Privacy Policy — AutoRent
Developed and operated by RMTracker S.L.
1. Who is who
AutoRent is not an application for the taxpayer: it is the tool used by a consultancy. The person who enters it is the consultant, and he manages the tax records of individuals and companies that he advises. This distributes the roles:
- The consultancy is responsible for processing. It is the one with the advisory relationship with the taxpayer, who decides what data to process and for what purpose, and who is obligated to keep them.
- RMTracker S.L. is in charge of processing (art. 28 GDPR): provides the tool and infrastructure, and processes the data according to the instructions of the consultancy.
Data of the responsible party:
- RMTracker S.L. («RMTracker»)
- NIF: B88803085
- Activity (CNAE): 6210 — Information technology services
- Registration and address data: as they appear in the Legal notice of RMTracker Solutions.
- Email:
legal@rmtrackersolutions.com
If you are a client of an advisory firm and want to exercise your rights, contact them., who is responsible. If she writes to RMTrackerwill be transferred to the appropriate department and will be informed of this; they will not be left without a means of redress.
2. There is no open record.
It is not possible to create an account on AutoRentThe financial advisors create the accounts, and the client's access to the portal is enabled by the advisory firm itself from their profile. Each advisory firm works in its own space and does not see the records of other firms.
3. What data is processed
3.1 Regarding the advisor who uses the tool
- Identification and access: name, email address and password. The password never stored in plain text: The derived value is stored using PBKDF2-SHA256 and 120,000 iterations with a random salt.
- Second factor: if it is activated, the TOTP associated with the account.
- Activity: The actions taken on cases are recorded in an audit history, and the server records the IP address from which access is made.
3.2 From the clients you advise – third-party data
This is the important part: the majority of personal data that is in AutoRent they are not owned by the person who uses them, but by third partiesThese include:
- Tax identification: name or company name, tax ID/CIF, address and contact details of clients, counterparties and taxpayers.
- Invoicing and accounting: invoices issued and received with their breakdown, registers, entries, investment assets and digitalized documents.
- Bank details: IBAN, accounts, statements and transactions, and SEPA transfers with their lines.
- Withholding and income from work: taxpayer's and landlord's NIF and name, bases and withholdings that are transferred to forms 111, 115 and 180.
- Personal and family circumstances of the IRPF: the minimum personal boxes, by descendants, by ascendants and by disability. Some of them reveal health data, which art. 9 GDPR treats as special category: they are processed only because tax regulations require them to be declared, not by consent.
It does not request these RMTracker: the advice introduces them in compliance with their professional mandate. The person who confirms that there is a legal basis for processing and has informed the interested parties is the advice.
4. For what purposes and on what legal basis
- To provide tax and accounting advisory services (execution of the contract between the advice and its client, art. 6.1.b GDPR).
- To comply with tax, accounting and invoicing obligations (legal obligation, art. 6.1.c GDPR). This is not an option that can be deactivated.
- Security and traceability: audit and access logging, in order to prove who did what on a tax file (legitimate interest, art. 6.1.f GDPR).
5. Document recognition
When an invoice or proof of payment is uploaded, the text is extracted on the own server using a local engine. The document is not sent to any third-party recognition service. The result always goes through human review before becoming an entry: the tool proposes, the advisor decides.
6. Who else intervenes
- Render — hosting of the service and database in Frankfurt (European Union). Data controller.
- Supabase — authentication and exchange of documents with the client's application. Data controller. The project is hosted in the European Union (
eu-north-1) and the files go to a private bucket. - GoCardless Bank Account Data — only if the firm activates automatic bank connection. It is an aggregation provider under PSD2 that receives data from connected accounts. If not activated, no one intervenes: statements enter as a file (N43, CSV or XLSX).
The data processing agreements of Render and Supabase in accordance with Article 28 of the GDPR are signed and archived by RMTracker S.L. GoCardless only intervenes if the firm activates the bank connection, under the applicable contractual terms for that service.
7. No profiling, no analytics, no advertising
AutoRent does not use any analytics or advertising SDKs, does not create profiles and does not make automated decisions with legal effects. The tax calculations it proposes are just that: proposals; the declaration is reviewed and assumed by a professional.
8. How long data is retained
- Tax and accounting documentation: as long as the advisor needs to retain it. Generally, four years of tax prescription (General Tax Law) and six years of commercial retention (Commercial Code), starting from the last entry.
- Audit log: is chained by hash while the file is active. Deleting an event would break the chain, which is precisely what gives it value.
- Advisor accounts: as long as the relationship with the advisor lasts.
It is important to be clear about this: the right of deletion exists, but clashes with the obligation to retain documentation. When they coincide, the deletion does not take place: the data remains locked and available to the administration and courts for the legal period.
9. Security
- Access only by invitation, with derived password and second TOTP factor available.
- Strict separation by advisor: each query is limited to its workspace.
- SHA-256 chained audit log, which allows for the detection of manipulations.
- Backups with manifest and hash integrity verification.
No measure makes a system invulnerable. If a breach poses a risk, the advisor, as responsible, must notify it to the AEPD in accordance with Article 33 of the GDPR, and RMTracker will communicate it without undue delay once they have knowledge.
10. Your rights
Access, rectification, deletion, limitation, portability and opposition. The natural way is through your advisor. If you prefer to write legal@rmtrackersolutions.comwill be transferred and informed of who.
can claim against the Agencia Española de Protección de Datos (www.aepd.es) if you believe that your data has not been processed correctly.
11. Changes
Versions are recorded with their effective date. If a change significantly affects processing, it will be communicated before it takes effect.
legal@rmtrackersolutions.com.