Data processing agreement
Last updated: 09/10/2026
This is an English translation for information only. The Spanish version is the one that applies.
It is part of the terms of service and is accepted when you sign up. It covers what article 28(3) of the GDPR requires.
- Controller: the client company of Bildeit (the account holder).
- Processor: Unai España Tejero (Bildeit), tax ID 47742127S, Calle Sant Salvador 13, 08191 Rubí (Barcelona), Spain. Email: privacidad@bildeit.com.
1. Subject, duration and nature
Bildeit processes personal data on behalf of the client only to provide the service: keeping its jobs, budgets, progress certificates and invoices, its clients and suppliers, its payments and retentions, and preparing its record books and tax forms. Processing lasts as long as the service, plus what section 9 says.
2. Data and data subjects
- Data subjects: the company's clients (individuals, businesses and homeowners' associations), its suppliers and the people the company gives access to the panel (its team, its site managers and its accountant).
- Data: identification and contact details (name, email, phone and address), tax ID, job details (address and type of work) and invoicing data (amounts, dates and taxes).
- No special categories of data are processed.
3. Processor's obligations
Bildeit:
- a) processes the data only on the client's documented instructions, which are these terms and what the client sets up in its account. If an instruction seems unlawful, it will say so;
- b) ensures that anyone with access to the data is bound by confidentiality;
- c) applies the security measures in annex I;
- d) only uses subprocessors under section 4;
- e) helps the client handle requests from data subjects exercising their rights;
- f) helps the client with security, breach notification and, where needed, impact assessments;
- g) when the service ends, deletes or returns the data under section 9;
- h) makes available to the client the information needed to show compliance, and allows for and contributes to audits.
Law: article 28(3) of the GDPR and article 33 of the LOPDGDD.
4. Subprocessors
The client gives general authorisation for the providers listed in Subprocessors. Before adding or changing one, Bildeit will email the client in advance, and the client may object. Each subprocessor is bound by the same data protection obligations.
Law: article 28(2) and (4) of the GDPR.
5. Transfers outside the EU
Only to the providers in the Subprocessors list and with the safeguard stated for each, under articles 44 to 46 of the GDPR.
6. Security breaches
Bildeit will notify the client without undue delay as soon as it becomes aware of a breach affecting its data, with the information available, so that the client can notify the Spanish Data Protection Agency within 72 hours where required.
Law: article 33 of the GDPR.
7. People invited by the client
People the client gives access to the panel act on the client's behalf and under its responsibility, with the role it gives them: office, site manager (their own jobs only) or accountant (read-only access to invoicing and tax). The database enforces those permissions, not just the screen.
8. Record of processing activities
Bildeit will keep a record of the processing it carries out as a processor: [PENDING: record of processing activities].
Law: article 30(2) of the GDPR.
9. End of the service
Before the end, the client can download its record books as CSV and Excel and its budgets as Excel. At the end, Bildeit deletes or returns the data, as the client chooses. Whatever a law requires to be kept, such as invoicing records, is blocked until it can be destroyed.
Laws: article 28(3)(g) of the GDPR and article 32 of the LOPDGDD (blocking).
Annex I · Security measures
- Encrypted connections (HTTPS).
- Passwords stored encrypted, never in plain text.
- Each company's data isolated row by row in the database (row-level security).
- Role permissions enforced by the database.
- Keys and secrets kept out of the code.
- Invoicing records cannot be changed or deleted.