Privacy Policy
Data controller: NEXUSNOIR VENTURES SL, Calle Nuñez de Balboa 114, Planta 3 Puerta 10, 28006 Madrid. SPAIN ("Foliotrail", "we", "our").
Contact: backoffice@foliotrail.com
1. What data we collect
Category | Examples | Purpose | Legal basis (GDPR Art.) |
---|---|---|---|
Account data | Name, email | Create & manage account | 6 (1)(b) Contract |
Billing data | Card details (handled by Stripe), invoices | Process payments | 6 (1)(b) Contract |
Usage analytics | Page views, clicks, IP address (via Plausible) | Improve product & security | 6 (1)(f) Legitimate interest |
Marketing consent | Email newsletter opt-in | Send product updates & promotions | 6 (1)(a) Consent (opt-out anytime) |
We do not collect sensitive categories (§9 GDPR).
2. Cookies
- Strictly necessary: session, CSRF.
- Analytics: first-party Plausible cookie-free analytics (aggregated, no cross-site tracking).
A cookie-consent banner appears on first visit.
3. Processors & third-country transfers
Processor | Location | Safeguards |
---|---|---|
Stripe | EU/US | Standard Contractual Clauses (SCCs) |
AWS (EU-North-1) | Stockholm, EU | Data stored in-region |
Substack | US | SCCs |
4. Data retention
Data | Retention |
---|---|
Billing records | 6 years (Spanish tax law) |
Active account data | While account remains active |
Inactive accounts | Deleted 24 months after last login or on request |
Marketing consent logs | Until you unsubscribe + 12 months |
5. Security
We use TLS encryption in transit, database encryption at rest, least-privilege IAM roles, and regular backups.
6. Your rights
You may access, rectify, erase, restrict, object to processing, or request data portability by emailing backoffice@foliotrail.com. You also have the right to lodge a complaint with the AEPD (Agencia Española de Protección de Datos).
7. Automated decision-making
None.
8. Changes to this policy
We will notify you by email 14 days before any significant change.