Skip to content

Privacy Policy

Last updated: June 25, 2026

1. General Information

At LAVORA we are committed to protecting the privacy and personal data of the users of our website (lavora.pro), our management application (app.lavora.pro), and those who contact us. This Privacy Policy is drawn up in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and Organic Law 3/2018 of 5 December on the Protection of Personal Data and guarantee of digital rights (LOPDGDD).

Accessing and using the site or contracting any of our services implies acceptance of this policy. We reserve the right to modify it to adapt to regulatory or jurisprudential developments; changes will be published on this same page.

2. Data Controller

The controller of the personal data collected through LAVORA is:

  • Controller: Carmelo Ruymán Quintana Santana (Autónomo).
  • Tax ID (NIF): 54083461L.
  • Address: Calle Espinero 24, 35119, Santa Lucía de Tirajana, Las Palmas de Gran Canaria.
  • Contact email (including data subject rights): info@lavora.pro.

3. Data We Process

We process the following categories of personal data, depending on your relationship with us and the services contracted:

  • Identifying data: first name, surname, ID/DNI/NIF, email address and contact phone number.
  • Company data: company name, CIF (tax identification number), registered address and banking details (IBAN) for direct debit collection.
  • Billing data: issued and received invoices, as well as customer and supplier data that the user enters in the application for managing their business.
  • Usage data: IP address, browser type and version, pages visited, date and time of access, and anonymous analytics metrics.
  • Payment data: managed exclusively by our provider Stripe through tokenization. LAVORA never stores card numbers or full card payment details at any time.

4. Purpose and Legal Basis of Processing

Data is processed solely for the purposes described below, based on the legal ground that in each case enables processing under the GDPR:

Purpose Legal basis Data processed
User account management and authentication Performance of a contract (Art. 6.1.b GDPR) Identifying data, email
Provision of the ERP service (invoicing, accounting, CRM, etc.) Performance of a contract (Art. 6.1.b GDPR) All data entered by the user
Billing and payment collection Performance of a contract + legal obligation (Art. 6.1.b and 6.1.c GDPR) Identifying data, banking (IBAN)
Submission of invoices to the AEAT (VeriFactu) Legal obligation — RD 1007/2023 and Order HAC/1177/2024 (Art. 6.1.c GDPR) Tax data of issued invoices
Anonymous web analytics and error tracking Consent (Art. 6.1.a GDPR) Anonymous usage data (IP, pages visited, session)
Customer support and issue resolution Legitimate interest (Art. 6.1.f GDPR) Identifying data, content of enquiries
Sending commercial communications and news Consent (Art. 6.1.a GDPR) Email

Where processing is based on consent, this may be withdrawn at any time, without affecting the lawfulness of the processing carried out prior to withdrawal. Withdrawing consent does not affect the use of the site, except in relation to the features linked to that processing.

5. Data Retention

Data is retained for as long as necessary to fulfil the purpose for which it was collected and, where applicable, for the legally required periods:

  • Account data: for as long as the contractual relationship is maintained and, after termination, for an additional 90-day period to allow reactivation. After that period, deletion is carried out.
  • Tax and billing data: 6 years, in accordance with Article 30 of the Spanish Commercial Code and applicable tax and accounting obligations.
  • Analytics data: a maximum of 12 months, properly anonymised.
  • Job applications: if you send us your CV spontaneously, we will keep your data for a maximum of 2 years to evaluate you in future selection processes, unless you request its deletion earlier.

6. Data Recipients (Processors)

LAVORA does not transfer personal data to third parties for commercial purposes. To provide the service, we rely on the following processors, all of them bound by the corresponding data processing agreements pursuant to Article 28 of the GDPR:

  • Supabase — Backend, PostgreSQL database and authentication. Servers in the European Union (Frankfurt / Ireland). GDPR compliant.
  • Stripe — Payment processing. Complies with the PCI-DSS Level 1 standard. Card data is tokenised and not stored on LAVORA servers. It may process data in the United States under Standard Contractual Clauses (SCC) approved by the European Commission.
  • Cloudflare — Hosting of the public website and content delivery network (CDN). GDPR compliant.
  • AEAT (Agencia Estatal de Administración Tributaria — Spanish Tax Agency) — Mandatory submission of invoices through the VeriFactu system (Order HAC/1177/2024). This is a transfer to a public authority by legal obligation.
  • PostHog (self-hosted installation) — Anonymous web analytics, error tracking and audience measurement. Hosted on our own infrastructure; does not share data with third parties.

7. International Data Transfers

As a general rule, data is processed within the European Economic Area (EEA). The international transfers that may occur are as follows:

  • Stripe may process data in the United States under Standard Contractual Clauses approved by the European Commission, as described in its privacy policy.
  • Supabase has servers in the European Union, so no transfers outside the EEA occur within the scope of our service.
  • The remaining processors (Cloudflare, AEAT and self-hosted PostHog) do not make international transfers relevant to the personal data processed.

8. User Rights (Data Subject Rights)

As a data subject, you have the right to exercise, free of charge, the following rights over your personal data:

  • Access to your personal data.
  • Rectification of inaccurate or incomplete data.
  • Erasure (right to be forgotten).
  • Restriction of processing.
  • Objection to processing.
  • Data portability.
  • Not to be subject to automated decisions, including profiling.
  • Withdrawal of consent given, at any time.

To exercise these rights you can write to us at info@lavora.pro attaching a copy of an identifying document (DNI/NIE/NIF). We will respond to your request within a maximum of one month of receipt, a period that may be extended up to three months in cases of special complexity, of which we will duly inform you.

Furthermore, if you consider that the processing of your data infringes applicable regulations, you may file a complaint with the Spanish Data Protection Agency (AEPD) through its electronic headquarters www.aepd.es.

9. Security Measures

We apply appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing, including:

  • Encryption of communications in transit using TLS 1.3.
  • Encryption of data at rest (AES-256) in the database.
  • PostgreSQL Row Level Security (RLS) for multi-tenant isolation between companies.
  • Secure user authentication managed by Supabase Auth.
  • Periodic backups and recovery procedures.
  • Logging and auditing of system access.

10. Modifications

The controller reserves the right to modify this Privacy Policy to adapt it to regulatory, jurisprudential or AEPD criteria developments. Changes will be communicated through this website, indicating the date of last update shown in the document header.

11. Data Protection Officer (DPO)

As the controller is a natural person operating as a sole trader (autónomo), the appointment of a Data Protection Officer (DPO) is not mandatory pursuant to Article 37 of the GDPR. Any enquiry related to data processing may be addressed to info@lavora.pro.

This document has been drafted in accordance with current regulations. For specific cases, we recommend consulting a specialised legal advisor.