This translation is provided for convenience. In case of any discrepancy, the Spanish version (/es/legal/…) prevails.
Privacy policy and data processing agreement (DPA)
Last updated: 30 July 2026
1. Purpose, roles, and scope
This document is Sedeclick’s Privacy Policy (operated by SedeClick LLC, Albuquerque, NM 87110, United States) and serves as a Data Processing Agreement (DPA) under GDPR Art. 28 and Spanish LOPDGDD.
B2B model: Data Controller — the Gestoría (decides what end-client data is uploaded). Data Processor — Sedeclick (processes on the Gestoría’s instructions).
Purpose: automated reading, structured extraction (LLM), and business-rule validation to optimise gestoría workflows.
2. Data processed
Identity documents (passport, NIE, TIE), employment and financial data (payslips, work history, tax forms), and other immigration case files.
Gestoría contact data (email, phone) and, when messaging channels are used (WhatsApp Business, Telegram), message content and attachments sent under the Controller’s instructions.
Technical data: logs, IP, browser type (security and diagnostics). We do not request Digital Certificate, Cl@ve, or public authority passwords.
3. Zero AI training clause
No personal data, uploaded document, or processing result will ever be used to train, fine-tune, calibrate, or benchmark AI models (ours or third parties).
Platform improvement uses synthetic data, empty public templates, and deterministic rule-engine updates — not client document content for model training.
4. Sub-processors
Railway — hosting, databases, and file storage (EU-region infrastructure).
Vercel — frontend hosting.
Google Ireland Limited / Gemini API — document perception layer (enterprise API; no training retention per provider terms).
Resend — transactional email (when active).
Lemon Squeezy, LLC — planned payment processor when commercial billing is activated (does not process case documents).
5. International transfers
Sedeclick is established in the United States (outside the EEA, no adequacy decision). Staff access for maintenance/support is covered by EU Standard Contractual Clauses (Modules 2 and/or 3).
Physical storage of Service data remains within the European Union.
6. Retention and lifecycle
Source files (PDF, JPG, scans): kept up to 90 days from last case activity, unless the Gestoría requests earlier deletion (info@sedeclick.com or “Delete case” in the panel).
Extraction results (JSON and validation reports): for the account lifetime and up to 90 days after cancellation, unless legally required otherwise.
Account metadata and security logs: minimum periods needed for operations, support, and legal compliance.
7. Security measures
TLS 1.2+ in transit; AES-256 at rest for databases.
Multi-tenant architecture with logical separation per gestoría.
Production access with MFA and least privilege for Sedeclick staff.
8. Data subject rights and breaches
Sedeclick provides tools for the Gestoría (Controller) to handle access, rectification, erasure, and objection requests. Sedeclick does not respond directly to the Gestoría’s end clients.
Security breaches: notification to the Gestoría without undue delay and within 48 hours of becoming aware, with information sufficient for AEPD notification if required.
9. Cookies
Technical cookies required for the site to function.
Analytics cookies only with prior consent (when implemented).
Privacy and DPA: info@sedeclick.com · Data Protection · SedeClick LLC · Albuquerque, NM 87110, United States