Who we are
Factu Labs S.L. ("Factu", "we") provides a service that helps companies and freelancers obtain invoices from suppliers. This policy explains what personal data we process, why, and how you can exercise your rights.
Data we process
- Account data: email and password.
- Organization data: legal name, tax ID, fiscal address, and contact email.
- Request data: supplier, transaction description, amount, and internal notes.
- Invoices and PDFs we receive or process to validate the request.
- Google data when you connect Gmail: mailbox address, authorized permissions, OAuth tokens and, only if you enable invoice search, message metadata and candidate PDF attachments.
- Legal confirmation with timestamp and IP when you create a request.
- Aggregated product events with privacy enabled.
Purposes
- Contact suppliers on your behalf to ask for the invoice.
- Validate received invoices before delivering them.
- Find, deduplicate, and process invoices you choose to search for or add.
- Comply with legal and accounting obligations.
- Improve the product based on aggregated usage.
Use of Google data
When you connect Gmail, Factu receives the mailbox address, the permissions you authorize, and OAuth tokens. We use gmail.send to send invoice requests, reminders, and follow-ups. Only if you separately enable invoice search do we use gmail.readonly to retrieve the metadata needed to identify messages that may contain invoices and download their PDF attachments within the period you select. Factu does not modify, move, or delete Gmail messages.
We use this data exclusively to deliver the features you request: send communications from the authorized mailbox, find invoices, prevent duplicates, show candidates inside Factu, and process relevant PDFs with OCR.
Factu does not sell Google data, use it for advertising, retargeting, credit scoring or lending, or use it to train general-purpose AI models.
Factu's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
Legal basis
We process your data based on contract performance, your explicit consent when confirming each request, and applicable legal obligations.
Recipients and transfers
To provide the service, Vercel runs the application; Supabase manages authentication, the database, and private PDF storage; Mistral receives a short-lived signed PDF URL during OCR; and Resend processes the contact details and minimum content needed to send Factu notifications. Resend does not send messages from your Gmail mailbox. These transfers are limited to delivering the features you request. The current provider list and purposes are maintained at /subprocesadores.
When you instruct or authorize us to do so, Factu may make invoices, documents, and related data available to your accounting firm or to other people in your organization who have the relevant permissions.
We may also disclose data when required by law, a court, or a competent authority, or when necessary to protect the security and rights of users, third parties, or Factu.
Human access
Human access to Google content is exceptional, limited to the minimum necessary, and permitted only with your affirmative authorization for specific data, for essential support you authorize, for security purposes, or to comply with a legal obligation. Authorized personnel and contractors are subject to confidentiality duties and restricted access.
How we protect data
- We protect data in transit using HTTPS/TLS.
- We specifically encrypt OAuth tokens at rest using AES-256-GCM.
- We keep PDFs in private storage and generate signed URLs that normally expire after 600 seconds.
- We isolate data by organization and apply access controls and roles to limit who can view it.
- We restrict secrets to server-side systems and take measures to prevent them from appearing in operational logs.
Retention and deletion
We apply different periods depending on the type of data and its purpose:
- OAuth credentials are retained in encrypted form while the connection exists or until we fulfill a deletion request, subject to applicable legal obligations. Disconnecting disables the connection and stops Factu from using it, but does not by itself revoke access at Google or immediately delete every stored credential.
- Unaccepted invoice candidates and their PDFs are purged after 30 days. If you ignore a candidate, its PDF is deleted after 30 days, but a minimal record without the PDF may remain for up to 400 days to prevent the same attachment from being imported again.
- Accepted invoices and PDFs, requests, and fiscal or commercial evidence may be retained for six years where necessary to comply with legal obligations or evidence transactions.
- Non-fiscal events for a closed organization are purged after 90 days.
Your rights and control over Google
You can request access, rectification, portability, or deletion of your data, and object to or restrict certain processing, by writing to privacy@mrfactu.com. Where a legal retention duty applies, we will restrict processing until it expires. You can also lodge a complaint with the Spanish Data Protection Agency.
You can disable Gmail reading without disabling sending and disconnect the mailbox in Factu. To withdraw Factu's access directly, use your Google Account's permissions page. You can also ask us to revoke access or delete data by writing to privacy@mrfactu.com.
Changes to this policy
If we update this policy, we will notify you by email and update the date above.
