Legal notice, privacy and cookies
Last updated: 5 August 2026. This document covers the obligations of the General Data Protection Regulation (EU 2016/679, GDPR) and of the Spanish laws applicable to Giormo, S.L. as a Spanish-domiciled entity (LSSI-CE Law 34/2002, LOPDGDD Organic Law 3/2018).
1. Legal notice and identification of the controller
The following are the identifying details of the owner of this website (giormo.com and all its subdomains), in compliance with article 10 of Spanish Law 34/2002 (LSSI-CE) and article 13 GDPR:
Company name: Giormo, S.L.
Tax ID (NIF / VAT): ES B88752050
Registered office: Av. de la Ciencia 1, 13005 Ciudad Real, Spain
Email: info@giormo.com
Activity: custom software development, multi-tenant SaaS platforms, cybersecurity and automation.
Accessing and using this website implies acceptance of the terms described below. If you disagree with any of them, please stop using the site.
Intellectual property
The source code, texts, visual design, logos and any other proprietary content published on this site are protected by intellectual and industrial property rights. Reproduction, distribution, public communication or transformation without express authorisation is prohibited.
Liability
We make reasonable efforts to keep the information up to date and accurate, but we do not warrant the absence of errors. We are not liable for the use you make of the information published or for damages arising from access to the site when caused by reasons outside our control.
Third-party links
The website may contain links to third-party sites. We do not control or endorse their content. Browsing those sites is governed by their own terms and policies.
2. Privacy policy and data processing
We process your personal data in accordance with the GDPR. The data controller is Giormo, S.L. (Tax ID ES B88752050), with registered office at Av. de la Ciencia 1, 13005 Ciudad Real, Spain. For any matter relating to your personal data you may contact us at info@giormo.com.
Giormo, S.L. has not appointed a Data Protection Officer (DPO) because none of the cases listed in art. 37(1) GDPR apply: the core activity does not consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale nor of large-scale processing of special categories of data. Data-protection enquiries are handled directly through the email above.
What data we collect and why
- Contact form: name, email, company (optional) and message. Purpose: replying to your enquiry and, where appropriate, preparing a commercial offer. Legal basis: pre-contractual measures at the request of the data subject (art. 6(1)(b) GDPR) and, subsidiarily, consent given by sending the form (art. 6(1)(a)). Retention: up to 2 years from last contact, unless you request earlier erasure.
- Server technical logs: IP address, user-agent, date/time and requested URLs. Purpose: security (abuse and attack detection), debugging and incident response. Legal basis: legitimate interest of the controller (art. 6(1)(f) GDPR) in protecting its systems. Retention: 30 days.
- Browser headers (Accept-Language): read on the client side to suggest a language. They never leave your browser and are not stored on the server.
We do not use tracking cookies, do not share data with marketing third parties and do not profile visitors.
Recipients and sub-processors
To deliver the web service we rely on cloud hosting and email providers, all located within the European Economic Area (EEA), which process the data exclusively under our instructions as processors bound by contract under art. 28 GDPR.
We do not carry out international transfers of personal data outside the EEA in the context of the public website. Fonts and illustrative images are served directly from our own servers: no contact is made with Google Fonts, Unsplash or third-party CDNs. For further information about our processors, please write to info@giormo.com.
Security measures
We apply appropriate technical and organisational measures under art. 32 GDPR: encrypted communications (HTTPS) on all domains, detection and blocking of malicious access, antivirus scanning of uploaded files, role-based access control with audit logging, encrypted backups and strict isolation of data between clients at database level.
3. Cookie and local-storage policy
This site does not install tracking, advertising or analytics cookies. We do not use Google Analytics, Meta Pixel or equivalents.
We do use localStorage (technical browser storage, not cookies) for a single functional purpose: remembering the language you selected in the header switcher so we can respect it on future visits. This information:
- Exists only in your browser. It is never sent to any server.
- Does not identify the user.
- Is a functional preference exempt from prior consent (art. 22(2) LSSI-CE; equivalent to EDPB guidance on strictly necessary technical storage).
- Can be deleted at any time from your browser settings (under "Site data" or equivalent).
If we ever add cookies that require consent, we will display a banner with genuine accept / reject options and update this page.
4. Access to email through Google APIs
When a Giormo customer chooses to connect their company mailboxes to the platform, Giormo accesses those mailboxes through the Gmail API. This section explains exactly what data is processed, for what purpose and within what limits.
Which permissions we request and why
Giormo requests a single Google permission (scope):
https://www.googleapis.com/auth/gmail.modify— allows reading the messages in the mailbox, marking them as read, applying labels to them and sending replies from the user's own address.
This is the minimum permission that covers those functions. We do not request
the https://mail.google.com/ scope, which would allow permanent
deletion of email: Giormo never permanently deletes messages from a mailbox.
What data we process and for what purpose
- Message content (subject, body, attachments) and metadata (sender, recipients, date, labels). Purpose: displaying the inbox inside the platform, linking each email to the corresponding shipment, delivery note, CMR or invoice, and allowing replies without leaving the application. Legal basis: performance of the contract with the customer.
Messages are not stored
Giormo does not keep a copy of the emails obtained from Google APIs. Every time the inbox is opened, a message is read or a search is run, the data is requested from Gmail at that moment and sent to the user's browser. No subject, sender, body or attachment is left behind in Giormo's database.
The only exception is a temporary technical cache held in memory that keeps the inbox listing for 60 seconds, so the same request is not repeated to Google while the user moves between pages. It is volatile, expires on its own and is never written to disk or to backups.
What is kept: the company's documents
Giormo is a logistics management platform. When an operational document is extracted from an email — the delivery note that becomes a shipment, the CMR filed alongside the transport, a supplier invoice — that document and the extracted data are stored, because they are the very purpose of the contracted service and the customer needs them for their operations and to meet their commercial and tax obligations.
The distinction is deliberate: we do not keep the mailbox, we keep the business document the user chose to add to their records. Those documents follow the retention period of the shipment or invoice they belong to, and are governed by section 6 of this policy.
Note: mail accounts connected through classic IMAP (providers other than Google) do keep a local message cache in the customer's database, isolated per tenant, so that the inbox responds quickly. That cache is likewise deleted when the account is disconnected.
Automated processing with artificial intelligence
In order to automatically extract operational data (order numbers, vehicle plate numbers, amounts and invoice references), the content of certain emails is processed using Google Gemini artificial-intelligence models, under a data processing agreement.
- This processing is automated: no Giormo staff member reads customer email.
- The data is not used to train artificial-intelligence models.
- No automated decisions with legal effects on natural persons are taken: the result is always reviewable by the user.
Limited Use of Google user data
Giormo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, and without exception:
- We do not use Gmail data for advertising or profiling purposes.
- We do not sell or transfer Gmail data to third parties.
- No human reads users' email, except with their express and specific consent to resolve a particular issue that the user has reported, for security purposes, or where required by law.
- We do not transfer the data except to the processors strictly necessary to provide the service, which are listed in this policy.
Security of credentials
Access credentials (service-account keys and OAuth tokens) are stored encrypted with AES-256-GCM, never in plain text, and are isolated per customer. Access to the infrastructure is restricted and audited.
How to revoke access
Access can be withdrawn at any time through any of these means:
- By disconnecting the account from the Giormo platform itself.
- From the user's Google account permissions page.
- By the domain administrator, withdrawing the authorisation in the Google Workspace admin console.
When an account is disconnected, Giormo performs the following in a single operation:
- Stops receiving notices from Google about that mailbox (the push notification subscription is cancelled).
- Deletes any messages and attachments that might remain stored for that account, as well as its synchronisation state.
- Deletes the contacts the application had automatically filed from the headers of those emails. Contacts the user created or edited by hand are kept.
- Deletes that account's access credentials, so that neither the password nor the tokens of a mailbox no longer in use are held.
The application shows a count of what was deleted when the disconnection is confirmed. Documents already added to a shipment or an invoice are not deleted: they belong to the customer's records and are governed by section 6.
5. Your rights and how to exercise them
As a data subject you may exercise at any time the following rights, foreseen in articles 15 to 22 of the GDPR:
- Access: know which of your data we process.
- Rectification: correct inaccurate data.
- Erasure: have your data deleted when it is no longer necessary.
- Objection: object to processing on legitimate grounds.
- Restriction: restrict processing while we verify your request.
- Portability: receive your data in a structured, commonly used and machine-readable format.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, write to info@giormo.com stating your request clearly and attaching, where necessary for identity verification, a copy of an identification document. We will reply within one month (extendable by two months in complex cases). If you believe your request has not been properly handled, you may lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan 6, 28001 Madrid) or with the supervisory authority of your country of residence.
6. Data processing in the SaaS platform (customers)
Giormo, S.L. operates a multi-tenant logistics-management platform accessible under client-specific subdomains (e.g. customer.giormo.com). In this context:
- The customer (the contracting company) acts as data controller for the personal data of its employees, drivers, third parties and end customers uploaded to the platform.
- Giormo, S.L. acts as data processor (art. 28 GDPR) and processes the data exclusively to provide the contracted service.
- The conditions of this processing (purposes, instructions, sub-processors, security measures, return and deletion, assistance with data-subject rights, breach notification and audit rights) are regulated by a Data Processing Agreement (DPA) signed with each customer.
- Data subjects (drivers, employees, etc.) should exercise their rights primarily before the customer acting as controller. Giormo, S.L. assists the customer in handling such requests with the diligence required by the GDPR.
Customers and prospective customers may consult the Data Processing Agreement (DPA) template with the up-to-date sub-processor list, or request an editable version for signature by writing to info@giormo.com.