Legal
Privacy Policy.
This policy explains how personal data is processed when you use SALOA. It uses the same defined terms as the Terms & Conditions.
How to read this document
Items marked in green are facts that still have to be confirmed against a provider's current documentation or the Operator's records. They are shown as open rather than stated as settled.
1. Controller
The controller for the processing described in clause 3 is the Operator of SALOA, trading name SALOA, established in Spain, address Málaga, Spain (correspondence by email only), contact studio@getsaloa.com.
Whether a data protection officer must be appointed: to be assessed; on current volumes an appointment is not expected to be mandatory.
2. When SALOA is controller and when it is processor
- Account data, authentication data, billing and purchase records, acceptance and consent records, security and audit logs, support correspondence and aggregate usage measurement: the Operator is controller.
- Personal data contained in User Content that a Business User submits about its own customers, employees, suppliers or contacts: that Business User is controller and the Operator acts as processor under the Data Processing Agreement.
- Personal data about individuals appearing in public sources retrieved during a Company Analysis (for example named executives): the role allocation depends on who determines the purpose of the analysis and requires confirmation on legal review.
Where you use SALOA as a Consumer for your own purposes, the Operator is controller for the data you provide about yourself and processes it to perform the contract.
3. What is processed and why
- Identity and account data (email address, authentication identifiers, sign-in metadata) to create and secure your account. Legal basis: performance of the contract, Art. 6(1)(b).
- Purchase data (payment status, amount, currency, payment provider identifiers, invoices) to take payment, provide receipts and meet accounting obligations. Legal basis: contract and legal obligation, Art. 6(1)(b) and (c). Card data is handled by the payment provider and never reaches SALOA.
- Acceptance and consent records (accepted document version, timestamp, declared capacity, immediate-performance request and withdrawal acknowledgement) to evidence contract formation. Legal basis: legal obligation and legitimate interest in evidencing the contract, Art. 6(1)(c) and (f).
- User Content (interview answers, company descriptions, documents, notes, memory entries) to run the Session and generate Output. Legal basis: performance of the contract.
- Generated Output and Intelligence to store your Projects and keep them available to you. Legal basis: performance of the contract.
- Research data retrieved from public web sources for a Company Analysis you request. Legal basis: performance of the contract and legitimate interest in providing evidence-based analysis, Art. 6(1)(b) and (f).
- Security and abuse data (IP-derived rate-limit subjects, security events, blocked attempts) to protect the service and other users. Legal basis: legitimate interest and legal obligation, Art. 6(1)(f) and (c).
- Support correspondence to answer you. Legal basis: contract and legitimate interest.
4. AI processing
To perform a Session, User Content and retrieved research material are sent to third-party AI model providers through an AI gateway. This is necessary to provide the service and cannot be switched off while using SALOA. Output is generated automatically without human review.
Whether a provider retains prompts, and for how long, is governed by that provider's terms: per-provider retention and training settings to be confirmed and documented. SALOA does not use your User Content to train its own models, and it is not claimed that third-party providers never receive your data, because they necessarily do.
Sessions produce automated recommendations. These are decision-support material: they do not produce legal effects for you and are not used to make automated decisions about you within the meaning of Article 22 GDPR.
5. Providers and subprocessors
The following categories of providers may process personal data on the Operator's behalf:
| Category | Provider | Purpose | Status |
|---|---|---|---|
| Application hosting and delivery | Lovable (application platform) and its infrastructure providers | Serving the application and running server-side functions. | CONFIRMED IN PRODUCT |
| Database and authentication | Supabase | Accounts, authentication, sessions, projects, generated output, purchase and acceptance records, security events. | CONFIRMED IN PRODUCT |
| Authentication email delivery | Supabase (built-in authentication email service; no separate transactional email provider is configured) | Sign-in, sign-up and password-reset emails. | CONFIRMED IN PRODUCT |
| AI models | Lovable AI Gateway, routing to Google and OpenAI models | Interviews, analysis, adversarial review, generated assets, support answers. User Content is transmitted to these providers; this cannot be switched off while using SALOA. | CONFIRMED IN PRODUCT |
| Web research | Firecrawl | Retrieving publicly available web pages used as evidence for a requested analysis. | CONFIRMED IN PRODUCT |
| Payments | Stripe | Checkout, payment processing, receipts, fraud prevention. Card data never reaches SALOA. | CONFIRMED IN PRODUCT |
Personal data is not sold. Data is disclosed to authorities only where legally required, and to advisers or insurers where necessary to defend a legal claim.
6. International transfers
Some providers process data outside the EEA, in particular AI model providers and infrastructure providers with United States operations. Where that happens, transfers rely on an adequacy decision, on Standard Contractual Clauses adopted by the European Commission with a transfer impact assessment and supplementary measures where required, or on another lawful mechanism under Chapter V GDPR.
Exact hosting regions and transfer mechanisms per provider: to be confirmed and listed before publication. EU-only processing, local-only processing and zero third-party processing are not promised.
7. Retention
- Account data: while the account exists, and a short period afterwards for security and dispute handling.
- Projects, User Content and Output: until you delete them or delete your account.
- Purchase, invoicing and tax records: for the statutory retention period in Spain, which requires confirmation of the exact term applicable to the Operator.
- Acceptance and consent records: for as long as needed to evidence the contract and any related claim, plus applicable limitation periods.
- Security and audit logs: a limited period proportionate to the security purpose.
- Backups: for the retention cycle of the database provider, after which they are overwritten.
Exact periods: retention schedule and backup window to be confirmed. It is not claimed that data is permanently and immediately erased everywhere at the moment of deletion; backup copies may persist temporarily and are not used for ordinary operations.
8. Security
Measures include authenticated access, tenant isolation enforced in the database, server-side authorisation, managed secret storage, encrypted transport, rate limiting, audit logging of security-relevant events, isolation of untrusted text before it reaches AI models, and server-side payment integrity checks. Implementation details are not published. No system is completely secure. Confirmed breaches are handled and, where required, notified under Articles 33 and 34 GDPR.
9. Your rights
You have the right to access, rectification, erasure, restriction, portability and objection, the right to withdraw consent where processing is based on consent, and the right not to be subject to solely automated decisions with legal effect. Many of these can be exercised directly in your account, which lets you export or delete your Projects and data.
To exercise a right, write to studio@getsaloa.com. You may lodge a complaint with the Spanish Agencia Española de Protección de Datos (aepd.es) or with the supervisory authority of your own country of residence.
10. Cookies and similar technologies
SALOA uses only strictly necessary and functional browser storage: the cookies and local storage that keep you signed in, remember the language and the session track you chose, and protect the payment flow. These do not require consent. No analytics, advertising, tracking or profiling technologies are in use, and no third-party marketing cookies are set, which is why no consent banner is shown. If that ever changes, consent will be requested before any such technology is set and this policy will be updated first.
11. Children
SALOA is not intended for anyone under 18 and accounts require legal capacity to contract. Data is not knowingly collected from children. If you believe a minor has provided data, contact us and it will be deleted.
12. External agents (MCP)
If you connect an external AI assistant through MCP, that assistant can read data from your own account only, with read-only permissions, after you have authorised it. What the external assistant then does with that data is governed by its own provider's privacy terms, not by this policy, and that provider is not a subprocessor acting on the Operator's behalf. You can stop providing access by revoking the authorisation.
13. Changes
This policy is versioned together with the Terms & Conditions. The current version, its effective date and its last-updated date are shown at the top of this page.