Privacy policy
Last updated: 29 September 2026
1. Data controller
FIREFISH ESPAÑA, S.L., NIF B56627821, with address at Calle Marie Curie 8, 3-1, 28703 San Sebastián de los Reyes, Madrid. Contact email: [email protected].
2. What data we process and why
| Data | Purpose | Legal basis |
|---|---|---|
| Name and email | Create and maintain the account, authenticate access and send service notices | Performance of the contract (art. 6.1.b GDPR) |
| Data entered on documents: loader and carrier identification, tax ID, address, registrations, origin, destination and goods | Generate, host and keep the control document | Performance of the contract (art. 6.1.b GDPR) |
| Billing and payment data | Charge the subscription and meet tax obligations | Performance of the contract and legal obligation (art. 6.1.b and 6.1.c GDPR) |
| IP address, user agent and session date | Account security and prevention of unauthorised access | Legitimate interest (art. 6.1.f GDPR) |
Data appearing on a control document may relate to third parties (for example, a loader who is a private individual). In that case the user acts as the controller of that data and El DeCA as the processor, limited to processing it according to the user's instructions in order to provide the service.
3. How long we keep it
- Account data: while the account is active and, afterwards, for the limitation periods of any potential liabilities.
- Issued documents: at least one year from the date of the transport they document, so the user can meet their retention obligation. They may be deleted afterwards.
- Billing data: the periods required by tax and commercial regulations.
- Access logs: a limited period, for security purposes.
4. Visibility of documents
Every issued document remains accessible at a web address that doesn't require logging in. This is a transport regulation requirement: the document must be directly downloadable when its QR code is scanned.
Those addresses contain a random fourteen-character code, are neither predictable nor enumerable, and are excluded from search engines via robots.txt and the X-Robots-Tag header. robots.txt X-Robots-Tag. Whoever has the link or the QR code can see the document: that's what allows it to work during an inspection.
5. Recipients
Data is not sold or transferred to third parties. It is only shared with the providers necessary to deliver the service, who act as processors:
| Provider | Purpose | Location |
|---|---|---|
| Railway Corp. | Hosting of the application and database | United States / EU |
| Cloudflare, Inc. | Content delivery network and security | United States / EU |
| Resend, Inc. | Transactional email delivery | European Union (eu-west-1) |
| Stripe Payments Europe, Ltd. | Subscription payment processing | Ireland |
When any transfer involves countries outside the European Economic Area, it relies on the safeguards set out in Chapter V of the GDPR, such as the European Commission's standard contractual clauses.
6. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability by writing to [email protected].
Note that deleting documents already issued may be limited while your own legal obligation to keep them still applies.
If you believe the processing doesn't comply with the regulation, you can file a complaint with the Agencia Española de Protección de Datos (aepd.es).
7. Cookies
See the cookie policy.
