Ir al contenido
Launch offerOnly until … — after that, prices go back to normal.See pricing

Legal information

Privacy policy

Version 1.2

Last reviewed: 19 July 2026.

This page explains what data of yours we process when you use tranquilia.wtr3.ch, what for and for how long. It is written to be understood first time. If anything is not clear to you, write to us at info@tranquilia.es and we will explain it.

We sell GDPR compliance software. It would be odd if we were not careful with your data.


1. Who processes your data

GRAC SA is the controller. In other words: we decide what is done with your data.

Item Value
Name GRAC SA
Legal form Company limited by shares under Swiss law
Registered office Morges, canton of Vaud, Switzerland
Business identification number (IDE) CHE-107.970.006
Register Commercial Register of the canton of Vaud
Contact email info@tranquilia.es
Telephone +34881352220
Website tranquilia.wtr3.ch

Representative in the European Union (art. 27 GDPR)

GRAC SA has no office in the European Union, but it processes data of people in the EU. That is why we appoint a representative in the EU. You can contact them just as you would contact us.

Representative in the EU pending

If it says "pending" there, it means the representative has not been appointed yet and we have not launched sales. We are not hiding it from you: we would rather say so than pretend it is already done.

Data protection officer

We do not have a data protection officer (DPO). We are not required to appoint one. For anything to do with data, write to info@tranquilia.es.


2. Two laws at once, and why that is good for you

We are a Swiss company selling to Spanish and European businesses. Two frameworks apply to us, and we comply with both:

  • Swiss data protection law (nLPD), because we are in Switzerland.
  • The European GDPR (Regulation (EU) 2016/679), because we offer services to individuals and businesses in the EU.

When the two laws say different things, we apply whichever is more protective of you.

Switzerland has the European Commission's approval

The European Commission decided that Switzerland protects personal data at an adequate level (Decision 2000/518/EC). In plain terms: sending data to Switzerland is, for GDPR purposes, like sending it to Germany or to Portugal. No special contract and no extra permission is needed.

This matters to you for two reasons:

  1. If you are a Spanish accountancy firm, taking us on does not create an "international transfer" with paperwork for you.
  2. Your data lives under two regulators at once, not under none.

3. What data we process and why

Here we are only talking about the Tranquilia website, shop and support. The data in your clients' files is not covered here: it lives in your instance and we do not use it. We explain that in section 5.

3.1 If you visit the website

What What for Legal basis
Server logs: IP address, page requested, date, browser Keeping the website working and detecting attacks and abuse Legitimate interest: maintaining and protecting the service (art. 6.1.f GDPR)

Legitimate interest = a reasonable business reason that does not harm you. Blocking a bot attacking the form is a legitimate interest.

And that is as far as it goes. We do not measure your visit: this website carries no Google Analytics and no other audience measurement tool, sets no cookies when you browse it and loads no scripts from other companies. We explain that in detail, and say why it makes the cookie banner unnecessary, in the Cookie policy.

3.2 If you create an instance or buy a licence

What What for Legal basis
Name of the accountancy firm, NIF, business email, telephone, subdomain Creating your instance and providing you with the service Contract (art. 6.1.b GDPR)
Check that the company really exists Preventing fake accounts and abuse Legitimate interest (art. 6.1.f GDPR)
Verification of the NIF-IVA in VIES Confirming that the sale is between businesses Legal obligation and contract
Billing details and payment history Charging you and keeping the accounts Contract and legal obligation

The sale is between businesses only (B2B) and the NIF is mandatory. We do not sell to private individuals.

3.3 If you write to us, chat with us or call us

What What for Legal basis
Emails you send us and our replies Helping you Contract or legitimate interest
Website chat conversations Helping you and not making you repeat yourself Legitimate interest (art. 6.1.f GDPR)
Call transcripts, and the audio, which ElevenLabs keeps Helping you, keeping a record and improving support Legitimate interest (art. 6.1.f GDPR)
Summaries and notes in our CRM Following the thread of our relationship with you Legitimate interest (art. 6.1.f GDPR)

We tell you at the start of every call that you are speaking to an artificial intelligence, that the call is being recorded and for how long it is kept. No surprises.

3.4 If you subscribe to the newsletter or ask us to call you

What What for Legal basis
Email and preferences Sending you content and news Your consent (art. 6.1.a GDPR)
Consent for us to call you Calling you back when you say so Your consent (art. 6.1.a GDPR)

The box is always empty. You can say no and still be a client all the same. You can unsubscribe in one click, in every email. If you ask us to stop calling you, we stop calling you.


4. How long we keep each thing

This is the part almost nobody spells out clearly. We do.

Data How long
Account, instance and contact details For as long as you are a client
Data in your instance after you leave and ask for deletion Deleted within 30 days, replicas and backups included
Invoices and accounting records 10 years, because Swiss law requires it of us (art. 958f CO)
Technical and security logs 12 months
Email, newsletter (if you unsubscribe) We keep only the proof of the unsubscribe
Call transcripts and chat conversations Indefinitely, encrypted in our CRM
Call audio We do not keep it: ElevenLabs does, for 2 years by default

Why we keep transcripts and chats indefinitely

We tell you exactly as it is, with no embellishment.

When you call us or write to us on the chat, we keep the transcript and the conversation in your account record, with no expiry date. The transcript is stored encrypted and is only read from the CRM record.

The reason is the memory of the commercial relationship: if you call us three years from now, we want to know what we agreed with you, what we promised you and what problem you had. It is a legitimate interest (art. 6.1.f GDPR): it serves the follow-up of the contractual relationship and lets us prove what was said.

What this is not: we do not sell those recordings, we do not use them for advertising and we do not train AI models with them.

And because an indefinite retention period cannot be left to fall asleep (art. 5.1.e GDPR):

  • We review it every year. An internal report requires us to reconfirm it or to shorten it.
  • If you ask us to delete your recordings and transcripts, we delete them. We do not ask you for reasons. It is your right (art. 17 GDPR) and we respect it even though we have that legitimate interest. We keep only what the law requires us to keep, such as the invoices.
  • You can object to this processing at any time (art. 21 GDPR).

Write to info@tranquilia.es and we will do it.

We do not keep the call audio ourselves

Here we are correcting something this page used to claim that was not accurate. We say it out loud because we sell compliance: putting the record straight is part of the product.

Our servers neither download nor store the audio of the calls. What lives in our CRM is the written transcript, encrypted field by field. The audio stays with ElevenLabs, the company that runs the telephone agent, under its own retention policy: two years by default.

And we say exactly how far our knowledge goes. ElevenLabs publishes a data processing agreement and standard contractual clauses, and states that it stores personal data in the United States. What it does not publish is that this audio is encrypted at rest, so we do not claim it. This page took it for granted and we had nothing to back it up: we would rather say less and have it be true.

If you need that detail for your own risk assessment, write to us at info@tranquilia.es and we will pass on in writing whatever the provider confirms to us.


5. Your client files are not in our hands

This is important and it is often misunderstood.

Each accountancy firm has its own instance, separate from the others. The data of your client companies — their documents, their answers, their signatures — stays there. We do not read it, we do not copy it to the CRM and we do not use it for anything.

For that data, your firm is the controller and we are only an external company hosting the software: what the law calls a processor. That is governed by a separate agreement (art. 28 GDPR), which we offer you when you take out the service.

Processor = an external company that handles data on your behalf. We, by hosting your instance, are a processor of yours.

You can export your data whenever you like and take it with you.


6. Who we share data with

We do not sell your data. Never. To anyone.

We work with these external companies, each with its own contract and only for what is needed:

Company What for Where
Our hosting provider Hosting the servers and your instance European Union
PayPal Collecting licence payments EU / USA
OpenRouter Artificial intelligence features USA (routes to different model providers)
ElevenLabs Telephone voice agent; keeps the audio and the transcript of the call USA
Zadarma Operator of the Spanish number: carries the call to the voice agent European Union, per the provider
Our email provider Sending and receiving email Switzerland

On hosting, we say exactly what is confirmed and not one word more. The servers are in the European Union: that is confirmed by GRAC SA and you can rely on it. The detail below that — exact country, provider company and data centre — is not fixed in writing yet, so we do not publish it here. If you need it for an annex to your contract, ask us at info@tranquilia.es and we will confirm it to you in writing. We prefer this answer to filling the gap with a name that would later have to be taken back.

The telephone chain, told in full. When you call our Spanish number, the call comes in through Zadarma, the operator that provides the number, and Zadarma hands it over to the ElevenLabs voice agent. Zadarma states that its databases are in the European Union; ElevenLabs states that it stores personal data in the United States, and its European data residency is an enterprise-plan option that we have not taken out. That leg between the operator and the agent is not end-to-end encrypted: the operator does not offer it on this line, and choosing otherwise would leave the phone silent. It is a real limitation and we would rather you knew it before telling us anything sensitive by phone. If what you have to tell us is delicate, email is the better place.

We do not use any web analytics tool, so Google does not appear on this list. If that changes, this table changes first.

We may also share data with public authorities when a law requires us to.

Transfers outside the European Union

Some of these providers are in the United States. For those transfers we rely, depending on the provider, on its adherence to the EU-U.S. Data Privacy Framework or on the European Commission's standard contractual clauses (art. 46 GDPR).

On AI, we say it plainly: OpenRouter routes the requests to different model providers, which may be outside the EU. That is why the AI features never receive your clients' files, and why in your instance settings you can pin a European model or provider if you prefer.


7. How we protect all this

  • Encryption in transit (TLS 1.3) on the web, and field-by-field encryption of sensitive data, including call transcripts.
  • The phone line is the exception and we flag it: the leg between the operator and the voice agent is not end-to-end encrypted, and we do not keep the audio ourselves. We explain this in sections 4 and 6.
  • Encrypted backups, with tested restoration.
  • A separate instance per accountancy firm: nothing is mixed between clients.
  • Mandatory two-factor authentication for our staff.
  • Audit log of accesses.
  • The servers expose nothing to the internet except through the controlled entry point.

If there is ever a security breach that could harm you, we tell you about it and we notify the authority when required (arts. 33 and 34 GDPR).


8. Your rights

You can ask us, at any time and free of charge:

Right In plain terms
Access (art. 15) That we tell you what data of yours we hold
Rectification (art. 16) That we correct whatever is wrong
Erasure (art. 17) That we delete your data
Restriction (art. 18) That we freeze it while something is being clarified
Portability (art. 20) That we give it to you in a file so you can take it away
Objection (art. 21) That we stop using it on the basis of legitimate interest
Withdrawal of consent (art. 7.3) To change your mind, whenever you like

You also have these rights under Swiss law (nLPD).

How it is done: write to info@tranquilia.es. We may ask you for something to confirm that it is you, and nothing more.

When we reply: within 1 month at the latest (art. 12.3 GDPR). If the case is complex we tell you and it can reach 3 months.

If we do not reply or you do not like the reply, you can complain:

  • In Spain, to the Agencia Española de Protección de Datos (AEPD)aepd.es.
  • In your own country, to your data protection authority.
  • In Switzerland, to the Federal Commissioner for Data Protection and Transparency (PFPDT)edoeb.admin.ch.

You do not have to tell us first. We would rather you wrote to us first, but that is your decision.


9. Automated decisions

We do not take decisions about you by machine alone with legal effect (art. 22 GDPR).

We use AI in two places and we tell you about it:

  • When the instance is created, we automatically check that your company exists. If the result is doubtful, a person reviews it. A machine never leaves you out just like that.
  • On the chat, by email and on the phone, the AI answers and drafts. We always tell you it is AI and you can always speak to a person.

10. Minors

Tranquilia is a business-to-business service. It is not aimed at minors and we do not knowingly collect data about minors.


11. Changes to this policy

If we change anything important, we tell you by email and we update the date at the top. We keep the previous versions and give them to you if you ask for them.


12. Honesty about this document

This policy has been drafted with AI assistance and verified against the official sources cited. It is pending review by a Swiss lawyer before the commercial launch. We hold ourselves to the same standard we ask of our clients: that is why we say it here and not in the small print.

This is the English translation. In the event of any discrepancy between language versions, the Spanish version prevails.


Sources

Español · Català · Galego · English · Français