Privacy policy
Version 1.0 · in force from 30 September 2026
This policy explains what personal data we process, why, on what legal basis, who we share it with, how long we keep it and how you can exercise your rights. It covers the website flexigotech.com, the shop (store.flexigotech.com), the customer area (app.flexigotech.com) and the support chat on the website. We apply it under Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and Spanish Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD). What we store in your browser is explained in the Cookie Policy.
This English version is a translation for reference only. The Spanish text is the one that applies.
1. Who processes your data
Flexibles y Accesorios Gobe, S.L., which sells software under the FlexigoTech brand.
- Tax ID (NIF): B56727993.
- Registered address: Calle Roger de Llúria 54, principal 1.ª B, 08009 Barcelona (Spain).
- Barcelona Commercial Registry, volume 49059, folio 216, section 8, sheet B-606144, entry 1.
- For anything about your data: comercial@flexigobe.com or +34 616 809 504.
We have not appointed a data protection officer because we are not required to (article 37 GDPR and article 34 LOPDGDD).
Atendyo, another product of this same company, has its own policy for its customers and for the businesses it writes to. This policy covers FlexigoTech's use of Atendyo as the chat on its own website.
2. What data we process, why, on what legal basis and for how long
When a retention period ends, we erase or anonymise the data. If a law requires us to keep it longer, we block it: it is set aside and used only to answer courts or public authorities while liability can still be claimed (article 32 LOPDGDD).
2.1 Your account in the customer area
With your account you download your modules, keep your invoices and licences at hand, get notices about new versions of what you bought and manage your privacy.
| Data | Legal basis | Retention |
|---|---|---|
| Your email address; a hash of your password computed with Argon2 (we do not store the password); the dates you signed up and last signed in; whether you confirmed your email; the language you prefer us to write in. If you turn on two-step verification, the secret of your authenticator app and your recovery codes. | Performance of the account contract, which you accept when you sign up (article 6.1.b GDPR). | While you have the account. If you do not confirm your email within 7 days, we delete the sign-up. If you do not sign in for 12 months, we warn you by email, and if you still do not sign in during the next 30 days, we delete the account as the terms of use explain. |
2.2 Account security
| Data | Legal basis | Retention |
|---|---|---|
| Security log: when you request or download a copy of your data, when your account is deleted and the changes staff make to it from the administration, with date, IP address and browser. | Legitimate interest in protecting your account and our systems (article 6.1.f GDPR) and the duty of security (article 32 GDPR). | 12 months. |
| Your session: an identifier stored on our server. | Contract (article 6.1.b GDPR). | Until you sign out. If you tick "Remember me", 14 days; otherwise, until you close the browser. |
| Attempt limits: the IP address and email used to try to sign in, recover a password or sign up and, in the shop, to ask for an access link, a free download or a licence activation. | Legitimate interest in stopping abuse (article 6.1.f GDPR). | In the customer area, as long as each limit lasts, one hour at most. In the shop, 48 hours. |
2.3 What you accept and what you consent to
| Data | Legal basis | Retention |
|---|---|---|
| Which document you accepted or consented to (terms of use, the news box) or were informed of (this policy), its version and the SHA-256 hash of the text, the date, the IP address, the browser and where it happened (sign-up, purchase, new acceptance or preferences). Also when you withdraw a consent. | Legal obligation to be able to prove what you accepted or consented to (articles 5.2, 6.1.c and 7.1 GDPR). | While you have the account and then, blocked, for 5 years, the period for claims under a contract (article 1964.2 of the Spanish Civil Code). If you withdraw your consent to receive news, we keep proof of what you consented to and when you withdrew it for 3 years, the limitation period for the most serious infringements (article 72.1 LOPDGDD). |
2.4 Purchases in the shop
Stripe processes the payment. We do not see or store your card details.
| Data | Legal basis | Retention |
|---|---|---|
| Email, name or company name, billing address, tax ID if you give it, country, modules, Odoo version, amount and taxes, order and licence identifiers, invoice number and the version of the terms you accepted when paying. | Performance of the purchase contract (article 6.1.b GDPR) and accounting and tax obligations (article 6.1.c GDPR). | Orders with an invoice, and invoices, for 6 years (article 30 of the Spanish Commercial Code), blocked as soon as the relationship ends. |
Orders are stored on our Netcup servers and, while we still use it, in a private GitHub repository.
2.5 Your licence
| Data | Legal basis | Retention |
|---|---|---|
| Mark on each copy: your company name, your email and the licence and order identifiers are written into the LICENSE, LICENSEE.txt, __manifest__.py and __init__.py files of the module we deliver. | Contract: the licence is yours and cannot be transferred (article 6.1.b GDPR). Legitimate interest in knowing where an unauthorised copy comes from (article 6.1.f GDPR). | The mark stays inside your copy. We keep the file we build for you on our server for 30 days; if you need it later, we build it again. |
| Delivery log: email, company, licence, order, module, version and SHA-256 hash of the delivered file. | Contract, and legitimate interest in proving delivery, not delivering twice and tracing copies (article 6.1.b and 6.1.f GDPR). | Same period as the order or download it belongs to. |
| Activation: your purchase email and the identifier of your Odoo database. The key we generate contains that email, that identifier, your modules and the issue and expiry dates, signed by us. | Contract (article 6.1.b GDPR). | We do not store the activation: we generate the key and show it to you. |
2.6 Free downloads
| Data | Legal basis | Retention |
|---|---|---|
| Email, module, version and licence identifier. The copy carries the same mark and goes into the same delivery log as a purchase. | The free licence contract you ask for (article 6.1.b GDPR). | While you have the account. If you have no account or delete it, 24 months from your last download. |
2.7 Emails we send you
Account emails come from cuenta@flexigotech.com and shop emails from comercial@flexigotech.com. If you reply, your reply goes to comercial@flexigotech.com. We write to confirm your email, send you a link to see your purchases, recover your password, warn you about security changes in your account, deliver a purchase or a free download, tell you about a new version of your modules, tell you your copy of your data is ready, warn you before deleting an inactive account and confirm we have deleted it.
| Data | Legal basis | Retention |
|---|---|---|
| Log of each email: type, recipient, subject, date and delivery status (delivered, bounced, blocked or marked as spam). We keep the content only until the email has been sent, because it may carry a one-time link. | Contract (article 6.1.b GDPR) and legitimate interest in proving we notified you and in detecting emails that do not arrive (article 6.1.f GDPR). | 12 months. |
New-version notices are part of the updates included in your purchase. Each notice has a link to stop receiving them.
Brevo sends these emails on our behalf. While we change email provider, Brevo adds an invisible image that tells it whether you open the email, and routes the links through its server to count clicks. We do not store opens or clicks in our database. We only look at that record in Brevo's dashboard when we need to check that an email reached you (legitimate interest, article 6.1.f GDPR).
2.8 Marketing news
We only write to you about new modules, offers or changes to our services if you tick the news box, when you sign up or later, in the Privacy section of your account.
| Data | Legal basis | Retention |
|---|---|---|
| Email, language and proof of your consent (section 2.3). | Your consent (article 6.1.a GDPR and article 21 of Spanish Law 34/2002, LSSI). | Until you withdraw it, by unticking the box or with the unsubscribe link in any of those emails. We then keep your email on an exclusion list so we do not write to you again (article 6.1.c GDPR and article 22.1 LSSI), for as long as needed to respect your opt-out. |
2.9 If you write to us
| Data | Legal basis | Retention |
|---|---|---|
| What you tell us through the website forms, by email, by phone or on WhatsApp: name, company, email, phone, website, your message and your answers to the form. | Pre-contractual steps you ask for (article 6.1.b GDPR) and legitimate interest in answering you (article 6.1.f GDPR). | 12 months from the last contact, unless it leads to a contract. In that case, the contract's period. |
The contact forms go through FormSubmit, which forwards them to us by email. If you write to us on WhatsApp, WhatsApp also processes that conversation under its own terms.
2.10 Connector checker and notices from our free modules
| Data | Legal basis | Retention |
|---|---|---|
| If you use the connector feasibility checker on the website: email, company, marketplace, Odoo version, what you need and the result. | Your request (article 6.1.b GDPR): we use it to answer you. | 12 months without a reply from you. |
| If, in our free VeriFactu check module, you ask for the report and tick the consent box: email, name, company, country and the result of the check. | Your consent (article 6.1.a GDPR). | Until you withdraw it and, at most, 12 months without a reply from you. |
This data goes through Netlify, which hosts the website, and reaches us by email through Brevo.
2.11 Support chat on the website
The chat runs on Atendyo, a program of this same company installed on our server at bot.flexigotech.com. The answers are written by an artificial intelligence model. For each answer we use one of these: Mistral AI (France), Groq (United States), Cloudflare Workers AI (United States) or a model installed on our own server, and we pass it the text of the conversation. Do not write passwords, card details or health data in the chat.
| Data | Legal basis | Retention |
|---|---|---|
| What you write and the text we extract from files you attach (the file is discarded as soon as it has been turned into text). If you ask to talk to a person, your name, your email and your message. A random identifier stored in your browser when you open the chat, to show you your previous conversations. | Pre-contractual steps or performance of the contract (article 6.1.b GDPR) and legitimate interest in helping people who ask us (article 6.1.f GDPR). | 12 months from the last message in the conversation. |
2.12 Booking a video call
| Data | Legal basis | Retention |
|---|---|---|
| Name, email, date and time of the meeting and your answers when booking on Calendly. | Pre-contractual steps you ask for (article 6.1.b GDPR). | 12 months from the meeting. |
2.13 Visits to the website and our servers
| Data | Legal basis | Retention |
|---|---|---|
| IP address, date and time, requested address and browser. Netlify logs them when serving flexigotech.com; our server, when serving the shop, the customer area and the chat. In our logs, access links are stored without their key. | Legitimate interest in the website working and being secure (article 6.1.f GDPR). | On our server, 30 days. At Netlify, the time its terms set. |
2.14 Analytics and advertising
Only if you accept them in the cookie notice, and they are two separate permissions. With analytics, Google Analytics 4 and PostHog record the pages you visit, clicks and page performance. With advertising, Google may use your visit for its advertising lists. The details are in the Cookie Policy.
| Data | Legal basis | Retention |
|---|---|---|
| Identifiers of your browser and what you do on the website. | Your consent (article 6.1.a GDPR and article 22.2 LSSI). You can withdraw it from the "Cookies" link at the foot of every page. | Cookies, up to 400 days (Google) and 365 days (PostHog). On their servers, the period each tool sets; in Google Analytics, 14 months at most. |
2.15 Invoicing and accounting
| Data | Legal basis | Retention |
|---|---|---|
| The details on each invoice. | Legal obligation (article 6.1.c GDPR). | 6 years (article 30 of the Spanish Commercial Code). |
We disclose them to the Spanish Tax Agency when the law requires it and to our tax and accounting advisers, who process them on our behalf.
2.16 Your requests and complaints
| Data | Legal basis | Retention |
|---|---|---|
| What you ask for, any data we need to check and our answer. | Legal obligation to handle your rights and your complaints (article 6.1.c GDPR, article 12 GDPR and article 21 of the Spanish consumer protection act, TRLGDCU). | 3 years from our answer. |
2.17 Accounts created on flexigotech.com before the customer area
Accounts opened on flexigotech.com/cuenta.html were stored with Supabase, a United States provider. That service no longer works. If you opened an account there, we will move it to the customer area or delete it, and then erase that data from Supabase.
3. Where the data comes from
You give us almost all of it. Stripe gives us the payment result and the billing details you type on its page, and Brevo tells us whether an email was delivered.
4. Who we share your data with
We do not sell personal data or share it for other companies' advertising. We disclose it to public authorities and courts when a law requires it. These providers process it on our behalf (article 28 GDPR), each only for what is shown:
| Provider | What for | Where |
|---|---|---|
| netcup GmbH | Servers for the shop, the customer area and the chat, their databases and their backups. | Germany |
| Stripe Payments Europe, Limited | Payments and invoices. Stripe also processes some data as a controller in its own right, to prevent fraud and meet its legal obligations. | Ireland; part of the processing in the United States |
| Sendinblue SAS (Brevo) | Sending the account and shop emails and reporting their delivery. | France |
| Netlify, Inc. | Hosting flexigotech.com and the forms of the checker and the free modules. | United States |
| GitHub, Inc. | Private repository with the log of orders and free downloads, while we still use it. | United States |
| ImprovMX Incorporated | Forwards email sent to @flexigotech.com addresses to our mailbox. | United States |
| GoDaddy | The comercial@flexigobe.com mailbox, where we receive forms and enquiries. | United States |
| Calendly LLC | Video call bookings. | United States |
| Mistral AI SAS | Chat answers. | France |
| Groq | Chat answers and descriptions of the photos you attach. | United States |
| Cloudflare, Inc. (Workers AI) | Chat answers. | United States |
| Google Ireland Limited and Google LLC | Analytics and advertising, only with your permission. Fonts on the three Arabic pages of the website. | Ireland and United States |
| PostHog | Analytics, only with your permission. | European Union (PostHog's European cloud) |
| Supabase, Inc. | Old flexigotech.com accounts, until they are erased (section 2.17). | United States |
| Odoo S.A. (Odoo.sh) | Our Odoo instance, where the service that connects our Amazon connector to the seller's account runs (section 10). | Belgium (Google Cloud servers in the European Union) |
| Our tax and accounting advisers | Accounting and taxes. | Spain |
Two other services receive data without a data processing agreement signed with us, because they do not offer one: FormSubmit (formsubmit.co), which receives what you write in the contact forms and forwards it to us by email, and jsDelivr, a file distribution network with servers in many countries that serves the icons on many flexigotech.com pages and sees your IP address. FormSubmit does not publish a privacy policy. If you would rather your enquiry did not go through FormSubmit, write to us directly at comercial@flexigobe.com.
5. Transfers outside the European Economic Area
Some of the providers in the table in section 4 process data in the United States. Each transfer has to rely on a GDPR safeguard: the adequacy decision on the EU-US Data Privacy Framework of 10 July 2023 (article 45 GDPR), if the provider is certified, or the European Commission's standard contractual clauses (article 46.2.c GDPR). Stripe (Stripe, LLC) and Cloudflare are certified under the Framework. Groq is not, and its safeguard is the standard contractual clauses. For Netlify, GitHub, Calendly, Google, GoDaddy, ImprovMX, PostHog and Supabase we are checking which of the two safeguards applies to each. If you want to know or would like a copy, ask us.
6. Automated decisions
We do not take decisions based solely on automated processing that have legal effects on you or affect you in a similar way (article 22 GDPR). The chat answers automatically, but it does not decide anything about you. The fraud checks Stripe applies to payments are Stripe's own.
7. Your rights
You can ask us for access to your data, its rectification or erasure, object to our processing it, ask us to restrict its use and take it with you in a machine-readable format (articles 15 to 22 GDPR). If you gave us your consent, you can withdraw it at any time, without affecting what we did before (article 7.3 GDPR).
In your account, in the Privacy section, you can download a copy of your data (a JSON file downloaded through a link that is valid for 7 days and only opens with your session signed in), turn the news on or off and delete the account. For anything else, or if you have no account, write to comercial@flexigobe.com or by post to the address in section 1. Any other channel you use to ask us is also valid.
We will not ask for your ID card. If you write from the email of your account or your purchase, that is enough for us. Only if we have reasonable doubts about who you are will we ask for the minimum detail that lets us check (article 12.6 GDPR).
We answer within one month at most. If the request is complex or we receive many, we can extend that by two more months, and we would tell you within the first month (article 12.3 GDPR). Exercising your rights is free.
Some data cannot be erased while its legal retention period lasts, such as invoices. In that case we block it and tell you which data and until when. If you ask us to erase an order or download that is in the GitHub repository, we remove it from the log, but it may remain in the repository's history while we still use it; we will tell you what remains and until when.
If you think we have not handled your rights properly, you can complain to the Spanish Data Protection Agency (C/ Jorge Juan 6, 28001 Madrid, www.aepd.es).
8. Security
- All connections to the website, the shop, the customer area and the chat are encrypted (HTTPS).
- Our servers are in Germany. The customer area has its own database, separate from those of our other products.
- For passwords we store only a hash (Argon2). They must have at least 12 characters and cannot be among the most common ones.
- Any account can turn on two-step verification, with an authenticator app and recovery codes. It is mandatory for staff who administer the area.
- We limit sign-in, password recovery and sign-up attempts.
- We email you when your password, your email or your two-step verification changes.
- We make a daily backup of the customer area database, and the copy that leaves the server is encrypted.
- What we erase also disappears from the backups within 30 days at most.
If we suffered a security breach, we would notify the Spanish Data Protection Agency within 72 hours when the law requires it, and the people affected if it poses a high risk to them (articles 33 and 34 GDPR).
9. Minors
The website and the shop are aimed at businesses and professionals, not at children under 14 (article 7 LOPDGDD). You must be of legal age to open an account or buy.
10. Data we process on behalf of our customers
Our modules and connectors run inside each customer's Odoo. The data they handle (orders, invoices, customers) belongs to the customer, who is its controller, and stays in their installation. When a connector passes data through one of our servers, or when we provide support with access to a customer's Odoo, we process it on their behalf, only for that purpose and under the data processing agreement we sign with them (article 28 GDPR). If you are a customer of one of our customers, ask that company for your rights; if you write to us, we will pass your request on to them.
The authorisation that connects our connector to the seller's Amazon account goes through our Odoo instance on Odoo.sh.
For data our connector obtains from the Amazon Selling Partner API, we also commit to:
- using it only to manage and fulfil the seller's orders;
- not keeping buyers' personal data longer than needed to fulfil the orders and meet legal obligations;
- encrypting it in transit and at rest and limiting access to those who need it;
- reporting any security incident affecting Amazon data to security@amazon.com within 24 hours of detecting it, and to the Spanish Data Protection Agency within 72 hours where applicable (article 33 GDPR);
- not sharing it with unauthorised third parties.
11. Changes to this policy
Each version has a number and a date, and previous versions remain available in the customer area. If a change affects how we use your data, we will tell you by email or in your account before it applies.
Approved on 30 September 2026 by the sole director of Flexibles y Accesorios Gobe, S.L.
