Privacy policy
Version 1.7, in force from 9 October 2026
This translation is provided for your convenience. Only the Spanish version is legally binding. Read the Spanish version
This policy explains which personal data Trimestria processes, why, on which legal basis, for how long and how you exercise your rights, under Regulation (EU) 2016/679 (GDPR, RGPD in Spanish) and Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
1. Who the controller is
The controller of your data is the provider of the service:
- Provider: Lebediev Tymofii
- NIF: Z0361888B
- Address: Calle Valparaíso 7, 6º B, 33008 Oviedo, Asturias
- Email: legal@trimestria.es
We have not appointed a data protection officer. Any question about your data is handled at the email address above.
2. What it covers
This policy covers the Trimestria application, at app.trimestria.es, its website, trimestria.es, which sets no cookies, and the data of the accounts created in it. Trimestria is software for a self-employed person (autónomo) in Spain to keep their books and prepare their tax returns.
3. Which data we process
We process only the data needed to provide the service:
- Account data: the nickname, the email address, the name you give us and the date you signed up. We do not keep your password, only a digest of it from which it cannot be recovered.
- Sign-in data: the secret of the second factor, if you turn it on, stored encrypted; of your passkeys, only the public part; and the open sessions, with the date each began and was last used.
- If you sign in with Google: the identifier of your Google account and the verified email address Google gives us. We do not receive your Google password or any other data of your Google account. Section 4 explains it.
- The account photo, if you choose to add one: your browser cuts out a small circle and only that reaches the server, without the metadata of the file. Only you see it.
- Data of your activity: the tax details of your business (name, NIF, region, VAT regime, IRPF method, IAE heading and start date), the income and expense entries, the invoices, your clients and suppliers, the bank statements you import, the documents you upload and the returns prepared from all of it.
- Help requests: the text you write to us, the reply address, the language and the context of the screen you write from (the screen, the period and the modelo), never the amounts or the content of your documents.
- The emails we send you: of each one we keep the address it went to, the subject, when it was sent and whether it was delivered, came back or was reported as unwanted; of the notices about your returns we also keep their text, as evidence of what we told you. If you open a return from the link in its email while signed in, we note that you have seen it; the emails carry no images and nothing that tells us whether you open them. From those answers your account keeps whether your address receives our emails.
- Security data: to stop improper sign-in attempts we count failures by IP address, and of the address we keep only a keyed digest from which it cannot be read. At the third failed attempt to sign in to your account with a password we email you the IP address the attempt came from: we use it to write that email and delete it from our records as soon as the email has been sent or cannot be sent. We also record the actions on your account and your business (who did what and when), without keeping the values or the IP address.
- Your preferences: language, theme and interface mode.
When you record data about other people, such as your clients or suppliers, you are the one who decides to process it. We process it on your behalf, as a processor, under the conditions of section 6 of the Terms of service.
4. Google user data
Signing in with Google is optional. When you choose it, Trimestria asks Google only for the openid and email permissions, the basic ones for signing in, and receives from Google:
- the identifier of your Google account, which tells us it is the same Google account each time;
- the email address of your Google account and whether Google has verified it; we accept only a verified address.
We do not ask Google for your name, your photo, your contacts, your emails, your files, your calendar or any other data of your Google account, and we never receive your Google password. Google’s answer is read once, at sign-in: we keep no Google access or refresh token, so Trimestria cannot reach your Google account afterwards.
We use this data only to create your account, to sign you in and to bind or unbind your Google account. If you create your account with Google, the verified address also becomes the email address of your account.
The identifier and the address are kept with your account while your Google account stays bound to it, together with the date it was bound and the date it was last used. Unbinding it deletes them at once, whether in Settings, Security, which is possible when the account has another way in, or through the link "This was not me" in the email that tells you it was bound. They are also deleted when your account is closed. A sign-up with Google that is not finished expires after fifteen minutes and is deleted afterwards.
We do not sell this data or transfer it to anyone, except to IONOS, which stores it for us as the hosting provider, to Amazon Simple Email Service, which delivers the service’s emails to that address if you created your account with Google, both of them providers that take part in the service (section 6), and to authorities when a law obliges us. We do not use it for advertising, or to develop, improve or train artificial intelligence or machine learning models. Nobody reads it, except to help you when you ask, to keep the service secure, or when the law requires it.
Trimestria’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
5. Why we process it and on which legal basis
- To provide the service: create and keep your account, keep your books, calculate and prepare your returns and store your documents. Legal basis: the performance of the contract you accept when you sign up (article 6.1.b GDPR).
- To protect the service and your account: detect improper sign-in attempts, check that a new password is not on public lists of breached passwords (the check runs on our own server) and record the actions on the account. Legal basis: our legitimate interest in the security of the service (article 6.1.f GDPR).
- To answer your help requests and the exercise of your rights. Legal basis: the performance of the contract and compliance with legal obligations (article 6.1.b and 6.1.c GDPR).
- To keep what the law requires to be kept and to be able to prove what we did if a claim arises. Legal basis: compliance with legal obligations and our legitimate interest (article 6.1.c and 6.1.f GDPR).
- To send you the emails of the service itself: those that confirm your address, open or close your account or help you recover access; security notices about your account, such as a lock or several attempts to sign in with a wrong password; the replies to your help requests; and the notices about your returns, with the modelo, the period and the amount. Legal basis: the performance of the contract. We send no advertising.
We do not sell your data, show advertising or build commercial profiles. We take no automated decisions with legal effects on you: the application calculates from what you record, but reviewing and filing a return is your decision. Today we use no artificial intelligence to process your data; if that changes, we will say so here first.
6. Who else processes your data
We disclose your data to no third party unless the law requires it. These take part in providing the service:
- IONOS, the hosting provider: the application, the database, the documents and the backups are on a server of theirs in their data centre in Logroño (Spain). It acts as a processor.
- Google, only if you choose to sign in with Google: Google identifies you and gives us back the identifier and the email address. In that step Google processes your data as a controller, under its own privacy policy, and may do so outside the European Economic Area.
- Amazon Simple Email Service, from Amazon Web Services, in its Ireland region, inside the European Union: it delivers the service’s emails. It receives the address and the content of each email, and tells us whether it was delivered, came back or was reported as unwanted; it does not track whether you open an email or which links you follow. It acts as a processor.
- The Spanish Tax Agency (Agencia Estatal de Administración Tributaria): today the application files nothing with the AEAT; you file your returns yourself. If we later offer filing from the application, data will be sent only when you instruct it.
- Authorities, judges and courts, when a law obliges us to disclose data to them.
Your data is stored and processed in Spain, and the emails we send you are processed in Ireland; all of it within the European Union, apart from what is said about Google.
7. How long we keep it
- Account data, until the account is closed; the nickname is kept, as explained below.
- The books of your activity, six years from the last entry, as article 30 of the Spanish Commercial Code (Código de Comercio) requires.
- The documents and data that support a return filed through the application or that you confirmed for filing, four years from the end of the period to file it, which is the limitation period of article 66 of the General Tax Law (Ley General Tributaria), or longer if that period is interrupted.
- Whatever is under a legal hold, until the hold is lifted.
- The papers of an investment good, for its regularisation period (article 107 of the VAT Law, Ley del IVA) and four years more; that day depends on the kind of good and the year it was first used, so we work it out if you ask us.
- The record of actions, for as long as what it proves is kept and, after that, for as long as a claim about it can be brought.
- The record of the emails, until the account is closed; that of the notices about your returns, with their text, like the record of actions, because it proves what we told you.
- The photo, until you remove it or the account is closed. Removing it deletes it; it remains only in the copies of the database, for up to fifteen days.
- A session open in a browser lasts at most 30 days.
- Help requests, for as long as needed to answer them and settle any matter that arises from them.
- Every night we make a copy of the database, and what is deleted from the database remains in those copies for up to fifteen days. The files of documents are copied every night to another disk of the same server, and what is deleted from the storage remains in that copy for up to fourteen days. When you remove a document on which no entry of your books and no return rests, its file and what we read from it are erased at that moment, and the record of actions keeps that you removed it and that it was erased. A document on which your books or a return rest is kept for its legal period and cannot be removed.
You can close your account in Settings, Your account, confirming it with the code of your authenticator app. Asking signs out every session, but deletes nothing: for thirty days you can sign in again to take your data or to keep the account. After that, our team closes the account following a list of steps and sends you an email saying what was deleted and what is kept of each business, and until which day.
When the account is closed we delete its ways in, its sessions, its link to Google, its photo, its preferences, its help requests, the record of the emails we sent to it and the record of what you did in it outside your businesses, and we take your email address and your name off it. Of each business no law obliges us to keep we delete everything, every record and every file; all that remains of it is our note that it was erased, with how many records and files.
Of a business the law obliges us to keep we erase the files of the documents on which nothing rests, and the rest is blocked for the periods above, as article 32 of the LOPDGDD provides: it is used only to meet legal obligations or deal with claims, and it is deleted when its period ends. We also keep, as evidence, your request to close and the record of what our team did on your account, and your nickname, bound to the emptied account, so that it is never given to someone else.
8. Your rights
At any time you can ask us for:
- Access: to know which of your data we process. In Settings, Your data shows what we hold about you and about your business.
- Rectification: to correct inaccurate data. You can correct most of it yourself in the application.
- Erasure: to delete your data, within the limits of the section above.
- Restriction: to stop using your data while a claim about it is being resolved.
- Portability: to receive your data in a structured format. In Settings, Your data you can download a file with the data of your business, in CSV and JSON tables, together with your original documents.
- Objection: to stop processing your data based on our legitimate interest, unless there are compelling legitimate grounds or we need it for a claim.
Write to us at legal@trimestria.es from the address of your account, or from Help inside the application. We will answer within one month, which may be extended by two further months if the request is complex, as article 12 GDPR provides. Exercising your rights is free.
If you are not satisfied with our answer, you can lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es, calle Jorge Juan 6, 28001 Madrid).
9. How we protect your data
The connection is encrypted. Passwords are stored with a slow hashing algorithm, and those found in known breaches are refused. You can protect your account with a second factor or with passkeys. Each account can read only its own data, and every access of the support team to an account is recorded, with its reason, in Settings, Who reached your account.
10. Cookies and storage in your browser
We use only what is strictly necessary for the application to work, so we do not need your consent (article 22.2 of Law 34/2002, LSSI):
- The session cookie, __Host-trimestria_session, which keeps you signed in. It lasts at most 30 days.
- The cookie __Host-trimestria_google, only while you sign in with Google. It lasts a few minutes.
- In the storage of your browser we keep your preferences (language, theme, mode and side panel), your recent searches, whether this device holds a passkey or you signed in with a password, to suggest the way in, and whether you have already closed a notice. All of this stays in your browser.
- On the calculator, your browser keeps the region you choose and the order of the cards if you change it, until you clear them, and a mark for the session if the page has to reload after an update.
The website trimestria.es counts its visits on our own server, from what your browser already sends to load a page: the address of the page, the page you came from if your browser says it, and the kind of browser and system. The IP address is cut before it is written down (its last part is deleted), and only the country is worked out from it. We use no cookies and no scripts for this and store nothing on your device. On the calculator we count that the page was opened; what you type stays in your browser, in a shared link too, because the browser does not send the part of the address after #. The lines are deleted after 7 days and the daily counts are kept for 13 months, on our server in the European Union; nobody else receives them. We do this on our legitimate interest in knowing which pages help and where people come from (article 6.1(f) GDPR). You can object by writing to us; since the IP address is cut before it is written down, we cannot tell your visits apart from other people's (article 11 GDPR).
We use no analytics or advertising cookies.
11. Minors
The service is meant for adults who carry on an economic activity and is not directed at anyone under 18.
12. Changes to this policy
If we change this policy, we will publish the new version here with its date. If the change is significant, when you enter the application you will see a notice of what changed, with a link to the new version.