Privacy policy
Last updated: August 2, 2026
1. Data controller
- Controller: Daniel Ruiz
- Address: Abejeras, Pamplona (Spain)
- Contact / exercising your rights: [email protected]
This policy covers both the public site hilbana.com and the application at app.hilbana.com, which links to this same text.
2. What data do we process, and why?
We process data in distinct situations, for distinct purposes:
- Email updates. If you subscribe from this site, we process your email address to send you writing about AI-assisted development and agents, plus Hilbana news. You can unsubscribe at any time from the link included in every email.
- Account and use of the service. If you create an account at app.hilbana.com, we process your sign-up details (email, name and credentials), your workspace data and the technical usage data needed to run the service, support you and keep it secure. If you subscribe to a paid plan, we also process the billing data required to issue your invoice; card details are handled directly by the payment provider and we never store them.
- Enquiries you send us. If you write to us through the contact form or by email, we process your name, email address and the content of your message to answer your enquiry and carry on any communication arising from it. We do not use that data to send you marketing: that's what the newsletter subscription is for, and it's accepted separately.
- Form protection. To prevent automated submissions we transiently process technical data through Cloudflare Turnstile (no profiling).
- Audience and campaign measurement. If you accept in the cookie notice, we load Google tags (Google Analytics 4 and Google Ads conversion measurement) through Google Tag Manager. They process technical browsing data (cookie identifier, pages viewed, device, referral source and IP address, which Google truncates) to build aggregated statistics and tell which campaigns work. If you decline, those tags stay blocked and set no cookies.
3. Legal basis
- Email updates: your consent (Art. 6.1.a GDPR), given when you tick the box and submit the form. You may withdraw it at any time without affecting the lawfulness of processing carried out beforehand.
- Account and service: performance of the contract (Art. 6.1.b GDPR) you accept when signing up, and compliance with legal obligations (Art. 6.1.c) in accounting and tax matters.
- Enquiries: your consent (Art. 6.1.a GDPR), given when you tick the box before submitting the form, and the taking of pre-contractual steps at your request (Art. 6.1.b) when what you ask for is information with a view to signing up.
- Measurement with Google tags: your consent (Art. 6.1.a GDPR), given in the cookie notice and withdrawable at any time from "Cookie preferences" in the footer.
- Security and abuse prevention: our legitimate interest (Art. 6.1.f) in keeping the service available and free of fraud.
4. Retention
We keep your subscription email for as long as you stay subscribed. If you unsubscribe or request erasure, we delete or anonymize it, except for the minimum record needed to avoid emailing you again.
Messages you send through the contact form are kept for as long as it takes to handle your enquiry and, after that, for one year, in case the conversation continues or we need to evidence what was answered. They are deleted once that period is over.
Account data is kept while the account is active and, after closure, for the applicable limitation periods. Billing records are kept for the periods required by commercial and tax law.
Account deletion: a 7-day grace window. You can request deletion from the platform itself. Erasure is not immediate: as soon as you request it, your account and the workspaces you own become inaccessible straight away, both to you and to everyone else, and open sessions are closed. The data is kept without being processed for 7 days, for the sole purpose of allowing the deletion to be undone, and is erased permanently and irreversibly once that period ends. You will receive the erasure date by email, along with a link to cancel it; you can also undo it by logging in with your credentials while the window is still open. Collaborators in the affected workspaces are notified so they can export their data before that date.
What is not deleted. Activity you left in other people's workspaces (comments, issues you created and the activity log) is not erased: it is anonymized, leaving no identifiable author. We keep it on the basis of the legitimate interest (Art. 6.1.f GDPR) of those workspace owners in the integrity of the history of their own work; once anonymized, it is no longer personal data.
5. Recipients and processors
We do not share your data with third parties except where legally required. To provide the service we use the following providers:
- Cloudflare, Inc.: site hosting (Cloudflare Pages), storage of subscriptions and contact messages (Workers KV) and anti-spam protection (Turnstile).
- BillionMail (self-hosted): sending confirmation emails, updates and the messages you send us through the contact form.
- Stripe Payments Europe, Ltd.: payment processing and billing for paid plans.
- Google Ireland Ltd.: tag management (Google Tag Manager) and audience and campaign measurement (Google Analytics 4, Google Ads), only if you accept cookies.
- First-party analytics (Umami, self-hosted): cookie-free usage statistics and a partial, masked session recording (session replay, on a sample of visits) to analyze usability and improve the site; see the Cookie policy.
6. Content you upload to the service
The issues, documents, comments and files you and your team create in Hilbana are yours. If that content includes personal data about other people (your clients or employees, say), you are the one deciding about it: you act as controller and we act as processor, handling it solely to provide the service and following your instructions. The data processing agreement (DPA) under Art. 28 GDPR is available on request at [email protected]. We do not use your workspace content to train artificial intelligence models.
7. International transfers
Some providers (e.g. Cloudflare or Google) may process data on servers located outside the European Economic Area. In that case, such transfers rely on the appropriate safeguards set out in Art. 46 GDPR (such as the European Commission's standard contractual clauses).
8. Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to [email protected]. You do not need to provide a copy of your ID; we will only ask for additional information if it is essential to verify your identity. If you believe the processing does not comply with the regulations, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es). If you have an account at app.hilbana.com, you can exercise erasure yourself from the platform, under the terms and timescales described in section 4.
9. Minors
The service is not directed at children under 14. If you are a minor, please do not provide your data without the consent of your parents or guardians.
10. Security
We apply appropriate technical and organizational measures to protect your data against unauthorized access, loss or alteration.