Privacy Policy
Last updated: September 2026
This Privacy Policy explains how iCommunity Labs & Tech S.L., operating as Privaro, collects, uses, stores, and protects personal data. We are committed to transparency and to your rights under the General Data Protection Regulation (GDPR) and applicable Spanish data protection law.
1. Data Controller
The data controller is iCommunity Labs & Tech S.L. (CIF B88350897), with registered address at C/ Colmenares 3, Bajo-D, 28004 Madrid, Spain, owner of the Privaro brand. For all privacy-related enquiries, you may contact our Data Protection Officer at contact@privaro.ai or by post to the address above. We are registered with the Spanish data protection authority (AEPD) as required by applicable law.
2. Data We Collect
We collect the following categories of personal data: (a) Account data: name, work email address, company name, job title, industry sector, and password hash when you register. (b) Usage data: API call metadata (timestamps, endpoint called, response codes, latency), dashboard interactions, feature usage, and pipeline configuration. We do not store the content of prompts or LLM responses. (c) Billing data: billing name, address, and payment method details (handled by our payment processor Stripe; we do not store full card numbers). (d) Communication data: emails you send us, form submissions, and support requests. (e) Technical data: IP address, browser type, device identifiers, cookies, and log data collected when you visit our website. (f) Lead and demo request data: information provided when requesting a demo, risk assessment, or partnership.
3. Purpose and Legal Basis for Processing
We process your personal data for the following purposes and on the following legal bases: (a) Service delivery (contract performance, Art. 6(1)(b) GDPR): to create and manage your account, process payments, provide access to the platform, and deliver customer support. (b) Security and fraud prevention (legitimate interest, Art. 6(1)(f) GDPR): to detect and prevent unauthorized access, abuse, and fraud. (c) Service improvement (legitimate interest, Art. 6(1)(f) GDPR): to analyze usage patterns, fix bugs, and develop new features. (d) Marketing communications (consent or legitimate interest, Art. 6(1)(a) or 6(1)(f) GDPR): to send product updates, newsletters, and relevant communications. You may opt out at any time. (e) Legal compliance (legal obligation, Art. 6(1)(c) GDPR): to comply with applicable laws, respond to legal requests, and maintain required records.
4. Data Processed on Behalf of Customers (Processor Role)
When customers use Privaro to process their end users' data through the API, iCommunity Labs & Tech S.L. acts as a data processor on behalf of the customer (the data controller). In this capacity: (a) We process only the data necessary to provide the Service. (b) We do not use customer data to train AI models or for any purpose other than providing the contracted Service. (c) We do not access or store the original content of prompts or LLM responses — only metadata (entity types detected, risk scores, timestamps) and tokenized references. (d) Customers may request a Data Processing Agreement (DPA) compliant with GDPR Article 28 by contacting contact@privaro.ai.
5. Sub-Processors and Data Sharing
We share personal data with the following categories of sub-processors, each operating under appropriate data processing agreements: (a) Infrastructure: Railway (application hosting, EU region), Supabase (database and authentication, EU region). (b) Blockchain certification: iCommunity Blockchain Services (iBS) operating on Fantom Opera Mainnet — audit event hashes only, no personal data written to the blockchain. (c) Email delivery: Resend (transactional emails). (d) Payment processing: Stripe (billing and payment processing). (e) Analytics: anonymized usage analytics only. We do not sell personal data to third parties. We do not share personal data with AI model providers — Privaro's core function is specifically to prevent that from occurring.
6. International Data Transfers
Our primary infrastructure is hosted within the European Union. Where we use sub-processors that may transfer data outside the EEA (for example, for payment processing or support tools), we ensure that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, or other lawful transfer mechanisms under Chapter V of the GDPR. Fantom Opera Mainnet, used for blockchain certification, processes only cryptographic hashes of audit events — no personal data is written to the blockchain.
7. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law. Our standard retention periods are: (a) Account data: retained for the duration of the contract plus 3 years after termination for legal and audit purposes. (b) Audit logs and blockchain certification records: minimum 5 years to satisfy GDPR record-keeping obligations for high-risk AI processing. (c) Billing and financial records: 7 years as required by Spanish commercial law. (d) Marketing data: until you withdraw consent or opt out. (e) Support communications: 2 years after ticket closure. You may request deletion of your account and associated data at any time by contacting contact@privaro.ai, subject to our obligation to retain certain data for legal compliance.
8. Cookies and Tracking Technologies
We use cookies and similar technologies on our website (privaro.ai) for the following purposes: (a) Essential cookies: required for the website and dashboard to function correctly, including session management and authentication. These cannot be disabled. (b) Analytics cookies: anonymous usage analytics to understand how visitors use our site (e.g. Google Analytics with IP anonymization). You may opt out via your browser settings or our cookie consent tool. (c) Preference cookies: to remember your language and display preferences. We do not use advertising or tracking cookies for third-party marketing purposes. You can manage cookie preferences through your browser settings or our cookie consent banner.
9. Your Rights Under GDPR
Under the General Data Protection Regulation (EU) 2016/679 and applicable Spanish data protection law, you have the following rights regarding your personal data: (a) Right of access (Art. 15): to obtain confirmation of whether we process your data and a copy of it. (b) Right to rectification (Art. 16): to have inaccurate data corrected. (c) Right to erasure (Art. 17): to have your data deleted in certain circumstances ('right to be forgotten'). (d) Right to restriction of processing (Art. 18): to restrict how we use your data in certain circumstances. (e) Right to data portability (Art. 20): to receive your data in a structured, machine-readable format. (f) Right to object (Art. 21): to object to processing based on legitimate interests or for direct marketing. (g) Right to withdraw consent (Art. 7(3)): where processing is based on consent, to withdraw it at any time without affecting the lawfulness of prior processing. To exercise any of these rights, contact contact@privaro.ai. We will respond within 30 days. You also have the right to lodge a complaint with the AEPD (Agencia Española de Protección de Datos) at aepd.es.
10. Security Measures
We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction. Our key security controls include: (a) AES-256-GCM encryption for all data at rest in the token vault, with per-organization key segmentation. (b) TLS 1.3 for all data in transit. (c) JWT-based authentication with SHA-256 hashed API keys — plaintext never stored. (d) Row Level Security (RLS) at the database level to enforce multi-tenant isolation. (e) Blockchain-certified immutable audit logs for all PII processing events. (f) Mandatory two-factor authentication (TOTP MFA) for admin and DPO roles. (g) Regular security testing and code review. (h) Incident response and business continuity procedures. We hold security documentation aligned to ISO/IEC 27001:2022 Annex A. Full security details are available at privaro.ai/security.
11. Data Breach Notification
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority (AEPD) within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay in accordance with GDPR Article 34. Notifications will include: the nature of the breach, categories of data affected, likely consequences, and measures taken or proposed to address the breach.
12. Children's Privacy
The Service is intended for use by businesses and professionals, not by individuals under the age of 16. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected data from a child, please contact contact@privaro.ai and we will delete it promptly.
13. AI and Automated Decision-Making
Privaro's core function is to detect and protect sensitive data before it reaches AI models. In the performance of the Service, we do not make automated decisions about you that produce legal or similarly significant effects within the meaning of GDPR Article 22. The detection engine identifies entity types (e.g. email address, national ID) and applies pre-configured governance policies set by your organization. These are technical processing functions, not automated profiling or decision-making about individuals.
14. Legal Basis for Spanish Residents
In addition to GDPR, Spanish residents are protected by the Ley Orgánica 3/2018 de Protección de Datos Personales y Garantía de los Derechos Digitales (LOPDGDD). We comply with all obligations under Spanish data protection law, including registration requirements with the AEPD where applicable. You may exercise your data protection rights before the AEPD (Agencia Española de Protección de Datos) at c/ Jorge Juan 6, 28001 Madrid, or online at www.aepd.es.
15. EU AI Act and Regulatory Compliance
The EU AI Act (Regulation (EU) 2024/1689) imposes obligations on providers and deployers of AI systems in the European Union. Privaro is designed to help organizations meet their obligations as deployers of AI systems, particularly for high-risk AI systems that process personal data. Our blockchain-certified audit trail supports the record-keeping and transparency requirements of the EU AI Act. We will update this Privacy Policy as guidance on the EU AI Act develops. Compliance with the EU AI Act is ultimately the responsibility of the organization deploying AI systems; Privaro provides infrastructure to support — but not guarantee — compliance.
16. Links to Third-Party Services
Our website and dashboard may contain links to third-party websites and services. This Privacy Policy applies only to Privaro. We are not responsible for the privacy practices of third-party sites and encourage you to review their privacy policies before providing any personal data.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by email or through a prominent notice on the dashboard at least 30 days before the changes take effect, and we will update the 'Last updated' date at the top of this page. We encourage you to review this Privacy Policy periodically. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the revised Privacy Policy.
18. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us: Data Protection Officer: contact@privaro.ai | Legal enquiries: contact@privaro.ai | Post: iCommunity Labs & Tech S.L., C/ Colmenares 3, Bajo-D, 28004 Madrid, Spain | Phone: available on request. We aim to respond to all privacy-related enquiries within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the Agencia Española de Protección de Datos (AEPD) at www.aepd.es.