1. Introduction
At Claix (hereinafter, the "Service" or the "Platform"), operated by ANAYA CARBALLO GAEL, we offer an API and SaaS platform for standardization, intelligent mapping, and data transformation powered by Artificial Intelligence (ETL engine).
We take privacy and information security very seriously. This Privacy Policy describes how we collect, use, and protect the personal data of our users and B2B customers, in compliance with Regulation (EU) 2016/679 (GDPR) and Law 34/2002 (LSSI-CE).
2. Data Controller
- Identity: ANAYA CARBALLO GAEL (Trade name: Claix)
- Address: Ronda Sur 203, 3º 3ª Der, 28053 Madrid, Spain
- Tax ID (NIF): 51030923H
- Contact and privacy email: info@claix.dev
3. Data Collection and Processing Purposes
We expressly distinguish between User/Customer Data (for account management) and Upload File / API Payload Data (the Excel/CSV files you upload for processing):
A. Account and B2B Management Data
- Account Registration: Email address, encrypted password, trade name or legal entity name, tax ID (NIF/CIF), and billing details.
- Service Communications and Support: Email for operational notifications, API usage alerts, and support ticket responses.
- Navigation and API Usage Data: IP address, HTTP headers, request logs (API Key usage logs for security and quota control purposes), and billing history.
B. Data Contained in Processed Files (API Payloads)
- Ephemeral Processing: When you send a file (.xlsx, .csv) through the Claix Dashboard or REST API, our Artificial Intelligence maps and standardizes columns to return a JSON structure.
- No-Training Guarantee: Data contained in your files is NEVER used to train, retrain, or improve public or third-party Artificial Intelligence models.
- Zero Retention Policy: Uploaded files are processed in memory / temporary storage only for the time strictly necessary to generate the JSON response and are deleted immediately after the request is completed.
4. Legal Basis for Processing
- Performance of a Contract: Processing account data and executing API requests is necessary for the provision of the contracted SaaS service.
- Compliance with Legal Obligations: Fraud prevention, invoice issuance, and response to requests from competent public authorities.
- Legitimate Interest: Ensuring the cybersecurity of the API infrastructure and preventing abuse or denial-of-service (DDoS) attacks.
- Consent: For the installation of optional cookies or the sending of newsletters/API updates (always revocable).
5. Storage, Infrastructure, and Data Location
All Claix servers and infrastructure are located within the European Economic Area (EEA), ensuring full GDPR compliance:
| Provider | Function / Purpose | Server Location |
|---|---|---|
| Supabase Inc. | Database, Authentication, and Edge Functions for API processing | European Union (Stockholm / Frankfurt / Ireland) |
No international data transfers are made to third countries outside the EEA that do not have an adequate level of protection or equivalent safeguards.
6. Data Retention
- Account and Billing Data: Retained for as long as the contractual relationship is maintained and, thereafter, for the legal periods established for addressing potential administrative or tax liabilities.
- Files Processed by the API: Zero temporary retention (0 seconds after a successful or failed HTTP response). We do not store persistent copies of your Excel files or resulting JSON output.
7. DPA Clause: B2B Data Processing Agreement (Art. 28 GDPR)
For business customers who use the Claix API to process personal data belonging to their own customers or end users, this Privacy Policy acts as a Data Processing Agreement (DPA) upon acceptance of our Terms of Service:
- Instructions:Claix will process file data solely following the Customer's instructions via HTTP/API requests sent to the platform.
- Confidentiality: Claix personnel and systems are subject to strict confidentiality and professional secrecy obligations.
- Security Measures: Claix applies encryption in transit (TLS/HTTPS) and at rest, as well as multi-tenant isolation.
- Sub-processors: The customer authorizes the subcontracting of technical hosting infrastructure in the EU (Supabase) indicated in this policy.
- Deletion and Erasure: Upon completion of each API request, Claix will securely destroy any temporary remnants of the processed information.
8. User Rights
You may exercise your GDPR rights by sending an email to info@claix.dev indicating the right you wish to exercise:
- Access: Know what personal data we process about your account.
- Rectification: Correct inaccurate or incomplete data in your B2B profile.
- Erasure ("Right to be forgotten"): Request complete deletion of your account and associated data.
- Restriction and Objection: Restrict certain data processing activities.
- Portability: Request export of your user data in a structured, machine-readable format (JSON/CSV).
If you believe your rights have not been adequately addressed, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.
9. Security Measures
Claix adopts technical and organizational measures to protect the confidentiality, integrity, and availability of the Service:
- Encryption in Transit: All connections to the API and Dashboard require HTTPS encryption with TLS 1.3 / RSA.
- Secure Authentication: Credential management via tokens and hashed API keys (x-api-key).
- Environment Isolation: Isolated Edge Functions for file processing without cross-client persistence.
10. Modifications
Claix reserves the right to update this Privacy Policy to adapt it to legislative changes or changes in the API architecture. Any material change will be notified by email to registered users.