Privacy policy
Last updated: 15 August 2026.
This policy describes what data misdatos.es processes, the purpose, how long we keep it, and how to exercise your rights. The service runs on European infrastructure by default and complies with the European General Data Protection Regulation (GDPR).
Data controller
misdatos.es is a product of Imani Soluciones, S.L. (Tax ID B-39826334), with registered office at 13600 Alcázar de San Juan (Ciudad Real), Spain, acting as data controller ("the Service"). For any privacy enquiry, write to misdatos.es@imani.es. You can find the full identifying details in the Legal notice.
What we process
We only process data you choose to connect:
- Account data: the email address used for magic-link sign-in and an optional display name.
- Synced mail and calendar data: when you connect Google (Gmail and Google Calendar), Microsoft (Outlook and its calendar) or Apple (iCloud Mail and its calendar), the Service reads, in read-only mode: from email messages, their metadata (subject, sender, recipients, date) and the body of recent messages to the extent needed to prepare briefings; from calendar events, their attendees, organizer, description, links and dates. The Service writes nothing back to those accounts: it does not send, move or delete any mail or event.
- Documents attached to your mail: on Google and Microsoft accounts, the Service downloads the files attached to the mail it syncs and extracts their text (PDF, Word, plain text) so they can be cited in your briefings. We do not access your Google Drive or your OneDrive.
- Google Meet meeting transcripts: if you grant the corresponding permission, the Service reads the automatic transcript of the meetings you organize, where such a transcript exists. Google only produces one if somebody turns it on during the call, tells the attendees at that moment that the meeting is being transcribed, and saves the file to the organizer's Drive; the Service reads it in read-only mode and does not access the rest of your Drive. A transcript holds the words each attendee spoke, along with their name, so it involves data about people who are not users of the Service: the legal basis is the legitimate interest in documenting what was discussed in a meeting among those who took part in it (Art. 6(1)(f) GDPR). The text is used to write briefings and minutes with citations, is never sent to the attendees when you share minutes (which cite the transcript by title, without its content), and is deleted when you disconnect the account. This permission is optional and separable: without it, the rest of the Service works exactly the same.
- Access credentials: Google and Microsoft OAuth tokens and, for Apple, the app-specific password you generate, are stored encrypted (AES-256-GCM) in our database. You can revoke them at any time from your provider or from the Service.
- Briefings, minutes and notes: texts produced by the Service's assistant from the data above, with mandatory citations to the original sources, plus any notes you write or paste when generating minutes.
- Data about the recipients of minutes: when you choose to send minutes, we process each recipient's email address, the timestamp of when they opened the link and, if they reply, their agreement or the text of the remarks they raise. The legal basis is the legitimate interest in documenting a meeting's agreements among its attendees (Art. 6(1)(f) GDPR). Of the reply link we store only its cryptographic hash, never the link itself.
- Activity log: actions performed in the Service (syncs, connections, briefing and minutes generations, emails sent) with timestamps, for auditability and support.
We do not process special categories of data within the meaning of Article 9 GDPR. We do not sell data to third parties, we do not profile you for advertising, and we do not train AI models on your data.
Purposes
- To deliver the Service: prepare briefings, list meetings, answer your questions about your own information and write the minutes of your meetings.
- To send transactional notifications: sign-in link, briefing email before each meeting, operational notices.
- To send the minutes you choose to share with your meeting's attendees, and to collect their agreement or remarks. The email always goes out from misdatos.es, never from your mailbox, and only when you expressly ask for it on a version you have reviewed. Your private notes never travel with it.
- Security and improvement: abuse detection, error debugging, aggregated metrics without personal identifiers.
Legal basis
Processing of your own data is based on your explicit consent, given when you create the account and when you authorise each external connector. You may withdraw consent at any time from the Service itself (see "Your rights").
Two processing activities involve people who are not users of the Service and therefore cannot consent to it: the recipients of minutes you send, and the attendees recorded in a meeting transcript. Both rest on legitimate interest under Art. 6(1)(f) GDPR, as set out in the entries above, and both are limited to what documenting that meeting requires.
Google user data
misdatos.es's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:
- We only use Gmail and Google Calendar data to provide the Service features you have enabled: preparing and showing your meeting briefings, answering your questions about them and writing their minutes.
- We do not transfer that data to third parties except the sub-processors strictly needed to run the Service (listed below), where required by law, or with your explicit consent.
- We do not use that data for advertising and we do not sell it.
- No human reads your Google data except with your explicit consent, for security purposes (e.g. investigating abuse), to comply with the law, or when the data is aggregated and anonymised.
Processors and sub-processors
To deliver the Service we rely on a small number of providers that act as processors under Article 28 GDPR, each limited to the function strictly needed:
- Hosting: the application and the database are hosted on infrastructure located in the European Union.
- Transactional email: a European provider delivers the Service's emails (sign-in link, briefings and the minutes you choose to send).
- Artificial intelligence: specialist providers draft the briefings and the minutes and power topic-based search, always under an agreement not to train their models on your contents.
We share with them only the data strictly needed for their function and under a data-processing agreement. You can ask us for the detailed, up-to-date list of processors at any time by writing to misdatos.es@imani.es.
Retention
Synced data is retained while the connection is active.
- Disconnecting an account stops syncing and revokes the grant at the provider, but keeps the already-synced information so you can still review it.
- Deleting an account's data (a separate action under "Connect accounts") immediately and permanently deletes every item synced through it and every derived briefing, including associated internal records.
- Sent minutes and their recipients' replies are retained while the meeting they belong to exists, and are deleted with it.
- The activity log is retained for up to 12 months for audit and support purposes.
Your rights
Under GDPR you have the right to access, rectify, delete, restrict processing, object, and to data portability. Some rights are exercised directly from the Service:
- Delete data: use "Delete data" under "Connect accounts" to immediately delete all data derived from that account.
- Account deletion: write to misdatos.es@imani.es and we will delete the account, all connectors, and all associated data within 30 days.
For any other right, contact misdatos.es@imani.es. You may also lodge a complaint with your national data protection authority.
International transfers
By default, data stays on European infrastructure. Some AI features (briefing drafting and topic-based search) involve transmitting content to providers located in the United States; these transfers rely on the European Commission's standard contractual clauses and on no-training agreements.
Changes to this policy
We will announce any material change at least 30 days in advance via the email address linked to the account. The "Last updated" date shows when it was last revised.