GIORMO
ES IT EN DE FR
← Back to home

Legal notice, privacy and cookies

Last updated: 25 August 2026. This document covers the obligations of the General Data Protection Regulation (EU 2016/679, GDPR) and of the Spanish laws applicable to Giormo, S.L. as a Spanish-domiciled entity (LSSI-CE Law 34/2002, LOPDGDD Organic Law 3/2018).

1. Legal notice and identification of the controller

The following are the identifying details of the owner of this website (giormo.com and all its subdomains), in compliance with article 10 of Spanish Law 34/2002 (LSSI-CE) and article 13 GDPR:

Company name: Giormo, S.L.

Tax ID (NIF / VAT): ES B88752050

Registered office: Av. de la Ciencia 1, 13005 Ciudad Real, Spain

Email: info@giormo.com

Activity: custom software development, multi-tenant SaaS platforms, cybersecurity and automation.

Accessing and using this website implies acceptance of the terms described below. If you disagree with any of them, please stop using the site.

Intellectual property

The source code, texts, visual design, logos and any other proprietary content published on this site are protected by intellectual and industrial property rights. Reproduction, distribution, public communication or transformation without express authorisation is prohibited.

Liability

We make reasonable efforts to keep the information up to date and accurate, but we do not warrant the absence of errors. We are not liable for the use you make of the information published or for damages arising from access to the site when caused by reasons outside our control.

Third-party links

The website may contain links to third-party sites. We do not control or endorse their content. Browsing those sites is governed by their own terms and policies.

2. Privacy policy and data processing

We process your personal data in accordance with the GDPR. The data controller is Giormo, S.L. (Tax ID ES B88752050), with registered office at Av. de la Ciencia 1, 13005 Ciudad Real, Spain. For any matter relating to your personal data you may contact us at info@giormo.com.

Giormo, S.L. has not appointed a Data Protection Officer (DPO) because none of the cases listed in art. 37(1) GDPR apply: the core activity does not consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale nor of large-scale processing of special categories of data. Data-protection enquiries are handled directly through the email above.

What data we collect and why

We do not use tracking cookies, do not share data with marketing third parties and do not profile visitors.

Recipients and sub-processors

To deliver the web service we rely on cloud hosting and email providers, all located within the European Economic Area (EEA), which process the data exclusively under our instructions as processors bound by contract under art. 28 GDPR.

We do not carry out international transfers of personal data outside the EEA in the context of the public website. Fonts and illustrative images are served directly from our own servers: no contact is made with Google Fonts, Unsplash or third-party CDNs. For further information about our processors, please write to info@giormo.com.

Security measures

We apply appropriate technical and organisational measures under art. 32 GDPR: encrypted communications (HTTPS) on all domains, detection and blocking of malicious access, antivirus scanning of uploaded files, role-based access control with audit logging, encrypted backups and strict isolation of data between clients at database level.

3. Cookie and local-storage policy

This site does not install tracking, advertising or analytics cookies. We do not use Google Analytics, Meta Pixel or equivalents.

We do use localStorage (technical browser storage, not cookies) for a single functional purpose: remembering the language you selected in the header switcher so we can respect it on future visits. This information:

If we ever add cookies that require consent, we will display a banner with genuine accept / reject options and update this page.

4. Access to email through Google APIs

When a Giormo customer chooses to connect their company mailboxes to the platform, Giormo accesses those mailboxes through the Gmail API. This section explains exactly what data is processed, for what purpose and within what limits.

Which permissions we request and why

Giormo requests a single Google permission (scope):

This is the minimum permission that covers those functions. We do not request the https://mail.google.com/ scope, which would allow permanent deletion of email: Giormo never permanently deletes messages from a mailbox.

What data we process and for what purpose

Messages are not stored

Giormo does not keep a copy of the emails obtained from Google APIs. Every time the inbox is opened, a message is read or a search is run, the data is requested from Gmail at that moment and sent to the user's browser. No subject, sender, body or attachment is left behind in Giormo's database.

The only exception is a temporary technical cache held in memory that keeps the inbox listing for 60 seconds, so the same request is not repeated to Google while the user moves between pages. It is volatile, expires on its own and is never written to disk or to backups.

What is kept: the company's documents

Giormo is a logistics management platform. When an operational document is extracted from an email — the delivery note that becomes a shipment, the CMR filed alongside the transport, a supplier invoice — that document and the extracted data are stored, because they are the very purpose of the contracted service and the customer needs them for their operations and to meet their commercial and tax obligations.

The distinction is deliberate: we do not keep the mailbox, we keep the business document the user chose to add to their records. Those documents follow the retention period of the shipment or invoice they belong to, and are governed by section 6 of this policy.

Note: mail accounts connected through classic IMAP (providers other than Google) do keep a local message cache in the customer's database, isolated per tenant, so that the inbox responds quickly. That cache is likewise deleted when the account is disconnected.

Automated processing with artificial intelligence

In order to automatically extract operational data (order numbers, vehicle plate numbers, amounts and invoice references), the content of certain emails is processed using Google Gemini artificial-intelligence models, under a data processing agreement.

Limited Use of Google user data

Giormo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, and without exception:

Security of credentials

Access credentials (service-account keys and OAuth tokens) are stored encrypted with AES-256-GCM, never in plain text, and are isolated per customer. Access to the infrastructure is restricted and audited.

How to revoke access

Access can be withdrawn at any time through any of these means:

When an account is disconnected, Giormo performs the following in a single operation:

The application shows a count of what was deleted when the disconnection is confirmed. Documents already added to a shipment or an invoice are not deleted: they belong to the customer's records and are governed by section 6.

Microsoft 365 mailboxes

Microsoft 365 / Outlook accounts are connected through Microsoft Graph and follow the same rule: no copy of the messages is kept in Giormo's database. The specific permissions requested, the detail of what is kept and how to revoke access are set out on the Microsoft 365 mailbox access page, written for the Entra ID administrator who has to approve the application.

5. Your rights and how to exercise them

As a data subject you may exercise at any time the following rights, foreseen in articles 15 to 22 of the GDPR:

To exercise any of these rights, write to info@giormo.com stating your request clearly and attaching, where necessary for identity verification, a copy of an identification document. We will reply within one month (extendable by two months in complex cases). If you believe your request has not been properly handled, you may lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan 6, 28001 Madrid) or with the supervisory authority of your country of residence.

6. Data processing in the SaaS platform (customers)

Giormo, S.L. operates a multi-tenant logistics-management platform accessible under client-specific subdomains (e.g. customer.giormo.com). In this context:

Customers and prospective customers may consult the Data Processing Agreement (DPA) template with the up-to-date sub-processor list, or request an editable version for signature by writing to info@giormo.com.

7. Mobile application for drivers (Android)

Giormo, S.L. distributes on Google Play an application for work use only, intended for the drivers of its client companies. It is not a public application: an account created by the company is required to sign in. As on the web platform, the data controller is the driver's company and Giormo, S.L. acts as processor (see section 6).

What data the application processes

Legal basis

Performance of the employment relationship and the employer's right of supervision (Articles 20.3 and 20 bis of the Spanish Workers' Statute), in accordance with the GDPR and the LOPDGDD. Before any position is recorded, the application shows the driver a specific notice about the processing of their geolocation, which they must read and accept.

Who the data is shared with

With no one outside the service. The data is hosted on Giormo, S.L.'s infrastructure and is only accessible to the driver's company. Sub-processors are engaged on the terms of the Data Processing Agreement; Google (Firebase Cloud Messaging) is used to deliver the alerts to the phone, and processes them solely to reach the device. There is no advertising, no commercial profiling and no transfer to third parties for their own purposes.

Security and retention

All communications travel encrypted over HTTPS. Data is retained for the duration of the relationship with the company and for the statutory transport document retention periods; it is then deleted or anonymised.

Rights and uninstalling

Drivers may exercise their rights of access, rectification, erasure, objection, restriction and portability by contacting their own company, which is the controller, as set out in section 5. Uninstalling the application immediately stops any collection of location and notification identifier from that device.