1. Who we are
Ediccio Digital Publishing SL ("Ediccio", "we", "us", "our") provides customer-profile infrastructure for software teams. We are based in Sant Cugat del Vallès, Barcelona, Spain, and the European Union's General Data Protection Regulation (GDPR) applies to how we handle personal data. For any question about this policy, write toprivacy@ediccio.ai.
2. What this policy covers
We act in two distinct roles, and it matters which one applies to you:
- Controller. For personal data about people who interact with Ediccio directly (you visit ediccio.ai, request access, apply to be a design partner, contact us, or hold an Ediccio account), we decide why and how the data is used. This policy covers that data.
- Processor. When a business customer uses Ediccio to power features in their own product, the end-user data that flows through Ediccio belongs to that customer. They are the controller; we process it only on their documented instructions, under a data-processing agreement. The notice that governs those end-users is the customer's own privacy notice, not this page. How we handle that data, where it runs, and who the sub-processors are is disclosed at/trust/substrate.
3. Data we collect
As a controller, we collect the following categories of personal data:
- Information you provide. Your name, work email, company, role, and anything you write when you request access, apply as a design partner, fill in a form, or email us. If you hold an account, the identifiers and settings tied to it. If you become a paying customer, the billing and tax details needed to invoice you.
- Information collected automatically. Minimal technical data generated when you use ediccio.ai or the service: device and browser type, approximate location derived from IP address, and security and diagnostic logs. We do not build advertising or cross-site behavioural-tracking profiles of site visitors from this passive technical data. Where you opt in, we build a profile of your stated needs from what you choose to share (see section 4).
- Data from connected platforms and integrations. Where you or your organisation connects a third-party platform or integration to Ediccio, we receive data from that platform solely to deliver the features you asked for. We use it for that purpose, not for advertising, and not for any use the connecting party did not authorise (see section 6).
We do not knowingly collect more data than we need for the purposes below, and we do not collect special-category data (health, biometric, and similar) for our own purposes.
4. How we use your data
We use personal data only for the purposes below. For each, we name the legal basis we rely on under the GDPR.
| Purpose | Legal basis |
|---|
| Respond to your enquiry, access request, or design-partner application | Steps at your request prior to a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Provide, operate, and maintain ediccio.ai and the Ediccio service | Performance of a contract (Art. 6(1)(b)) |
| Keep the service secure, prevent fraud and abuse, and debug failures | Legitimate interests (Art. 6(1)(f)) |
| Send service and security messages about your account | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Send product updates where you have opted in | Consent (Art. 6(1)(a)), withdrawable at any time |
| Build a profile of your needs (intent, pain points, sentiment, preferences) from what you share on the early-access form or with our assistant, to show you the product and personalise how it helps you | Consent (Art. 6(1)(a)), optional and withdrawable at any time |
| Meet legal, tax, and regulatory obligations | Legal obligation (Art. 6(1)(c)) |
We do not use your personal data for automated decisions that produce legal or similarly significant effects on you.
5. How we share data
We share personal data only with the recipients below, and only to the extent each purpose needs:
- Service providers acting on our instructions. The infrastructure, AI-inference, hosting, and communication providers that help us run the service, under contract and on our instructions. The named sub-processors that touch service data, with their region and role, are published at/trust/substrate.
- Messaging platforms you choose to contact us on. If you message us on WhatsApp, Meta/WhatsApp processes your phone number and message content under its own terms; we receive and keep your messages to respond to you.
- Professional advisers. Lawyers, auditors, and accountants, under confidentiality obligations.
- Authorities and courts. Where we are legally required to share data, or to protect our rights or the safety of others.
- A successor entity. In a merger, acquisition, or sale of assets, with appropriate safeguards and notice where required.
We do not sell personal data, and we do not share it for cross-context behavioral advertising.
6. Data from connected platforms
Ediccio is built to receive data from other platforms and integrations that you, or the organisation you belong to, choose to connect. When a connection is established:
- We receive only the data the connection is scoped to, and we use it solely to provide the features the connecting party asked for.
- We do not use that data for advertising, and we do not combine one organisation's data with another's.
- The connecting party can disconnect the integration at any time, and can ask us to delete the data we received through it. We act on a deletion request within the timelines in section 8.
- Each connected platform has its own privacy policy and controls. Your relationship with that platform is governed by its terms, which we encourage you to review.
7. International transfers
Service data is processed in the European Union by default. Where any personal data is transferred outside the European Economic Area (for example, through a content-delivery edge that serves the public website), we rely on a recognised transfer mechanism: an adequacy decision where one exists, or the European Commission's Standard Contractual Clauses with supplementary safeguards. Some providers, such as a DNS and certificate control plane, operate outside the EEA but hold no personal data. To request a copy of the safeguards that apply to a specific transfer, write to privacy@ediccio.ai.
8. Data retention
We keep personal data only for as long as we need it for the purposes in this policy, then we delete or anonymise it.
- Enquiries and applications. Kept while there is an active interest in the exchange, then deleted within 30 days, unless you ask us to delete sooner. A profile you opted into stays until you withdraw consent or ask us to delete it.
- Account and billing data. For the life of the account, and afterwards only for the period tax and accounting law requires.
- Security and diagnostic logs. A short rolling window for security and operations, then deleted.
- Service data and data from connected integrations. Deleted on request. We act within 30 days of a verified deletion request, and backups age out on a defined rotation within the same window. The mechanism is described at /trust/substrate.
9. Security
We apply technical and organisational measures appropriate to the risk, including:
- Encryption of personal data in transit and at rest.
- Strict access controls, authentication, and need-to-know access for staff.
- Logical separation so one organisation's data is not exposed to another.
- Security testing, monitoring, and an incident-response process.
- Contractual security obligations on our service providers.
No system is perfectly secure. If we become aware of a personal-data breach likely to put your rights at risk, we will notify the relevant supervisory authority, and you where the law requires, within the applicable timelines.
10. Your rights
Depending on where you live, you have some or all of these rights:
- Access a copy of the personal data we hold about you.
- Rectify data that is inaccurate or incomplete.
- Erase your data ("right to be forgotten").
- Restrict or object to certain processing, including direct marketing.
- Receive your data in a structured, machine-readable format (portability).
- Withdraw consent at any time where we relied on it, without affecting prior processing.
To exercise any right, write to privacy@ediccio.ai. We may ask for enough information to confirm your identity before we act, to protect your data against impersonation. We respond within one month, and will tell you if a complex request needs longer. There is no fee unless a request is manifestly unfounded or excessive.
If you are not satisfied with our response, you may lodge a complaint with a supervisory authority. In Spain this is the Agencia Española de Protección de Datos (AEPD); in the rest of the European Union it is the authority where you live, work, or where the issue arose.
11. Cookies
The public ediccio.ai website sets no cookies of its own and uses no analytics, advertising, or cross-site tracking. There is nothing here to consent to, and we show no cookie banner because none is needed. Where you sign in to the service, we use strictly necessary local browser storage for authentication and session management only. Any cookies your browser receives from our hosting or security provider are likewise strictly necessary (for example, to serve pages and block abuse). You can control cookies in your browser, though disabling the strictly necessary ones may affect how the site works.
12. Children
Ediccio is a tool for businesses and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us data, write toprivacy@ediccio.ai and we will delete it.
13. Changes to this policy
We may update this policy, for example when we add a feature, change a provider, or respond to a change in the law. The last-updated date at the top shows when the current version took effect. Where a change is material, we will give notice before it takes effect through the service or by email.
14. Contact
- Data controller: Ediccio Digital Publishing SL
- Privacy contact: privacy@ediccio.ai
- Based in: Sant Cugat del Vallès, Barcelona, Spain
- Sub-processors and infrastructure disclosure: /trust/substrate