Privacy Policy
This Privacy Policy ("Policy") explains how
pibiCo Compañía de Inteligencia de Negocio y Control SL
("pibiCo", "we" or "our") collects, uses, discloses and protects personal data
when you use the application pibiMemo ("the
Platform"), a SaaS solution by pibiCo enhanced with AI and IoT capabilities.
pibiCo is a Spanish company incorporated under the laws of Spain and the
European Union (EU), with VAT number ES B52567831 and registered
office at Avenida de La Costa, 35-6T, 33201 Gijón, Asturias, Spain.
pibiCo is the data controller for the personal data described in this Policy, for the purposes of Article 4(7) of Regulation (EU) 2016/679. For anything concerning that data, including the exercise of your rights, you may write to soporte@pibico.es.
1. Scope of this Policy
1.1 Applicability
This Policy applies to personal data we collect from whoever uses the Platform: both those who open their own account and contract on their own behalf — an individual, in most cases — and the authorised Users and employees of the organisations that contract it. There is no guest mode: all Users must register to obtain an account. Visitors of the public website may view general information without logging in; no personal data is collected from such visitors unless they voluntarily provide it through contact or sign-up forms.
1.2 Data Protection Officer (DPO)
We have appointed our CTO as Data Protection Officer. For privacy-related inquiries, contact: soporte@pibico.es.
2. Personal data we collect
2.1 Types of personal data
While using pibiMemo we may collect the following categories of data:
- Email address: address used by the User to create the account, authenticate and receive service notices.
- Name: the name the User chooses to identify their account with.
- User identifier: internal identifier linking stored content to the account that created it.
- Audio recordings: voice notes recorded by the User and the automatic transcription generated from them.
- Images: photographs the User expressly selects to attach to their notes or documents.
- Documents: PDF, office or text files the User stores on the Platform.
- Other User content: titles, written notes, categories, tags and any other content created by the User.
- Technical data: IP address, user-agent, anti-abuse device fingerprint hash and session logs.
2.2 No special categories
We do not collect health, biometric or sensitive financial data beyond what is strictly necessary for the contract payment methods.
2.3 Mobile app permissions (Android / iOS)
The pibiMemo mobile app may request the following operating-system permissions. They are only used when the User explicitly enables the corresponding feature and resulting data is processed under the legal bases described in section 5.
- Microphone (
android.permission.RECORD_AUDIO/ iOS NSMicrophoneUsageDescription): required exclusively for the Voice Notes module. Recording starts and stops only on explicit User action. While active, a persistent system notification is displayed. Recordings are automatically transcribed, stored within the User's personal workspace and never shared with third parties. The User can delete any recording individually or delete their account for full purge. No background recording without explicit User action. - Notifications (
android.permission.POST_NOTIFICATIONS): to deliver meeting + task reminders configured by the User. Not used for advertising. - Network connectivity (
INTERNET,ACCESS_NETWORK_STATE): to sync with pibiCo services (auth, storage, processing) over encrypted HTTPS. - Foreground service (
FOREGROUND_SERVICE,FOREGROUND_SERVICE_MICROPHONE): prevents the OS from interrupting a voice recording started by the User. Active only while the recording lasts. - Wake lock (
WAKE_LOCK): keeps the device awake exclusively during an active recording.
Attaching photographs and files gives no access to the photo library. When the User attaches an image or a document, the app opens the operating system's picker, which returns only the chosen file. The app does not browse the photo library nor device storage, and cannot read any file the User has not expressly selected.
The camera is used, and only when the User asks for it. When attaching, there is an option to take a photo there and then; the system asks for permission the first time and the app cannot open the camera without it. The image is stored as one more attachment and is not sent anywhere other than the rest of the archive. The app does not record video and writes nothing to the device's photo library.
Attached files are stored within the User's personal workspace; the User can delete them individually or delete their account for full purge.
The app does NOT collect location, contacts or device calendar. It only accesses the photographs and files the User expressly selects through the operating-system picker; it does not browse the photo library nor the device storage. It does NOT contain ads nor third-party trackers. It does NOT share or sell User data.
2.4 Third-party data provided by the User
Some pibiMemo features let the User enter personal data belonging to other people. The User decides what data to provide and declares having a legitimate basis to do so. pibiCo processes it solely to carry out the User's instruction: it is not used for marketing, not enriched from other sources and not disclosed to third parties. The categories involved are:
- Designated recipient emails: email addresses of third parties the User designates as recipients of their content.
These individuals may exercise their rights of access, rectification, objection and erasure by writing to soporte@pibico.es under the terms of section 10, even if they are not registered Users of the Platform.
3. How we collect your data
3.1 Direct collection
Personal data is mainly collected when authorised Users or employees enter their information into Platform forms or complete the organisation onboarding.
3.2 System logs and local storage
We use local storage and logs to track User activity, ensure security, debug issues and keep accurate billing records.
3.3 No automated external collection
We do not collect personal data through external APIs or automated third-party integrations without prior agreement. Any additional integration is explicitly agreed with the account holder or, where the account belongs to an organisation, with that organisation.
4. Purposes of processing
4.1 Service delivery
We process personal data to provide and maintain pibiMemo's features, including analytics, reporting, calendar or IoT synchronisation where applicable, and integration with other pibiCo services under the same SSO.
4.2 Support and billing
Personal data may be used to provide customer support, issue Verifactu invoices, manage contracts and their payments, and handle incidents.
4.3 Communications
With your explicit consent, we may send newsletters or notifications about service updates. Service communications (incidents, changes, legal notices) are always sent on legitimate-interest basis even without marketing consent.
4.4 No profiling or automated decisions
We do not use personal data to build profiles or make automated decisions with legal or similarly significant effects.
5. Legal bases for processing
| Legal basis (Art. 6 GDPR) | Application |
|---|---|
| Contract performance (Art. 6.1.b) | Service delivery, account management, authentication, collection of the contract fee. |
| Legal obligation (Art. 6.1.c) | Invoicing, accounting retention and Spanish tax law (incl. RD 1007/2023 Verifactu). |
| Legitimate interest (Art. 6.1.f) | Security, anti-abuse, fraud prevention, service communications. |
| Consent (Art. 6.1.a) | Marketing communications, analytics and marketing cookies. |
6. Disclosure and data sharing
6.1 External processors
We share data with the following processors under a DPA contract pursuant to Art. 28 GDPR:
| Third party | Purpose | Location |
|---|---|---|
| Transcription service | Turn speech into text | EU |
| Embeddings service | Index the text so it can be searched | EU |
| Document conversion service | Turn a document into text | EU |
| Language model service | Extract reminders and hold the conversation | EU |
| pibiCo Auth | Identity, contract and usage | EU |
| IONOS Cloud, S.L.U. | Servers where the Service runs and disks where its data resides | EU |
| Telegram Messenger Inc. | Capture and conversation channel through the pibiMemo bot, when the User chooses to use it | Outside the EU |
6.2 AI processing
AI data processing in pibiMemo: on pibiCo's own servers.
AI processing runs on pibiCo's own machines within the European Union, not on a third-party AI provider: content is not disclosed to anyone and is not used to train models, ours or anyone else's. GPU compute runs on a dedicated server in Germany and the rest of the Service on another in Spain; both with the same hosting provider, which appears in the Annex. Data does not leave the European Economic Area.
6.3 No external transfers without agreement
We do not transfer personal data to external APIs, third-party software or services that are not explicitly agreed in your organisation's contract.
6.4 Disclosure to recipients designated by the User
pibiMemo lets the User designate recipients to receive certain of their content. This is not a disclosure to third parties on pibiCo's initiative: it happens solely on the User's express instruction and covers only the content the User has assigned to each recipient.
Delivery is triggered by a periodic activity check. The feature is disabled by default; if the User enables it, they set a check interval and a grace period. If both elapse without the User confirming activity, each recipient receives a personal read-only link limited to the content assigned to them. The User can change or revoke recipients and assigned content at any time, and links already issued are automatically removed if the User confirms their activity again.
7. Data retention
7.1 Retention periods
- Account with a contract in force: for as long as the contract remains in force.
- Account after the contract ends: 365 days in consultation mode — the account can still be opened and all content read, but it no longer has an active plan. After that period it is permanently deleted, with an email warning 30 days beforehand.
- Billing data: 6 years (Spanish commercial and tax obligation).
- Security logs: 12 months.
7.2 Post-contract retention
After the contract ends, the User's archive is deleted within the period stated in the section above. The only thing kept longer is billing data, for 6 years, under Spanish commercial and tax obligations. The content is not kept.
8. Data security
8.1 Technical and organisational measures
We use role-based access control (RBAC), permission management, encryption in transit (TLS 1.2+) and at rest where applicable, passwordless authentication (passkey + email-OTP), and complete activity logging. Only authorised personnel have access to personal data.
8.2 Data breaches
In case of a suspected breach we will investigate immediately, identify the scope, and where applicable notify affected data subjects and the AEPD within the 72-hour period set by Art. 33 GDPR.
9. International transfers
Where a processor is located outside the European Economic Area, transfers are made on the basis of Standard Contractual Clauses (SCCs) approved by the European Commission, or under an Adequacy Decision. By default, pibiMemo data is stored on European infrastructure.
10. Data subject rights
10.1 Your rights (GDPR and LOPDGDD)
- Access: obtain confirmation of which data we process and a copy of it.
- Rectification: correct inaccurate or incomplete data.
- Erasure ("right to be forgotten"): request deletion of your data.
- Objection: object to processing based on legitimate interest.
- Restriction: request temporary restriction of processing.
- Portability: receive your data in a structured, exportable format.
- Withdraw consent: at any time without affecting the lawfulness of prior processing.
10.2 Exercising your rights
To exercise any right write to soporte@pibico.es or to the DPO at soporte@pibico.es indicating the affected app and providing identification. We will respond within one month.
10.3 Complaint to the AEPD
If you believe your rights have not been properly addressed, you may file a complaint with the Spanish Data Protection Agency at www.aepd.es.
11. Children's data
pibiMemo is not directed at children under 16. We do not knowingly collect data from minors without proper authorisation from whoever holds parental responsibility or guardianship and, where the account belongs to an organisation, from that organisation as well. If you detect that a minor has provided data without authorisation, contact soporte@pibico.es for immediate deletion.
12. Cookies
The use of cookies is governed by the Cookies Policy.
13. Updates to this Policy
Material changes (data collected, purposes, third parties, retention) will require fresh explicit consent and will be notified to subscribed Users by email before they take effect. Minor changes (corrections, formatting) are published with a new version and effective date without affecting prior consent.
14. Contact information
pibiCo Compañía de Inteligencia de Negocio y Control SL
Avenida de La Costa, 35-6T
33201 Gijón, Asturias, Spain
Email: soporte@pibico.es ·
DPO: soporte@pibico.es
Last updated: 2026-08-29 · Version 2.2.0