted using HTTPS; the server instructs the browser never to use unencrypted connections. Uploaded files are stored under a random name and served only to those entitled to see them.
The provider, as operator of the service, can see each customer company's name, plan, number of accounts and administrators' names, and the requests and support messages it sends. Viewing the full list of a company's accounts and any intervention on them is recorded in the provider's own log. In addition, as server administrator, the provider has technical access to the database, uploaded files and backups of the entire service, which it can download from the application; that access is used solely to operate, maintain and protect the service, and each download of a backup is recorded in the log.
Prevailing version
This document is an English translation of the original Spanish text, which is the one accepted and the one with contractual effect. In the event of any discrepancy between the two versions, the Spanish version prevails.