Privacy Policy
Last updated: October 2026
1. Introduction
At Ganesha Trade Advisors, we work to offer you the best possible experience through our services. Therefore, and for the purposes of Regulation (EU) 2016/679 ("GDPR"), Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), and Law 34/2002 on Information Society Services and Electronic Commerce (LSSI), we inform the user that Ganesha Trade Advisors, as data controller, will process the personal data provided in accordance with this Privacy Policy and current data protection regulations.
Within the scope of certain professional services, Ganesha Trade Advisors may access documentation containing the personal data of third parties. In general, said data will be processed for the provision of documentary audit, analysis, and professional reporting services. Where the specific nature of the service requires Ganesha Trade Advisors to process personal data exclusively upon the client's instructions, it shall act as a data processor. In such cases, the corresponding data processing agreement will be formalised in accordance with Article 28 of the GDPR.
2. Data Controller
- —Holder: Joan Salvador Gatell Martínez (Ganesha Trade Advisors)
- —Professional address: Calle Violeta, 13, 08329 Teià (Barcelona)
- —NIF: see Legal Notice
- —Email: administracion@ganeshatradeadvisors.com
3. Collection and processing of personal data
The data contained in the documentation provided will be processed by Ganesha Trade Advisors for the provision of documentary audit, analysis, and professional reporting services.
Browsing information: IP address, browser identifier (User-Agent), date and time of access to our services, browser used, and device operating system data.
Web contact form
Handling enquiries and requests for information: first name, surname, corporate email, telephone number, company, role, and message content. The legal basis will be the data subject's consent when they voluntarily contact us via the form, as well as the controller's legitimate interest in responding to professional and commercial requests made by company representatives.
Provision of the documentary audit service (free or paid)
Client contact details, provided commercial and banking documentation (LCs, invoices, BLs, etc.). Legal basis: performance of a contract or application of pre-contractual measures (Art. 6.1.b).
Compliance with legal and tax obligations
Identification and billing data. Legal basis: compliance with a legal obligation (Art. 6.1.c).
Tax Identification Number (CIF/NIF)
In the Confidential Audit form, we request the company's Tax ID (CIF/NIF) or, if foreign, its tax identifier. In the case of self-employed professionals, the NIF is personal data.
Purposes: to identify the client company, to apply the 'First review free of charge' offer (one per company), and to issue the service invoice. Legal basis: performance of a contract or application of pre-contractual measures at the data subject's request (Art. 6.1.b) and compliance with tax obligations regarding invoicing (Art. 6.1.c).
The Tax ID (CIF/NIF) used for managing the audit file will be deleted within a maximum period of 60 days from the case's closure. However, where it must be retained for tax, accounting, or billing obligations, it will remain blocked for the legally required periods. To detect repeated requests for the 'First review free of charge' offer, we will retain only an encrypted and irreversible hash of the identifier for a maximum of three years, from which it is not possible to recover the original data.
Processing of Commercial Documentation and Third-Party Data
For the provision of audit services, the user may attach commercial documents containing third-party data (representatives, buyers, suppliers, or bank personnel). Said data will be processed exclusively for the purpose of issuing the technical audit report. In accordance with Article 14.5.b of the GDPR, given the impossibility of informing said third parties individually, the client guarantees that they have the appropriate legal basis to transmit this information for exclusively analytical and professional purposes.
4. Legal basis for processing your personal data
The processing described in this Policy is based on:
- —The consent of the data subject (Art. 6.1.a GDPR).
- —The performance of a contract or the application of pre-contractual measures (Art. 6.1.b GDPR).
- —Compliance with legal obligations (Art. 6.1.c GDPR).
- —The legitimate interest of the controller (Art. 6.1.f GDPR).
5. Retention of personal data
The processing of data for the purposes described will be maintained for the time necessary to fulfil the purpose for which it was collected and/or until you revoke your consent, without prejudice to complying with the legal obligations arising from the data processing and when it is necessary for the establishment, exercise or defence of potential claims, provided that this is permitted by the applicable legislation. For more information, please contact us at administracion@ganeshatradeadvisors.com
Documentation attached for audit (Letters of Credit, invoices, etc.): will be retained during the provision of the service in Supabase and will be deleted from active storage systems within a maximum period of 60 days from case closure.
Data related to billing and commercial documentation will be retained for the periods required by the applicable tax and commercial regulations, currently up to 6 years in accordance with the Commercial Code and 4 years in accordance with tax regulations, without prejudice to other applicable statute of limitation periods.
6. Data disclosure, Recipients and Data Processors
No data disclosures to third parties are foreseen, except under legal obligation or when necessary for the performance of the service requested by the client.
Ganesha Trade Advisors does not make automated decisions that produce legal or similarly significant effects on data subjects. Artificial intelligence tools are used exclusively to support documentary analysis, under human supervision.
Ganesha Trade Advisors is not legally obliged to appoint a Data Protection Officer.
To provide the service, the platform uses the services of the following infrastructure providers (Data Processors):
- —Dify AI LLC: workflow automation and orchestration platform.
- —Anthropic PBC: artificial intelligence services used to support documentary analysis.
- —Resend: management of transactional notifications and sending of reports by email.
- —Lovable: hosting and management of the web interface and user console.
- —Supabase: database and document storage located primarily in the European Union.
- —Google Workspace: corporate email services.
- —Holded: invoicing and administrative management.
- —Stripe: card payment processing.
- —Revolut Pro: management of professional collections and payments.
Data is primarily stored on infrastructure located within the European Union. However, certain technology providers may be located outside the European Economic Area or may process data from such territories. In such cases, international data transfers will be carried out in accordance with Articles 44 et seq. of the GDPR, through European Commission adequacy decisions, adherence to the EU-U.S. Data Privacy Framework, or the signing of Standard Contractual Clauses approved by the European Commission. Other recipients of your data may be public bodies and competent authorities where there is a legal obligation to disclose it.
Data subjects may request additional information about the safeguards applied to international data transfers by writing to administracion@ganeshatradeadvisors.com.
Ganesha Trade Advisors endeavours to ensure the security of personal data when it is sent outside the company and ensures that third-party service providers respect confidentiality and have adequate measures in place to protect personal data. These third parties are obliged to ensure that the information is processed in accordance with data privacy regulations.
7. Exercising your rights
You may send communications and exercise your rights by sending a request to the following email address: administracion@ganeshatradeadvisors.com
In accordance with the GDPR, you have certain rights when it comes to our processing of your personal data:
- —Right to be informed: You have the right to be provided with clear, transparent and easily understandable information about how we use your personal data and your rights.
- —Right of access: You have the right to obtain access to your personal data.
- —Right to rectification: You are entitled to have your personal data rectified if it is inaccurate or incomplete.
- —Right to erasure: This right enables you to request the deletion or removal of your personal data where there is no compelling reason for us to keep using it. This is not an absolute right to erasure and exceptions apply.
- —Right to restrict processing: You have rights to ‘block’ or suppress further use of your personal data. When processing is restricted, we can still store your personal data, but may not use it further.
- —Right to data portability: You have the right to obtain and reuse your personal data for your own purposes across different services.
- —Right to object to processing: You have the right to object to certain types of processing.
- —Right not to be subject to a decision based solely on automated processing: You have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal (or similarly significant) effects for you.
In some cases, your request may be denied if you ask for the deletion of data necessary for compliance with legal obligations. Likewise, if you consider that the processing of your personal data does not comply with current regulations, you may file a complaint with the Spanish Data Protection Agency (www.aepd.es).
8. Responsibility for the accuracy and veracity of the data provided
The user is solely responsible for the veracity and correctness of the data included, being responsible for the accuracy, validity, and updating of the information provided. Users guarantee and are liable, in any case, for the accuracy, validity, and authenticity of the personal data provided, and undertake to keep them duly updated. The user undertakes to provide complete and correct information in the forms on the Website. Ganesha Trade Advisors reserves the right to terminate the services contracted with users if the data provided is false, incomplete, inaccurate, or not up-to-date.
Ganesha Trade Advisors is not responsible for the veracity of information that it has not created itself and for which another source is indicated, and therefore assumes no liability whatsoever for any hypothetical damages that may arise from the use of said information.
Ganesha Trade Advisors reserves the right to update, modify, or delete the information contained on its web pages, and may even limit or deny access to said information.
9. Security measures applied to protect personal data
Ganesha Trade Advisors applies appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR. These measures are aimed at preventing the loss, alteration, processing of, or unauthorised access to personal data. However, the user must be aware that security measures on the Internet are not absolutely invulnerable and that the absence of unlawful access by third parties beyond the control of Ganesha Trade Advisors cannot be guaranteed.
10. Changes to the Privacy Policy
This Privacy Policy may be modified. We recommend that you review the Privacy Policy from time to time.
11. Links to third-party websites
This website may contain links to third-party websites. Ganesha Trade Advisors is not responsible for the privacy policies, data processing practices, or content of such websites. The user is advised to first review the legal notices and privacy policies of each website they visit.
In the event of any discrepancy between versions, the Spanish version shall prevail.