Legal
Privacy Policy
How SpainPath AI collects, uses and protects your personal data under the EU GDPR and the Spanish LOPDGDD.
Last updated 21 June 2026 · Data controller: SpainPath AI (the operator of this website). Contact: privacy@spainpath.ai.
1. Who we are
SpainPath AI ("we", "us") operates this website and provides an AI-based information service for people relocating to, living in or doing business with Spain. This policy applies to all visitors and registered users and complies with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on Personal Data Protection and Digital Rights (LOPDGDD).
2. What data we collect
Account data: name, email, password hash, language. Profile data you provide voluntarily: nationality, country of residence, employment type, income range, family status, immigration goals, NIE/TIE status. Documents you upload: passports, criminal-record certificates, contracts, insurance and similar files you choose to store. Usage data: conversations with the AI assistant, checklists, page views, IP address, browser and device information. Cookies and similar technologies as described in our Cookie Policy.
3. Why we process it (legal bases)
Performance of the contract (Art. 6.1.b GDPR) to provide the service, your account and the AI assistant. Your consent (Art. 6.1.a GDPR) for non-essential cookies, marketing communications, and the processing of any special-category data you choose to upload in documents. Legitimate interest (Art. 6.1.f GDPR) for security, fraud prevention and product improvement. Legal obligation (Art. 6.1.c GDPR) to respond to lawful requests from authorities and meet accounting/tax rules.
4. AI processing
Your questions and the relevant parts of your profile are sent to large-language-model providers (currently the Lovable AI Gateway, which routes to Google and OpenAI models) solely to generate answers. We do not use your content to train third-party foundation models. Documents you upload are stored in encrypted object storage and are only sent to AI models when you explicitly attach them to a question.
5. Recipients and international transfers
We share data only with processors needed to run the service: Lovable Cloud / Supabase (hosting, database, storage — EU region), the Lovable AI Gateway and underlying model providers, our email provider, and analytics providers if you accept analytics cookies. Where processors operate outside the EEA, transfers are protected by the European Commission's Standard Contractual Clauses.
6. Retention
Account and profile data are kept while your account is active and for up to 24 months after deletion for legal and accounting purposes. Uploaded documents are deleted within 30 days of account deletion. AI conversation logs are kept for 12 months. Anonymous analytics data may be kept longer.
7. Your rights
Under the GDPR and the LOPDGDD you may at any time access, rectify, erase, restrict or object to the processing of your personal data, withdraw consent, and ask for data portability. Write to privacy@spainpath.ai. You may also file a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es) or your local supervisory authority.
8. Security
We apply technical and organizational measures including TLS in transit, encryption at rest, role-based access control, row-level security on the database, audit logging, and least-privilege service credentials.
9. Children
The service is not intended for users under 14 years old (the minimum age for valid consent under Spanish law). We do not knowingly collect data from minors.
10. Changes
We will publish any update to this policy on this page and, for material changes, notify registered users by email at least 15 days before the change takes effect.