Privacy policy

What personal data TallerIQ processes, why, for how long, and what you can require of us.

Last updated: 24 August 2026

1. Two different roles, worth not confusing

TallerIQ is a platform that car workshops subscribe to in order to run their work. That means we process personal data in two different legal positions, and your rights are exercised differently in each.

We are the CONTROLLER of the data we collect on our own account: the website mockup requests sent from this site, the accounts of the people who use the platform, and the technical security logs. That is what this policy is about.

We are a PROCESSOR for the data belonging to each workshop's own customers: their vehicles, repair orders, invoices, and the bookings made from the workshop's website. There the workshop is the controller, not us. We process that data only on the workshop's instructions and under a data processing agreement. If you are a workshop's customer and wish to exercise your rights, contact the workshop.

2. What we process as controller

Website mockup requests. When a workshop asks for a mockup of its future website, we store the business name, address, telephone number, current website if there is one, brand colours, and any logo or image uploaded. The legal basis is consent (GDPR art. 6.1.a), recorded with its date and the exact wording accepted, and it can be withdrawn at any time.

User accounts. For people who use the platform we process the email address, name, and the role held within their workshop. The legal basis is performance of the subscription contract (GDPR art. 6.1.b).

Workshop staff. When the workshop owner records someone who works there — whether or not they ever have an account on the platform — we process their name, the job they do, and their start and end dates. When the workshop chooses to record them, also their NIE or DNI, postal address, phone, email and the employer's internal notes. The legal basis is the workshop's legitimate interest in managing its own staff (GDPR art. 6.1.f), and compliance with the labour and tax obligations that apply to it as an employer where they exist (GDPR art. 6.1.c). The NIE or DNI, the address and the employer's notes are accessible only to the workshop owner and whoever administers the team; the rest of the staff see only the name and the job. These are kept for as long as the relationship with the workshop lasts and the obligations that follow from it, not indefinitely by default.

Technical logs. We keep a record of significant actions taken in the platform, including the IP address. The legal basis is our legitimate interest in the security of the service and in being able to investigate unauthorised access (GDPR art. 6.1.f).

Subscription billing. The tax details needed to invoice you are processed to comply with a legal obligation (GDPR art. 6.1.c).

Visitor measurement, without cookies. We count visits to the public pages from the server. For each visit we keep four things: the page's route, the language it was served in, the domain the visitor arrived from — the domain only, never the full address and never what was searched for — and whether the device is a phone, a tablet or a computer. The time is rounded to the hour. We do not keep the IP address, the browser, any identifier, or anything that would let two visits be joined together as the same person. We write nothing to your device: no cookies, no local storage, no script. That is why this measurement does not ask for your consent: article 5(3) of the ePrivacy Directive governs what is stored on or read from your equipment, and here nothing is stored or read; and what we do record cannot identify you, so it is not personal data. These records delete themselves after 90 days.

3. How long we keep each thing

The periods below are what the system actually carries out, not an intention: they are implemented in the database retention function and run on a schedule.

Mockup requests: 24 months from submission, then deleted.

Bookings received through a workshop's website: 24 months, unless the workshop instructs a different period as controller.

IP addresses in the technical logs: 90 days, after which they are cleared and the log keeps only the action and its date.

Invoices issued through the platform: kept for the periods Spanish tax law requires. In addition, and this matters, they form a chained, immutable sequence required by the verifiable invoicing regime (VeriFactu, Royal Decree 1007/2023). An issued invoice cannot be deleted or modified, not even at the request of the data subject or of the controller itself; an error is corrected by issuing a corrective invoice. This retention relies on GDPR art. 17.3.b.

The visit records described above: 90 days, and they delete themselves.

4. Who else processes this data

We do not sell personal data and we do not share it for advertising. We do rely on providers who process it on our behalf, each under a processing agreement:

Supabase — database, file storage and authentication. The data is held in the eu-west-1 region (Ireland), inside the European Union. Checked on 24 August 2026 against the real project, not assumed.

Netlify — site hosting and execution of server functions.

Stripe — subscription payment processing. Full card details are entered into Stripe's systems; TallerIQ neither receives nor stores them.

Anthropic — the assistant and the indicative estimator send text to its API to obtain a response. In the estimator that text is the free description a visitor writes; in the assistant, workshop notes that may contain customer data.

No email provider has been engaged yet. When one is, this list will be updated before any mail is sent.

Nor is there an error-tracking service. The code is ready to send server errors to one but it is switched off: nothing is sent. If it is switched on, the provider will appear in this list before the first event, the project will be in the European Union, and a processing agreement will be signed. The errors that would be sent contain no customer data.

5. Transfers outside the European Union

The database is in Ireland, within the EU. Some of the providers above are, however, United States entities or process data from outside the European Economic Area — in particular Anthropic and Netlify.

Those transfers rely on the safeguards in Chapter V of the GDPR: standard contractual clauses approved by the European Commission and, where the provider is certified, the EU-US Data Privacy Framework. You may ask us for a copy of the safeguards applying to a particular provider.

6. Automated decisions

The cost estimator on the site suggests which services might be involved in the fault a visitor describes, and shows an indicative price range. It is not a quotation and it produces no legal effect on anyone: no decision is taken automatically. The estimate a customer receives is prepared and approved by a person at the workshop.

There is therefore no automated individual decision-making of the kind covered by GDPR art. 22. That is stated here expressly so nobody has to infer it.

7. Your rights

You may request access to your data, its rectification or erasure, restriction of processing, portability, and you may object to processing based on legitimate interest. Where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out beforehand.

To exercise them, write to us through the contact channel shown above, identifying yourself sufficiently. We will reply within one month.

There is one exception worth knowing in advance: invoices already issued cannot be deleted, for the legal reason described in section 3.

If you believe we have not handled your request properly, you may complain to the Spanish Data Protection Agency (www.aepd.es), without prejudice to any other remedy.

8. Changes to this policy

If we change this policy, the date at the top changes with it. Earlier versions are recorded in the platform's source history, so it is always possible to establish what this page said on a given date.

    Política de privacidad — TallerIQ