Autonomo Pilot Autonomo Pilot
Legal notice Terms of Service Privacy Policy Cookie Notice
EN · ES

Privacy Policy

Last updated: 21 July 2026. This is an English courtesy translation; in case of any discrepancy, the Spanish version prevails.

This policy explains how personal data is processed when you use Autonomo Pilot (autonomo-pilot.com, app.autonomo-pilot.com, demo.autonomo-pilot.com), in accordance with the EU General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

1. Data controller

Liam Cordrey, self-employed professional, NIF Y7966498W, Andasol Business Center, Avenida Andasol, 29604 Marbella, Málaga, Spain — [email protected].

2. What data is processed

  • Account data: the email address you sign in with (it identifies your account).
  • Financial data you upload: bank-statement exports (CSV/XLS) and the transactions derived from them — dates, amounts, descriptions, the categories you assign, income details (gross amounts, withholdings), and settings you configure. This is treated as highly sensitive data and protected accordingly.
  • Uploaded files: the original statement files, kept as an encrypted archive so imports can be audited.
  • Feedback: if you use the in-app Feedback button, the message you write and your email address.
  • Technical data: minimal server logs necessary to operate and secure the service. No analytics or advertising trackers are used, on any of the sites.

The public demo processes no real personal data: visitors get a temporary sandbox with fictional data, deleted automatically after 48 hours.

3. Purposes and legal bases

Purpose Legal basis
Providing the service: storing and processing the data you upload, producing estimates and exports Performance of contract (GDPR art. 6.1.b)
Security, abuse prevention, technical logs Legitimate interest (art. 6.1.f)
Answering feedback and support requests Legitimate interest / pre-contractual steps (art. 6.1.b/f)
Legal obligations (e.g. responding to competent authorities) Legal obligation (art. 6.1.c)

Your data is never sold, never shared with third parties for their own purposes, and never used to train AI models. No automated decisions with legal effect are made about you; the service's categorisation suggestions are always subject to your review.

4. Where data is stored and who processes it

  • Data is stored on a private server located in the European Union, operated by the controller.
  • Encryption in transit: TLS on every connection. Encryption at rest: the database is encrypted in full (SQLCipher, AES-256) and uploaded statement archives are encrypted with AES-256-GCM before touching disk.
  • Every account's data is isolated: all storage and queries are scoped to your account identity; exports contain your own data only.
  • Processors / recipients: Cloudflare, Inc. (content delivery, network security and login/access control; may involve transfers outside the EEA protected by the EU–US Data Privacy Framework and Standard Contractual Clauses). Feedback notifications are relayed to the operator via Telegram (message content only, no financial data). No other third party receives your data.

5. Retention

  • Account and financial data: kept while your account is active. You can delete everything yourself at any time (below); account data of a closed or lapsed account is retained no longer than 12 months unless law requires otherwise, and you will always be able to export it first.
  • Uploaded statement archives: kept while your account is active, encrypted, for import-audit purposes.
  • Demo sandboxes: deleted automatically after 48 hours.
  • Feedback messages: kept as long as needed to act on them.

6. Your rights

You may exercise the rights of access, rectification, erasure, restriction, portability and objection at any time:

  • In the app (immediate): Settings → Backup gives a full JSON export (portability/access); Settings → Backup → Danger zone deletes all your data irreversibly (erasure). Transactions and settings can be edited directly (rectification).
  • By email: [email protected] — answered within one month at most.
  • Complaint: you may lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (aepd.es).

7. Security and breaches

Beyond the encryption and isolation measures above, the service port is never exposed publicly, access requires authenticated identity on every request, and nothing sensitive is written to logs. In the event of a personal-data breach likely to result in a risk to your rights, the controller will notify the AEPD within 72 hours and affected users without undue delay, as GDPR requires.

8. Cookies

Only technical cookies strictly necessary for the service to function are used — see the Cookie Notice. No analytics or advertising cookies are set.

9. Changes to this policy

Material changes will be announced in the app or by email before they take effect. The "last updated" date at the top reflects the current version.

Back to the app Autonomo Pilot — Liam Cordrey