Privacy policy

Last updated: July 2026

Data controller

The controller of personal data for users of the Viruta platform is Manuel Joaquín Izquierdo Tomás, tax ID 22596796D, operating the trade name «Viruta» (https://viruta.app), with registered address at Plaza Bandas de Música, 7, piso 12, puerta 75, 46013 Valencia, España, España. For privacy matters contact info@viruta.app.

Data we collect

We process identification and contact data (name, email, phone), organization data (business name, sector), client and lead data you manage, conversation content (WhatsApp, Gmail, Instagram or other connected channels), calendar events (including those synced with Google Calendar), tasks, commercial documents (quotes and invoices), usage metadata, subscription billing data and technical logs (IP, security) required to run the service.

Tax and financial data

If you use invoicing, Verifactu or VAT settlement, we process tax-related data: tax IDs, fiscal address, invoice lines, tax bases, VAT/IRPF rates, deductible expenses, digital certificates (.p12/.pfx) you voluntarily upload, e-invoicing records and draft tax returns (303, 349, 390, etc.). This may reveal economic and tax information about your business.

Google data (Gmail and Google Calendar)

If you connect Gmail and/or Google Calendar from Integrations, Viruta accesses only the data needed from your authorized Google account: (1) Gmail — email address, message metadata (from, to, subject, dates, thread IDs) and message content we sync into your inbox/CRM to display conversations and create or update contacts; (2) Google Calendar — calendar lists, event title, description, location, dates/times, attendees and event IDs that we sync or create/update/cancel from Viruta. We do not request scopes to modify labels or delete messages in Gmail (we do not use gmail.modify). OAuth tokens are stored encrypted. You may disconnect the integration at any time; we then stop syncing and revoke access as allowed by the API. This section covers raw data and, where applicable, aggregated or derived data (e.g. AI-generated conversation summaries).

Google API Services — Limited Use

The use of raw or derived user data received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: (a) we use Gmail and Google Calendar data only to provide or improve user-facing features (unified inbox, CRM, sending replies, calendar and bookings); (b) we do not sell that data or transfer it to third parties for advertising, data brokerage or credit scoring; (c) we do not use Workspace API data (Gmail/Calendar) to develop, improve or train generalized AI/ML models; (d) when AI features process Gmail content (e.g. lead scoring, summaries or reply suggestions), content may be sent to an AI provider (OpenAI) solely to run that feature for your organization, under a contract that prohibits using that data to train the provider’s models; (e) we do not transfer Google data to third-party services for them to train models on it. Any exception would be limited to what Google’s policy allows (e.g. security or legal compliance).

Viruta as data processor

When you manage client, lead or third-party contact data in Viruta, you are the data controller towards those individuals and Manuel Joaquín Izquierdo Tomás (tax ID 22596796D) acts as processor on your behalf under GDPR Art. 28. If you require it as a B2B customer, you may request or use the Data Processing Agreement (DPA) at https://viruta.app/dpa. PDF invoices you issue include an information clause when they contain the recipient's personal data.

Legal basis

We process data to perform the service contract (Art. 6(1)(b) GDPR) for CRM, inbox and documents. Fiscal data is processed to perform the contract and, where applicable, to comply with legal invoicing record obligations (Art. 6(1)(c) GDPR). AI features rely on performance of the contract and your service configuration. Direct marketing, if any, requires consent. Access to Gmail/Calendar is based on your explicit OAuth authorization when connecting the integration.

Purposes

We use your data to provide and improve Viruta, sync communication channels (including Gmail and Google Calendar), generate documents and fiscal drafts, process payments, provide support, ensure security, meet legal obligations and run AI features on conversations and contacts (including Gmail content when the integration is active) to help score leads, summarize threads or suggest replies.

Recipients

We do not sell or share your data for third-party marketing or advertising. We disclose data only to processors essential to the service (see below), authorities when required by law, or to AEAT/other bodies when you explicitly request electronic submission from the platform. Data obtained via Google APIs is not transferred to data brokers or advertisers.

Processors

We use providers that process data on our behalf under contract: hosting and database (e.g. Supabase), payments (Stripe), platform transactional email (e.g. Resend), AI providers (e.g. OpenAI) when the service processes conversations or Gmail content for AI features, and messaging/productivity APIs (Meta/WhatsApp, Google Gmail and Google Calendar) when you connect those integrations. Google acts as the API provider you authorize; OpenAI only receives the fragments needed for the requested or product AI feature, without permission to train models on that data. All are bound by confidentiality and security obligations.

Retention

We keep data while your account is active and as long as needed to comply with legal obligations (e.g. invoicing records under Spanish law). Messages and events synced from Google are kept in your organization until you delete them, disconnect the integration or delete the account. After closure we delete or anonymize within a reasonable period unless legally required to retain. You may request deletion at info@viruta.app, subject to legal retention duties. Disconnecting Gmail or Google Calendar stops new sync; you may also request deletion of data already imported.

Security

We apply appropriate technical and organizational measures: encryption in transit (HTTPS/TLS), encryption of OAuth tokens and secrets at rest, organization-scoped access control, tenant data isolation, and secure storage of certificates. No system is perfect; protect your credentials and digital certificates.

International transfers

Some processors may process data outside the EEA (e.g. USA, including Google and OpenAI). We require appropriate safeguards under GDPR, such as EU Standard Contractual Clauses or adequacy decisions, depending on the provider.

Your rights (GDPR)

You may exercise access, rectification, erasure, restriction, objection and portability by emailing info@viruta.app. Where processing is consent-based, you may withdraw consent without affecting prior lawfulness. You may object to processing based on legitimate interest. We respond within the statutory period (usually one month).

Supervisory authority

If you believe processing breaches the law, you may lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es, in addition to contacting us.

Cookies

We use cookies and local storage strictly necessary for session, preferences (language, theme) and security. If we add web analytics in the future (e.g. Google Analytics), this will be described in our separate cookie policy at https://viruta.app/cookies, with consent options as required by law. You may restrict cookies in your browser, which may affect functionality.

Privacy contact

To exercise rights or ask about data protection: info@viruta.app. Controller: Manuel Joaquín Izquierdo Tomás (tax ID 22596796D). Suggested subject: «Privacy / GDPR». Related documents: cookie policy (https://viruta.app/cookies), DPA (https://viruta.app/dpa) and processing register (https://viruta.app/processing-register).