Privacy policy
A note on language. This document is offered in translation for convenience. In the event of any discrepancy, the Spanish version prevails, as it is the only legally binding one. Recompi is a Spanish company and Spanish law applies to this relationship.
How we process your personal data, in accordance with Regulation (EU) 2016/679 (GDPR) and the LOPDGDD.
1. Data controller
- Controller: Recompi S.L. [in incorporation]
- Tax ID (NIF): [B-00000000]
- Registered address: [full address], Valencia, Spain
- Email:privacidad@recompi.com
- Data Protection Officer: [if applicable, name and contact details]
2. Data we process
Depending on your relationship with us, we may process:
- Shops (customers): registration data (business name, business type, contact name, email and phone number; the phone number is required in order to verify the account and notify you of service incidents) and, only if you take out a paid plan, billing data (name or registered company name, tax ID (NIF/CIF), tax address and billing email). Card details are processed directly by our payment gateway; Recompi does not store them.
- Technical security data: when the registration form is submitted we check basic signals to stop automated sign-ups (for example, whether a hidden field only a bot would complete has been filled in, or whether the form was submitted in a time impossible for a person). These are one-off checks; they do not create a profile and are not used for any other purpose.
- Site visitors: browsing data and cookies (see Cookie Policy).
- Members / end customers of the shops: loyalty data (identifier and, where applicable, name, email, phone number and birthday) which we process on the shop's behalf (see point 7).
3. Purposes and legal basis
- Providing and managing the contracted service — performance of a contract (art. 6.1.b GDPR).
- Billing and compliance with legal and tax obligations — legal obligation (art. 6.1.c GDPR).
- Customer service and support — performance of the contract / legitimate interest.
- Sending commercial communications — consent (art. 6.1.a GDPR), which may be withdrawn at any time.
- Security of the Service (preventing automated sign-ups and abuse of the form): legitimate interest (art. 6.1.f GDPR) in protecting the Service and its users.
4. Data retention
We will keep your data for as long as the contractual relationship lasts and, thereafter, for the periods required by law (e.g. tax and commercial obligations). Data processed on behalf of a shop is kept in accordance with its instructions and the data processing agreement.
5. Recipients and processors
We do not disclose your data to third parties except where legally required. We work with providers acting as data processors, with whom we have signed the corresponding agreement under article 28 of the GDPR:
- Payment gateway: Getnet (Banco Santander Group), to process payments for paid plans. At no point does Recompi store your full card details.
- Hosting of the Site and the platform, with servers in the European Union.
- Transactional email delivery (account verification, invoices and service notices).
- Apple and Google, solely when you or your customers add a card to Apple Wallet or Google Wallet: the pass is delivered through their services.
Except in the case of digital wallets, we aim to keep data within the European Economic Area. Where a provider is located outside the EEA, the appropriate safeguards provided for by the GDPR apply (standard contractual clauses or others).
6. Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability by writing to privacidad@recompi.com, stating the right you wish to exercise. You may also lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) if you consider that the processing does not comply with the regulations.
7. Recompi as data processor
With regard to the data of the end customers of each shop, the shop is the data controller and Recompi acts as data processor (art. 28 GDPR), processing that data solely in accordance with the shop's instructions and the data processing agreement signed when contracting the Service. Each shop is responsible for informing its customers and for having the appropriate legal basis.
8. Security
We apply appropriate technical and organisational measures to protect personal data against loss, misuse or unauthorised access.
9. Changes to this policy
We may update this Privacy Policy. We will publish any changes on this page, stating the date of the last update.