Login
Open navigation menu
Privacy & compliance

Privacy Policy

Last updated December 2025

1. Introduction

This Privacy Policy describes how Facturium ("Facturium", "we", "us", "our") processes personal data in connection with the use of the Facturium platform (the "Service").

This policy applies to users of the Service and to visitors of our website.

2. Roles Under Data Protection Law

For the purposes of Regulation (EU) 2016/679 ("GDPR"):

  • Customers using the Facturium platform act as Data Controllers with respect to the personal data they process through the Service.
  • Facturium acts as a Data Processor, processing personal data on behalf of its customers in accordance with their instructions.

For limited website-related data (such as contact requests), Facturium acts as Data Controller.

3. Personal Data We Process

3.1 Data Processed on Behalf of Customers

When providing the Service, Facturium may process the following categories of personal data on behalf of customers:

  • Identification data (name, tax identification number, address)
  • Contact data (email address)
  • Invoicing and fiscal data (invoice numbers, dates, amounts, tax details)
  • Any other data entered by the customer into the platform

Facturium does not determine the content or purpose of such data.

3.2 Website and Account Data

Facturium may process limited personal data directly, including:

  • Account registration data (name, email address, login credentials)
  • Communication data (support requests, emails)
  • Technical data (IP address, browser type, timestamps, logs)

4. Purposes of Processing

Personal data is processed for the following purposes:

  • Providing and operating the Service
  • Managing user accounts and authentication
  • Generating, storing, and transmitting invoices and records
  • Complying with legal and regulatory obligations
  • Ensuring platform security and reliability
  • Responding to inquiries and support requests

Facturium does not use personal data for advertising, profiling, or unrelated purposes.

5. Legal Bases for Processing

Depending on the context, processing is based on:

  • Performance of a contract (Article 6(1)(b) GDPR)
  • Compliance with legal obligations (Article 6(1)(c) GDPR)
  • Legitimate interests related to security and service operation (Article 6(1)(f) GDPR)
  • Consent, where explicitly required

6. Data Retention

Personal data is retained only for as long as necessary to fulfill the purposes described in this policy or as required by applicable law.

Customers control retention periods for data processed through the Service, subject to legal retention obligations.

7. Data Sharing and Subprocessors

Facturium may engage carefully selected subprocessors to support service delivery, such as hosting, backup, email, and monitoring providers.

All subprocessors are subject to contractual data protection obligations consistent with the GDPR.

Details are available at /legal/subprocessors.

Facturium does not sell personal data.

8. International Data Transfers

Primary processing and storage occur within the European Union.

If personal data is transferred outside the EU, appropriate safeguards are implemented in accordance with applicable data protection laws.

9. Security Measures

Facturium implements appropriate technical and organizational measures designed to protect personal data, including:

  • Encrypted communications (TLS/HTTPS)
  • Logical access controls
  • Data segregation
  • Regular backups
  • Monitoring and logging

Security measures evolve in line with industry practices and risk assessments.

10. Data Subject Rights

Where Facturium acts as Data Processor, data subject requests should be addressed to the relevant customer acting as Data Controller.

Where Facturium acts as Data Controller, individuals may exercise their rights under GDPR, including:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object

Requests may be submitted to [email protected].

11. Personal Data Breaches

In the event of a personal data breach affecting data processed on behalf of customers, Facturium will notify the affected customer without undue delay, in accordance with applicable law.

12. Changes to This Privacy Policy

Facturium may update this Privacy Policy from time to time.

Material changes will be communicated through reasonable means.

Continued use of the Service constitutes acceptance of the updated policy.

13. Contact

For privacy-related inquiries or data protection matters, please contact:

[email protected]

14. Language Precedence

This Privacy Policy is drafted in English.

In the event of any discrepancy between the English version and any translated version, the English version shall prevail.

Electronic invoicing software for freelancers, SMEs, and firms that need a solid foundation to operate in Spain.

+34 900 815 523