Privacy Policy
Last updated: 16 August 2026.
Scope and controller
This policy explains how Negative Epsilon SL (“FiscalRail”) processes personal data as a controller when people visit fiscalrail.com, use the dashboard or API on behalf of a client, contact us, or administer and pay for an account.
- Controller: Negative Epsilon SL.
- NIF: B02850360.
- Address: Paseo de la Castellana 194, 28046 Madrid, Spain.
- Privacy contact: contact@negativeepsilon.com.
This policy does not govern personal data that a client submits inside invoices, customer records or related API payloads. For that data, the client normally acts as controller and we act as processor under the Data processing addendum. Contact the relevant invoice issuer first if your request concerns that data.
Data we collect
- Identity and contact data: name, work email, company, role, phone number and communications.
- Account data: user identifiers, memberships, invitations, sign-in token metadata, settings and actions attributed to a user or API key.
- Business and billing data: legal name, tax ID, business address, billing contact, Stripe customer and transaction references, balance and usage records. We do not receive full card details from Stripe.
- Technical and security data: IP address, request identifiers, timestamps, browser and device information, authentication events, API and webhook metadata, logs and security signals.
- Support and prospect data: messages, requested help, diagnostic information and business context you provide.
- Public or official verification data: responses from tax-ID validation services or public authorities when used for account administration or a supported Client instruction.
We receive data directly from you, from the Client whose account you use, from your integration, from payment and infrastructure providers, and from official services such as AEAT or VIES.
Why and on what legal basis we process data
- Provide and administer FiscalRail: create accounts, authenticate users, provide support, communicate service information and perform the contract. Basis: contract and steps requested before contract.
- Billing and accounting: process top-ups, maintain the balance ledger, issue our own invoices, handle disputes and keep statutory records. Basis: contract and legal obligations.
- Security and abuse prevention: protect accounts, investigate incidents, enforce acceptable use and maintain reliable operations. Basis: our legitimate interests and, where applicable, legal obligations.
- Improve the service: diagnose errors and analyse aggregated operational usage. Basis: our legitimate interest in maintaining and improving FiscalRail. We do not use Client invoice content to train general-purpose AI models.
- Respond to enquiries: answer requests and manage prospective relationships. Basis: requested pre-contract steps and legitimate interests.
- Legal compliance and claims: respond to lawful requests, protect rights and establish, exercise or defend legal claims. Basis: legal obligation and legitimate interests.
- Marketing: send product communications where you requested them or where Spanish electronic-marketing rules permit communications about similar services to an existing client. Basis: consent or legitimate interests, as applicable. You can opt out at any time.
We do not make decisions producing legal or similarly significant effects about users solely by automated processing.
Required data
Account identity, authentication and essential business data are required to provide the service. If you do not provide them, we may be unable to create or administer the account. Optional fields are identified by the product context.
Recipients
We disclose data only as needed to:
- authorised users and administrators of the relevant Client account;
- infrastructure, storage, email, security and support providers acting for us;
- Stripe and related payment participants for checkout, fraud prevention, refunds and disputes;
- AEAT, VIES and other authorities or official services where the Client uses a supported validation or submission feature;
- professional advisers, auditors, insurers and prospective transaction parties under confidentiality duties; and
- courts, regulators, law enforcement or other recipients where disclosure is legally required or necessary to protect rights and safety.
Service providers that process Client Data are listed on our Subprocessors page.
For payment activity, Stripe acts as our processor when it executes payment services on our instructions. Stripe also acts as an independent controller for purposes it determines, including fraud prevention, regulatory compliance and operation and improvement of its payment platform, as explained in Stripe's own privacy information. FiscalRail does not send invoice-customer data to Stripe. Disclosures to AEAT and VIES occur only when the Client initiates the relevant validation or submission.
International transfers
We aim to host core application and database data in the European Economic Area. Some providers, including Cloudflare, Amazon and Stripe, may process data from or in countries outside the EEA. Where required, we rely on an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful safeguard. You may request information about the applicable safeguard.
Retention
We keep personal data only for as long as needed for the purposes above, then delete or anonymise it unless law requires retention. In particular:
- active account, user and Client Data records are deleted when the Client closes its final account through the dashboard;
- payment records, including the payer's business identity and Stripe transaction references, are retained for applicable statutory tax and accounting periods;
- security and operational logs are retained for a limited period appropriate to investigation and reliability needs, longer where linked to an incident or legal hold;
- prospect communications are deleted or reviewed when the relationship is no longer active; and
- suppression data may be kept to honour a marketing opt-out.
During the relationship, Client Data follows the DPA and Client instructions. Closing the account is the Client's instruction to delete it. The Client must export any records it needs before closure; FiscalRail does not retain issued invoices or fiscal records for the Client afterwards. Data already present in isolated backups expires through the normal backup rotation and is not restored to active systems except for disaster recovery.
Your rights
Subject to applicable conditions, you may request access, rectification, erasure, restriction, portability or objection. You may withdraw consent at any time without affecting prior lawful processing. Where processing is based on legitimate interests, you may object based on your particular situation.
Send requests to contact@negativeepsilon.com. We may need to verify your identity and route requests concerning Client Data to the relevant Client. You may complain to the Spanish Data Protection Agency (AEPD) or another competent supervisory authority.
Security
We use technical and organisational measures designed to protect personal data, including encrypted public transport, scoped access controls, credential hashing where appropriate, logging filters and immutable record controls. No system is risk-free. You must protect your email account, API keys and webhook secrets and notify us promptly of suspected compromise.
Cookies
See the Cookie policy for the current use of authentication, security and preference technologies.
Changes
We may update this policy to reflect legal, vendor or product changes. We will post the updated date and give appropriate notice of material changes.
Contact
Contact Negative Epsilon SL at contact@negativeepsilon.com or Paseo de la Castellana 194, 28046 Madrid, Spain.