SKANDA Logo
SKANDA

Legal

Privacy Policy

Last updated: 25 May 2025

This is a courtesy translation. In the event of any discrepancy, the Spanish version prevails, as it was drafted under the GDPR and Spanish law.

At Skanda we process your data solely to provide the service. We don't sell it, we don't share it with third parties for advertising and we never use it for purposes other than those described here. Your business data (recipes, events, clients) is yours.

1.

Data controller

The data controller is SKANDA. You can reach us at somosskanda@gmail.com or by phone on +34 644 41 50 42.

2.

What data we collect

  • ·Account data: name and email, managed through Clerk.
  • ·Billing data: card and payment details, processed by Stripe. Skanda never sees or stores card details.
  • ·Operational data: recipes, ingredients, events, suppliers, clients and any information you enter into the platform.
  • ·Technical data: IP address, browser type and pages visited, for security and service improvement.
3.

Legal basis for processing

  • ·Performance of the contract (Art. 6.1.b GDPR): to provide the service you contracted.
  • ·Consent (Art. 6.1.a GDPR): for optional marketing communications.
  • ·Legitimate interest (Art. 6.1.f GDPR): for service improvement and security.
  • ·Legal obligation (Art. 6.1.c GDPR): for tax and regulatory compliance.
4.

What we use your data for

  • ·Providing and maintaining the service.
  • ·Processing payments and managing your subscription.
  • ·Sending you important communications about your account.
  • ·Detecting and preventing fraud and misuse.
  • ·Improving the service's features (in aggregated, anonymised form).
5.

Data retention

  • ·Operational data: deleted within 30 days of cancelling the account.
  • ·Billing data: retained for 5 years under Spanish tax obligations.
  • ·Technical data: anonymised after 13 months.
6.

Processors and international transfers

To provide the service, your data is processed by:

ClerkUser authenticationUSA · EU-US Data Privacy Framework
StripePayment processingUSA · EU-US DPF + PCI DSS level 1
SupabaseDatabase and storageEU (Frankfurt) · Data held in the EU
GoogleAI services (Gemini)USA · EU Standard Contractual Clauses
7.

Security

  • ·SSL/TLS encryption on all communications.
  • ·Per-user data isolation (multi-tenant architecture).
  • ·Stripe is PCI DSS certified; Supabase is SOC 2 certified.
  • ·Automatic, encrypted backups.
8.

Your rights (GDPR)

You may exercise the following rights at any time by writing to somosskanda@gmail.com:

  • ·Access: request a copy of your personal data.
  • ·Rectification: correct inaccurate or incomplete data.
  • ·Erasure: request deletion of your data (the "right to be forgotten").
  • ·Portability: receive your data in a structured format (CSV/JSON).
  • ·Objection: object to processing for specific purposes.
  • ·Restriction: restrict processing in certain circumstances.

We will respond within a maximum of 30 days.

9.

Cookies

We use only cookies necessary for the service to function (authentication and payments). There are no advertising or tracking cookies. See our Cookie Policy for the full detail.

10.

Data Protection Officer (DPO)

For specific data protection queries, write to somosskanda@gmail.com with "DPO" in the subject line.

11.

Right to complain to the Spanish DPA

If you believe the processing of your data does not comply with the regulation, you have the right to lodge a complaint with the Spanish Data Protection Agency: www.aepd.es.

12.

Changes to this policy

We will notify material changes by email or through a notice in the application at least 15 days in advance.

somosskanda@gmail.com · +34 644 41 50 42