Legal
Privacy policy
What personal data we process when you use this website or contact us, why, for how long and how to exercise your rights, under the General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
Summary
- Controller
- AxisOne Group SL
- Purposes
- Answering your requests (demo, contact, trial account, quote, support and custom development, including asking from the website assistant to have someone email you) and confirming by email that we received them, answering your questions in the assistant, emailing you a calculator result or a downloadable guide if you ask for it and the newsletter if you subscribe, managing our relationship with customers, protecting the website and, if you agree, measuring which campaigns and pages bring us requests.
- Legal basis
- Your consent, the request you make, the contract with customers and our legitimate interest.
- Recipients
- We do not sell or disclose your data. Cloudflare, Brevo, the team’s internal messaging tool (Teams or Slack) and, for the assistant, Google provide services to us under a data processing agreement. Cloudflare, Google and, depending on the tool, the messaging tool may process data outside the EU, with safeguards.
- Rights
- Access, rectification, erasure, objection, restriction and portability, at privacy@attendo.me.
Data controller
- Controller
- AxisOne Group SL
- Tax ID (CIF)
- B88764816
- Registered office
- Calle Pompeu Fabra, 5 – Complejo Podium, 08840 Viladecans (Barcelona), Spain
- Privacy and rights requests
- privacy@attendo.me
- General email
- sales@attendo.me
We have not appointed a data protection officer. For any privacy question, write to privacy@attendo.me.
What data we process, why and on what basis
We only process the data you give us in the forms or by email and the data generated by your visit. Here is each purpose, with its data and legal basis:
| Purpose | Data | Legal basis |
|---|---|---|
| Demo requests and contacting sales, including from the assistant (“Have someone email me”) | DataWork email, full name, company, phone (optional), area of interest, approximate number of users, the tool you use today and your question. From the assistant: your email address, your name and phone if you give them, the page you were on and, if you tick the box, the questions you asked it in that conversation. | Legal basisYour consent when you submit the form (GDPR art. 6.1.a) and steps taken at your request before entering into a contract (art. 6.1.b). |
| Trial account | DataName, company, email, phone, job title, number of people who would use it, industry, what you want to try and your acceptance of the terms of service. | Legal basisPre-contractual steps and the relationship created when you accept the terms of service (art. 6.1.b), and your consent (art. 6.1.a). |
| Quote | DataWhat it must include, office and field users, integrations, when you want to start, current tool, name, company, email, phone and comments. | Legal basisPre-contractual steps (art. 6.1.b) and your consent (art. 6.1.a). |
| Custom development | DataWhat you need and its description, systems involved, timeline, whether you are already a customer, name, company, email and phone. | Legal basisPre-contractual steps (art. 6.1.b) and your consent (art. 6.1.a). |
| Customer support | DataRequest type and urgency, subject and description, module, your attendo instance address, name, company, email and phone. | Legal basisThe contract with your company (art. 6.1.b) and our legitimate interest in assisting our customers’ contact people (GDPR art. 6.1.f and LOPDGDD art. 19). |
| Emailing you a calculator result | DataYour email address, the calculator, the values you enter, the currency, the result and the link to open the calculation again. The request is recorded in our CRM so we can reply if you write to us about the calculation. | Legal basisYour request: you ask us to send you the calculation (GDPR art. 6.1.b). We send it once and do not send you marketing communications because of it. |
| Sending you a downloadable guide | DataYour email address, your name and company if you give them, the guide you request and the language. The request is recorded in our CRM so we can reply if you write to us about the guide. | Legal basisYour request: you ask for the guide and we send you the link to download it (GDPR art. 6.1.b). We send it once and do not send you marketing communications because of it. The newsletter is a separate, unticked box with its own legal basis: your consent. |
| Newsletter | DataYour email address, language, the date and text of the box you tick, and the subscription status (confirmed or unsubscribed). | Legal basisYour consent (GDPR art. 6.1.a and LSSI-CE art. 21), which you can withdraw at any time with the unsubscribe link in every email or by writing to privacy@attendo.me, without affecting what was sent before. |
| Customer relationship | DataBusiness contact details of people at the customer company, and subscription and billing data. | Legal basisThe contract (art. 6.1.b), tax and commercial obligations (art. 6.1.c) and our legitimate interest (GDPR art. 6.1.f and LOPDGDD art. 19). |
| Emails you send us | DataYour email address and whatever you include in the message. | Legal basisYour consent or, if you are a customer, the contract. To handle rights requests, a legal obligation (art. 6.1.c). |
| Source of the request | DataThe page you submit the form from, the referring page and, if that page’s address carries them, the campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content) and the click IDs of Google Ads (gclid), Microsoft Advertising (msclkid), Meta (fbclid) and LinkedIn (li_fat_id). If you accept analytics cookies, also those of the page you landed on, that page itself and the website you came from, which we keep in your browser during the visit (cookie policy). | Legal basisOur legitimate interest in knowing which channels, campaigns and pages bring us requests (art. 6.1.f). Storing this data in your browser, only with your consent (LSSI-CE art. 22.2). |
| Website security | DataIP address, browser and device data and interaction signals that Cloudflare Turnstile analyzes when you submit a form, and technical logs of requests to the website. | Legal basisOur legitimate interest in protecting the website and the forms from abuse (GDPR art. 6.1.f and recital 49). |
| Visit statistics | DataVisit data that Cloudflare Web Analytics counts in aggregate (page, referrer, country, device type and browser), without cookies and without identifying you. | Legal basisOur legitimate interest in knowing which content is read (art. 6.1.f). |
| “Ask attendo” assistant | DataThe questions you type and the parts of the website used to answer them. The assistant says that an AI is answering and that you should not share personal data. If we turn on conversation logging, we keep the questions without IP addresses or identifiers for 90 days to improve our content. If you click “Have someone email me”, what you send in that form is handled as a request to contact sales (first row). | Legal basisOur legitimate interest in answering what you ask us (art. 6.1.f): you start the conversation, you expect an answer and we only use what you type. For logging, our legitimate interest in improving the website without identifying you (art. 6.1.f). |
| Whistleblowing channel | DataAs explained on the whistleblowing channel page. | Legal basisA legal obligation or the public interest (GDPR art. 6.1.c and 6.1.e and article 30 of Spanish Law 2/2023). |
Required fields are marked on each form: without them we cannot handle your request. Optional fields help us prepare it better. If you give us someone else’s data, make sure you are allowed to and that they know about this policy.
We do not make decisions based solely on automated processing that produce legal effects on you or similarly affect you (GDPR art. 22).
Marketing communications
We only write to you about what you asked for. We do not send you marketing communications by email or other electronic means unless you have requested or expressly authorized them, or you are a customer and they concern products or services similar to the ones you subscribed to (LSSI-CE art. 21). Every communication lets you unsubscribe easily and free of charge.
Newsletter. If you subscribe by ticking the box on the form, we send you one email a month with attendo news and new content from the website. We ask you to confirm your subscription from your inbox, and every email lets you unsubscribe with one click. You can also ask to unsubscribe at privacy@attendo.me. We send it with the mailing module of our own platform, attendo.
Confirmation of your request. When you request a demo, a trial account, a quote or custom development, write to us from the contact form or ask from the assistant to have someone email you, we send you an email confirming that we received it, with a summary of what you sent us and when we will reply. It is part of handling your request, with the same purpose and legal basis, and it is not a marketing communication. So that nobody can use the forms to flood someone else’s inbox, we send at most one confirmation every 10 minutes and three a day to the same address.
Calculator result. If you ask us to email you a calculator result, we send it once, because you asked for it. It is not a marketing communication and does not subscribe you to anything.
Downloadable guides. If you request a guide, we show you the download link and email it to you once, because you asked for it. It is not a marketing communication and does not subscribe you to anything: the newsletter is a separate, unticked box on the same form.
How long we keep data
We keep data only as long as needed for the purpose we collected it for:
- Requests that do not lead to a subscription: up to two years from the last contact, so we can pick up the conversation if you come back.
- Customer data and support requests: for as long as the contract lasts.
- After that, blocked for the limitation periods of legal claims and of tax and commercial obligations (for example, six years for accounting records under article 30 of the Spanish Commercial Code), available only to courts and public authorities (LOPDGDD art. 32).
- Campaign parameters and landing page in your browser: until you close the tab. In our systems, source data stays with the request it belongs to.
- Confirmation of your request by email: we do not keep a separate copy; Brevo keeps the sending log for the period its terms set.
- Calculator result: your email address, the values and the result are kept like other requests that do not lead to a subscription. We do not keep a separate copy of the email we send you; Brevo keeps the sending log for the period its terms set.
- Downloadable guides: your email address, name, company and the guide you requested are kept like other requests that do not lead to a subscription. Brevo keeps the log of the email with the link for the period its terms set.
- Newsletter: for as long as you stay subscribed. When you unsubscribe we stop sending it, and we keep proof of your consent and of the unsubscription only as long as needed to prove them if challenged.
- Assistant conversations: in your browser, until you close the tab. At Google, the period its API terms set for abuse monitoring. If we turn on logging, 90 days, without IP addresses or identifiers.
- Turnstile signals and technical logs: the short period Cloudflare sets for the security of the service.
- Whistleblowing reports: the periods set by Spanish Law 2/2023, explained on the whistleblowing channel page.
- Rights requests: as long as needed to prove we handled them.
When data is no longer needed, we delete or anonymize it.
Recipients and processors
We do not sell your data or disclose it to third parties, except when required by law (for example, to courts or public authorities that request it).
To provide our services, some vendors access the data as processors, under a contract that requires them to process it only on our instructions and with security measures (GDPR art. 28):
| Vendor | What for | Where |
|---|---|---|
| Cloudflare, Inc. (US) | What forHosting and delivery of the website, receiving the forms and storing them (Workers and D1), bot checks (Turnstile) and cookieless visit statistics (Web Analytics). | WhereCloudflare’s global network. Form database in the European Union. |
| Brevo (Sendinblue SAS, France) | What forEmailing our team a notice of each request, emailing you the confirmation that we received your request, and emailing you a calculator result or a guide link when you ask for them. | WhereEuropean Union. |
| Microsoft (Teams) or Slack | What forAn instant notice of each request in the sales or support team’s internal channel, with the contact details and a summary. | Where |
| Google (Gemini API) | What forGenerating the answers of the “Ask attendo” assistant from your questions and parts of the website. With the paid API, Google does not use this data to train its models. | WhereUnited States, with safeguards, or an EU region if Vertex AI is used. |
| attendo (our own CRM and ticketing) | What forHandling sales and support requests in our own attendo instance, and sending the newsletter with its mailing module. | WhereEuropean Union. |
| Business email | What forEmails you send us. | Where |
If your company subscribes to attendo, other vendors take part in the service. They are listed as sub-processors in the data processing agreement.
International transfers
We process data in the European Union. The exceptions are Cloudflare, Google and, depending on the tool, the internal notice in Teams or Slack. Because of how the network of Cloudflare, Inc., based in the United States, works, some data (such as the IP address and Turnstile signals) may be processed outside the European Economic Area or be accessible from there.
Cloudflare participates in the EU-U.S. Data Privacy Framework, recognized by the European Commission’s adequacy decision of July 10, 2023, and its data processing addendum also includes the standard contractual clauses approved by the Commission.
The assistant’s questions and the parts of the website sent with them go to Google to generate the answer, and may be processed in the United States. The transfer is covered by the EU-U.S. Data Privacy Framework, in which Google LLC participates, or by the standard contractual clauses in its data processing terms. If we use Gemini through Vertex AI in an EU region, answers are generated in the EU.
Brevo processes data in the European Union.
If the internal notice of requests goes to Slack, or to Microsoft Teams with data outside the European Union, the transfer is covered by the EU-U.S. Data Privacy Framework, in which Salesforce (Slack) and Microsoft participate, or by the standard contractual clauses in their data processing terms.
You can ask for more information or a copy of the safeguards at privacy@attendo.me.
Your rights
You can exercise these rights at any time:
- Access: find out whether we process your data and get a copy.
- Rectification: correct data that is inaccurate or incomplete.
- Erasure: ask us to delete it when it is no longer needed or you withdraw your consent.
- Objection: object to processing based on our legitimate interest and, always, to marketing communications.
- Restriction: ask us to stop using it while we resolve a complaint of yours.
- Portability: receive the data you gave us in a structured, commonly used format, or have us send it to another controller.
- Withdraw consent whenever you want, without affecting prior processing. For cookies, use “Cookie settings” in the footer of every page.
How to exercise them: write to privacy@attendo.me, or by letter to our registered office, stating which right you want to exercise. If we have reasonable doubts about your identity, we may ask for additional information to confirm it. We reply within one month, which may be extended by two more months if the request is complex or there are many, and we will tell you about the extension within the first month. It is free, except for manifestly unfounded or excessive requests.
If your data is in attendo because a company that uses the service stored it (for example, you are its customer or employee), send your request to that company, which is the controller. If it reaches us, we will forward it to them.
Complaints to the supervisory authority
If you think we have not handled your data properly, you can lodge a complaint with the Spanish Data Protection Agency, AEPD (www.aepd.es), C/ Jorge Juan, 6, 28001 Madrid, Spain, or with the supervisory authority of the EU country where you live or work. We would appreciate it if you wrote to privacy@attendo.me first so we can try to resolve it.
Children
The website and the service are intended for businesses and professionals. We do not knowingly collect data from children under 14 (LOPDGDD art. 7). If we find that we have received any, we delete it.
Security
We apply technical and organizational measures appropriate to the risk (GDPR art. 32): encrypted connections, bot checks on the forms, access to requests limited to the team members who handle them, and vendors bound by data processing agreements. The security measures of the attendo service are described under Security.
No system is infallible. If a personal data breach affects your data, we will notify the Spanish Data Protection Agency within 72 hours and, when it poses a high risk to you, we will tell you (GDPR arts. 33 and 34).
If your company uses attendo
When a company subscribes to attendo, the data it stores on the platform (its customers, contacts, assets, documents and communications) belongs to it, and it is the controller. AxisOne Group SL processes that data as a processor: only to provide the service and on the customer’s instructions, under the data processing agreement (GDPR art. 28) that is part of the terms of service.
That data is hosted in the European Union, in a separate database for each customer. Some vendors act as sub-processors, as listed in the data processing agreement. The integrations the customer turns on (for example, its AI provider, WhatsApp or its email) work under those providers’ terms. The attendo mobile app processes data the same way, on behalf of the customer that uses it.
We process the data of the customer’s contact people and users that we need to manage the contract (account setup, billing, support, service notices and access security) as a controller, with the bases and periods in this policy.
Changes to this policy
We may update this policy when our processing or the law changes. We will publish the new version here with its date and, if the change is significant, we will announce it prominently.