> For the complete documentation index, see [llms.txt](https://docs.salescaling.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.salescaling.com/en/compliance-and-legal/privacidad.md).

# Privacy Policy

**Last policy review:** 13/05/2025

## Who is the Data Controller?

**SALESCALING SOFTWARE, S.L.**\
**Tax ID (N.I.F.):** B19825488\
**Postal address:** C/ Crujiola, 6-Alsaca Building, Tower 2, Floor 5, 38530, Candelaria (Santa Cruz de Tenerife)\
**Email:** <legal@salescaling.com>

If you wish to contact us regarding your personal data, you may do so at the address indicated in the previous point.\
The Data Controller may alternatively be referred to as “SALESCALING”, the “Controller”, “Platform” or “we”.

## Introduction

SALESCALING (is the owner of the domain <https://salescaling.com>, <https://app.salescaling.com>) as well as of this website and/or the web app and/or any other type of software developed, operated and/or maintained by SALESCALING (hereinafter the “Platform”).

By means of this text, the User (hereinafter also referred to as the “User”, “Data Subject” or “you”) is provided with SALESCALING’s Privacy Policy for the purpose of describing the personal information we collect, the purpose for which we use it and, in general, the processes and ways in which we process it during the course of Users’ use of and/or navigation through the Platform (whether registered or unregistered, depending on the processing).

SALESCALING may make this Privacy Policy available to the User in different languages. In such case, this Spanish version shall prevail in the event of any interpretative conflict.

## Processing of personal data on behalf of our clients

When the Platform is integrated by our end customers within their business activity under a service agreement, the Platform will process personal data for the provision of the services on behalf of such customers, acting as a Data Processor.

In such case, the aforementioned customer shall be the Data Controller of the personal data that they share with, or introduce into, the Platform.

The processing of personal data by SALESCALING as Data Processor shall not be governed by this Privacy Policy, but by the provisions of the service agreement between the Platform and the end customer, in accordance with the instructions and purposes specified therein, as well as in the specific Data Processing Agreement and the end customer's privacy policy that integrates our services, in compliance with the applicable data protection regulations.

## Processing activities and purposes for which we process your data as data controllers

### Processing activities we carry out as Data Controllers:

#### Platform functionality

* **Purpose:** to enable Users to use and navigate the Platform, ensuring the proper functioning of the Platform, allowing updates and technical maintenance, improving its usability, security and performance.
* **Categories of data processed:**\
  Platform usage data by the User and application and device data; including the following: browsing and usage data, IP address, usage preferences, visits made, language, device information, browser type, device type and operating system, approximate location by region and country of access; as well as cookies; and anonymized statistical data.\
  Likewise, if the User reaches the Platform through an external source (such as, for example, through a link from a website or third-party social network), the Controller will collect anonymous statistical information about the source from which the visitor comes in order to better understand how users discover and reach the Platform and/or to improve the company's marketing and positioning strategies.
* **Categories of Data Subjects:** Registered and unregistered Users who make use of the Platform.
* **Method of collection:** shared by the User through browsing the Platform environment.
* **Legal basis:** our legitimate interest in ensuring the proper, up-to-date functioning of the Platform and the Users, and in knowing the origin and source from which the user comes; or, otherwise, the User’s consent (e.g.: regarding cookies that are not necessary to ensure the functioning of the Platform)
* **Retention period:** Usage Data will be retained for a maximum of 12 months from collection, in accordance with Law 25/2007 on data retention in electronic networks. After said period, the data will be deleted unless required by a public authority. Anonymized statistical data may be stored indefinitely as it does not contain personal data.
* **Disclosure:** the collected data may be disclosed to our technology, IT and/or data hosting service providers that are essential to ensure the purpose for which it was collected. Your data will not be sold to third parties.

#### Security and fraud prevention

* **Purpose:** We collect and analyze data from the Data Subject to ensure the security of our Users, prevent fraud, and carry out appropriate investigations and use the information for possible claims in our own interest or that of third parties. This processing includes:
* **Collection of traffic data:** We collect information about visits to our website, including IP addresses, browser type, pages visited, time spent and other browsing data.
* **Behavior pattern analysis:** We use analysis tools to identify unusual or suspicious behavior patterns that may indicate attempts at fraud or unauthorized access.
* **Threat detection:** We implement intrusion detection systems and other threat detection tools that analyze traffic in real time to identify and block malicious activity.
* **Identity verification:** We use traffic data to verify users' identities and ensure that transactions and accesses are legitimate.
* **We keep detailed records** of accesses and activities on our website in order to carry out security audits and respond quickly to any incident.
* **Cooperation with authorities:** If fraudulent or suspicious activities are detected, we may cooperate with the competent authorities by providing the necessary information for the investigation in compliance with a legal obligation. These processes allow us to protect the integrity of our website and the security of our Users, ensuring a safe and reliable digital environment.
* **Categories of data processed:**\
  Browsing and usage data, IP address, access logs, failed login attempts and suspicious activity, device information, browser type, device type and operating system, approximate location by region and country of access.
* **Category of data subjects:** Users who make use of the Platform
* **Method of collection:** shared by the User through browsing the Platform.
* **Applicable legal basis:**\
  Compliance with legal obligations regarding access and activity logging.\
  The processing will be based on the Controller's legitimate interest in investigating, detecting, preventing and prosecuting fraud, protecting its interests or those of third parties; as well as defending its interests against possible claims for contractual breaches or breaches of applicable regulations by Users and ensuring the correct and secure operation of the Platform, Users and third parties.
* **Retention period:**\
  Access and activity logs will be kept for 1 year, in accordance with Law 25/2007 on data retention in electronic networks. After said period, the data may be blocked for the legally established periods in order to comply with regulatory obligations and legal limitation periods if we consider there may be a risk of receiving a claim.
* **Disclosures to third parties:**\
  The collected data may be disclosed to our technology, IT and/or data hosting service providers that are essential to ensure the purpose for which it was collected, as well as to public authorities and security forces, when required.

#### Provision of contracted services

* **Purpose:**\
  The processing is carried out for the purpose of ensuring the provision of the Platform’s services consisting of:
  * Recording conversations through video calls in video and audio format, as well as transcribing them into text format and storing the recordings and transcripts. The Data Subject must be authorized to record and transcribe conversations in which third parties appear and must inform them of this circumstance and of their data protection rights.
  * Processing the Data Subject's calendars whose access has been explicitly granted.
  * Processing the Data Subject's emails whose access has been explicitly granted.
  * The processing will include handling requests, mandates or steps prior to and during contracting, as well as making communications regarding the operation of the service.
  * Likewise, data will be processed to ensure registration on the Platform and to manage payments, among other related processing activities that allow the provision of services and the performance of the contract.
  * If consent is obtained and the User configures it on their device, they may receive notifications on their device.
* **Categories of data processed:**
  * Billing identification data: first and last name, identity or tax number, passport or similar
  * Contact details: including email address and telephone number
  * Service-related information, including audio and video recordings, which may contain images and voice recordings of the Data Subject and of the third parties participating in the conversation
  * Payment data, including some digits of the bank card, security code and card expiration date, in case the services are contracted through the Platform. However, payment data will be shared by the User and stored by the payment gateway provider made available to the User to make payment for the services
  * Access data of registered Users, such as username, email address and, where applicable, the avatar designated by the User on the third-party platform through which they log in or register with SALESCALING (such as, for example, Google or Microsoft)
* **Categories of Data Subjects:**\
  Registered Users who contract and make use of the Platform's services and third parties who participate in conversations with the Data Subject; and workers or personnel dependent on the end customers who contract the Platform's services to integrate it within their company.
* **Method of collection:**
  * Directly from the Data Subject when the data is provided by them through use of the Platform
  * Through the companies that have integrated the Platform's services into their company and share the data with the Platform for the provision of the services
* **Legal basis:**\
  The processing is necessary for the performance of a contract to which the Data Subject or the company is party or in order to take pre-contractual steps at their request.
* **Retention period:**\
  While the services are being provided and, after their termination, your data may be blocked for the legally established periods in order to comply with regulatory obligations, including tax, commercial and anti-money laundering regulations, as well as during the statutory limitation periods.\
  Video and/or audio recordings will be retained for the period agreed in the service agreement and/or for the plan or subscription contracted by the User.
* **Disclosures to third parties:**\
  Your data will generally not be disclosed.\
  However, it may be disclosed to our external providers of essential technology, IT services, including cloud service providers, payment services, communications, generative artificial intelligence, and/or communication services when necessary to ensure the purpose in compliance with the performance of the service agreement. Likewise, it may be shared with the authorities when required by legal obligation or court order.

#### Sending commercial communications

* **Purpose:**\
  Sending commercial communications, offers, promotions, or similar, for products offered by the Controller, according to the different possibilities:
  * **Email communications:** Sending promotions and/or offers to the User's email address. The User may object to receiving commercial communications at any time by contacting the Controller's email address or, where applicable, through the enabled option included in the email itself.
  * **“Push” notifications:** Sending promotions and/or offers to Users' devices when they voluntarily configure this and through their consent. The user may stop receiving this type of notification by configuring their device accordingly.
  * **Third-party communications:** Users may receive communications from third parties only when they have previously given their consent. They may withdraw their consent at any time through the Controller's contact addresses.
  * **Personalized communications:** sending personalized communications according to Users' interests and preferences will require their prior consent, and it may be withdrawn at any time.

If the User wishes to stop receiving commercial communications, they may object at any time by contacting the Controller through its postal address, email address or through the channels enabled according to the different communication methods.

* **Data processed:**
  * Identification data: first and last name
  * Contact details: email
  * Organization data: trade name
  * Data related to the User's preferences, where applicable
* **Method of collection:** directly from the User.
  * **Registered Users or SALESCALING customers:** directly from the Data Subject through their registration on the platform.
  * **Unregistered Users:** directly from the Data Subject through their registration in forms, newsletter, and similar.
* **Legal basis:**
  * With regard to Registered Users or customers: it will be based on the Controller's legitimate interests in informing Users about contracted or similar products and relevant information, unless the User objects to such processing.
  * With regard to Users with whom there is no contractual relationship: consent will be required.
  * Consent will also be required for both registered and unregistered Users for the sending of push notifications, personalized communications, and third-party communications, until consent is withdrawn, objection is made or the account is deleted by the User.
* **Retention period:**\
  The data will be processed until the User withdraws their consent. In the event of user inactivity for 24 months, the Controller will stop sending commercial communications and will delete the data related to this processing.\
  Once the period has elapsed or consent has been withdrawn, the data may be blocked for the legally established periods in order to comply with the applicable regulatory obligations and legal limitation periods.
* **Disclosure:**\
  Your data will not be disclosed to third-party companies, except to those that provide IT, technology and/or technical services, and only to ensure the purposes mentioned.\
  Your data will not be sold or disclosed to third parties except after prior notice to the Data Subject and prior obtaining of their consent.

#### Resolution of inquiries made by the User

* **Purpose:**\
  To ensure communication by Users with the Controller to make customer service inquiries, file complaints, or similar, through any of the Controller's contact points including forms, email or postal addresses or others made available to the User.
* **Categories of data processed:**\
  Identification data, specifically first and last name and contact details, including email address and/or telephone number.
* **Categories of Data Subjects:**\
  Users who make the inquiry.
* **Method of collection:**\
  Directly from Users, when they contact the Controller directly or through external third-party providers subcontracted for this purpose.
* **Legal basis:**\
  Users' consent or the Controller's legitimate interest in responding to an inquiry after having received the request.
* **Retention period:**\
  Once the purpose for which they were collected has been achieved, the data will be kept for a maximum period of 24 months, unless longer retention is required for reasons of legitimate interest or legal limitation periods.
* **Disclosure:**\
  Your data may be disclosed to our providers of technology, IT and/or data hosting services, which are essential to ensure the purpose for which it was collected. Your data will not be sold to third parties.

#### Internal analysis and development

* **Purpose:**\
  The Controller may collect and process anonymized usage data to analyze the behavior and use of the Platform, browsing patterns, and functionalities used by the User in order to improve the user experience and optimize functionalities, analyze usage trends for the development of new tools or services, etc.
* **Categories of data:**\
  Anonymized data about platform usage, browsing patterns, and functionalities used.
* **Categories of Data Subjects:**\
  Registered Users and visitors to the platform (in anonymized form).
* **Legal basis:**\
  Legitimate interests in analyzing statistical and aggregated information to offer improved products and services to Data Subjects.
* **Method of collection:**\
  Data shared by the User in relation to the use of the Services.
* **Retention period:**\
  In order to fulfill the indicated purpose, the data may be stored and retained indefinitely, always in disassociated or anonymous form, so that the Data Subjects cannot be identified.
* **Disclosure:**\
  Your data will generally not be disclosed. However, it may be disclosed to our external technology, IT and/or data hosting service providers essential to ensure the purpose for which it was collected, including automation service providers; or to the authorities when required by legal obligation or court order. Your data will not be sold to third parties.

### Where do your data come from?

As a general rule, unless otherwise indicated in specific sections of this Policy, all data come from the Data Subject, either through browsing or using the Platform or through communication made by the User by any of the means made available to them.

### To whom do we disclose your data?

As a general rule, the Controller will not disclose your personal data to third parties, except when the provision of a service involves the need for a contractual relationship and it is strictly necessary for the management and maintenance of the relationship between the User and the Controller and/or to fulfill the purposes.

In such case, the disclosure will always take place only for the time strictly necessary to allow the purposes and in accordance with data protection principles, by applying the necessary and appropriate measures to ensure the protection of personal data (including the signing of a data processing agreement). Such processing will take place under the same or similar privacy and data protection conditions, commitments and responsibilities as those to which the Controller is subject. At the end of the transfer, the aforementioned transferees or processors will return the personal data to the Controller and delete any copies in their possession.

In this regard, and strictly for the purpose of fulfilling the purposes described in this Policy, the Controller may disclose your personal data to the categories of recipients indicated below:

* Essential service providers, including IT and technology services, such as, by way of example, payment gateway providers, cloud storage, communication sending, authentication and security services, and providers of artificial intelligence technologies, among others similar that are necessary to ensure the purposes.
* Public authorities, by court order or by legal requirement.
* Companies and/or consultants that help us in managing our services and fulfilling purposes.

You may request additional information about the disclosures made to the Controller through any of the contact points indicated in this Policy.

### Do we transfer data to third countries or international organizations?

As a general rule, no transfers of personal data to third countries or international organizations (“TTI”, hereinafter) will be carried out.

However, in order to ensure the purposes, TTI may be carried out to our service providers that are essential to ensure the purpose(s) for which they were collected. Likewise, regardless of the fact that SALESCALING does not carry out such TTI directly, such TTI may be carried out by the service providers.

In such case, the Controller will contract with providers that comply with the GDPR and by applying some of the safeguards provided for in Articles 44 et seq. of the GDPR, to ensure an adequate level of security in the processing of personal data, including an adequacy decision (list of countries based on an adequacy decision) or through Standard Contractual Clauses of the European Commission (“SCCs”, hereinafter).

For more information about international data transfers and the specific safeguards applied, you may contact us through the contact details indicated in this Privacy Policy.

### Do we process special categories of personal data?

The Controller will not request or process “special categories of personal data”, understood as data revealing “racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation”, in accordance with Articles 9 and 10 of Regulation (EU) No. 2016/679.

However, if the user decides to share such information, such processing will be carried out in accordance with their consent.

### Processing method

The processing of the data provided is based on the principles of lawfulness, fairness, transparency, purpose limitation and storage limitation, data minimization, accuracy, integrity and confidentiality, and will in any case be subject to the provisions of EU Regulation 2016/679 and Organic Law 3/2018, of December 5, on Personal Data Protection and guarantee of digital rights.

In particular, the processing may be carried out using paper, IT and telematic tools, also in accordance with the provisions of Article 29 of EU Regulation 2016/679 and, in any case, with appropriate means to ensure its security and confidentiality in accordance with the provisions of Article 32 of the same EU Regulation No. 2016/679.

### Automated decisions

There is no automated decision-making process, not even for profiling purposes, in accordance with Article 13.2(f) of EU Regulation No. 679/2016.

### Cookies

In addition to the processing described in this Policy, the Controller may also collect personal data through the use of cookies and other similar or analogous tracking technologies, as described in the Cookie Policy accessible via the following link.

### Retention of your personal data

As a general rule, the Controller will retain your personal data only for as long as necessary for the purpose for which it was originally collected, and for the maximum periods indicated in each of the processing activities referred to in this Policy.

#### Retention periods according to data type, purposes and applicable regulations:

| Type of Document/Data                          | Legal basis / applicable regulation | Retention period                         |
| ---------------------------------------------- | ----------------------------------- | ---------------------------------------- |
| Contractual documentation with clients         | Commercial Code                     | 6 years from termination of the contract |
| Money laundering                               | Law 10/2010                         | 10 years                                 |
| Users of the Platform and website              | GDPR and LOPDGDD                    | 5 years or until deletion request        |
| Traffic data (IP, IMSI, IMEI, etc.)            | LSSI and Data Retention Law         | 1 year                                   |
| Cookies and similar technologies               | LSSI                                | 18 months                                |
| Internal analysis and development (anonymized) | Art. 4.1 and Recital 26 GDPR        | Indefinite                               |
| Legal limitation periods (general)             | Art. 1967 of the Civil Code         | 5 years                                  |

Once the aforementioned periods have elapsed, the data will be automatically deleted, without prejudice to its subsequent retention in blocked form when necessary for compliance with certain obligations, by legal provisions or liability, or requests and/or orders issued by Public Administrations and/or Supervisory Authorities, for some of the reasons indicated in the previous sections.

With regard to anonymous information, the Controller will apply what is described in Recital 26 of the GDPR, which states that “the principles of data protection should therefore not apply to anonymous information, that is information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable”. Consequently, this Regulation does not affect the processing of such anonymous information, including for statistical or research purposes.

### What are the rights over your data?

In accordance with the GDPR, the Data Subject has the following rights regarding their personal data:

* **Access** to your data, which you can also consult in the “my data” section.
* **Rectification** of your data, because we also want to ensure that your information is accurate and up to date.
* **Erasure** of your data.
* **Restriction** of the processing of your data.
* **Objection** to the processing of your data, when the legal basis for processing is our legitimate interest.
* **Withdrawal of consent**, when the legal basis is your consent.
* **Portability** of your data, when the legal basis for processing your data is your consent or the performance of a contract.

To exercise your rights, the Data Subject may contact the Controller through the addresses designated in this Policy.

In addition, the Data Subject has the right to file a complaint with the Spanish Data Protection Agency (AEPD) if they have doubts or are not satisfied with the exercise of their rights or the processing we carry out. Their contact details are:

**Spanish Data Protection Agency -Spain- (AEPD)**\
Jorge Juan Street, 6\
Postcode: 28004 - Madrid\
Telephone assistance: +34 901 100 099 / +34 91 266 35 17\
<https://www.aepd.es>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.salescaling.com/en/compliance-and-legal/privacidad.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
