Privacy policy
Last updated: July 22, 2026
At Papely we process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on Personal Data Protection and digital rights (LOPDGDD).
1. Data controller
The data controller is Jesús Olazagoitia (Tax ID 16613653V), operating under the Papely brand, with registered address at Av. Lope de Vega, 55, 26006 Logroño (La Rioja), Spain. Contact: [email protected].
2. Data we collect
- Account: name, email and login credentials.
- Billing: tax identification and payment details, processed by our provider (Polar).
- User content: PDF templates, datasets, generated documents, fonts you upload and workspace configuration.
- Technical data: IP address, browser type, language, usage metrics and error logs.
- Communications: support emails and survey responses.
3. Purposes and legal basis
- Providing the service (performance of contract): operating the platform, generating documents and sending deliverables.
- Billing and legal obligations: issuing invoices and complying with accounting and tax obligations.
- Support: responding to your inquiries.
- Product improvement (legitimate interest): analyzing aggregate usage to debug errors and prioritize improvements.
- Marketing (consent): only when you agree to receive promotional communications.
4. Data retention
We keep account data while the account is active. Once cancelled, billing data is retained for as long as legally required. Generated documents are retained according to the subscribed plan (see the plans table on the pricing page). Technical logs are anonymized or deleted after 12 months.
5. Recipients and processors
To provide the service we share data with GDPR-compliant data processors:
- Infrastructure: Railway (hosting), Cloudflare R2 (object storage).
- Payments: Polar.
- Transactional email: Postmark.
- Authentication: Google (when you sign in with Google).
- Observability: Sentry (error logs).
We do not sell personal data to third parties. International transfers rely on standard contractual clauses or adequacy decisions of the European Commission.
6. Google Workspace data (Google Sheets™ add-on)
If you install our Google Sheets™ add-on, it accesses data from your Google account. We describe that processing here in accordance with the Google API Services User Data Policy.
- What we access: the add-on can only read the spreadsheet you open it from (the spreadsheets.currentonly permission). It does not access your Google Drive, other files, or your email. While the sidebar is open it reads the header row, the sheet name and how many rows you have selected — what it needs so you can map columns to fields — and refreshes that periodically to track your selection. Row values are read only when you start a generation.
- How we use it: when you start a generation, and only then, the values of the columns you mapped to fields in your template are sent to our servers (api.papely.app) to generate the corresponding PDFs. Columns you do not map are not sent. If you enable email delivery, the columns you designate as recipient and name are also used to deliver each document.
- How we store it: the submitted rows and the resulting PDFs are stored in your Papely workspace under the same processing and retention periods as the rest of your user content (section 4). The token connecting the add-on to your Papely account is stored in Google Apps Script user properties, tied to your Google user, and is never written into spreadsheet cells. You can revoke it at any time from the add-on itself or from the Papely integrations page.
- Who we share it with: with the processors listed in section 5, as required to generate and deliver the documents. Our error-logging service (Sentry) receives only the error message and stack trace, never the contents of your spreadsheet.
Limited Use: the use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. In particular, we do not use Google Workspace data for advertising purposes, we do not sell it or transfer it to data brokers, and we do not use it to develop, improve or train generalized or non-personalized artificial intelligence or machine learning models.
7. Your rights
You may exercise at any time your rights of access, rectification, erasure, objection, restriction of processing, portability and the right not to be subject to automated decision-making. Write to us at [email protected]. If you believe your request has not been properly handled, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
8. Security
We apply reasonable technical and organizational measures to protect data: encryption in transit (TLS), access control, backups and monitoring. No system is 100% secure; we recommend using strong passwords and enabling the protections available in your account.
9. Minors
Papely is not directed at children under 16. If we detect that data of a minor has been collected without appropriate consent, we will delete it.
10. Changes to this policy
We may update this policy to reflect legal or service changes. We will give you reasonable advance notice of substantial changes.