Legal

Privacy Policy

How we process your personal data under the GDPR and the LOPDGDD.

Last updated: September 22, 2026 · Version: 2026-09-22

At Cofactu we take our users' privacy seriously. This policy describes what data we collect, how we use it, and what rights you have over it, in accordance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD).

1. Data controller

Codificado SL (sole-shareholder company), Tax ID (CIF) B75761601, registered office at Paseo de la Castellana 194, 28046 Madrid (Spain). Email: legal@cofactu.com

2. Data we collect

  • Account data: name, email, hashed password.
  • Tax data: tax ID, company name, address, your clients' and invoices' data. Required for compliance with VeriFactu regulations.
  • Payment data: managed by Stripe (we do not store card numbers).
  • Usage data: technical logs, product events via PostHog (with your explicit consent), errors via Sentry.
  • Employment data (only if you use the payroll and staff modules): your employees' identifying data, pay, withholdings, working time and absences. Some absences reveal health data (temporary incapacity, maternity or paternity leave) and certain payroll items may reveal trade union membership: these are special categories under Art. 9 GDPR and we process them solely on your behalf, in your capacity as employer, to manage the employment relationship and meet your obligations.

3. Purposes, legal bases and retention periods

Each purpose rests on its own legal basis under Art. 6 GDPR and has its own retention period:

PurposeLegal basisRetention period
Provision of the service (account, invoicing, accounting, contracted modules)Performance of a contract (Art. 6.1.b)Life of the account; after closure, deletion or blocking per category (see below)
Issuing and submitting invoicing records to the AEAT; retention of invoices and booksLegal obligation (Art. 6.1.c — Spanish General Tax Act, RD 1007/2023)Tax and commercial periods: 4-year limitation (art. 66 LGT) and 6-year commercial retention (art. 30 Commercial Code)
Payroll and staff management (if you enable the module, on the employer's behalf)Performance of a contract + the employer's legal obligationsThe employment and Social Security periods applicable to the employer
Service communications (support, operational notices, account notifications)Performance of a contract (Art. 6.1.b)Life of the account + 1 year
Platform security: technical logs, abuse and fraud prevention, access auditingLegitimate interest (Art. 6.1.f): keeping the service safe for all customers. Balancing test available on requestTechnical logs: 12 months; audit records: life of the account
Error monitoring (Sentry)Legitimate interest (Art. 6.1.f): detecting and fixing software defects90 days
Product analytics (PostHog)Consent (Art. 6.1.a) — only if you accept analytics cookies; withdrawable at any timeUntil consent is withdrawn; event data, 12 months at most
Codificado SL's own invoicing to the customer (our invoices)Legal obligation (Art. 6.1.c)Codificado SL's own tax and commercial periods

4. Retention after account closure

  • Data the customer must retain (invoices, VeriFactu records, books): kept blocked for the tax and commercial periods, or returned/deleted per the DPA where the customer is a controller of third-party data.
  • Account data: deleted upon user request or after 24 months of inactivity, with prior email notice.
  • Blocked archive (art. 32 LOPDGDD): deleted data is kept blocked, with restricted access, solely for disclosure to courts and public authorities during limitation periods, and destroyed afterwards.

5. Recipients

We share data with the following data processors, from whom we require sufficient guarantees under Art. 28 GDPR. Those marked optional are only involved if you enable the corresponding feature:

Infrastructure

  • Cloudflare — hosting, content delivery, file storage and abuse protection (EU). Since August 2026 it also operates the service that transmits invoicing records to the AEAT, and therefore processes the invoice content and, when you use your own digital certificate, the certificate during submission
  • Neon — PostgreSQL database (EU, eu-central-1 region, Frankfurt)
  • Sentry — error monitoring
  • PostHog — product analytics (EU, only with your consent)

Communications and payments

  • Stripe — payment processing
  • Resend — transactional email delivery
  • Twilio — SMS and WhatsApp delivery (account with data residency in Ireland) — optional

Artificial intelligence (assistant and automatic document reading)

  • Google (Gemini API) — language model
  • Voyage AI — indexing of the tax knowledge base; receives only the text of the query

Features you enable

  • Google Wallet — issuance of digital loyalty cards, if your business offers them — optional
  • Third-party integrations (Sage, Holded, Microsoft, Google and similar) — when you connect one of these accounts, the data you choose to synchronise is sent to that provider on your instruction — optional

Public administration

  • AEAT — submission of invoicing records and tax returns (legal obligation)

Where you act as controller of third-party data (e.g. accounting firms managing their clients), processing is additionally governed by our data processing agreement (DPA), whose annex holds the current list of sub-processors.

6. What data the artificial intelligence receives

The assistant and automatic document reading (OCR) send the AI provider the information needed to resolve each request. That includes the text of your query, the results of the searches the assistant runs against your own data (names and tax IDs of clients and suppliers, amounts, due dates, balances), the content of the documents you upload or that arrive in your expense inbox and, if you use the payroll module, the payslip data, including the employee's name, tax ID and amounts.

These providers act as data processors and, under their terms for paid API customers, do not use this data to train their models. The assistant and OCR are optional features: if you do not use them, nothing is sent to these providers.

7. International transfers

Hosting and the database are located within the European Union. Some processors (Stripe, Resend, Sentry, Google and Voyage AI) may process data outside the European Economic Area; in that case, the transfer relies on an adequacy decision or on the European Commission's Standard Contractual Clauses (SCC), with any appropriate supplementary measures.

8. User rights

You have the right to access, rectify, erase, object to, restrict the processing of, port your data, and withdraw consent. To exercise these rights, write to privacidad@cofactu.com from your account email. You do not need to provide identity documents: we will only ask for them if there are reasonable doubts about your identity, and then only the minimum needed to resolve them (Spanish DPA criterion).

You may also file a complaint with the Spanish Data Protection Agency (aepd.es).

9. Cookies

See our Cookie Policy.

10. Transport documents signed or received through Cofactu

If you sign an electronic consignment note (e-CMR) or proof of delivery (POD) generated with Cofactu, the company issuing the document is the controller and Codificado SL acts as its processor. Before signing, you are shown a specific notice identifying the controller, the purpose, the legal basis and how to exercise your rights.

Identity and technical signing evidence are used to document the transport and prove the integrity of the document, based on performance of the contract where the signer is personally a party or on the parties' legitimate interest in proving the transaction. Consent is not requested for this processing. A handwritten POD signature is retained as an image of acknowledgement: Cofactu does not extract its dynamics or create a biometric template.

e-CMR records and their evidence file are retained for the applicable commercial period, normally six years. Standalone PODs are retained for 24 months and, where they support an e-CMR, inherit its six-year period. Public access to the POD PDF expires after twelve months; photographs and location data remain private. Exercise your rights with the issuing company. If you do not know who it is, email privacidad@cofactu.com and we will help identify it.

11. Electronic transport control document (DeCA)

From 5 October 2026 the control document that accompanies every road freight transport in Spain must be electronic (Resolution of the Directorate-General for Road Transport of 5 June 2026; Order FOM/2861/2012). When a Cofactu customer issues a DeCA, that company is the controller and Codificado SL acts as its processor.

What it contains. The data listed in article 6 of the Order: identity and tax ID of the contractual shipper and the effective carrier, the shipper's address, transport date, licence plates, origin, destination, nature and weight of the goods and, only in passenger route sheets, the driver's identity. It is provided by the customer issuing the document.

Purpose and legal basis. Producing the document required by transport regulations and making it available to the inspection authorities and to the other party to the contract. The legal basis is compliance with a legal obligation of the issuing company (Art. 6(1)(c) GDPR). No consent is requested.

Recipients. The regulation requires the document to be downloadable directly, without logging in, through a unique link shown in the PDF and in a QR code. That link is given to the driver and to the other party and may be presented to roadside transport inspectors. Anyone holding the link can download the document while it is active; the link is therefore protected by a high-entropy random identifier, is not indexed by search engines and is rate-limited against automated sweeps. The download history records only the date, the document and its version — not the IP address or the browser. For a separate purpose — preventing automated bulk downloading — the requester's IP address is processed temporarily, kept for at most ten minutes from their last request and never linked to that history.

Retention. The regulation sets a floor: Art. 9 of Order FOM/2861/2012 requires the document to be kept for at least one year, available to the Land Transport Inspectorate. On top of that minimum, Cofactu applies its own custody policy: it retains the full file — every version included — for twelve months counted from the later of the issue of its last version and the effective end of the transport. Once that period elapses, the document is deleted. That period also applies if the account or the issuing company is closed, because the document contains the other party's data and both parties must be able to produce it to the inspection authorities. Availability of the public link is independent of retention of the file: the regulation allows downloads to be disabled seven days after the service ends, and Codificado SL may replace or disable a link for security or compliance reasons without affecting retention of the document. The download log is kept for twelve months.

Your rights. Exercise them with the issuing company; if you do not know who it is, email privacidad@cofactu.com and we will help identify it. Erasure requests are handled under the applicable law. Where certain data must be retained to comply with a legal obligation or to defend legal claims, you will be told which data, why, and for how long or on what criteria; that necessity is assessed case by case and does not prevent erasing the rest (Art. 17(3)(b) GDPR).

Ready to invoice without the headaches?

Start free or browse the plans. Your first VeriFactu invoice in under 10 minutes.

No card requiredCancel in 1 clickExport anytime