Privacy Policy
Last updated: February 5, 2026
1. Data Controller
ExpertOS ("we", "our", or "the Platform") is the data controller for personal data collected through this platform.
Contact details:
Email: [email protected]
Address: Madrid, Spain
2. Data We Collect
We collect different types of information depending on how you interact with our platform:
2.1 Data provided directly
- Registration information: name, email, password
- Profile information: biography, photo, social media links
- Billing information: payment details, tax address
- Content: texts, audio, videos you upload or generate on the platform
- Communications: support messages, feedback
2.2 Automatically collected data
- Usage data: pages visited, features used, session time
- Technical data: IP address, browser type, operating system
- Device data: unique identifiers, device model
- Cookies and similar technologies (see Cookie Policy)
2.3 Third-party data
- Social media information when you connect your accounts
- Payment provider data to process transactions
- Authentication service information (OAuth)
3. Purposes of Processing
We use your personal data for the following purposes:
- Service provision: Create and manage your account, provide platform features
- Payment processing: Manage subscriptions and transactions
- Communications: Send service notifications, newsletters (with consent), respond to inquiries
- Service improvement: Analyze usage to improve features and user experience
- Security: Detect and prevent fraud, protect the platform
- Legal compliance: Fulfill legal and tax obligations
4. Legal Basis for Processing
The processing of your data is based on the following legal grounds under GDPR:
- Contract performance (Art. 6.1.b): To provide contracted services
- Consent (Art. 6.1.a): For marketing communications and non-essential cookies
- Legitimate interest (Art. 6.1.f): To improve service and ensure security
- Legal obligation (Art. 6.1.c): To comply with tax and legal requirements
5. Data Recipients
We may share your data with the following categories of recipients:
- Service providers: Hosting, payment processing, email, analytics
- AI services: For transcription and content generation features
- Authorities: When required by law
- Business partners: Only with your express consent
All our providers are subject to data processing agreements that ensure protection of your information in compliance with GDPR.
6. International Transfers
Some of our providers may be located outside the European Economic Area. In these cases, we ensure transfers are made with appropriate safeguards:
- European Commission adequacy decisions
- EU-approved standard contractual clauses
- Certifications such as the EU-US Data Privacy Framework
7. Data Retention
We retain your data for the time necessary to fulfill the described purposes:
- Account data: While your account is active and up to 2 years after cancellation
- Billing data: 6 years for tax obligations
- Generated content: Until you delete it or cancel your account
- Usage data: 2 years for analysis and service improvement
- Support communications: 3 years from last interaction
8. Your Rights
Under GDPR, you have the following rights over your personal data:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Restrict processing in certain circumstances
- Portability: Receive your data in structured format
- Objection: Object to processing based on legitimate interest
- Withdraw consent: Revoke given consent at any time
To exercise these rights, contact us at [email protected]. We will respond within a maximum of 30 days.
9. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Data encryption in transit (TLS/SSL) and at rest
- Role-based access control
- Monitoring and intrusion detection
- Regular backups
- Staff training in data protection
- Periodic security assessments
10. Minors
ExpertOS is not intended for minors under 18 years of age. We do not knowingly collect data from minors. If you become aware that a minor has provided us with personal data, please contact us to arrange for its deletion.
11. Changes to this Policy
We may update this policy periodically. Significant changes will be notified by email or notice on the platform at least 30 days in advance.
12. Complaints
If you believe that the processing of your data violates data protection regulations, you have the right to file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.
13. Contact
For any inquiries about this policy or the processing of your data:
Email: [email protected]
Data Protection Officer: [email protected]
Address: Madrid, Spain
