Skip to content

PRIVACY POLICY

Version of 11 May 2026 · Golova Europe SL
1. Introduction

1.1. This Privacy Policy (the “Policy”) describes how Golova Europe SL (the “Controller”, “Golova”, “we”) collects, uses, discloses and protects personal data of users of the website golova.ai, the mobile applications (Android, iOS), the Golova platform (SaaS) and the related solutions Golova.work, Golova.wiki and Golova.market (together, the “Services”).

1.2. This Policy is published in compliance with Regulation (EU) 2016/679 (the “GDPR”) and Spanish Organic Law 3/2018, of 5 December, on Personal Data Protection and Guarantee of Digital Rights (“LOPDGDD”), which apply to the Controller as a company established in Spain. The Controller acts as operator of the Services in all jurisdictions where they are offered.

1.3. Identification of the Controller:

  • Company name: Golova Europe SL
  • Tax ID (CIF): B70717004
  • EU VAT: ESB70717004
  • Registered office: Calle l’Hospital, 95, Planta 1, Puerta 2, 08001 Barcelona, Spain
  • Commercial Registry: Mercantile Registry of Barcelona, Volume 49139, Folio 218, Sheet B-609178, First Entry (15.02.2024); EUID ES08005.000701808
  • Startup status: certified by ENISA pursuant to Spanish Law 28/2022 of 21 December on the Promotion of the Startup Ecosystem (certification date: 18.02.2026).
  • Email: privacy@golova.ai
  • Telephone: +34 672 390 777

1.4. Data protection contact: privacy@golova.ai. The Controller has not formally appointed a Data Protection Officer (DPO), as the conditions of Article 37 GDPR are not met. The contact person for data protection matters is privacy@golova.ai.

1.5. This Policy applies to all personal data processed by Golova in the context of the Services. The current version is available at https://golova.ai/en/privacy-policy and in the other languages in which the Services are offered.

1.6. This Policy does not apply to: (a) websites or services operated by third parties, even when accessible via links from the Services; (b) data processed by our business customers who use the Services to manage their own customers and personnel — in these cases, our business customer is the controller and Golova acts as processor under a separate Data Processing Agreement.

2. Definitions

2.1. For the purposes of this Policy:

  • Personal data — any information relating to an identified or identifiable natural person (Article 4(1) GDPR).
  • Processing — any operation performed on personal data (collection, recording, storage, modification, retrieval, use, disclosure, erasure, etc.).
  • Data subject — the natural person to whom the personal data relate.
  • Controller — the entity that determines the purposes and means of processing.
  • Processor — the entity that processes personal data on behalf of the Controller.
  • Customer — legal entity, self-employed professional or natural person registered to use the Services.
  • End User — natural person whose data are uploaded into the Services by a Customer (e.g., the Customer’s clients, personnel or counterparties).
  • Services — the Golova SaaS platform, the website, the mobile applications and the related solutions Golova.work, Golova.wiki and Golova.market.
3. Categories of data subjects and personal data

3.1. We process personal data of the following categories of data subjects:

  • Registered Customers (including representatives of corporate Customers);
  • Unregistered visitors of the website and mobile applications;
  • Persons who contact us through contact forms, email or telephone;
  • End Users whose data are uploaded into the Services by a Customer (in this case, Golova acts as processor and the Customer is the controller — see section 12);
  • Candidates on Golova.work and persons who post or consult equipment on Golova.market and Golova.wiki.

3.2. Categories of personal data we process from Customers and individual users:

  • Identification data: name, surname, company name, position.
  • Contact data: email address, telephone, postal address.
  • Account data: username, password (stored as hash), account preferences, language, account type (business / individual).
  • Billing data: billing address, tax identification number, invoices issued. Payment card data are processed directly by our payment provider (Stripe) and are not received by Golova.
  • Usage and technical data: IP address, browser type and version, operating system, device identifiers, language, time zone, pages visited, features used, activity logs, error logs, session identifiers.
  • Content data: any data the Customer uploads into the platform — inventory items, projects, quotations, documents, internal notes, messages. Where such data include personal data of End Users, see section 12.
  • Marketing data: marketing consent status, unsubscribe records, response data to previous communications (opens, clicks).
  • AI feature data: rider documents uploaded for AI recognition, recognition output and feedback on recognition quality (see section 11).

3.3. We do not knowingly process special categories of personal data (Article 9 GDPR — racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, data concerning sex life or sexual orientation). Where Customers upload such data (for example, dietary or accessibility requirements in artist riders), Golova will process them solely as processor following the Customer’s documented instructions (section 12), and the Customer remains responsible for ensuring the applicable legal basis under Article 9 GDPR.

3.4. We do not knowingly collect personal data from persons under 14 years of age (Article 7 LOPDGDD). The Services are intended for business use and not directed at minors. Where a stricter age threshold applies in the data subject’s country of residence, that threshold prevails for the data subject concerned.

4. Purposes and legal bases of processing

4.1. We process personal data solely for the purposes set out in this section and on the basis of one or more of the legal bases in Article 6(1) GDPR.

4.2. Performance of the contract (Art. 6(1)(b) GDPR)

Creation and management of your account, provision of access to the platform, processing of your subscriptions, technical support, exchange of service-related communications, issuance of invoices and, in general, performance of the User Agreement concluded with you.

4.3. Compliance with legal obligations (Art. 6(1)(c) GDPR)

Compliance with Spanish tax and accounting legislation (in particular Law 58/2003 General Tax Law and Article 30 of the Spanish Commercial Code), response to legitimate requests from public authorities, and retention of the records required by applicable legislation on anti-money-laundering prevention and consumer protection.

4.4. Legitimate interests of the Controller (Art. 6(1)(f) GDPR)

Subject to a balancing test in your favour, we process certain data on the basis of our legitimate interests. You have the right to object to this processing at any time (section 9).

  • Service security and abuse prevention: log monitoring, detection of fraud, abuse and unauthorised access, protection of the platform against attacks.
  • Service improvement: aggregate usage analytics to improve features and stability.
  • Direct marketing to existing business customers: limited communications about features and similar Services to existing customers (Article 21(2) LSSI-CE). Each message includes an easy unsubscribe option.
  • Defence of claims: processing of data necessary to bring, exercise or defend claims arising from the Services.

4.5. Consent (Art. 6(1)(a) GDPR)

Where required by law and where no other legal basis applies, we process personal data on the basis of your prior, free, specific, informed and unambiguous consent. This applies in particular to:

  • Non-essential cookies and similar tracking technologies (Article 22(2) LSSI-CE, transposing Article 5(3) of Directive 2002/58/EC) — see our Cookie Policy;
  • Marketing communications addressed to individuals and all communications by SMS or push notification;
  • Processing of data uploaded into the AI rider recognition function where special categories of data may be involved (Article 9(2)(a) GDPR).

You can withdraw your consent at any time, without affecting the lawfulness of processing carried out beforehand. The procedure for withdrawing consent is set out in section 9.

4.6. Summary table of purposes

  • Account creation and authentication — legal basis: contract; data: identification, contact, account; retention: account lifetime + 6 years.
  • Subscription management and payments — legal basis: contract + legal obligation; data: identification, contact, billing; retention: 6 years from year-end (Article 30 of the Spanish Commercial Code).
  • Customer service — legal basis: contract; data: contact, content of request; retention: 3 years from case closure.
  • Service security and logs — legal basis: legitimate interest; data: technical and usage, IP address; retention: 12 months.
  • Direct marketing to existing customers — legal basis: legitimate interest (Article 21(2) LSSI-CE); retention: until objection or 3 years of inactivity.
  • Marketing communications to other recipients — legal basis: consent; retention: until withdrawal of consent.
  • Analytics and product improvement — legal basis: consent (for non-essential analytics cookies); retention: as set out in the Cookie Policy.
  • Tax and accounting compliance — legal basis: legal obligation; retention: 6 years (Spanish Commercial Code).
  • AI rider recognition — legal basis: performance of contract (Customer input) + consent if special categories of data are involved; retention: project lifetime + 12 months.
5. How we collect personal data

5.1. Directly from you: when you register, fill in a form, contact us, subscribe to communications, make a payment, upload data into the platform or otherwise interact with the Services.

5.2. Automatically: through cookies, server logs, analytics tools and diagnostic systems of the mobile applications — as set out in our Cookie Policy.

5.3. From third parties: from our Customers, who may upload your data into the Services as controllers (see section 12); from payment providers, in relation to the outcome of a transaction; from public registers, in limited cases, to verify a Customer’s corporate or tax data.

6. Recipients of personal data and processors

6.1. We do not sell, rent or trade personal data. We disclose personal data only to the categories of recipients indicated below, to the extent necessary for the purposes of this Policy and with appropriate safeguards.

6.2. Service providers acting as our processors under written contracts compliant with Article 28 GDPR. The updated list of processors is published at https://golova.ai/en/subprocessors and includes the following categories:

  • Hosting and cloud infrastructure: Hetzner Online GmbH, data centres in Helsinki, Finland (EU); Cloudflare Inc. (CDN, DDoS protection, traffic routing).
  • Payment processing: Stripe Payments Europe Ltd (Ireland) and its US subsidiaries where required by card networks.
  • Email and transactional messaging: Brevo (Sendinblue, France — EU).
  • Customer support tools: Crisp (France — EU).
  • Analytics: Plausible (France — EU, cookieless).
  • Error monitoring: Functional Software Inc. (Sentry) — EU region (Frankfurt).
  • Push notifications: Apple Push Notification Service (Apple Inc., USA) for iOS; Firebase Cloud Messaging (Google LLC, USA) for Android.

6.3. We will notify Customers of any changes to the list of processors at least 30 days before they take effect, by publishing the updated list at the URL above and, when the change is material, by email.

6.4. Independent controllers — we may share personal data, in their own capacity as controllers, with: (i) our professional advisers (lawyers, accountants, auditors) subject to duties of confidentiality; (ii) public authorities, when required by law (tax, judicial, law enforcement authorities); (iii) acquirers or investors in the context of a corporate transaction (merger, acquisition, financing), with appropriate confidentiality safeguards.

6.5. We do not share personal data with non-essential commercial partners without your prior consent.

7. International transfers

7.1. We host the Services in data centres located within the European Economic Area (EEA), primarily in the Republic of Finland and the Federal Republic of Germany. Personal data of EU/EEA users are stored within the EEA by default.

7.2. Some of our processors are established or operate servers outside the EEA, in particular in the United States. International transfers of personal data may occur in the context of the Services for:

  • Payment processing (Stripe — Ireland with US subsidiaries);
  • Push notification services (Apple, Google — United States);
  • Cloudflare global network (data may transit through points of presence in the US);
  • Error monitoring when the provider operates from outside the EEA.

7.3. For each of these transfers, we rely on one or more of the following safeguards under Chapter V of the GDPR:

  • Adequacy decision of the European Commission (Article 45 GDPR), where available — in particular the EU-US Data Privacy Framework for certified US recipients and the adequacy decision for the United Kingdom.
  • Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Decision 2021/914 (Article 46(2)(c) GDPR), supplemented by a Transfer Impact Assessment (TIA) and, where appropriate, additional technical and organisational measures (encryption in transit and at rest, pseudonymisation).
  • Derogations under Article 49 GDPR in limited cases (your explicit consent, performance of contract), only when no other safeguard applies.

7.4. You may request a copy of the safeguards applied to a specific transfer by writing to privacy@golova.ai. We may redact commercially sensitive information from the documents provided.

7.5. We do not transfer personal data to the Russian Federation or to any other third country for which no applicable adequacy decision exists and for which we have not implemented adequate safeguards. The Russian-language version of the platform operated on golova.io is a separate service, operated by a distinct legal entity, with no shared data infrastructure with golova.ai.

8. Retention periods

8.1. We retain personal data only for as long as necessary for the purposes for which they were collected, taking into account legal retention obligations, limitation periods for claims and the legitimate expectations of data subjects.

8.2. Specific retention periods by category of data:

  • Account data (active accounts): retained for the lifetime of the account.
  • Account data after deletion: removed from active systems within 30 days of account closure. Backups are purged according to the standard rotation cycle, within a maximum of 90 days.
  • Billing and accounting records: 6 years from year-end (Article 30 of the Spanish Commercial Code).
  • Customer contracts and correspondence: 5 years from the end of the contractual relationship.
  • Customer service records: 3 years from case closure.
  • Access and security logs: 12 months from generation.
  • Marketing data: until objection, withdrawal of consent or 3 years of inactivity (whichever comes first).
  • Cookie and analytics data: as set out in the Cookie Policy.
  • Consent records and withdrawal records: for the duration of the processing based on such consent and 3 years thereafter, to demonstrate compliance with Article 7(1) GDPR.
  • AI rider recognition inputs and outputs: for the lifetime of the project and 12 months thereafter, unless deleted earlier by the Customer.

8.3. On expiry of the applicable retention period, we delete or anonymise the data so they can no longer be associated with you.

9. Your rights as a data subject

9.1. Subject to the conditions and limits set out in Articles 15 to 22 GDPR, you have the right to:

  • Access (Article 15) — to confirm whether we process your data, obtain a copy and information about the processing.
  • Rectification (Article 16) — to correct inaccurate or incomplete data.
  • Erasure (Article 17) — “right to be forgotten”, subject to the exceptions in Article 17(3).
  • Restriction of processing (Article 18).
  • Data portability (Article 20) — to receive your data in a structured, commonly used and machine-readable format.
  • Object (Article 21) — including the unconditional right to object to direct marketing.
  • Not to be subject to a decision based solely on automated processing (Article 22) where it produces legal effects or significantly affects you. Currently, Golova does not make such decisions in respect of data subjects.
  • Withdraw your consent at any time (Article 7(3) GDPR), without affecting the lawfulness of processing carried out beforehand.
  • Lodge a complaint with a supervisory authority. Since Golova is established in Spain, the lead supervisory authority is the Spanish Data Protection Agency (AEPD, www.aepd.es). Under the one-stop-shop mechanism (Article 56 GDPR), you may also lodge a complaint with the supervisory authority of your habitual residence in the EU/EEA, which will cooperate with the AEPD.

9.2. How to exercise your rights:

  • Send your request to privacy@golova.ai, with the subject “GDPR Rights Request”;
  • Specify the right you wish to exercise and provide sufficient information to identify yourself (we may request additional information in case of reasonable doubt about your identity);
  • When acting on behalf of another data subject (minor, person under guardianship), provide proof of representation.

9.3. We will handle your request as soon as possible and, in any event, within one month of receipt (Article 12(3) GDPR). Where the request is complex or numerous, we may extend this period by a further two months, informing you of the extension and its reasons. The exercise of your rights is free of charge, except where the request is manifestly unfounded or excessive (Article 12(5) GDPR).

9.4. Many rights can be exercised directly from your Golova account (download your data, delete your account, manage marketing preferences, manage cookies). We recommend using these self-service options where available.

10. Security of personal data

10.1. We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Article 32 GDPR), including:

  • Encryption of data in transit (TLS 1.2 or higher) and at rest;
  • Role-based access control following the principle of least privilege;
  • Strong password policy and multi-factor authentication available for accounts;
  • Regular backups stored separately from the production environment;
  • Network segmentation, firewalls and intrusion detection;
  • Logging of access to systems containing personal data;
  • Vendor management and security review of processors;
  • Periodic security assessments and vulnerability management;
  • Confidentiality commitments for all personnel;
  • Incident response procedures and personal data breach register.

10.2. In the event of a personal data breach that may involve a risk to the rights and freedoms of natural persons, we will notify the breach to the AEPD without undue delay and, where feasible, within 72 hours of becoming aware of it (Article 33 GDPR). Where the breach involves a high risk, we will notify the affected data subjects without undue delay (Article 34 GDPR).

11. Automated decisions and AI features

11.1. Golova uses artificial intelligence (“AI”) features to help Customers operate the Services more efficiently. In particular, the platform offers an AI rider recognition function that processes uploaded rider documents and suggests matching equipment from the Customer’s inventory.

11.2. These AI features do not produce decisions that have legal effect or significantly affect data subjects within the meaning of Article 22 GDPR. The output is a proposal for the Customer, who manually reviews and confirms it.

11.3. Pursuant to Regulation (EU) 2024/1689 (AI Act), we classify our AI features as “limited-risk” AI systems. We inform users that they are interacting with an AI system; where AI generates or substantially modifies content, this circumstance is indicated.

11.4. We do not use personal data of EU data subjects to train general-purpose AI models of third parties without an appropriate legal basis. Where Golova trains AI models to improve specific Service features, this is done on anonymised or aggregated data, or following the Customer’s instructions as controller.

12. Processing of End User data on behalf of Customers

12.1. Where a Customer uploads personal data of their own customers, personnel, suppliers or other third parties (the “End Users”) into the Services, Golova acts as processor and the Customer is the controller of those data within the meaning of Article 4(7) GDPR.

12.2. The conditions of this processing are governed by a Data Processing Agreement (DPA) that forms part of the Customer’s contract with Golova and is available at https://golova.ai/en/dpa.

12.3. End Users who wish to exercise their rights or raise concerns about data uploaded by a Customer should direct their requests to the Customer in the first instance. When Golova directly receives such a request, it will forward it to the relevant Customer without undue delay and assist the Customer in responding as required by the DPA.

13. Privacy of minors

13.1. The Services are not directed at minors. We do not knowingly collect personal data from persons under 14 years of age without parental consent (Article 7 LOPDGDD). If you become aware that a minor has provided personal data to us without consent, please contact us at privacy@golova.ai and we will take the necessary steps to delete the data and close the account. Where a stricter age threshold applies in the data subject’s country of residence (for example, 15 in France, 16 in Germany), that threshold prevails for the data subject concerned.

14. Updates to this Policy

14.1. We may update this Policy periodically to reflect changes in our Services, legal requirements or industry practice.

14.2. Where the changes are material — that is, where they affect the categories of data processed, the purposes of processing, the legal bases, the recipients of the data, the retention periods, the international transfers or the rights of data subjects — we will notify registered Customers by email or by a prominent notice within the Services, at least 30 days before they take effect.

14.3. Non-material changes (clarifications, typographical corrections, updates to processor contact details) take effect upon publication. The current version, with the date of the last update, is always available at https://golova.ai/en/privacy-policy.

15. Final provisions

15.1. This Policy is published in English as the master version. Translations into Spanish, Catalan, German, French and Brazilian Portuguese are provided for the convenience of users of those languages. For business Customers, in the event of any discrepancy between language versions, the English version prevails. For Consumers, the language version in which the Customer concluded the contract is binding.

15.2. If any provision of this Policy is deemed invalid or unenforceable, the remaining provisions shall continue in full force and effect.

15.3. Enquiries, requests and complaints concerning this Policy may be addressed to privacy@golova.ai.

— End of Privacy Policy —