Legal · Privacy Policy

Your data, handled with care.

How Ediccio collects, uses, shares, retains, and protects personal data across ediccio.ai and the Ediccio service. Privacy and security are not features we bolt on. They constrain how the product is built.

Effective 2026-06-21 Last updated 2026-06-21 Applies to ediccio.ai and the Ediccio service.

Who we are

Two roles. Stated plainly.

Ediccio Digital Publishing SL ("Ediccio", "we", "us", "our") provides customer-memory infrastructure for software teams. We are based in Sant Cugat del Vallès, Barcelona, Spain, and the European Union's General Data Protection Regulation (GDPR) is our baseline.

We act in two distinct roles, and it matters which one applies to you:

For any question about this notice or about how we handle your personal data, write to privacy@ediccio.com.

What we collect

Only what the service needs.

As a controller, we collect the following categories of personal data:

We do not knowingly collect more data than we need for the purposes below, and we do not collect special-category data (health, biometric, and similar) for our own purposes.

How we use it

Purposes, with a legal basis for each.

We use personal data only for the purposes below. For each, we name the legal basis we rely on under the GDPR.

Purpose Legal basis
Respond to your enquiry, access request, or design-partner application Steps at your request prior to a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f))
Provide, operate, and maintain ediccio.ai and the Ediccio service Performance of a contract (Art. 6(1)(b))
Keep the service secure, prevent fraud and abuse, and debug failures Legitimate interests (Art. 6(1)(f))
Send service and security messages about your account Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))
Send product updates where you have opted in Consent (Art. 6(1)(a)), withdrawable at any time
Meet legal, tax, and regulatory obligations Legal obligation (Art. 6(1)(c))

We do not use your personal data for automated decisions that produce legal or similarly significant effects on you.

Sharing

We do not sell your data.

We share personal data only with the recipients below, and only to the extent each purpose needs:

We do not sell personal data, and we do not share it for cross-context behavioral advertising.

Connected platforms

Data from integrations you connect.

Ediccio is built to receive data from other platforms and integrations that you, or the organisation you belong to, choose to connect. When a connection is established:

Transfers

EU-resident by default.

Service data is processed in the European Union by default. Where any personal data is transferred outside the European Economic Area (for example, a content-delivery edge that serves the public website, or a DNS and certificate control plane that holds no personal data), we rely on a recognised transfer mechanism: an adequacy decision where one exists, or the European Commission's Standard Contractual Clauses with supplementary safeguards. To request a copy of the safeguards that apply to a specific transfer, write to privacy@ediccio.com.

Retention

Kept only as long as needed.

We keep personal data only for as long as we need it for the purposes in this notice, then we delete or anonymise it.

Security

Appropriate to the risk.

Customer profiles are uniquely sensitive, so security constrains the architecture rather than sitting beside it. We apply technical and organisational measures appropriate to the risk, including:

No system is perfectly secure. If we become aware of a personal-data breach likely to put your rights at risk, we will notify the relevant supervisory authority, and you where the law requires, within the applicable timelines.

Your rights

What you can ask of us.

Depending on where you live, you have some or all of these rights:

To exercise any right, write to privacy@ediccio.com. We may ask for enough information to confirm your identity before we act, to protect your data against impersonation. We respond within one month, and will tell you if a complex request needs longer. There is no fee unless a request is manifestly unfounded or excessive.

If you are not satisfied with our response, you may lodge a complaint with a supervisory authority. In Spain this is the Agencia Española de Protección de Datos (AEPD); in the rest of the European Union it is the authority where you live, work, or where the issue arose.

Cookies

Essential only.

The public website runs on strictly necessary cookies and equivalent storage: the items needed to serve pages securely and to remember choices you make. We do not use advertising or cross-site tracking cookies on ediccio.ai. Where the service uses cookies, they are for authentication and session management only. You can control cookies in your browser, though disabling the essential ones may affect how the site works.

Children

Not directed to children.

Ediccio is a tool for businesses and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us data, write to privacy@ediccio.com and we will delete it.

Changes & contact

How to reach us.

We may update this notice, for example when we add a feature, change a provider, or respond to a change in the law. The effective date at the top shows when the current version took effect. Where a change is material, we will give notice before it takes effect through the service or by email.