Privacy

Privacy policy

Last updated: July 8, 2026

At Fibady we handle very little personal data — only what's needed to respond to your demo request, schedule a meeting, or assist you through chat. This policy explains what data we collect, why, on what legal basis, who we share it with, and what rights you have.

1. Who is the data controller

  • Legal name: Fibady Technologies SL
  • Tax ID (CIF): ESB24982795
  • Registered address: Carrer d'Àngel Marquès, 15, 08035 Barcelona, Spain
  • Privacy contact: contact@fibady.com

We have not appointed a Data Protection Officer (DPO) because, given the type and volume of data we process, we are not required to under Article 37 GDPR. Any privacy question can be directed to the contact above.

2. What data we collect and why

WhenWhat dataWhy
Demo request form (/demo)First name, last name, work email, company, number of entities managed, ERP used, how you heard about us, and any additional comments you writeRespond to your request, qualify the commercial contact and, if you proceed, pre-fill the meeting scheduler
Meeting scheduling (HubSpot embedded calendar)First name, last name and email (reused from the previous step); HubSpot may ask for additional confirmation within its own calendarCoordinate the meeting date/time and send you the confirmation
Chat assistantName, email and country you provide when starting the conversation, and the content of the messages you writeAnswer your product questions and help you schedule a demo
Browsing the site (cookies)See the Cookie PolicyRemember your language and, if you consented, measure where visits come from

We do not use this data to build automated profiles with legal or significant effects on you, nor do we make fully automated decisions.

3. Legal basis for each processing activity

  • Demo form, meeting scheduling and chat: pre-contractual measures taken at your request (Art. 6.1.b GDPR) and, to the extent you act on behalf of a company, our legitimate interest in managing B2B business contacts (Art. 6.1.f GDPR).
  • Non-essential cookies (analytics/attribution): your consent (Art. 6.1.a GDPR), which you can withdraw at any time — see the Cookie Policy.

4. Who we share your data with

We don't sell your data. We only share it with the providers we need to run the site and the chat assistant, who act as data processors on our instructions: HubSpot (CRM, forms and scheduling), Amazon Web Services (chat backend infrastructure) and Anthropic (generating the assistant's replies). Details on each — including their basis for international transfers — are on the Subprocessors page.

5. International transfers

Some of these providers process data outside the European Economic Area: in particular, Anthropic stores the data it processes in the US by default, and HubSpot transfers certain usage-analytics data there. In both cases, the transfer is covered by European Commission Standard Contractual Clauses, incorporated into each provider's data processing agreement (see the Subprocessors page for details and links to each DPA).

6. How long we keep your data

GDPR doesn't set a fixed number of years: it requires keeping data only as long as necessary for the purpose of processing. Applying that principle, here's the criteria we follow:

  • If you share your data with us but don't become a customer: we keep it for up to 3 years from your last real interaction with us (for example, your demo request or your last message), using as a comparative reference the criterion published by the French data protection authority (CNIL) for this exact scenario, in the absence of an equivalent figure set by the Spanish authority. After that period without new interaction, we delete or anonymize the data.
  • If you become a customer: we keep your data for the duration of the business relationship and, for whatever falls under accounting or invoicing records, for up to 6 years after it ends, per the Spanish Commercial Code's record-keeping obligation (Article 30) — and up to 4 more years, or 10 in case of a tax audit, for whatever is strictly tax-related.
  • Chat data: your browser only keeps it while the tab is open (cleared when you close it). The copies processed by our backend and by Anthropic to generate replies are automatically deleted within a maximum of 30 days of receipt or generation, per Anthropic's standard API retention policy, unless the law requires keeping them longer (for example, to investigate misuse of the service).
  • Cookies: each has its own retention period — see the Cookie Policy.

7. Your rights

You can exercise your rights of access, rectification, erasure, objection, restriction of processing and data portability at any time by writing to contact@fibady.com. If you believe we haven't properly handled your request, you can file a complaint with the Spanish Data Protection Agency (AEPD) or your local supervisory authority.

8. Security

We apply reasonable technical and organizational measures to protect your data, such as encrypting communications with the site (TLS) and using providers that in turn apply their own security measures under their DPAs (see the Subprocessors page). No system is 100% foolproof; if we detect a security breach affecting you, we will notify you as required by GDPR.

9. Minors

The site is aimed at professionals acting on behalf of a company and is not intended for minors. We do not knowingly collect data from individuals under 16.

10. Changes to this policy

We may update this policy to reflect regulatory, site, or provider changes. The last-updated date is shown above; if the change is significant, we'll flag it visibly on the site.