HAVIXO — Privacy Notice
**Version V1.0-draft · 2026-07-19 · counsel review pending (RA-06)**
**HAVIXO Legal Pack V1.0** · Status: DRAFT-FOR-FOUNDER-APPROVAL (FDR Addendum-1 / R-10)
Internal record (RA-06): This text is produced from the counsel brief drafting specification. It is not legal advice;
independent counsel review is targeted within 60 days of publication; findings will be published as V2.
Jurisdiction baseline: Spain/Catalonia + EU. Languages: EN master; ES/CA translations required before ES-market publication.
Acceptance is versioned and audit-logged (M10).
Controller
[ENTITY NAME, address, contact, DPO contact — founder to complete].
What we process and why
- **Account/identity data** (contract performance; Art. 6(1)(b) GDPR)
- **Listing, evidence and mandate data** (contract + legitimate interest in marketplace integrity)
- **Application/offer/viewing data** (contract; shared only with the counterparty you choose)
- **Vault documents** (processed only under your purpose-bound grant; consent, Art. 6(1)(a))
- **Messages** (contract; PII-scrubbed operational logs)
- **AI interaction records** (legitimate interest in safety/audit; synthetic disclosure always shown)
- **Billing data** (legal obligation + contract)
We do **not** solicit special-category data; do not enter it into free-text fields.
Automated decision-making
AI assistants prepare and explain; they make **no** decision producing legal or similarly significant effects.
Accept/reject decisions are made by humans.
Recipients
PSP (platform fees), hosting (EU region), error monitoring, notifications, maps — each under DPA; current list: LEG-14 Subprocessors.
No sale of personal data. No transfer outside the EEA without safeguards.
Retention
Account data: life of account + statutory periods. Ledger/audit: statutory retention (append-only; personal data
minimized/hashed). Vault docs: until you delete or grant expiry. Details per category in the retention schedule.
Your rights
Access, rectification, erasure (with cryptographic shredding where hashes must remain), restriction, portability
(PDF+JSON export, p95 < 24h), objection, and complaint to the AEPD. Requests via the Trust Center; identity verification required.
Security
RLS tenant isolation, encryption at rest and in transit, append-only audit, access on least-privilege with time-boxed grants.