Privacy policy
What data of yours we keep, why, for how long, who else sees it and how it is deleted.
Last updated: 22 September 2026
1.Who processes your data
- Controller
- María Cantó Martínez
- NIF (tax ID)
- 47947433T
- Address
- Calle de Pastora Martos 23, 3.º C, 08174 Sant Cugat del Vallès (Barcelona)
- Privacy email
- hola@ganasubvenciones.com
- Data Protection Officer
- None has been appointed: it is not mandatory in this case (art. 37 GDPR and art. 34 LOPDGDD). Everything is handled at the privacy email address.
This processing is governed by Regulation (EU) 2016/679 (GDPR) and by Ley Orgánica 3/2018, de protección de datos personales y garantía de los derechos digitales (LOPDGDD), Spain's data protection and digital rights act.
2.What data we collect
Only what the service needs to work. We do not buy lists, we do not enrich profiles with outside data and we do not track browsing.
- From the account: name, email address, the password – of which only a digest is stored, one that cannot be used to recover it, never the password in plain text – whether the email address has been verified, the plan taken out, alert preferences and the date on which the legal notice and this policy were accepted.
- From the organisation: name, type, CIF, date established, register entry details, address, telephone number and contact email, website, fields of work, territories, the groups it supports, budget, number of paid staff, volunteers and beneficiaries, years of experience, mission, recognitions, certifications and logo. Also the name, position and NIF (personal tax ID) of the person who signs on its behalf, and the composition of its board or board of trustees.
- From each open session: the IP address and the browser it was opened from, with the date. They are there so sessions can be seen and closed from the dashboard, and so unusual logins can be spotted.
- From use of the service: the calls you follow, the applications you prepare, the tasks, the documents you upload and the analyses you request.
- From billing, if there is a paid plan: the Stripe customer, subscription and invoice IDs, and the payment history. Card details never pass through our servers at any point: Stripe collects them directly.
- From project-writing orders, if you place one: the project title and description, the amount being requested, the date it is needed by, the notes, the attached documents and the report that is delivered. They are read by the team that writes it, who are people, and the card hold and the charge are handled by Stripe.
- From the newsletter, if someone signs up: only the email address, which page they signed up from and the date.
- Technical logs: the web server and the API record the IP address, the date and the browser of every request. They are used to diagnose faults and curb abuse, and they rotate automatically. Cookies and credentials are stripped from the log before it is written.
3.What for, and on what legal basis
- Providing the service: creating the account, storing the organisation's profile, working out fit with the calls, alerting you to deadlines and managing applications. Basis: performance of the contract (art. 6(1)(b) GDPR).
- Charging for the paid plans and keeping the accounts. Basis: performance of the contract and compliance with legal tax and commercial obligations (arts. 6(1)(b) and 6(1)(c)).
- Keeping the service secure: sessions, request limits, detection of unauthorised access and backups. Basis: the legitimate interest in protecting accounts and information (art. 6(1)(f)).
- Storing the date on which these texts were accepted, so we can show when and which version was accepted. Basis: compliance with a legal obligation and the duty of accountability (arts. 6(1)(c) and 5(2)).
- Sending the newsletter and commercial communications. Basis: consent (art. 6(1)(a) GDPR and art. 21 of the LSSI-CE, Spain's information society services and e-commerce act). It starts out switched off: you have to tick a box yourself, and it can be withdrawn whenever you like from the email itself or from the dashboard.
Alerts about deadlines and about changes to your calls are not advertising: they are the service you have signed up for, which is why they come switched on. Even so, they can be switched off completely, or only certain kinds, from the account preferences.
No automated decisions with legal effects are taken about anyone. Fit analysis is guidance addressed to the organisation about itself: it decides nothing – whoever reads it decides.
4.What your organisation uploads
The annual reports, the projects and the documents an organisation uploads are its own. It is the controller of that content and we act as its processor: it is stored, it is processed for what was asked for and it is used for nothing else.
A warning worth reading: those documents sometimes carry data about the people the organisation supports, and analysing them means sending them to the artificial intelligence provider. Before uploading anything, remove the names and identifying details the analysis does not need. With an anonymised project the result is the same.
5.How long we keep them
- The account and the organisation's profile, for as long as the account is open. When it is closed they are deleted, and with them the sessions, the documents and everything else hanging off the account.
- Sessions, with their IP address and browser, thirty days at most. They are deleted sooner when you log out or change the password, which closes them all.
- The links for verifying an email address and for resetting a password expire on their own and are marked as used as soon as they are used.
- Invoices and accounting entries, six years from the last entry, as the Código de Comercio, the Spanish commercial code, requires, and four years for tax purposes. That period cannot be shortened even if the account is closed.
- The record of who does what inside an organisation — who uploaded a document, who moved a grant to submitted, who closed a task — for as long as the organisation exists. The person's name stays there even if they later leave the team: it is what lets the organisation know who touched its files, and deleting it would leave its own history meaningless. It goes entirely when the organisation is closed.
- The date these texts were accepted, for as long as the account exists and for as long as it may be needed to prove it.
- The email address of whoever signs up to the newsletter, until they unsubscribe. On unsubscribing the date is recorded instead of deleting the row, so that a mailing already prepared does not reach them anyway; the address is deleted entirely on request.
- The files sent to the AI provider for analysis, ninety days at most on its systems, after which they expire on their own.
6.Who else sees your data
They are not sold and not passed on to anyone. They are processed on our behalf only by the providers the service needs to work, and each one sees only the part it needs:
- Resend (Resend, Inc., United States): sends the service emails. It sees the name and email address of the recipient and what the message says.
- Stripe (Stripe Payments Europe, Ltd., Ireland, and Stripe, Inc., United States): charges for the plans. It collects payment details directly in its own form and keeps the invoice history.
- Anthropic (Anthropic Ireland, Limited, Ireland, which processes the data in the United States with Anthropic PBC): supplies the AI model that reads the bases reguladoras – the binding rules of each call – works out fit, answers in the assistant and helps prepare drafts. It receives the organisation's profile and the documents sent to it for analysis.
- Moyas Development: develops, maintains and hosts the platform. For maintenance it has technical access to the servers and the database, and may use it for nothing else.
- OVHcloud (OVH Groupe SAS, France): hosts the servers and the file store where the database and the uploaded documents live.
There is a data processing agreement with each of them, as article 28 of the GDPR requires. With Resend, Stripe, Anthropic and OVHcloud it is the data processing agreement that forms part of their terms of service and is accepted when signing up. With Moyas Development, a contract signed between the parties. [PENDIENTE: sign the data processing agreement with Moyas Development]
Data is also disclosed to public bodies and to the courts where a law requires it. There is no other recipient.
7.Transfers outside the European Union
The database and the files stay on OVHcloud servers in the European Union. Three providers process data in the United States, and each transfer is covered as follows:
- Stripe, Inc. and Resend, Inc. are certified under the EU-U.S. Data Privacy Framework, which the European Commission found adequate on 10 July 2023. Their data processing agreements also include the Commission's standard contractual clauses.
- Anthropic is contracted through its Irish subsidiary, and what that subsidiary sends to Anthropic PBC in the United States is covered by the European Commission's standard contractual clauses (art. 46 GDPR), included in its data processing agreement.
8.What happens to what the AI reads
The AI provider does not train its models on what is sent to it through its API. Your projects and your annual reports do not end up inside a model and are not used to improve one.
The dashboard assistant is an artificial intelligence, not a person, and what it writes may contain mistakes. The fit analyses and the readings of the rules are also generated by it. The reports for project-writing orders, on the other hand, are prepared and reviewed by people, who may use AI as a tool.
The files uploaded to it for analysis expire on their own after ninety days at most. What is sent as text – the organisation's profile, the project description – is processed within the request and is not stored there permanently.
10.How they are protected
What is stored of a password is not the password: it is a digest worked out with a function designed for the job, one that cannot be reversed. Not even we can read them. Of the session token only its fingerprint is stored, so anyone who walked off with a copy of the database could not impersonate anyone. All traffic is encrypted. Private documents are not reachable at a public address: they are served through signed links that expire.
If there is ever a security breach that could pose a risk, it will be reported to the Agencia Española de Protección de Datos, the Spanish data protection authority, within seventy-two hours and, where the risk is high, to the people affected as well. To report a security flaw: hola@ganasubvenciones.com.
11.Your rights
The GDPR grants these rights over personal data, and exercising them is free:
- Access: finding out what data is held and getting a copy.
- Rectification: correcting anything wrong or incomplete. Almost everything can be corrected from the dashboard without writing to anyone.
- Erasure: asking for data to be deleted. It is deleted except for what has to be kept by legal obligation, such as invoices.
- Restriction: asking for data to stop being used while a dispute about it is resolved.
- Objection: objecting to processing based on legitimate interests.
- Portability: taking the data away in a format that can be opened somewhere else.
- Withdrawing consent at any time, without affecting anything done before it was withdrawn.
They are exercised by writing to hola@ganasubvenciones.com, saying which right you want to exercise. We reply within one month; if the matter is complicated, that period can be extended by a further two months, with notice beforehand. A copy of an identity document may be requested only if there is reasonable doubt about who is writing.
If the answer is not convincing, or does not arrive, you can complain to the Agencia Española de Protección de Datos (C/ Jorge Juan 6, 28001 Madrid – www.aepd.es), which is the supervisory authority. You do not have to write to us first, although that is usually quicker.
12.Minors
The service is designed for organisations and for the people who work or volunteer in them. It is not aimed at children under fourteen and their data is not knowingly collected. If it comes to light that such an account has been created, it is deleted.
13.Changes to this policy
This policy is updated when the service changes, when a provider changes or when the law changes. The date at the top says when it was last reviewed. If the change affects something important – a new purpose, a new provider – we say so by email before it takes effect.