Privacy policy
Version of 29 September 2026
This page is a translation. The Spanish original at holacasilla.com/privacidad/ is the binding text; if the two differ, the Spanish text prevails.
This policy explains which personal data Casilla processes, why, who it is shared with, how long it is kept and what you can do about it. It covers the site holacasilla.com and the application app.holacasilla.com. It is written to be understood: if something is unclear, write to us and we will fix it.
Who is responsible
The data controller is Indieline, S.L.; for anything about your data: acceso@holacasilla.com.
What we process, and where it comes from
Three groups, and all three come from you or from your use of the application:
- Your Google account data, when you sign in with it: the account identifier, your email address and your name. The details are in the next section.
- Data you enter in the application to run your activity: your tax identification (name, NIF, tax address, IBAN), your invoices and your suppliers', your clients and counterparties, the bank statement movements you upload, the documents you attach and the returns you record as filed. Part of this is third-party data — your clients and suppliers — and you are responsible for holding it lawfully.
- Technical data generated by using the service: the IP address and time of each request in the server logs, a technical request identifier, and the cookies described below.
We do not process special categories of data (art. 9 GDPR). We do not profile you, we make no automated decisions with legal effects on you (art. 22 GDPR), and we buy no data from anyone to complete yours.
Your Google account data
Casilla uses Sign in with Google only to know who you are. When you sign in, Google sends us your account identifier, your email address, your name and the address of your profile picture (the openid, email and profile scopes). We store the identifier, the email and the name; the picture is not stored.
- We use them to authenticate you, to know which books you have access to and to show your name inside the application. We may write to that address to manage your access — an invitation, a notice about your account or about changes to this policy. We send no newsletters and no advertising.
- We do not request access to your Gmail, Drive, contacts or calendar, and we will not use such permissions in the future without publishing a new version of this policy and asking you explicitly.
- We do not sell, rent or transfer your Google account data to anyone, we do not use it for advertising and we do not pass it to third parties for advertising purposes.
- You can withdraw the permission at any time at myaccount.google.com/permissions. Once withdrawn you cannot sign in until you grant it again; your books are not deleted by that, and you can ask us to erase them as explained under "Your rights".
Why we process it, and on what legal basis
| Providing the service: keeping your ledger, computing modelos 130, 303 and 349 from it and showing where each figure comes from | Performance of the contract you accept by using the beta (art. 6.1.b GDPR) |
|---|---|
| Identifying you and controlling who accesses which books | Performance of the contract (art. 6.1.b) and legitimate interest in the security of the service (art. 6.1.f) |
| Keeping invoices, movements and documents for the periods the law sets | Legal obligation (art. 6.1.c GDPR; art. 30 of the Código de Comercio; art. 29 of Ley 58/2003, General Tributaria) |
| Technical logs: detecting abuse, diagnosing errors, keeping backups | Legitimate interest in the security and integrity of the service (art. 6.1.f GDPR) |
| Answering what you write to us | Legitimate interest in attending to you (art. 6.1.f GDPR) |
Casilla does not file returns with the Agencia Tributaria and does not access the Sede Electrónica on your behalf: it prepares the figures and their breakdown, and you file. That is why we process neither your electronic certificates nor your AEAT credentials.
Who we share it with
With nobody who uses it for their own purposes. Only with the processors that make the service possible, each under a contract compliant with art. 28 GDPR:
| Amazon Web Services EMEA SARL (Luxembourg) | Hosting of the application and your data, backups and transactional email. Region eu-central-1 (Frankfurt, Germany). |
|---|---|
| Google Ireland Limited (Ireland) | Identity provider when you choose to sign in with Google. Google processes that sign-in under its own privacy policy. |
Your data is hosted in the European Union and is not transferred outside the European Economic Area. We would hand it to an authority only where a law obliges us to, and we would tell you unless the law forbids it.
How long we keep it
| Invoices, bank movements, documents, recorded returns | Six years from the last entry of the financial year (art. 30 of the Código de Comercio) and, in any case, while the Administration may audit that year (art. 66 Ley General Tributaria, four years) |
|---|---|
| Your account data (identifier, email, name) and your tax identification | While you have access to the service, and thirty days after you leave |
| Technical server logs (IP, time, request identifier) | Ninety days |
| Backups | Fourteen days in rotation; they contain the data above and are deleted with the rotation |
When you ask for erasure, the data the law obliges us to keep is blocked: it is no longer used for any purpose other than answering the Administration or the courts, and it is deleted when the period ends.
Cookies
This site, holacasilla.com, uses no cookies. The application uses only technical cookies, necessary for it to work and exempt from consent (art. 22.2 of Ley 34/2002, LSSI):
| casilla_session | Your signed session. Thirty days; eight hours for administration. |
|---|---|
| casilla_nif | The book you have chosen when you have access to several. Lasts the session. |
| casilla_locale | The interface language. Kept until you change it. |
| casilla_oidc | Protection of the Google sign-in against forgery. Ten minutes. |
There are no analytics, advertising or third-party cookies.
Your rights
You can ask us for access to your data, rectify it, erase it, restrict its processing, object to it and receive it in a structured format to take it elsewhere (arts. 15 to 21 GDPR). From the application itself you can download the full content of your ledger. For the rest, write to acceso@holacasilla.com from the email you sign in with, or attaching a document that identifies you. We answer within one month (art. 12.3 GDPR).
If you believe we have not honoured your rights, you can complain to the Spanish data protection authority, the Agencia Española de Protección de Datos, www.aepd.es.
How we protect it
- All communication is encrypted (TLS); the application does not answer unencrypted.
- Data and backups live in the European Union, in encrypted storage, and every backup is verified before it counts.
- Nobody accesses the server with shared keys or passwords: operational access goes through an authenticated, logged channel.
- Each ledger is isolated from the others: the application only shows you the books you were given access to, and no address, cookie or parameter can widen that list.
- If a breach affecting your data occurred, we would inform you without delay and notify the AEPD within seventy-two hours (arts. 33 and 34 GDPR).
Minors
The service is aimed at self-employed professionals and companies and is not intended for people under eighteen. We do not knowingly process minors' data.
Changes to this policy
When something that affects you changes, we will publish the new version here with its date and notify you at your account email before it takes effect. Previous versions are kept and can be requested.