Privacy Policy
Last updated: 2026-08-10
This policy explains what personal data PrimeApp Studio collects, why, and what you can do about it. It is written to meet Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
1. Who is responsible
- Controller: [LEGAL_NAME]
- Tax ID (NIF): [NIF]
- Address: [STREET, POSTAL CODE, CITY, SPAIN]
- Contact: admin@primeappstudio.com
No data protection officer has been appointed, as the criteria in art. 37 GDPR do not apply. Write to the address above for any privacy matter.
2. Two very different roles
This distinction decides which parts of this policy apply to you.
- Your own account data — the email, name and billing details of the person who signs up. Here we are the controller, and this policy governs it.
- The records you enter — members, donors, contributions. Here you are the controller and we merely process on your behalf, under the terms of Annex A of the Terms. We do not decide what goes in, and we do not use it for anything other than running the service for you.
3. What we collect and why
| Data | Purpose | Legal basis |
|---|---|---|
| Email, name, workspace name, password hash | Create and run your account | Performance of the contract (art. 6.1.b) |
| Billing details held by Stripe; subscription status | Take payment, meet accounting duties | Contract (6.1.b) and legal obligation (6.1.c) |
| IP address, sign-in attempts, timestamps | Rate limiting and abuse prevention; keeping accounts secure | Legitimate interest in service security (6.1.f) |
| Service emails (sign-up, password reset, billing notices) | Operate the account | Contract (6.1.b) |
| Website analytics (see section 6) | Understand how the site is used and improve it | Your consent (6.1.a) |
| The records you enter about other people | Provide the module you subscribed to | Processed on your instructions — you set the basis |
We do not run advertising, we do not sell personal data, we do not share it with third parties for their own marketing, and we do not use it to train machine-learning models.
4. Who else sees the data
We use the service providers below, each bound by a data processing agreement and permitted to act only on our instructions.
| Provider | Purpose | Location |
|---|---|---|
| Neon | Database hosting — stores all workspace records | European Union |
| Vercel | Application hosting — serves the app and processes requests | European Union / United States (SCCs) |
| Stripe Payments Europe, Ltd. | Subscription billing and card processing | Ireland / United States (SCCs) |
| Resend | Transactional email (sign-up, password reset) | United States (SCCs) |
We also disclose data where a law, a court or a competent authority requires it.
5. International transfers
Customer records are hosted in the European Union. Where a provider processes data outside the EEA, the transfer relies on an adequacy decision, on the EU-U.S. Data Privacy Framework, or on the European Commission’s Standard Contractual Clauses with any supplementary measures needed. You can ask us for a copy of the safeguards in place.
7. How long we keep it
- Account data: while the account exists, then deleted within 30 days of a deletion request.
- Workspace records: while the workspace exists; they survive cancellation so you can still export them, and are deleted on request.
- Backups: aged out within a further 30 days after deletion.
- Sign-in and rate-limiting logs: short-lived, cleared as counters reset.
- Invoicing records: kept for the periods Spanish tax and commercial law require (generally 4 to 6 years).
8. Your rights
You have the right to access your data, to have it corrected or deleted, to restrict or object to processing, to data portability, and to withdraw a consent you have given (which does not affect processing already carried out).
Exercise them by writing to admin@primeappstudio.com. We reply within one month. If your request concerns records held inside a customer’s workspace, we will refer you to that customer, who is the controller for them.
If you are not satisfied, you may complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos, or to the authority where you live.
9. Security
Traffic is served over HTTPS, data is encrypted at rest, passwords are stored only as bcrypt hashes, each workspace is isolated and checked on every request, sessions can be revoked centrally, and sign-in is rate limited by both account and network address. The full list is in Annex A.5 of the Terms.
10. Children
The service is not directed at children and accounts may only be created by adults. Records about minors may be entered by a customer acting as controller; the legal basis for doing so is that customer’s responsibility.
11. Changes to this policy
We may update this policy. The date at the top changes with it, and we will notify account owners by email of material changes.