---
title: "Privacy policy"
description: "What data of yours we process in Tranquilia, what for, how long we keep it and how you exercise your rights. Two frameworks: Swiss law (nLPD) and the European GDPR."
version: "1.2"
reviewed: "2026-07-19"
canonical: "https://tranquilia.es/en/legal/privacidad"
prevailing: "This document is published in several languages. If they differ, the Spanish version is the one that legally applies."
---


<!-- Translation of `es.md`. The Spanish original prevails (language-precedence clause). Legal review notes live only in `es.md`, so they are not duplicated across six languages. -->

# Privacy policy

**Last reviewed: 19 July 2026.**

This page explains what data of yours we process when you use tranquilia.es, what for and for how long. It is written to be understood first time. If anything is not clear to you, write to us at info@tranquilia.es and we will explain it.

We sell GDPR compliance software. It would be odd if we were not careful with your data.

---

## 1. Who processes your data

**GRAC SA** is the controller. In other words: we decide what is done with your data.

| Item | Value |
|---|---|
| Name | GRAC SA |
| Legal form | Company limited by shares under Swiss law |
| Registered office | Morges, canton of Vaud, Switzerland |
| Business identification number (IDE) | CHE-107.970.006 |
| Register | Commercial Register of the canton of Vaud |
| Contact email | info@tranquilia.es |
| Telephone | +34881352220 |
| Website | tranquilia.es |

### Representative in the European Union (art. 27 GDPR)

GRAC SA has no office in the European Union, but it processes data of people in the EU. That is why we appoint a representative in the EU. You can contact them just as you would contact us.

| Representative in the EU | **pending** |
|---|---|

If it says "pending" there, it means the representative has not been appointed yet and we have not launched sales. We are not hiding it from you: we would rather say so than pretend it is already done.

### Data protection officer

We do not have a data protection officer (DPO). We are not required to appoint one. For anything to do with data, write to info@tranquilia.es.

---

## 2. Two laws at once, and why that is good for you

We are a Swiss company selling to Spanish and European businesses. Two frameworks apply to us, and we comply with both:

- **Swiss data protection law (nLPD)**, because we are in Switzerland.
- **The European GDPR (Regulation (EU) 2016/679)**, because we offer services to individuals and businesses in the EU.

When the two laws say different things, we apply whichever is more protective of you.

### Switzerland has the European Commission's approval

The European Commission decided that Switzerland protects personal data at an adequate level (Decision 2000/518/EC). In plain terms: **sending data to Switzerland is, for GDPR purposes, like sending it to Germany or to Portugal.** No special contract and no extra permission is needed.

This matters to you for two reasons:

1. If you are a Spanish accountancy firm, taking us on does not create an "international transfer" with paperwork for you.
2. Your data lives under two regulators at once, not under none.

---

## 3. What data we process and why

Here we are only talking about the Tranquilia website, shop and support. **The data in your clients' files is not covered here: it lives in your instance and we do not use it.** We explain that in section 5.

### 3.1 If you visit the website

| What | What for | Legal basis |
|---|---|---|
| Server logs: IP address, page requested, date, browser | Keeping the website working and detecting attacks and abuse | Legitimate interest: maintaining and protecting the service (art. 6.1.f GDPR) |

> **Legitimate interest** = a reasonable business reason that does not harm you. Blocking a bot attacking the form is a legitimate interest.

And that is as far as it goes. **We do not measure your visit**: this website carries no Google Analytics and no other audience measurement tool, sets no cookies when you browse it and loads no scripts from other companies. We explain that in detail, and say why it makes the cookie banner unnecessary, in the [Cookie policy](/en/legal/cookies).

### 3.2 If you create an instance or buy a licence

| What | What for | Legal basis |
|---|---|---|
| Name of the accountancy firm, NIF, business email, telephone, subdomain | Creating your instance and providing you with the service | Contract (art. 6.1.b GDPR) |
| Check that the company really exists | Preventing fake accounts and abuse | Legitimate interest (art. 6.1.f GDPR) |
| Verification of the NIF-IVA in VIES | Confirming that the sale is between businesses | Legal obligation and contract |
| Billing details and payment history | Charging you and keeping the accounts | Contract and legal obligation |

The sale is **between businesses only (B2B)** and the NIF is mandatory. We do not sell to private individuals.

### 3.3 If you write to us, chat with us or call us

| What | What for | Legal basis |
|---|---|---|
| Emails you send us and our replies | Helping you | Contract or legitimate interest |
| Website chat conversations | Helping you and not making you repeat yourself | Legitimate interest (art. 6.1.f GDPR) |
| Call transcripts, and the audio, which ElevenLabs keeps | Helping you, keeping a record and improving support | Legitimate interest (art. 6.1.f GDPR) |
| Summaries and notes in our CRM | Following the thread of our relationship with you | Legitimate interest (art. 6.1.f GDPR) |

**We tell you at the start of every call** that you are speaking to an artificial intelligence, that the call is being recorded and for how long it is kept. No surprises.

### 3.4 If you subscribe to the newsletter or ask us to call you

| What | What for | Legal basis |
|---|---|---|
| Email and preferences | Sending you content and news | **Your consent** (art. 6.1.a GDPR) |
| Consent for us to call you | Calling you back when you say so | **Your consent** (art. 6.1.a GDPR) |

The box is always empty. You can say no and still be a client all the same. You can unsubscribe in one click, in every email. If you ask us to stop calling you, we stop calling you.

---

## 4. How long we keep each thing

This is the part almost nobody spells out clearly. We do.

| Data | How long |
|---|---|
| Account, instance and contact details | For as long as you are a client |
| Data in your instance after you leave and ask for deletion | Deleted **within 30 days**, replicas and backups included |
| **Invoices and accounting records** | **10 years**, because Swiss law requires it of us (art. 958f CO) |
| Technical and security logs | 12 months |
| Email, newsletter (if you unsubscribe) | We keep only the proof of the unsubscribe |
| **Call transcripts and chat conversations** | **Indefinitely**, encrypted in our CRM |
| **Call audio** | We do not keep it: ElevenLabs does, for **2 years** by default |

### Why we keep transcripts and chats indefinitely

We tell you exactly as it is, with no embellishment.

When you call us or write to us on the chat, we keep the **transcript** and the conversation **in your account record, with no expiry date**. The transcript is stored encrypted and is only read from the CRM record.

The reason is the **memory of the commercial relationship**: if you call us three years from now, we want to know what we agreed with you, what we promised you and what problem you had. It is a legitimate interest (art. 6.1.f GDPR): it serves the follow-up of the contractual relationship and lets us prove what was said.

What this is **not**: we do not sell those recordings, we do not use them for advertising and we do not train AI models with them.

And because an indefinite retention period cannot be left to fall asleep (art. 5.1.e GDPR):

- **We review it every year.** An internal report requires us to reconfirm it or to shorten it.
- **If you ask us to delete your recordings and transcripts, we delete them.** We do not ask you for reasons. It is your right (art. 17 GDPR) and we respect it even though we have that legitimate interest. We keep only what the law requires us to keep, such as the invoices.
- **You can object** to this processing at any time (art. 21 GDPR).

Write to info@tranquilia.es and we will do it.

### We do not keep the call audio ourselves

Here we are correcting something this page used to claim that was not accurate. We say it out loud because we sell compliance: putting the record straight is part of the product.

**Our servers neither download nor store the audio of the calls.** What lives in our CRM is the written **transcript**, encrypted field by field. The audio stays with **ElevenLabs**, the company that runs the telephone agent, under its own retention policy: **two years** by default.

And we say exactly how far our knowledge goes. ElevenLabs publishes a data processing agreement and standard contractual clauses, and states that it stores personal data in the **United States**. What it does **not** publish is that this audio is encrypted at rest, so **we do not claim it**. This page took it for granted and we had nothing to back it up: we would rather say less and have it be true.

If you need that detail for your own risk assessment, write to us at info@tranquilia.es and we will pass on in writing whatever the provider confirms to us.

---

## 5. Your client files are not in our hands

This is important and it is often misunderstood.

Each accountancy firm has **its own instance**, separate from the others. The data of your client companies — their documents, their answers, their signatures — **stays there**. We do not read it, we do not copy it to the CRM and we do not use it for anything.

For that data, **your firm is the controller** and we are only an external company hosting the software: what the law calls a processor. That is governed by a separate agreement (art. 28 GDPR), which we offer you when you take out the service.

> **Processor** = an external company that handles data on your behalf. We, by hosting your instance, are a processor of yours.

You can export your data whenever you like and take it with you.

---

## 6. Who we share data with

We do not sell your data. Never. To anyone.

We work with these external companies, each with its own contract and only for what is needed:

| Company | What for | Where |
|---|---|---|
| Our hosting provider | Hosting the servers and your instance | **European Union** |
| PayPal | Collecting licence payments | EU / USA |
| OpenRouter | Artificial intelligence features | USA (routes to different model providers) |
| ElevenLabs | Telephone voice agent; keeps the audio and the transcript of the call | USA |
| Zadarma | Operator of the Spanish number: carries the call to the voice agent | European Union, per the provider |
| Our email provider | Sending and receiving email | Switzerland |

**On hosting, we say exactly what is confirmed and not one word more.** The servers are **in the European Union**: that is confirmed by GRAC SA and you can rely on it. The detail below that — exact country, provider company and data centre — is not fixed in writing yet, so **we do not publish it here**. If you need it for an annex to your contract, ask us at info@tranquilia.es and we will confirm it to you in writing. We prefer this answer to filling the gap with a name that would later have to be taken back.

**The telephone chain, told in full.** When you call our Spanish number, the call comes in through **Zadarma**, the operator that provides the number, and Zadarma hands it over to the **ElevenLabs** voice agent. Zadarma states that its databases are in the European Union; ElevenLabs states that it stores personal data in the United States, and its European data residency is an enterprise-plan option that we have not taken out. That leg between the operator and the agent **is not end-to-end encrypted**: the operator does not offer it on this line, and choosing otherwise would leave the phone silent. It is a real limitation and we would rather you knew it before telling us anything sensitive by phone. If what you have to tell us is delicate, email is the better place.

**We do not use any web analytics tool**, so Google does not appear on this list. If that changes, this table changes first.

We may also share data with public authorities when a law requires us to.

### Transfers outside the European Union

Some of these providers are in the United States. For those transfers we rely, depending on the provider, on its adherence to the **EU-U.S. Data Privacy Framework** or on the **European Commission's standard contractual clauses** (art. 46 GDPR).

On AI, we say it plainly: **OpenRouter routes the requests to different model providers**, which may be outside the EU. That is why the AI features never receive your clients' files, and why in your instance settings you can pin a European model or provider if you prefer.

---

## 7. How we protect all this

- Encryption in transit (TLS 1.3) on the web, and field-by-field encryption of sensitive data, including call transcripts.
- **The phone line is the exception and we flag it**: the leg between the operator and the voice agent is not end-to-end encrypted, and we do not keep the audio ourselves. We explain this in sections 4 and 6.
- Encrypted backups, with tested restoration.
- A separate instance per accountancy firm: nothing is mixed between clients.
- Mandatory two-factor authentication for our staff.
- Audit log of accesses.
- The servers expose nothing to the internet except through the controlled entry point.

If there is ever a security breach that could harm you, we tell you about it and we notify the authority when required (arts. 33 and 34 GDPR).

---

## 8. Your rights

You can ask us, at any time and free of charge:

| Right | In plain terms |
|---|---|
| Access (art. 15) | That we tell you what data of yours we hold |
| Rectification (art. 16) | That we correct whatever is wrong |
| Erasure (art. 17) | That we delete your data |
| Restriction (art. 18) | That we freeze it while something is being clarified |
| Portability (art. 20) | That we give it to you in a file so you can take it away |
| Objection (art. 21) | That we stop using it on the basis of legitimate interest |
| Withdrawal of consent (art. 7.3) | To change your mind, whenever you like |

You also have these rights under Swiss law (nLPD).

**How it is done:** write to info@tranquilia.es. We may ask you for something to confirm that it is you, and nothing more.

**When we reply:** within **1 month** at the latest (art. 12.3 GDPR). If the case is complex we tell you and it can reach 3 months.

**If we do not reply or you do not like the reply**, you can complain:

- In Spain, to the **Agencia Española de Protección de Datos (AEPD)** — [aepd.es](https://www.aepd.es).
- In your own country, to your data protection authority.
- In Switzerland, to the **Federal Commissioner for Data Protection and Transparency (PFPDT)** — [edoeb.admin.ch](https://www.edoeb.admin.ch).

You do not have to tell us first. We would rather you wrote to us first, but that is your decision.

---

## 9. Automated decisions

We do not take decisions about you by machine alone with legal effect (art. 22 GDPR).

We use AI in two places and we tell you about it:

- **When the instance is created**, we automatically check that your company exists. If the result is doubtful, **a person reviews it**. A machine never leaves you out just like that.
- **On the chat, by email and on the phone**, the AI answers and drafts. We always tell you it is AI and you can always speak to a person.

---

## 10. Minors

Tranquilia is a business-to-business service. It is not aimed at minors and we do not knowingly collect data about minors.

---

## 11. Changes to this policy

If we change anything important, we tell you by email and we update the date at the top. We keep the previous versions and give them to you if you ask for them.

---

## 12. Honesty about this document

This policy has been drafted with AI assistance and verified against the official sources cited. **It is pending review by a Swiss lawyer before the commercial launch.** We hold ourselves to the same standard we ask of our clients: that is why we say it here and not in the small print.

This is the English translation. In the event of any discrepancy between language versions, the Spanish version prevails.

---

## Sources

- [Regulation (EU) 2016/679 (GDPR)](https://eur-lex.europa.eu/eli/reg/2016/679/oj)
- [Decision 2000/518/EC — adequate protection of personal data in Switzerland](https://eur-lex.europa.eu/eli/dec/2000/518/oj)
- [Ley Orgánica 3/2018, de 5 de diciembre (LOPDGDD)](https://www.boe.es/eli/es/lo/2018/12/05/3)
- [Swiss Federal Act on Data Protection (nLPD), RS 235.1](https://www.fedlex.admin.ch/eli/cc/2022/491/fr)
- [Agencia Española de Protección de Datos (AEPD)](https://www.aepd.es)
- [Swiss Federal Commissioner for Data Protection and Transparency (PFPDT)](https://www.edoeb.admin.ch)
- [ElevenLabs — conversation retention (2 years by default)](https://elevenlabs.io/docs/eleven-agents/customization/privacy/retention)
- [ElevenLabs — privacy policy (storage in the United States)](https://elevenlabs.io/privacy-policy)
- [Zadarma — personal data processing policy](https://zadarma.com/legal/privacy-policy/)
