This policy explains how Esteve Castells Calpe handles personal data when you visit sunsetdocs.com, create or use an account, contact us, pay for the service, or submit documents to a customer workspace.
1. Scope
This policy covers the Sunset Docs website, accounts, workspaces, support, billing integration, upload portals, and document email intake. A customer may have its own privacy notice explaining why it asks for documents and how it uses them.
2. Who decides how data is used
Esteve Castells Calpe is the controller for account, billing, support, website, and service-security data. Contact [email protected].
A customer decides why documents are requested, who may access them, and how the information will be used. That customer is normally the controller. Sunset Docs processes submitted documents on the customer's behalf under the Data Processing Addendum.
3. Personal data we handle
Account data includes name, work email, password hash, optional two-step verification data, workspace membership, settings, and service preferences. Billing data includes subscription, invoice, tax, currency, and payment status. Stripe collects payment-card details directly; Sunset Docs does not store full card numbers.
Customer workspace data can include document contents, filenames, sender email addresses, file metadata, submission references, IP-derived security data, access activity, and deletion settings. Support data includes ticket messages and related account details.
4. Purposes and legal bases
We process account, subscription, support, and service-communication data to enter into and perform our contract with the customer. We process billing and tax records to meet legal obligations.
We process limited request, access, and security data for our legitimate interests in protecting the service, preventing abuse, diagnosing failures, and establishing or defending legal claims. Customer documents are processed only on the customer's documented instructions, including the deletion settings selected in the service.
5. Customer documents
Document data comes from senders, workspace members, and customer email intake. Automated checks may reject unsupported, malformed, password-protected, or suspicious files. These checks decide whether a file can enter the workspace; they do not make a legal or similarly significant decision about the sender.
We do not sell document data, use it for advertising, or use document contents to train AI models.
6. Who receives data
We share data only as needed with providers listed on the Subprocessors page, payment and financial providers, professional advisers bound by confidentiality, authorities where disclosure is legally required, and a successor involved in a merger, acquisition, or sale subject to appropriate protections.
Transactional email is sent through Cloudflare and never includes documents, filenames, previews, sender identity, or document contents.
7. International transfers
The primary application and database run on infrastructure in the European Union. Cloudflare and Stripe may process limited traffic, email, account, or payment data outside the EEA. Where a restricted transfer occurs, we rely on an applicable adequacy decision, Standard Contractual Clauses, or another lawful mechanism, with supplementary measures where appropriate.
The current provider roles, data, and regions are listed on the Subprocessors page.
8. Retention
Every customer document has a deletion date. Scheduled or authorised manual deletion removes the active original, previews, temporary print output, wrapped keys, filename, sender details, and sensitive metadata from active storage. Encrypted database backup residuals expire within 30 days.
Minimal non-content deletion and related audit records remain for 12 months. Completed background jobs remain for 30 days. Account and workspace data remain while the account is active and are removed or anonymised after account deletion, except where law requires us to keep a record. Billing and tax records are kept for the periods required by applicable law.
9. Your rights
Where Esteve Castells Calpe is the controller, you may request access, correction, deletion, restriction, objection, or portability where applicable. You may withdraw consent where processing relies on consent. Email [email protected]; we may need to verify your identity.
If you submitted documents to a customer workspace, contact that customer first about the reason for collection, access, correction, deletion, restriction, or withdrawal. Sunset Docs will assist the customer with valid requests. If you cannot identify or reach the customer, contact us with your submission receipt and do not attach the document.
You may lodge a complaint with your local supervisory authority. In Spain, this is the Spanish Data Protection Agency, AEPD, at aepd.es.
10. Cookies
Sunset Docs uses first-party cookies needed for sign-in, session security, CSRF protection, language, and billing-currency preferences. We do not use advertising cookies or third-party analytics on the document viewer. Stripe may use its own technologies when you visit hosted Checkout or the billing portal. The Cookie Policy gives the current details.
11. Security
We use technical and organisational measures intended to protect personal data, as described on the Security page and in the DPA. No internet service can eliminate every risk.
12. Business use and children
Sunset Docs is for business and professional use. Accounts are not intended for children. Customers must not request children's data or special-category data through the service unless Sunset Docs has agreed to that processing in writing.
13. Changes
We may update this policy when the service, providers, or legal requirements change. We will give reasonable advance notice of a material change where appropriate and keep the current version on this page.
14. Contact
Privacy questions and rights requests can be sent to [email protected]. General support is available at help@sunsetdocs.com. Do not send documents to either address.