Privacy Policy
Last updated: December 2024
1. Data Controller
- Company:
- [PENDIENTE — completar con dato fiscal real]
- CIF:
- [PENDIENTE — completar con dato fiscal real]
- Address:
- [PENDIENTE — completar con dato fiscal real]
- Email:
- info@livix.es
2. Data We Collect
Account Data
Profile Data
Roommate Matching Data
Listing Data
Usage Data
3. Legal Basis for Processing
| Processing | Legal Basis | GDPR Article |
|---|---|---|
| Account creation and management | Contract execution | Art. 6.1.b |
| Roommate matching (profiling) | Explicit consent | Art. 6.1.a + Art. 22 |
| Analytics | Consent | Art. 6.1.a |
| Commercial communications | Consent | Art. 6.1.a |
| Security and fraud prevention | Legitimate interest | Art. 6.1.f |
| Legal compliance | Legal obligation | Art. 6.1.c |
4. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion + 30 days |
| Listings | Until deleted by user |
| Messages | 2 years after last activity |
| Analytics data | 26 months (anonymized) |
| Legal/billing records | 5 years (legal requirement) |
5. International Transfers
Your data is stored in the European Union using Supabase (with a signed Data Processing Agreement - DPA). We do not transfer personal data outside the EU unless absolutely necessary and with appropriate safeguards (Standard Contractual Clauses).
6. Your Rights (ARCOPOL)
Under GDPR and LOPDGDD, you have the following rights regarding your personal data:
Access
Request a copy of your data
Rectification
Correct inaccurate data
Deletion
Delete your account and data
Objection
Object to certain processing
Portability
Export your data in JSON
Limitation
Limit how we use your data
To exercise any of these rights, click on the cards above or contact us at info@livix.es. We will respond within 30 days.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es
7. Automated Decision Making & Profiling
Our roommate matching feature uses algorithmic profiling to suggest compatible matches based on your preferences. This processing:
- Requires your explicit consent before activation
- Can be disabled at any time in Settings
- Does not produce legally binding effects
- Uses only the data you explicitly provide for matching
8. Security Measures
We implement technical and organizational measures to protect your data:
- Encryption in transit (HTTPS/TLS)
- Encryption at rest for sensitive data
- Secure password hashing (bcrypt)
- Row Level Security (RLS) in database
- Regular security audits
9. Policy Updates
We may update this policy to reflect changes in our practices or legal requirements. We will notify you of significant changes via email or in-app notification.