Privacy policy
Last updated: 28/07/2026
At Sarean, we process personal data in two different ways, and it is important to distinguish between them from the outset:
- As a data controller, when we manage the data of people who visit our website, request information, or subscribe to and use the platform. This is the processing described in this policy.
- As a data processor, when we process, on behalf of our customers, the data they add to the platform, such as conversations with their own customers through WhatsApp or Instagram. In those cases, the customer is the data controller, and the applicable terms are set out in the Data Processing Addendum.
1. Data Controller
- Company: Desarrollo de Plataformas Digitales, S.L.
- Tax ID (CIF): B87.934.352
- Registered office: Avda. Lisboa 4, 28924 Alcorcón (Madrid), Spain
- Privacy contact email: hola@softspring.es
- Data Protection Officer: [no Data Protection Officer has been appointed, as the circumstances set out in Article 37 of the GDPR do not apply / DPO contact details]
2. What Data We Process, Why We Process It and Our Legal Basis
2.1. Contact Form and Information Requests
- Data: name, email address, telephone number, company and the content of your message.
- Purpose: to respond to your enquiry and contact you.
- Legal basis: your consent (Article 6(1)(a) GDPR) or taking steps at your request before entering into a contract (Article 6(1)(b) GDPR).
- Retention: for as long as necessary to handle your request and, afterwards, for [1 year] in case you contact us again, unless you request deletion sooner.
2.2. Registration and Use of the Platform
- Data: identification and contact details of the user, login credentials, customer company details, billing information, activity logs and technical connection data, such as IP address, browser and timestamps.
- Purpose: to create and manage your account, provide the contracted service, offer support, issue invoices and collect payments, and ensure the security and traceability of the platform.
- Legal basis: performance of the contract (Article 6(1)(b) GDPR), compliance with accounting and tax-related legal obligations (Article 6(1)(c) GDPR), and our legitimate interest in protecting the platform and preventing fraud (Article 6(1)(f) GDPR).
- Retention: for as long as the account remains active. After cancellation, the data will be restricted for the applicable statutory limitation periods—up to 6 years for commercial documentation under Article 30 of the Spanish Commercial Code and 4 years for tax purposes under Spanish Law 58/2003—and will then be deleted.
2.3. Marketing Communications
- Data: name and email address.
- Purpose: to send you product updates, content and offers from Sarean.
- Legal basis: your consent (Article 6(1)(a) GDPR). If you are already a customer, our legitimate interest in promoting products or services similar to those you have purchased, in accordance with Article 21.2 of the LSSI, with the option to object at any time.
- Retention: until you withdraw your consent or object to the processing. You can unsubscribe using the link included in each communication or by writing to hola@softspring.es.
2.4. Connecting Third-Party Accounts
When you connect an external account to Sarean, such as Google Business Profile, WhatsApp Business or Instagram, we access it through the providers' official interfaces and only with the permissions you expressly grant during the connection process.
- Data: account identifiers, access tokens, business profile information, and the messages and content you manage through the platform.
- Purpose: to allow you to manage your online presence and conversations from one place.
- Legal basis: performance of the contract (Article 6(1)(b) GDPR).
- Important: personal data relating to your own customers that reaches the platform through these channels is processed under your responsibility. We act as a data processor in accordance with the Data Processing Addendum.
2.5. Website Browsing and Analytics
- Data: aggregated website usage metrics, such as pages visited, traffic source, device type and country.
- Purpose: to understand how the website performs and improve it.
- Legal basis: our legitimate interest in analysing and improving our services (Article 6(1)(f) GDPR).
- How we do it: we use Plausible Analytics, a tool that does not place cookies, create persistent identifiers or build user profiles, and which hosts data in the European Union. There is no cross-site tracking or disclosure of data for advertising purposes.
- Retention: [24 months] in aggregated form.
You can find further information in our Cookie Policy.
3. Source of the Data
The data is provided by you, by the person in your organisation who manages the account, or by the third-party platforms you choose to connect. We do not obtain data from publicly available sources or purchase it from third parties.
4. Recipients and Data Processors
We do not disclose your data to third parties unless required to do so by law. We do, however, use service providers that may access the data in order to provide services to us. We enter into the data processing agreements required under Article 28 of the GDPR with those providers.
| Provider | Service | Location |
|---|---|---|
| Google Cloud EMEA Ltd. | Hosting and infrastructure | European Union ([region]) |
| Plausible Insights OÜ | Cookie-free web analytics | European Union |
| Stripe Payments Europe, Ltd. | Payment processing and billing | Ireland, with possible access from the United States |
| Brevo SAS | Service emails and marketing communications | France / European Union |
| Meta Platforms Ireland Ltd. | WhatsApp Business and Instagram messaging | European Union / United States |
| ARBICHAT, S.L. (Zernio) | WhatsApp Business API intermediation | Spain |
| Tax and accounting adviser | Compliance with legal obligations | Spain |
In the case of Stripe, your payment card details are entered directly into Stripe's secure payment environment and are never stored in our systems. We retain only your billing details and a transaction reference. Stripe also acts as an independent data controller in relation to processing carried out to comply with its own legal obligations concerning fraud prevention and anti-money laundering, in accordance with its own privacy policy.
We may also disclose data to courts, public authorities and law enforcement agencies where required by law.
5. International Data Transfers
We prioritise providers whose infrastructure is located in the European Union. Where processing involves a transfer outside the European Economic Area, we rely on:
- An adequacy decision adopted by the European Commission, such as the EU-U.S. Data Privacy Framework for certified providers.
- The Standard Contractual Clauses approved by the European Commission, together with a transfer impact assessment and additional technical measures such as encryption in transit and at rest.
You may request a copy of the safeguards applied by writing to hola@softspring.es.
6. Your Rights
You may exercise your rights of access, rectification, erasure, objection, restriction of processing and data portability at any time, as well as your right not to be subject to automated decision-making that produces legal effects or similarly significantly affects you. Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before its withdrawal.
To exercise these rights, write to hola@softspring.es or to Avda. Lisboa 4, 28924 Alcorcón (Madrid), Spain, stating which right you wish to exercise and attaching a document that allows us to verify your identity. We will respond within one month. This period may be extended by a further two months where the request is particularly complex.
If you believe that we have not handled your request correctly, you may lodge a complaint with the Spanish Data Protection Agency, located at C/ Jorge Juan 6, 28001 Madrid, through www.aepd.es, without prejudice to your right to contact us first.
If you are a customer of a company that uses Sarean and wish to exercise your rights in relation to data managed by that company through our platform, you must contact the company directly, as it is the data controller. If you contact us, we will forward your request to the relevant company without undue delay.
7. Security Measures
We implement technical and organisational measures appropriate to the level of risk, in accordance with Article 32 of the GDPR. These measures include encryption of communications using TLS and encryption of data at rest, role-based access controls, enhanced authentication for staff with privileged access, activity logs, regular backups with restoration testing, separation of environments and confidentiality commitments for all personnel.
If a personal data breach is likely to pose a risk to your rights and freedoms, we will notify the Spanish Data Protection Agency within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk, we will also notify you directly.
8. Children
Sarean is a service intended for businesses and professionals. It is not intended for children under the age of 14, and we do not knowingly collect their personal data.
9. Changes to This Policy
We may update this policy to reflect legal, regulatory or service-related changes. The current version will always be published on this page together with its last updated date. If the changes are material, we will notify you by email or through the platform.