Cookies on Rechnia

Five first-party cookies — session, save notice, language and your own choice — none for analytics or advertising. Inside the application, Google Maps maps may set their own. If you choose nothing, only the necessary ones are used. Cookie policy

Skip to content
rechnia.IMPORT · MANAGE · SELL
PlatformPricingAbout usContact
ESCAEN
Sign in ↗View plans ↗
LEGAL INFORMATION

Data processing agreement

The allocation of roles when the customer uploads data about their staff and contacts: who is responsible for what.

Legal noticeTerms and conditionsPrivacyCookiesProcessing agreement

Last drafted: 19 September 2026

1. Why this document exists

When using Rechnia, the company contracting the service (hereinafter, «the customer») enters personal data of third parties: its own staff —including identity documents, contracts, payslips, clocking records and absence certificates—, job applicants, contact persons of its suppliers and buyers, and private individuals acting as sellers or buyers in a sale.

With regard to that data, the customer is the controller and the owner of Rechnia, with tax ID 48244334V and registered address at Vilafranca del Penedès (Barcelona), 08720, e-mail rechnia@rechnia.com (hereinafter, «the provider»), is the processor: it processes the data on the customer's behalf and following the customer's instructions, not for its own purposes. Their full identification details appear on the invoices they issue and are provided to anyone who requests them at rechnia@rechnia.com. This document sets out the conditions of that processing, in accordance with article 28 of Regulation (EU) 2016/679.

It forms part of the service contract and is accepted together with the terms and conditions.

2. Subject matter, duration and nature of the processing

Subject matter: the provision of the Rechnia service described in the terms and conditions.

Duration: for as long as the subscription is in force, plus the thirty (30) days of data recovery following termination.

Operations: collection, recording, organisation, storage, consultation, alteration, erasure, export and making available to the customer itself; and, when the customer uses the corresponding features, disclosure to the external services indicated in section 4.

Categories of data subjects: the customer's staff, job applicants, contact persons of its suppliers and buyers, and private individuals involved in sale transactions.

Categories of data: identification and contact details, professional and payroll data, working hours (clocking records), identity documents, contracts, CVs and application data, absence and expense certificates, profile photos, postal addresses and financial data of transactions.

Health data: the application allows staff sick leave to be recorded, with a free-text reason and an attached certificate. This is special category data under article 9 of the GDPR. The customer processes it as an employer to comply with its obligations under employment and social security law, to the extent authorised by Spanish law (art. 9(2)(b) GDPR, in connection with the obligations imposed on employers by employment and social security legislation), and undertakes not to record the diagnosis or any clinical information beyond what appears in the certificate the company receives. The application limits who sees it: the type of absence, the reason and the certificate are seen only by the administrator and the person concerned; the rest of the staff see only who is absent and on which dates, because this is needed to organise work. No other special category of data is expected to be processed, and the customer undertakes not to enter such data in fields not intended for it.

3. Obligations of the provider as processor

To process the data only on the customer's documented instructions, including with regard to international transfers, unless required by law.

Not to use the data for its own purposes, not to disclose it to third parties other than authorised sub-processors, and not to use it to train artificial intelligence systems.

To ensure that the persons authorised to process it have committed themselves to confidentiality.

To apply appropriate technical and organisational measures, including: access only with an identified account and a password meeting minimum requirements; a single open session per account, with expiry on inactivity and an absolute expiry; temporary blocking after failed attempts; strict separation of data between customer companies, verified by automated tests; passwords stored irreversibly; documents stored under random names and served only to those entitled; encrypted communications; and a daily backup of the database, of which the seven most recent are kept.

To assist the customer, as far as possible, in handling requests to exercise rights that it receives, and in complying with its security and breach notification obligations.

To notify the customer without undue delay of any data security breach it becomes aware of, with the information available so that the customer can comply with its own obligations.

To make available to the customer the information necessary to demonstrate compliance with these obligations.

At the end of the processing, and at the customer's choice, to return its data —which it can obtain through the application's exports while it retains access and, in the thirty (30) calendar days following termination, through a complete copy on request— and to delete it, except for data that must be kept by legal obligation.

To inform the customer immediately if, in its opinion, an instruction from the customer infringes data protection law.

4. Sub-processors and external services

The customer gives general authorisation for the involvement of the sub-processors necessary to provide the service. There are three: the hosting provider, Render Services, Inc. (a United States company; servers in Frankfurt, European Union), which hosts the application, the database, uploaded files and backups; the built-in help provider, Groq, Inc. (United States; or Mistral AI, France, should the provider switch), which receives only what the person types in the question field and the previous turns of that conversation, with the transfer safeguards indicated in the privacy policy; and the provider's e-mail provider, Zoho Corporation B.V. (Netherlands, European Union), which receives and stores the correspondence that the customer and the people with access accounts maintain with the provider, and through which the application sends the e-mails it sends by itself to those people (the link to reset a forgotten password, the invitation link to complete registration and the welcome e-mail).

In addition, when certain screens are used, the application communicates postal addresses and coordinates to third parties that are not sub-processors and do not access the stored data: to Google LLC (Google Routes), which processes them under its own terms, and to the OpenStreetMap community services (Nominatim and OSRM), with which there is no contract. These communications occur when the import calculator or an import file is opened and when an address is typed in a form with a map, and the addresses are those the customer itself has entered to locate a vehicle or calculate a route; the customer expressly authorises them by accepting this agreement, as a documented instruction. Vincario is sent only the vehicle identification number when a person presses the decode button. Apart from those addresses, that VIN and that text, the application sends none of them any staff or contact data.

Screens with a map load the frame from Google Maps (or OpenStreetMap) in the browser of the person opening them, so that the map provider receives the coordinates of the point and that browser's IP address and may set its own cookies; the customer authorises this by accepting this agreement and is responsible for informing its staff of it.

The provider will give notice of any planned change of sub-processors or external services sufficiently in advance for the customer to object. If the customer objects on reasonable grounds, either party may terminate the contract without penalty.

The provider will impose on each sub-processor, by contract, obligations equivalent to those in this document, and will be liable to the customer for their compliance.

5. Obligations of the customer as controller

To have a valid legal basis for the processing it carries out through the application, and to inform data subjects —its staff, applicants and contacts— in accordance with the law.

To enter only the data necessary for the intended purpose, and in particular not to upload documents containing more personal information than required.

To manage its staff's access accounts diligently, assigning the administrator role only to those who need to see invoicing, accounting and staff data, and removing accounts that are no longer needed.

To communicate to the provider the instructions it wishes to give and any relevant change to them.

6. Audit

The customer may request, with reasonable notice and without interfering with the provision of the service or with the confidentiality of other customers, the information necessary to verify compliance with this agreement, and carry out, itself or through an authorised auditor, the audits and inspections permitted by law.

Prevailing version

This document is an English translation of the original Spanish text, which is the one accepted and the one with contractual effect. In the event of any discrepancy between the two versions, the Spanish version prevails.

rechnia.IMPORT · MANAGE · SELL

Software for dealerships importing vehicles from Europe.

ProductPlatformPricingSign in
RechniaAbout usContactFAQrechnia@rechnia.com
LegalLegal noticeTerms and conditionsPrivacyCookiesProcessing agreement
© 2026 Rechnia · Vilafranca del Penedès, Barcelona