Privacy Policy
Last updated:
14 September 2026
This policy explains how we collect, use, share and protect your personal data.
Controller: HELLOMATIK, S.L. (CIF B22803126)
Contact: administracion@hellomatik.com
Effective date: 1 October 2025. Last updated: 14 September 2026.
1) Who we are and how this policy applies
This Policy explains how Hellomatik collects, uses, shares and protects personal data. Sometimes we control the data (for account, billing, support, security). Other times we process data on behalf of customers (for content in our Voice, Chat and Procedures modules). When we process data for customers, a Data Processing Agreement (DPA) sets our duties and limits. See sections 9 (Disclosures and recipients) and 10 (International data transfers) for more details.
2) Data we process
A) Data you provide
Account and billing: name, company, role, business email, phone, payment identifiers (tokenised by our payment provider), invoice details.
Customer content: texts, files, records, call audio, transcripts, chat messages, workflow payloads and metadata from your users.
Support and communications: requests and messages (including attachments).
B) Data we collect automatically
Technical and usage data: IP address, device/browser type, pages or features used, timestamps, logs and error events, telemetry needed to secure and run the Services.
C) Data from third parties
Integrations you connect (e.g. CRM/ERP, messaging, telephony, authentication, analytics) may provide identifiers or content needed for your workflow. When we get personal data that does not come directly from you, we tell you the source and the categories. We provide the information required by Article 14 of the GDPR within one month, or at the first contact or the first disclosure, whichever happens first. Our Cookie Policy covers cookie‑related identifiers and consent for non‑essential cookies.
3) Purposes and legal bases
We process personal data only for these purposes and legal bases:
Purpose | Examples | Legal basis |
|---|---|---|
Provide and maintain the Services | account creation, authentication, core features, customer support | Contract: Article 6(1)(b) of the GDPR |
Security and abuse prevention | access control, logs, fraud prevention, incident response | Legitimate interests: Article 6(1)(f) of the GDPR |
Service analytics and quality | measure feature use to improve reliability and user experience (no third‑party ad profiling) | Legitimate interests: Article 6(1)(f) of the GDPR |
Billing and compliance | accounting/tax retention | Legal obligation: Article 6(1)(c) of the GDPR |
Our own marketing communications | product updates, events, offers | Consent, or the prior‑relationship exception for similar services under Article 21 of the LSSI (with an easy opt‑out) |
Right to object or withdraw consent. When we rely on legitimate interests (Article 6(1)(f) of the GDPR), you can object at any time on grounds relating to your particular situation. When we rely on consent, you can withdraw it at any time. This does not affect the lawfulness of processing carried out before withdrawal. Contact: administracion@hellomatik.com. We can provide a short summary of our legitimate‑interest assessment (LIA) on request.
4) Model training and product improvement
No default training on your content. We do not use customer content (inputs, outputs, call audio, transcripts, chats, workflow payloads) to train AI models by default.
Opt‑in only. Any optional sharing of data for training will be based on clear, specific consent that you can withdraw. Without your consent, we do not use your content for training.
Safety and abuse review. If content is flagged on security or misuse grounds, we may review the minimum amount of content needed to investigate and enforce our policies.
These commitments follow the purpose‑limitation and data‑minimisation rules.
5) Retention
We keep personal data only as long as needed for these purposes or as required by law. Current defaults:
Account and billing: kept for the subscription term and required accounting and tax periods.
Operational and diagnostic logs: kept for defined periods (e.g. 90 to 180 days for security telemetry, extended only for incident investigation). We then delete or anonymise the data.
Customer content (processor role): kept and deleted based on the customer's settings and instructions.
Voice module (current defaults): call recordings kept for 14 days, transcripts kept for 6 months. When you end the service, we keep operational data for 10 days for reconciliation, then delete or anonymise it.
Do you have to provide this data? Some data is needed for the contract (e.g. account and billing). Without that data, we cannot create or maintain your subscription. When we ask for data that is not needed for the contract, we will tell you and explain what happens if you do not provide it.
6) Your rights
You can exercise these rights: access, correction, deletion, restriction, objection, portability. You also have the right not to be subject to decisions based solely on automated processing which produce legal effects or similarly significant effects.
Objection: you can object at any time for processing based on legitimate interests, including direct marketing.
Withdrawal of consent: you can withdraw at any time.
Response time: one month or less. Contact: administracion@hellomatik.com. You have the right to file a complaint with the Spanish Data Protection Authority (AEPD).
7) Children
Our Services are not for children. In the UK, the age of digital consent is 13. Below that age, a holder of parental responsibility must give consent (subject to any stricter sector‑specific laws).
8) Automated decision‑making
We do not make decisions based solely on automated processing which produce legal effects or similarly significant effects for you. If this changes, we will give advance notice of the logic involved and of your related rights.
9) Disclosures and recipients
We do not sell personal data. We share data only with:
Processors under contracts made in accordance with Article 28 of the GDPR: hosting, email, payments, telephony, text‑to‑speech and speech‑to‑text for Voice, in‑house service analytics, etc. We provide the current list of sub‑processors (providers, locations and transfer basis, DPF or SCC) on request at administracion@hellomatik.com. We give prior notice of material changes.
Corporate transactions (merger or acquisition), subject to this Policy's safeguards.
Legal or safety disclosures when needed to comply with law, protect users or investigate abuse.
10) International data transfers
When data leaves the EEA/UK, we use the valid transfer mechanisms in Chapter V of the GDPR, such as:
a European Commission adequacy decision (e.g. the EU‑US Data Privacy Framework for certified US organisations); or
the Standard Contractual Clauses (SCCs) 2021/914, with extra measures where needed and a transfer impact assessment following EDPB guidance.
You can get a copy of the SCCs by contacting us. You can check whether a US provider is certified on the official DPF public list.
11) Marketing communications
We comply with Article 21 of the LSSI: no unsolicited electronic marketing without prior consent, except to existing customers for similar services, always with a clear, no‑cost opt‑out in every message.
12) Security
We use appropriate technical and organisational measures to protect personal data. This includes encryption in transit, access controls and least‑privilege access, environment isolation, monitoring, and backup and restore capabilities. No system is perfectly secure. Keep your credentials confidential and enable available security controls.
13) Roles by product (operational summary)
Account/Billing/Support: Hellomatik acts as controller.
Voice: for call handling, recordings and transcripts tied to your workflows, Hellomatik typically acts as a processor. The customer is the controller. We display a notice about recording and transcription. We follow your retention settings and local law.
Chat and Procedures / Enterprise: for end‑user conversations, files and workflow payloads, Hellomatik acts as a processor. For service telemetry and security, Hellomatik may act as controller to maintain and protect the platform.
Your DPA defines the exact allocation of responsibilities.
14) Third‑party services and links
Our Services may link to or integrate with third‑party sites and apps. Their privacy practices are governed by their own policies.
15) This website: contact form, meeting booking and measurement
This section covers the data of people who visit hellomatik.com or write to us from it. For this processing, Hellomatik acts as controller.
"Request a meeting" form. Data: work email address and name; phone number and task description, if you enter them; the page you send it from and, if you arrived from an ad, the campaign parameters. Purpose: to reply to your request and arrange the meeting. Legal basis: steps taken at your request before entering into a contract (Article 6(1)(b) of the GDPR). Retention: while your request is handled and, if no business relationship follows, up to 12 months from the last contact; the data is then deleted.
Abuse prevention. When you send the form, your IP address is used to limit the number of submissions and detect bots. Legal basis: legitimate interest in the security of the website (Article 6(1)(f) of the GDPR). Retention: as for the security logs in section 5.
Meeting booking. The calendar is provided by Calendly LLC, which processes the data you enter when booking (name, email, date and time, and your answers to the booking form) and technical browser data, supported by Cloudflare, Stripe, Google reCAPTCHA and OneTrust. Calendly is based in the United States and certified under the EU‑US Data Privacy Framework. Legal basis: steps taken at your request before entering into a contract (Article 6(1)(b) of the GDPR). Its cookies are listed in the Cookie Policy.
Website measurement. Only with your consent (Article 6(1)(a) of the GDPR), given per purpose. With analytics, Google Analytics 4 counts visits and pages. With advertising, Google Ads attributes the enquiry to an ad and, when you send the form, receives your hashed email address ("enhanced conversions") so the enquiry is counted once. These services are provided by Google Ireland Limited, which may transfer data to the United States under the EU‑US Data Privacy Framework. You can withdraw consent at any time from the Cookie Policy; this does not affect the lawfulness of earlier processing.
Recipients. The hosting and email providers that run the website, as processors; Calendly, when you book; and Google, only with your consent. This data is not disclosed to other third parties unless the law requires it.
16) Changes to this policy
If we make material changes (e.g. new purposes or recipient categories), we will give appropriate advance notice and update the "Last updated" date. Where consent is required, we will ask for it again.
17) Contact
Questions or requests about this Policy or your rights:
Supervisory authority (Spain): AEPD
We are not required to appoint a Data Protection Officer under Article 37 of the GDPR. For any privacy enquiry, please contact our team at administracion@hellomatik.com.