Privacy Policy
Last updated October 1, 2026
Who is responsible
ArquiFlow operates https://arquiflow.es and is the controller of the personal data described on this page. Write to us about anything here at architectureminutes@gmail.com.
This policy is written under Regulation (EU) 2016/679 (the GDPR) and Spanish Organic Law 3/2018 on data protection and the guarantee of digital rights.
There are two relationships here and this policy only covers the first. For the data that makes you an account holder — your name, your sign-in, your studio membership, your subscription — ArquiFlow decides what happens to it and answers for it. For what a studio uploads about its own clients, sites and the people at a site visit — recordings, photographs, plans, documents — the studio decides, and ArquiFlow acts on its instructions. That second relationship is governed by the data processing agreement between the studio and ArquiFlow, not by this page.
What we hold, why, and on what legal basis
Every category the service holds, what we do with it, and the Article 6 basis that permits it.
| Data | What it covers | Why we hold it | Legal basis |
|---|---|---|---|
| Account | Your name, email address, a hash of your password, your interface language and — if you sign in with Google — the identity Google returns. | To create your account, sign you in and keep you signed in. | Contract, Art. 6(1)(b). |
| Studio | The studio name, its seats, each member’s role, and invitations sent, accepted or revoked. | To run the shared workspace and decide who may do what inside it. | Contract, Art. 6(1)(b). |
| Meeting audio | Recordings a studio uploads from a site visit or a meeting, and the transcript produced from them. | To transcribe the recording and draft the acta from it. | Contract, Art. 6(1)(b), on the studio’s instructions. |
| Photographs | Site photographs a studio uploads, and the descriptions written from them. | To describe each photograph and place it in the acta. | Contract, Art. 6(1)(b), on the studio’s instructions. |
| Report content | Drafted and issued actas, plans, technical documents, supplier quotes and the text extracted from them. | To produce the acta and the PDF the studio issues to the parties. | Contract, Art. 6(1)(b), on the studio’s instructions. |
| Cadastral lookups | Addresses a studio types when it looks up the cadastral reference of a site. | To query the Spanish Cadastre and return the reference for that address. | Contract, Art. 6(1)(b), on the studio’s instructions. |
| Billing | Your name, email address, billing address, the state of your subscription and the invoices raised. Card details are typed into the payment provider’s own form and never reach our servers. | To sell you a subscription and to keep the accounting and tax records the law requires. | Contract, Art. 6(1)(b), and legal obligation, Art. 6(1)(c). |
| Public-site analytics | On the public pages only: the page path, a coarse location derived from your IP address, and your device and browser. | To see which public pages people read. | Consent, Art. 6(1)(a). Nothing is collected until you accept, and refusing costs you nothing. |
Analytics on the public site
The public site — this page, the home page, the pricing page — carries Google Analytics 4 and nothing else. It runs only once you have accepted analytics cookies, and it is taken off the page the moment you refuse or change your mind. The tag denies advertising storage outright, so no advertising or profiling cookie is set at all and there is no marketing category to consent to.
No analytics runs on the authenticated studio pages. The tag is removed from the page as soon as you enter the application, rather than being left loaded and quiet, because Google Analytics 4 attaches the page address to what it reports by itself — and inside the application that address carries customer, project and report identifiers. They never reach Google.
Your choice is stored in your own browser, and you can change it at any time from the cookie settings on this page. The cookie policy on this site lists every cookie the application can cause to exist.
The pricing page loads the payment provider’s script so it can show you the price in your own currency, which means the provider reads your IP address to work out which country you are in. We treat that as strictly necessary to the price display you asked for, so it is not gated behind consent. It is disclosed here and in the cookie policy rather than left unsaid.
Who else receives it
These are the providers the service runs on. Each one receives only what its row describes. The last column links to the provider’s own terms, because where a company processes data is a fact about that company and we will not assert it on its behalf.
| Recipient | What it receives | Where | Their terms |
|---|---|---|---|
| Groq | Meeting audio, for transcription. | US | Privacy policy |
| DeepSeek | The transcript and the report text; building-code questions, which routinely carry a street address; supplier-quote text; comparisons between quotes; and dictated incidents, with the studio’s supplier names, to fill in their fields — five tasks in all. | CN — China, for which the European Commission has adopted no adequacy decision. | Privacy policy |
| OpenAI (chat) | Only when DeepSeek is unavailable for a request: the same content as DeepSeek’s row, for the same five tasks. | US | Privacy policy |
| OpenAI (vision) | Site photographs, for description. | US | Privacy policy |
| OpenAI (embeddings) | In production only: passages of every issued acta and every uploaded regulation, and every question asked of them. | US | Privacy policy |
| Google (Analytics 4) | On public pages only, and only with your consent: the page path, a coarse location from your IP address, your device and your browser. Never on the authenticated studio pages. | IE / US | Privacy policy |
| Paddle (payments) | Your name, email address, billing address and payment data. Paddle is the merchant of record: it is who sells you the subscription and who charges you. | UK / US | Privacy policy |
| Paddle.js (in your browser) | Your IP address, so the pricing page can show a price in your own currency. | UK / US | Privacy policy |
| Google Identity | Your sign-in identity, and only if you choose to sign in with Google. | US | Privacy policy |
| Google (Gmail SMTP) | In production only: the recipient and the body of transactional email — studio invitations, address verification, password recovery. | US | Privacy policy |
| Hetzner Object Storage | In production only: every file uploaded or generated — audio, photographs, plans, documents and the issued PDFs. | DE — EU | Privacy policy |
| The server host | Everything. The database, every application process and the ingress access logs run on one single-node k3s server. | To be confirmed. | Named here, with its jurisdiction, before the service takes its first live payment. |
| Catastro (Spanish Cadastre) | Addresses a studio types when looking up a cadastral reference. | ES — EU | Electronic office |
The server host is the row a list like this most often leaves out and least can afford to: it is the infrastructure the whole product runs on, so every category above passes through it.
Transfers outside the European Economic Area
Some of the recipients above are outside the EEA. This is what each transfer rests on.
- The United States — Groq, OpenAI, Google and Paddle’s US operations. OpenAI also receives the content DeepSeek receives, for a request DeepSeek does not answer. The safeguard is the European Commission’s standard contractual clauses under Article 46(2)(c) GDPR, incorporated in each provider’s data processing terms; where a provider is certified under the EU–US Data Privacy Framework, that certification applies instead.
- China — DeepSeek, which receives transcripts, report text, building-code questions, supplier-quote text and dictated incidents. The European Commission has adopted no adequacy decision for China, so the transfer rests on standard contractual clauses under Article 46(2)(c) GDPR. We say plainly that what those clauses achieve in practice may be weaker than inside the EEA, and that the studio chooses what goes into a recording or a document in the first place.
Ask us at architectureminutes@gmail.com for the safeguard relied on for any single provider, and we will send you what we hold.
What the AI does, and what it does not decide
The transcription, the photograph descriptions and the first draft of an acta are produced by the providers listed above. What comes back is a draft. A person at the studio reads it, edits it and issues it, and the professional who signs the acta remains responsible for what it says.
Nothing in this service takes a decision about you by automated means that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR.
Our own record of an AI call holds a digest — which model, which task, timings, token counts and a hash — and not the transcript or the document text. That record exists so the service can be run and debugged, and it rests on our legitimate interest under Art. 6(1)(f).
What we do not claim: the material sent to those providers goes as the studio uploaded it. We do not strip personal data out of a recording, a photograph or a document before it is sent. If a recording should not leave the EEA, it should not be uploaded.
How long we keep it
We keep what a studio uploads and what the service produces from it for as long as the studio’s account is open, and afterwards until someone asks us in writing to remove it.
We are not going to put a number here, because the service does not enforce one. No scheduled job erases old material: closing an account marks it closed and leaves the studio’s reports, photographs, plans and files in place; a transcript outlives the audio it came from; audio from a failed generation and every version of an uploaded plan are kept deliberately, so a studio can retry. The one automatic expiry in the whole system is a one-hour cache of answers to building-code questions.
That is a description of the service as it is built rather than an intention. When automatic deletion exists, this section changes and the date at the top of the page changes with it.
Your rights, and how to use them
You have the right of access, rectification, erasure, restriction of processing, objection and portability, and the right to withdraw consent at any time — withdrawing it does not affect what was done while it was given.
Every one of them is handled by hand. Write to architectureminutes@gmail.com from the address on your account, say which right you are exercising, and we answer within one month of receiving the request, as Article 12(3) GDPR requires. We extend that by up to two further months only where the request is genuinely complex, and we tell you inside the first month if we do.
There is no button for this. The service has no self-service mechanism for access, erasure or portability, and we would rather say so than imply one exists: a written request to the address above is the only route, and it is a real one that a person answers.
If you are unhappy with how we handle it, you can complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos (AEPD), at www.aepd.es, or to the authority of the country you live in.
What happens if a studio removes you from its team
A studio administrator can remove a member. That does two things at once: it ends the membership, and it closes that person’s whole platform account — not only their access to that one studio.
It is written down here because it means an action by a studio administrator ends an account for which ArquiFlow is the controller. If it happens to you and you did not expect it, write to architectureminutes@gmail.com.
Changes to this policy
The date at the top of this page is the day it last changed. When something material changes — a new recipient, a new purpose, a different legal basis — we update this page, and where the change requires it we tell account holders by email before it takes effect.
Anything on this page, including a question you would rather ask before signing up, goes to architectureminutes@gmail.com.