Legal
Privacy Policy
What we do with your personal data when you use the portal and the services on it — including the documents you upload, how they are read by artificial intelligence, who else sees them and for how long we keep them.
Version 2026-09-01 · in force since September 1, 2026 · Hola Money SL · CIF B26671347 · Calle Granada 7, 04820 Vélez-Rubio, Almería, Spain
The rules of the service itself are in the Terms and Conditions.
Draft pending review by a Spanish lawyer. Not yet the published version.
1. Who is responsible for your data
The data controller is Hola Money SL, CIF B26671347, Calle Granada 7, 04820 Vélez-Rubio, Almería, Spain. Write to [email protected] for anything about your data; the same address reaches our data protection contact. For the TIE renewal service you may also write to [email protected] and for the digital certificate service to [email protected] — they all reach the same people.
For the video identification that a digital certificate requires, the issuer Firmaprofesional, S.A. and its registration authority Gong Time, S.L. are controllers in their own right for the recording and the identification evidence, under the regulation that obliges them to keep it (Orden ETD/465/2021). We forward any request about that data to them within 24 hours and tell you we have done so.
For a gestor-provided service, the gestor you choose processes your data as a controller for their own professional work, under their own obligations of professional secrecy. This policy covers what Hola does; the gestor tells you anything additional they need to.
2. What we collect
- Identity and contact details: name, surnames, email, phone, postal address, date and place of birth, nationality, sex, marital status and parents' first names where an official form requires them, and your preferred language.
- Identity documents and what is on them: images of your passport, TIE, DNI or national identity card, NIE certificate, padrón and any other document a service asks for; and the details we read from them — document numbers, NIE, dates of issue and expiry, the machine-readable zone.
- Photographs: the photograph on your identity documents, and any photograph you upload of yourself or of a document.
- Video identification: performed by the issuer's registration authority for a digital certificate, on their systems, under their responsibility. We receive only the outcome (passed or failed) and the date.
- Your application or case: the answers you give, the documents we generate for you (an EX-23 form, an appointment pack), appointments and their outcomes, messages with our staff or a gestor, reviews and disputes.
- Billing: the name, tax number (NIF/NIE) and address that go on your invoice, and the record of what you paid, when and by which means. Card numbers are handled by our billing system's payment gateway and never stored by us.
- Technical: the IP address, browser and time of your sign-ins and of each acceptance of the terms, the cookies described below, and the logs our systems keep to run securely.
We ask for what a service needs and nothing more. Where a question is optional, we say so.
3. Why we use it, and on what legal basis
- To perform the contract with you (GDPR art. 6.1.b): running your account, reading your documents, preparing and filing your application, booking appointments, collecting payment, handling your case with a gestor, answering you.
- To meet our legal obligations (art. 6.1.c): issuing invoices and keeping accounting and tax records, anti-money-laundering checks where they apply, responding to lawful requests from authorities, keeping the record of your acceptance of the terms.
- With your consent (art. 6.1.a): sending your documents to be read by artificial intelligence as described in the next section — a consent you give when you accept the terms on the first step of a service, and which you can withdraw by cancelling the service; and marketing messages about other Hola services, which you can stop at any time.
- For our legitimate interests (art. 6.1.f): keeping the portal secure and preventing fraud and abuse, verifying gestors, improving the service using aggregate statistics that do not identify you, and defending our rights in a dispute. We weigh these against your interests, and you may object (see your rights below).
Where a form requires data of a special kind — for instance a document that reveals nationality or, indirectly, ethnic origin — we process it only because the administration's form asks for it, on the basis of your explicit consent and the establishment of legal claims (art. 9.2.a and f).
4. How your documents are read: artificial intelligence
The images and files you upload, and photographs in them, are read by an artificial-intelligence model so that you do not have to type their contents. For that purpose they are transmitted to AI model providers through OpenRouter, Inc. (United States), under OpenRouter's Zero Data Retention mode, as OpenRouter itself defines it in its Zero Data Retention documentation. Under that mode the model provider does not retain your data after processing the request and does not use it to train or improve a model, as that documentation describes. The models we currently use are Anthropic's Claude models.
Our systems refuse to send any request that cannot be routed under Zero Data Retention. That is a fixed setting, not a preference: if a request cannot be routed that way, it fails, and a person at Hola reads the document instead. On request we will confirm in writing which provider handled your documents.
The model produces a draft reading. You check and confirm it on the review step, and our staff check it before anything is filed. We keep the reading, and a note of which model produced it, as part of your application for as long as we keep the application.
5. Who receives your data
We share your data with the following, each only for what is listed, and under a contract that binds them to protect it:
- OpenRouter, Inc. and, through it, the AI model provider (currently Anthropic, PBC) — reading your documents, under Zero Data Retention as described above.
- Our billing system (WHMCS, at billing.hola.money) and its card payment gateway, Stripe — invoicing and collecting payment. Stripe processes card data as an independent controller under its own policy.
- Buzzmark — sending our transactional emails (confirmation links, notices about your application, invoices).
- Hetzner Online GmbH (data centres in Germany and Finland) — hosting the portal and storing your documents, encrypted; and Laravel Forge — managing the servers.
- Gong Time, S.L. (registration authority) and Firmaprofesional, S.A. (issuer) — for a digital certificate: your identity details and documents, to sign the contract, run the video identification and issue the certificate. Both are controllers for what the regulation requires them to keep.
- The Policía Nacional and the Oficina de Extranjería, and their appointment and application systems — for a TIE renewal: the official form, your documents and the fee receipt, and the appointment booked in your name.
- The gestor you choose — for a gestor-provided service: your case, its answers, documents and messages, so that they can do the work.
- Public administrations, courts and regulators where the law requires it, and professional advisers bound by confidentiality where we need them to defend a claim.
We never sell personal data and never share it for anyone else's advertising.
6. Transfers outside the European Economic Area
Your documents are stored in the EU. The AI reading described above involves a transfer to the United States (OpenRouter and the model provider), as does card processing by Stripe and, depending on its infrastructure, email delivery. For each such transfer we rely on an adequacy decision of the European Commission where one covers the recipient (including the EU-US Data Privacy Framework for certified companies) and otherwise on the Standard Contractual Clauses approved by the Commission, together with the Zero Data Retention setting described above, which means the model provider keeps nothing to transfer. Copies of the clauses are available on request.
7. How long we keep it
- Uploaded documents and the images we generate from them: their contents are deleted 365 days after the application or case closes. The record that a document existed (its name, type, dates) stays with the application.
- Your application or case, its answers, history and messages: while it is open and for the statute of limitations on contractual claims afterwards (five years in Spain), then deleted.
- Invoices and payment records: the period tax and accounting law require — at least four years for tax, six for accounting — then deleted.
- The record of your acceptance of the terms (version, date, language, IP address, browser): for as long as we keep the application, case or account it relates to, plus the statute of limitations.
- Your account: while it is active, and for the statute of limitations after it is closed or after the last activity on it. An account with nothing on it that has been idle for three years is deleted.
- Video identification recordings: held by the issuer, Firmaprofesional, for the period the regulation prescribes (twenty years), not by us.
- Security logs: twelve months.
8. Your rights
You have the right to ask us for access to your data, to have it rectified, to have it erased, to restrict its processing, to receive the data you gave us in a portable format, and to object to processing based on our legitimate interests. Where processing rests on your consent, you may withdraw it at any time without affecting what was done before; withdrawing consent to the AI reading means we cannot continue the service, and the cancellation and refund rules in the terms apply.
To exercise a right, write to [email protected] from the email address on your account, or by post to the address above, saying which right and, if it is not obvious, which data. We answer within one month; if a request is complex we may take up to two further months and will tell you. We may ask you to confirm your identity first. Much of this you can do yourself: your documents and invoices are in the portal, and your details are editable on your profile.
A request about data held by the issuer or the registration authority (the video identification) is forwarded to them within 24 hours, and we tell you we have done so.
9. Complaints
If you think we have handled your data wrongly, tell us first and we will try to put it right. You also have the right to complain to the supervisory authority, the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es, or to the authority of the EU country where you live.
10. Cookies
The portal uses only the cookies it needs to work: a session cookie that keeps you signed in, a cookie that remembers your language, and the security token that protects forms. It sets no advertising or analytics cookies. Our marketing websites have their own cookie policies: holagestoria.es/cookies, tierenewal.es/cookies and digitcertificate.es/cookies.
11. Automated decision-making
Artificial intelligence reads your documents and our rules check that an application is complete — for instance that a passport has not expired. Neither takes a decision about you on its own: a reading is confirmed by you and checked by our staff, and a rule that does not pass sends the application to a person, who decides. You are not subject to a decision based solely on automated processing that produces legal effects for you or similarly significantly affects you.
12. Security
Documents are stored encrypted on private storage that is not reachable from the internet; download links are signed and expire within minutes; every access by staff is logged. Confirmed details cannot be overwritten by a machine — the database itself refuses. Staff access is by role, limited to the products a person works on, and reviewed. We use two-factor authentication internally and offer it to you on your account. If a breach ever affects your data we tell you and the AEPD as the law requires.
13. Children
The portal is for adults. Where an application concerns a minor — a child's TIE renewal, say — the adult who starts it does so as the child's parent or guardian, and only that adult's account is created.
14. Changes to this policy
This policy is versioned by date, and the version in force is shown at the top. When we change it in a way that affects you, we tell you by email or in the portal and, where the change concerns an application or case you have open, ask you to accept the new version before you continue. Older versions are available on request.
This document is published in English, Spanish and German. The Spanish version prevails in case of any difference between them.