Privacy Policy

1. Who processes your data

Data controller: [RAZON_SOCIAL], owner of the GoPOS brand, tax ID [NIF], registered address at Carrer Doctor Pi i Molist 29, 08031 Barcelona, Spain. Registry details: [REGISTRO_MERCANTIL].

Contact: goposbcn@gmail.com, telephone +34 667 756 999, website https://gopos.es.

Data protection contact: you may write to goposbcn@gmail.com or, where a specific privacy contact or data protection officer has been appointed, to goposbcn@gmail.com.

GoPOS is a cloud POS/TPV software for mobile phone shops in Spain, operating since [ANO_FUNDACION]. It covers sales, VERI*FACTU invoicing with the AEAT QR code, IMEI and serial number inventory, repair jobs, warranties, trade-in contracts, quotations, expenses, multi-shop management, reports, user roles and PWA operation with offline mode.

2. The two roles of GoPOS: controller and processor

This is the most important part of this policy. GoPOS processes personal data in two different situations, and the rules are not the same in each.

As CONTROLLER we process the data of our own customers and contacts: the person who takes out the subscription, the users they create in the application, anyone who writes or calls us for information or support, and visitors to our website. In this case we decide why and how that data is used, and this policy is the applicable document.

As PROCESSOR we handle the data that a shop enters into the software about its own end customers: name, telephone number, ID document, address, together with device data such as the IMEI or serial number, and everything associated with sales, repairs, warranties, trade-in contracts, quotations and invoices. Here the controller is the shop, not GoPOS. The shop decides what data it collects, for what purpose, for how long, and to whom it is disclosed.

In that second case we act solely on the shop's documented instructions. The terms of that processing are governed by the Data Processing Agreement (Article 28 of Regulation (EU) 2016/679, GDPR) available at [URL_DPA], which the shop accepts when subscribing to the service.

We do not use shops' end-customer data for our own purposes, we do not sell it and we do not disclose it to third parties on our own initiative. We only process technical data and aggregated, anonymised statistics, which do not allow any individual or any shop to be identified, in order to secure the platform and improve the product.

If you are a customer of a shop that uses GoPOS and you wish to exercise your rights, you must contact that shop, which is the controller. If you write to us, we will forward your request to the shop without undue delay and let you know.

3. What data we process as controller

Identification and contact data: first name and surname, shop trading name, email address, telephone number and postal address.

Subscription and billing data: the plan and payment cycle contracted (POS Starter EUR 29.99/month or EUR 399/year; POS Plus EUR 49/month or EUR 499/year; POS Pro EUR 99/month or EUR 999/year), use of the free trial, the tax details needed to issue our invoice, payment history, sign-ups, cancellations and renewals.

Payment data: card or payment method details are processed directly by [PASARELA_PAGO]. We do not store the full card number or the security code.

Account and usage data: username and access credential (the password is not stored in clear text), assigned role (admin, sales, repair or wholesale), the shops the user can access, and the technical access and activity logs generated by the application, detailed in [REGISTROS_TECNICOS].

Support and communications data: the content of emails, messages or calls exchanged with you to resolve incidents or answer queries.

We do not process special categories of data (Article 9 GDPR) in our relationship with you, and we ask you not to enter health, ideology, religion, trade union membership, biometric or criminal data into free-text fields in the software.

4. Why we use that data and on what legal basis

Creating the account, enabling the free trial, providing and maintaining the service and handling support: performance of the contract (Article 6(1)(b) GDPR).

Collecting subscription payments, handling renewals and refunds, and issuing our invoices: performance of the contract and compliance with legal obligations (Articles 6(1)(b) and 6(1)(c) GDPR).

Complying with accounting, tax and invoicing obligations under Ley 58/2003 (General Tax Act), Real Decreto 1619/2012 (Invoicing Regulation), the Spanish Commercial Code and the rules on invoicing software systems (Ley 11/2021 and Real Decreto 1007/2023): compliance with a legal obligation (Article 6(1)(c) GDPR).

Securing the platform, preventing unauthorised access, detecting abuse or non-payment and keeping technical logs: legitimate interest (Article 6(1)(f) GDPR). You may object as explained below.

Sending communications about GoPOS to existing customers, relating to products or services similar to those contracted: legitimate interest, in the terms of Article 21 of Ley 34/2002 on information society services and electronic commerce. Every message includes an unsubscribe link.

Sending marketing communications to people who are not yet customers, and using cookies or similar technologies that are not strictly necessary: consent (Article 6(1)(a) GDPR), which you may withdraw at any time without affecting the lawfulness of processing carried out beforehand.

5. What we process as processor on behalf of the shop

On behalf of each shop we process, among others, the following data about its end customers: first name and surname, telephone number, ID document, address, together with the device IMEI or serial number, purchase history, repair jobs, warranties, second-hand device trade-in contracts, quotations and invoices.

The purpose is strictly limited to providing the service the shop has contracted, together with the processing strictly necessary for the security of the platform and to comply with our own legal obligations: recording sales, issuing invoices, managing inventory and repairs, generating contracts and quotations, and producing reports for that shop.

Our obligations as processor, under Article 28 GDPR, are: to process data only on the shop's documented instructions; to maintain confidentiality, including on the part of our staff; to apply the security measures required by Article 32 GDPR; to assist the shop in responding to data subject requests and in notifying personal data breaches; not to subcontract without authorisation; and, at the end of the service, to delete or return the data as the shop chooses, except for what we must retain by law.

It is for the shop to decide which data is genuinely necessary. We recommend applying the data minimisation principle: for example, considering whether a copy of the ID document is really needed or whether recording the number is enough, and limiting the use of free-text fields.

GoPOS provides features designed to help shops meet their obligations, but it does not guarantee the shop's legal compliance. As producer of the invoicing software system, GoPOS assumes the obligations incumbent on it under Real Decreto 1007/2023 and Article 29.2.j) of Ley 58/2003 (General Tax Act), including the responsible declaration (declaración responsable) on the software. The obligations that fall on the taxpayer itself — issuing, retaining and, where applicable, submitting its own invoices — and the status of controller vis-à-vis the Spanish Data Protection Agency and end customers lie with the shop.

6. How long we keep data

Account data and content entered into the application: for as long as the subscription is active. After cancellation we keep the data for the recovery and export period set out in the terms of service and, once that period has elapsed, we delete or anonymise it, except for what we must keep by law.

Billing, accounting and tax data: for the applicable statutory limitation periods, in particular four years under Ley 58/2003 (General Tax Act) and six years for commercial books and records under the Spanish Commercial Code.

Data needed to handle possible claims: until the relevant actions become time-barred, which for personal actions with no special period is five years under the Spanish Civil Code.

Technical and security logs: for the limited time necessary for their security purpose and to evidence access.

Data processed on the basis of consent, such as marketing communications: until you withdraw consent or unsubscribe.

VERI*FACTU invoicing records: kept in accordance with applicable tax law, and the system does not allow them to be edited or deleted. This is explained in the next section.

7. VERI*FACTU, immutable invoicing and the right to erasure

The GoPOS invoicing system generates invoicing records chained to one another by means of a hash or fingerprint, in line with Ley 11/2021 on measures to prevent and combat tax fraud and with Real Decreto 1007/2023. That chain allows any subsequent alteration of the invoicing records to be detected: if a record is modified, the fingerprint no longer matches and the tampering becomes evident.

The practical consequence is that the system does not allow an issued invoice to be deleted or edited. If there is an error or a return, it is corrected by issuing a corrective invoice or a cancellation record, which is itself chained. The original record remains.

If an invoice contains an end customer's personal data, such as their name, tax ID or address, that data remains in the invoicing record even if the customer asks for it to be erased. The right to erasure is not absolute: Article 17(3)(b) GDPR disapplies it where processing is necessary for compliance with a legal obligation, and retaining invoices is a legal tax and commercial obligation.

What can be erased or anonymised at the data subject's request, if the shop so decides: customer records, contact telephone numbers and addresses, internal notes, quotations that were never invoiced, and generally any data that does not form part of an invoice or an accounting entry.

What cannot be erased: issued invoices, their associated VERI*FACTU records and the linked accounting information, for the duration of the statutory retention periods.

In those cases the data blocking mechanism set out in Article 32 of Ley Orgánica 3/2018 (LOPDGDD) applies. Where end-customer data is concerned, it is for the shop, as controller, to decide on the blocking; GoPOS implements it technically on the shop's instructions. Blocked data is set aside, is not used for any other purpose, and remains available only to Judges and Courts, the Public Prosecutor's Office (Ministerio Fiscal) and the competent public authorities, in particular the data protection authorities, to address possible liabilities until those liabilities become time-barred.

8. Who we share data with, and international transfers

Hosting and infrastructure provider: Amazon Web Services (AWS), acting as processor or sub-processor.

Payment gateway: [PASARELA_PAGO], for collecting subscription payments. That provider also processes payment data for its own purposes and under its own privacy policy.

Other sub-processors involved in delivering the service (for example backups, transactional email delivery or support tools): [SUBENCARGADOS].

The Spanish Tax Agency (AEAT): in the cases and to the extent provided for by the rules on invoicing software systems, and where a formal request is answered.

Public authorities, judges, courts and law enforcement bodies where there is a legal obligation, and accountants and banks strictly as needed for accounting and payment collection.

We do not sell personal data and we do not disclose it for third-party advertising purposes.

International transfers: we aim to host and process data within the European Economic Area. Where a provider processes data outside the EEA, the transfer relies on a European Commission adequacy decision or on the standard contractual clauses approved by Implementing Decision (EU) 2021/914, with any additional measures required. Provider-by-provider detail is set out in [SUBENCARGADOS].

If we change or add sub-processors that process data on behalf of shops, we will give advance notice so that the shop can object, in accordance with Article 28(2) GDPR.

9. Your rights and how to exercise them

You may exercise the rights of access, rectification, erasure, restriction of processing, data portability and objection set out in Articles 15 to 22 GDPR, and you may withdraw at any time any consent you have given.

We do not take decisions based solely on automated processing that produce legal effects concerning individuals or similarly significantly affect them, within the meaning of Article 22 GDPR.

To exercise your rights, write to goposbcn@gmail.com or to goposbcn@gmail.com, or by post to Carrer Doctor Pi i Molist 29, 08031 Barcelona, Spain. State which right you wish to exercise and enclose something that allows us to verify your identity. Exercising your rights is free of charge.

We will respond within one month of receiving the request, extendable by a further two months where the request is complex, in which case we will explain the reason for the extension.

If you are an end customer of a shop that uses GoPOS, the controller is the shop: please contact it directly. If you ask us instead, we will forward your request to the shop and tell you we have done so, but we cannot decide on our own about data we do not control.

If you believe we have not handled your rights properly, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD), calle Jorge Juan 6, 28001 Madrid, www.aepd.es, under Article 77 GDPR. You may also complain to us first at the addresses above.

10. Information security

We apply technical and organisational measures appropriate to the risk, in accordance with Article 32 GDPR, including role-based access control (admin, sales, repair and wholesale) and separation of each shop's data in multi-shop environments. The specific security measures applied are set out in [MEDIDAS_SEGURIDAD].

GoPOS runs as a PWA and can operate offline. This means some information may be stored temporarily on the device until it is synchronised. We recommend using devices with a screen lock, not sharing accounts between employees, and logging out on shared equipment.

No security measure offers absolute protection. If a personal data breach occurs, we will notify the supervisory authority and, where applicable, the individuals affected, in accordance with Articles 33 and 34 GDPR. Where we act as processor, we will notify the shop without undue delay so that it can meet its own obligations.

We make no claim to hold security certifications, external audits or quality seals.

11. Minors

The service is aimed at businesses and professionals, not at minors. We do not knowingly collect data about minors in our capacity as controller.

If a shop records data about a minor as an end customer, it is for the shop to assess the lawfulness of that processing and, where consent is required, to bear in mind that Article 7 of Ley Orgánica 3/2018 (LOPDGDD) allows consent from the age of fourteen, with parental or guardian consent required below that age.

12. Changes to this policy

We may update this Privacy Policy to reflect legal, technical or service changes. The current version will always be published at https://gopos.es, with its update date.

If a change materially affects how we process your data or which sub-processors are involved, we will notify you by email or through the application before it takes effect.

Date this document was last updated: 18 July 2026.