Privacy Policy
This privacy policy explains what personal data Contratista processes, why, on what legal basis, and what rights you have. It applies to everyone who interacts with the platform: property owners, tradespeople, and guests who report a fault via QR code.
1. Who we are
Contratista is a software platform for managing and coordinating maintenance of (holiday) properties, focused on the Spanish market. The platform is operated by Contratista, a company established in the Netherlands at Wilhelminastraat 54, Vlaardingen (Chamber of Commerce (KvK) no. 82351627; VAT no. NL003672419B82). For any question about this policy or your data, reach us via the contact page, by email at info@contratista.eu or by phone on +31 6 11045776. For the processing we carry out to provide our own service, we are the data controller within the meaning of the GDPR and the Dutch GDPR Implementation Act (UAVG).
2. Our role: controller and joint controller
For owner and tradesperson data — accounts, properties, profiles, billing — we are the data controller: we determine the purpose and means. For the data a guest leaves in a report, we and the owner jointly determine how it is processed: the owner wants their property managed, and we determine the essential means — the diagnosis, the severity assessment, the matching, the retention and the security. For that processing, we and the owner are joint controllers within the meaning of Article 26 GDPR. The essence of our arrangement is that we are the point of contact for guests and fulfil the duty to inform; you can in any event exercise your rights directly with us. That arrangement forms part of our terms for owners and is available on request via info@contratista.eu. In all cases we process no more data than necessary.
3. What data we process
From owners: name, email and login credentials, plus the data needed to run your portfolio (properties, addresses, access instructions, photos and documents). We treat access instructions such as key-safe and alarm codes as particularly sensitive, because they grant physical access to a property. From tradespeople: name, contact details, working region, rate, professional documents and, after approval, profile information. From guests reporting via QR: a name plus the photos and description of the fault — guests report without an account, and we ask only for what is needed to assess the fault. Photos of a fault may inadvertently capture people; photograph only what is necessary and keep identifiable people out of frame. We also process technical data (IP address, device and usage data) inherent to any online platform. We do not knowingly ask for special categories of personal data; please do not include them in a report.
4. Purposes and legal bases
We process data to (a) provide the platform and your account and perform our contract with you — basis: performance of the contract (Art. 6(1)(b) GDPR); (b) diagnose reports, match the right tradesperson, coordinate the job, check invoices and generate reports — basis: performance of the contract and our legitimate interest in a working platform (Art. 6(1)(f)); (c) receive, diagnose and make a guest report available to the owner and tradesperson concerned — basis: the legitimate interest of the owner and of us in managing and repairing the property (Art. 6(1)(f) GDPR), having weighed that interest against your privacy and asking only for what is needed; you may object to this processing and request deletion of your report; (d) comply with legal obligations such as accounting and tax — basis: legal obligation (Art. 6(1)(c)); and (e) inform you or improve the platform with your consent. You can withdraw consent at any time.
5. AI and automated processing
Contratista uses automated processing, including AI models, to read photos and descriptions, assess severity, estimate costs and cross-check invoices. This output is supporting advice: a human always makes the final decision on assignment, approval and payment. There is therefore no decision producing legal effects based solely on automated processing (Art. 22 GDPR). Where automated output may noticeably affect a person — in particular the invoice check concerning a tradesperson — you can always request human intervention, make your point of view known and contest the outcome via info@contratista.eu; an automated flag never, on its own, leads to refusal of payment, exclusion from the pool or any other measure. We clearly inform you when you are dealing with AI-generated output. Under our agreement with the AI processor, the content sent through the platform is not used to train its models; the processor may briefly retain input for security and abuse monitoring, to which the safeguards and the risk noted in section 8 apply.
6. How long we keep data
We keep account and property data for as long as your account is active and thereafter as long as needed to meet legal (notably tax) retention obligations. We delete or anonymise access instructions such as key-safe and alarm codes as soon as the related job is closed. We automatically delete guest-report data (photos and description) 24 months after the related job is closed. We retain billing data in line with statutory retention obligations (seven years for tax purposes in the Netherlands). If you delete your account, we erase or anonymise your personal data, except for what we are legally required to keep.
7. Who we share data with
We share data only as needed to deliver the service: with the tradesperson assigned to your job (the diagnosis, photos and property context the work requires), and with the processors below for hosting, storage, email, payments and AI. Each is bound by a data-processing agreement (Art. 28 GDPR) and may use the data only for our instructions. If we add a new or replacement processor that processes data we handle jointly with the owner, we inform owners in advance via the dashboard or by email, so you can object on reasonable grounds. We never sell personal data. Without your consent for marketing cookies we share nothing for advertising either. If you do give that consent, we report to Meta Platforms Ireland Limited that you visited the site or created an account, together with a hashed version of your email address, your IP address and your browser details, so Meta can match a sign-up to an advert; your email address never leaves our server in readable form. Meta does not use that data solely on our instructions, so Meta’s own privacy policy applies to it alongside this one. If you withdraw consent via the cookie settings, we stop sending from that moment. We may disclose data where the law requires it.
Our processors
| Party | Purpose | Location & safeguard |
|---|---|---|
| Supabase | Database and file storage | EEA (Frankfurt) |
| Vercel | Hosting and website delivery | US — SCCs / Data Privacy Framework |
| Anthropic | AI diagnosis (Claude) | US — DPF / SCCs; no training on API data, short retention (ZDR available) |
| Resend | Sending transactional email | US — SCCs / DPF |
| Stripe | Subscriptions and payments | EU/US — SCCs / DPF |
Meta Platforms Ireland Limited is deliberately absent from this table: for advertising measurement Meta is not a processor acting on our instructions but a controller in its own right. For the collection of those data we and Meta are joint controllers within the meaning of Article 26 GDPR. We report nothing there unless you have turned marketing cookies on. Meta is established in Ireland (EEA) and transfers data to the United States under the EU–US Data Privacy Framework and the standard contractual clauses. See section 7 and our cookie policy.
8. Transfers outside the EEA
Our database and file storage are located within the EEA. Some processors are established in the United States. For those transfers we rely on appropriate safeguards within the meaning of the GDPR: the European Commission’s Standard Contractual Clauses (SCCs) and, where applicable, certification under the EU–US Data Privacy Framework, supplemented by technical and organisational measures. You can request a copy of the safeguards we use. Note: some processors — including the parent group of our hosting provider (AWS) — are subject to US law. Under legislation such as the US CLOUD Act, US authorities can in principle compel access to data even when it is stored within the EEA. We mitigate this with encryption and the safeguards above, but cannot fully exclude it.
9. How we secure data
We take appropriate technical and organisational measures to protect your data: encryption in transit, access control and role-based authorisation, separated environments and logging. We encrypt access instructions such as key-safe codes and show them only to the owner and the specifically assigned tradesperson, and only for the duration of the job; we strongly advise owners to change a code after a job. No system is entirely without risk; if you discover a vulnerability, please report it to info@contratista.eu. In the event of a data breach that poses a risk to you, we notify the supervisory authority and, where required, you, within the legal timeframes.
10. Your rights under the GDPR
You have the right to access, rectify, erase, restrict and port your data, and the right to object to processing based on legitimate interest. Where processing relies on consent — such as a guest report via QR — you may withdraw it at any time without affecting the lawfulness of earlier processing. Guests can request deletion of a report they submitted. You exercise your rights via the contact page or your dashboard; we respond to verified requests within one month. Exercising your rights is free of charge.
11. Cookies
We use three kinds of cookies. Functional cookies are needed to run the platform and are always on. Analytics cookies are placed only with your consent, so we can see how the service is used and improve it. Marketing cookies are also placed only with your consent: through the Meta pixel (Facebook and Instagram) they let us measure which adverts lead to a sign-up. If you refuse a category, it is not placed, and nothing about that category leaves our server either. You can manage your choice at any time via the cookie settings, and withdrawing consent is as easy as giving it. Exactly which cookies we place, with their names and retention periods, is set out in our cookie policy.
12. Children
Contratista is aimed at property owners and tradespeople and is not intended for children. We do not knowingly collect data from persons under 16 (the digital-consent age under Dutch law). If you believe we have inadvertently collected a minor’s data, please contact us so we can delete it.
13. Changes to this policy
We may update this policy when the service or the law changes. The date at the top indicates the latest version; for material changes we inform you via your dashboard or by email before they take effect.
14. Contact and complaints
For questions or to exercise your rights: info@contratista.eu or the contact page. As our establishment is in the Netherlands, our lead supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl). If you disagree with how we handle your data, you can lodge a complaint there or with the authority in your own EU member state — for users in Spain, the Agencia Española de Protección de Datos (www.aepd.es). We would appreciate the chance to resolve it with you first.