Legal document
Privacy policy
This translation is provided for information only. In case of any discrepancy, the Spanish version prevails.
1. Data controller
- Owner: Norberto Berrueco Betoré (sole trader)
- Tax ID (NIF): 73229777P
- Address: Calle Pizarro, 8, Tauste, Zaragoza (Spain)
- Contact email: support@terrinde.com
- Phone: +34 637 21 11 16
2. What data we process and why
| Source of the data | Purpose | Legal basis |
|---|---|---|
| Website contact form | Answering enquiries and managing the pre-contract business relationship | Consent of the data subject (art. 6.1.a GDPR) |
| Platform users (name, email, encrypted password, role, chosen language) | Giving access to the Platform and managing the customer's account | Performance of a contract (art. 6.1.b GDPR) |
| Farm data entered by the customer (plots, activities, costs, landowners, etc.) | Providing the contracted farm management service | Performance of a contract — Terrinde acts as data processor of this data on the customer's behalf |
| Access and activity logs | Security of the Platform and prevention of unauthorised access | Legitimate interest (art. 6.1.f GDPR) |
The farm data entered by each customer company (plots, landowners, workers, costs, etc.) is isolated and can only be accessed by the users of that same company. Terrinde does not share this data between different customers of the Platform.
Particularly sensitive data processed by the Platform
- Bank details: the IBAN of plot owners that the Customer may record is stored encrypted at rest (AES-256), and is only decrypted to show it to the Customer within their own account.
- Plot geolocation: the Platform stores the coordinates and outline of the Customer's plots (from the SIGPAC register) in order to show them on the map. It is the location of a piece of land, not of a person on the move, and only the Customer can see it.
- Terrinde app for Android: it uses the same account and the same data as the web Platform. On the phone it stores the session (encrypted in the system's secure storage) and a copy of the data so that you can work offline, which is sent to the server when coverage returns. The app does not access the phone's location, camera, contacts or files, and includes no advertising and no third-party analytics or tracking tools.
- Device location (the Map's "locate me" button): if the user presses that button and their browser allows it, their position is used only to centre the map on their screen at that moment — it is not sent to or stored on any server.
3. Retention period
Data will be kept for as long as the contractual relationship lasts and, once it has ended, for the periods required by law (in general, the limitation periods for liability and the applicable tax and accounting obligations, usually up to 6 years). Technical account security data (login attempts, expired sessions, used verification codes) is deleted automatically after much shorter periods, days or weeks, as soon as it is no longer useful. If a user requests the deletion of their account, the request is reviewed and, once approved, their personal login data is anonymised (it no longer identifies them), except for information that must be kept by law.
4. Recipients and data processors
No data is disclosed to third parties unless required by law. To provide the service we may use technology providers (for example, web hosting) who act as data processors under article 28 GDPR, through the corresponding processing agreement:
- Hosting provider: Hostinger
- Transactional email delivery: Resend
- Subscription billing: Stripe
In addition, the Platform uses two technical services that receive no account data:
- Satellite imagery for the Map (NDVI index): Copernicus Data Space Ecosystem, part of the European Union's Copernicus programme. It only receives the coordinates of the enclosure being viewed.
- Map libraries used in the dashboard: cdnjs (Cloudflare). When they load, the user's browser connects to that service, which can see the user's IP address.
The site's fonts are served from Terrinde's own server, with no connection to third parties.
5. International transfers
Some of the providers above (Resend, Stripe and Cloudflare, based in the United States, and Hostinger, which may rely on companies of its group outside Europe) may process data outside the European Economic Area. In those cases the transfer relies on the safeguards required by the GDPR: the Standard Contractual Clauses approved by the European Commission included in their processing agreements and, where the provider has joined it, the EU-U.S. Data Privacy Framework. No other international transfers are made.
6. Rights of data subjects
Everyone has the right to obtain confirmation of whether Terrinde is processing personal data concerning them. Data subjects have the right to:
- Access their personal data.
- Request the rectification of inaccurate data.
- Request the erasure of their data when, among other reasons, it is no longer needed.
- Request the restriction of processing in certain circumstances.
- Object to the processing of their data.
- Request the portability of their data.
If you are a user of the Platform, the quickest way to exercise access, portability and erasure over your own account's data is from within the Platform itself: Ajustes → Privacidad y tus datos (Settings → Privacy and your data), where you can download a copy of your data straight away or request the deletion of your account (in the Android app: Más → Privacidad y tus datos). The steps and which data is kept are described in Delete your account. For the other rights, or if you do not have an account, you can write to support@terrinde.com, attaching a copy of a document proving your identity. If the data over which you want to exercise a right belongs to a third party (for example, you are the owner of a plot or a worker on a farm that is a Terrinde customer), you must contact the relevant customer company, which is the controller of that data — Terrinde acts only as data processor (see section 2). You also have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) if you consider that the processing does not comply with the regulations in force.
7. Minors
The services offered are not aimed at minors. Terrinde does not knowingly collect data from children under 14.
8. Security measures
Terrinde applies appropriate technical and organisational measures to protect personal data, including: passwords stored using secure hashing algorithms (bcrypt), encrypted connection (HTTPS), access control based on roles and permissions, and isolation of each customer company's data from the other customers of the Platform.
9. Changes to this policy
This privacy policy may be updated to reflect new legislation or changes to the service. We recommend reviewing it from time to time.
Last updated: 2 October 2026.