Privacy, plainly explained
Last updated: 22 August 2026
Data controller
- Company: VG Capital, S.L.U.
- Spanish tax ID (NIF): B93863066
- Registered address: Calle La Sagra s/n, Res. Los Huertos 1, 9 · 03185 Torrevieja (Alicante), Spain
- Registry details: Registro Mercantil de Alicante (Commercial Registry of Alicante), Sección 8, Hoja A-207556, Inscripción 1.ª, Año 2026, IRUS 1000477988911
- Privacy contact: info@kontora.es
Data protection officer
We have not appointed a data protection officer because none of the cases in GDPR art. 37 or art. 34 of the Spanish LOPDGDD applies: we are not a public authority, our core activity does not consist of regularly and systematically monitoring people on a large scale, and we do not process special categories of data on a large scale. The reasoned analysis behind that conclusion is documented in writing, kept on file and available to the Spanish Data Protection Agency on request. For any privacy matter, write to info@kontora.es.
Scope of this policy
This policy covers kontora.es only: its waitlist, its contact forms and browsing the site. Once you sign up for the product, your accounting data is governed by the privacy policy at app.kontora.es and, as regards your own clients' data, by the data processing agreement (DPA), where you are the controller and we are the processor.
What we process, why, and on what legal basis
- Waitlist. Data: your email, the language you browse in, your profile if you tell us (autónomo, SL, e-commerce), and a record of your consent with its date. Purpose: to let you know when the beta opens and when we launch. Basis: your consent (GDPR art. 6.1.a), the box you tick when signing up.
- Email enquiries. Data: whatever you include in your message. Purpose: to answer you. Basis: your consent and, where your enquiry precedes signing up, steps taken at your request prior to entering into a contract (GDPR art. 6.1.b).
- Usage analytics. Data: aggregate visit statistics, with no cookies and without identifying individuals or building profiles. Basis: legitimate interest (GDPR art. 6.1.f) in understanding which content is useful; we have weighed that the impact on your privacy is minimal because the data does not identify you.
- Server logs. Data: IP address, date and time, page requested, response code and browser. Purpose: keeping the service running, diagnosing incidents and preventing abuse and attacks. Basis: legitimate interest (GDPR art. 6.1.f) in network and information security, recognised in GDPR recital 49.
How long we keep each thing
- Waitlist: until launch, when we will let you choose between staying on the list or being deleted, or until you withdraw your consent, whichever comes first.
- Email enquiries: for as long as the conversation lasts and, afterwards, as long as needed to handle any liability arising from it.
- Analytics: aggregated, with no personal data to keep.
- Server logs: 30 days at most, unless one needs to be kept longer to investigate a specific security incident.
Who else sees your data
We do not sell or share your data with anyone. The only third parties with access are the providers we need in order to operate, acting as processors under a signed contract: Resend (delivery of our emails). Hosting of the site, the waitlist and the analytics is our own, on a server located in the European Union. We may also disclose data to courts or public authorities where a law requires us to.
International transfers
Resend is established in the United States. That transfer relies on the Standard Contractual Clauses approved by the European Commission (GDPR art. 46.2.c), together with the technical measures in our contract with the provider. You can ask us for a copy of the safeguards at info@kontora.es. All other processing takes place entirely within the European Union.
Your rights
At any time and free of charge you can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw your consent, which does not affect the lawfulness of processing carried out before the withdrawal. Just write to info@kontora.es, or reply to any email we send you, saying which right you are exercising; we may ask you to prove your identity if there is reasonable doubt about who you are.
We will reply within one month, extendable by two more if the request is complex, telling you why. If you believe we have not handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency (aepd.es, C/ Jorge Juan 6, 28001 Madrid), without prejudice to contacting us first.
Automated decisions and profiling
We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, and we do not build profiles from your data.
Where the data comes from
Everything we process comes from you directly, except the technical server logs, which your own browser generates when visiting the site. We do not buy databases and we do not obtain your data from third parties.
Children
This site and the product are aimed at people carrying out an economic activity, not at children. We do not knowingly collect data from anyone under 14; if we find that a record belongs to a child, we delete it. If you believe that has happened, write to info@kontora.es.
Security
We apply technical and organisational measures appropriate to the risk (GDPR art. 32): HTTPS encryption in transit, restricted system access, backups and access logging. We have a written procedure for handling security breaches: were one to occur that poses a risk to your rights, we would notify the Spanish Data Protection Agency within 72 hours and you without undue delay where the risk is high.
Cookies and local storage
This site does not use cookies that require your consent (art. 22.2 of the Spanish LSSI): there are no advertising, third-party or tracking cookies, and the analytics work without them. We only store your light/dark theme preference in your browser's local storage: that is not a cookie, holds no personal data and never leaves your device. You can clear it from your browser settings.
Full legal documents for the product
This page covers the website. The documents governing the contracted product are public and you can read them before signing up, with no account needed:
- Terms and Conditions, the service contract.
- Full Privacy Policy, how we handle your data as a customer.
- Data Processing Agreement (DPA), when you upload your own clients' data, you are the controller and we are the processor.
- List of sub-processors, every provider with access, one by one.
- Responsible declaration for the invoicing system, the VERI*FACTU self-certification required by Orden HAC/1177/2024.
Changes to this policy
We may update this policy when our processing, our providers or the applicable rules change. The version in force is the one published here, with its date at the top; if a change affects you materially and you are on the waitlist, we will tell you by email before applying it.