← Volver a GITBI
Legal NoticePrivacy PolicyTerms & Conditions

Privacy Policy

Last updated: 23/07/2026

This Privacy Policy explains how the personal data of users of gitbi.app (hereinafter, the "Website" and the "Service") is processed in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and, where applicable, other relevant data protection laws.

1. Data Controller

  • Owner: Sergio Garo
  • Contact email: [email protected]
  • Website: https://gitbi.app

2. Data We Process

When you register and use the Service, we process the following personal data:

  • Registration data: name, email address, and password. Passwords are always stored using secure cryptographic hashing techniques and are never stored or accessible in plain text.
  • Technical data: IP address, browser type, and access logs automatically generated for security and operational purposes.

The information requested during registration is necessary to create and maintain your user account. If you do not provide this information, we will be unable to provide the Service.

3. Minors

The Service is not intended for children under the age of 14, and we do not knowingly collect personal data from children of that age. If we become aware that personal data has been collected from a child without the authorization required by applicable law, we will delete such data as soon as reasonably possible.

4. Purpose of the Processing

We process your personal data for the following purposes:

  • To create and manage your user account.
  • To provide the Service and its functionalities.
  • To communicate with you regarding incidents, technical issues, or changes affecting the Service.
  • To ensure the security of the Website and prevent fraudulent or unauthorized use.
  • To send you informational or marketing communications about GITBI, where you have provided your explicit consent.

5. Legal Basis

The processing of your personal data is based on the following legal grounds:

  • Performance of a contract (Article 6(1)(b) GDPR): registration data is necessary to provide the Service requested by the user.
  • Legitimate interests (Article 6(1)(f) GDPR): technical and security-related processing required to ensure the proper operation and security of the Service.
  • Consent (Article 6(1)(a) GDPR): for sending marketing communications, where you have expressly agreed to receive them. You may withdraw your consent at any time.

6. Data Retention

We retain your personal data for as long as your account remains active.

Once your account is deleted or you request its removal, your personal data will be deleted or retained only for the period required to comply with legal obligations or to address potential liabilities, after which it will be permanently erased.

Technical and security logs may be retained for as long as necessary to ensure the security of the Service, prevent fraud, or comply with applicable legal obligations.

7. Recipients and Data Processors

We do not disclose your personal data to third parties except where required by law.

To provide the Service, we rely on the following data processors under the corresponding Data Processing Agreements (DPAs):

  • Hetzner Online GmbH — hosting infrastructure and data storage. Servers located in Germany (EU).
  • Resend — delivery of transactional emails (account confirmation, password recovery, and technical notifications).
  • Cloudflare — DNS, CDN, website performance optimization, and security services.

8. International Data Transfers

Where one of our service providers involves an international transfer of personal data outside the European Economic Area (EEA), such transfer will only take place where appropriate safeguards are in place in accordance with Chapter V of the GDPR, such as an adequacy decision adopted by the European Commission (including the EU-U.S. Data Privacy Framework, where applicable) or the execution of Standard Contractual Clauses (SCCs).

9. Your Rights

You may exercise your rights of access, rectification, erasure, objection, restriction of processing, data portability, and withdrawal of consent at any time by contacting us at [email protected] and specifying the right you wish to exercise.

We will respond to your request within the time limits established by applicable data protection legislation.

If you believe that the processing of your personal data does not comply with applicable law, you have the right to lodge a complaint with the competent data protection authority. If you are located in Spain, this authority is the Spanish Data Protection Agency (AEPD).

10. Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, alteration, or disclosure, in accordance with Article 32 of the GDPR.

These measures include, among others, the storage of passwords using secure cryptographic hashing algorithms, encrypted communications via HTTPS/TLS, and strict access control to our systems.

11. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect legal, technical, or operational changes.

Any updates will be published on this page together with the date of the latest revision.

12. Links to Third-Party Websites

The Website may contain links to third-party websites or services. We are not responsible for their privacy practices, content, or policies. We encourage you to review the privacy policies of those third parties before providing them with any personal data.

13. Language

This Privacy Policy is available in both Spanish and English. In the event of any inconsistency between the two versions, the Spanish version shall prevail, without prejudice to the user's right to receive information in a clear and understandable language.

Built with Reflex