This policy explains what Draf IT holds about you and your business, why, and what we do not hold.
1. What we hold
- Your account: name, email address, the language you read in, and your role.
- Your business: its name, its tax identification, its address and contact details.
- Your shops: their names, where they are, their time zone, and which application each
one runs.
- Your devices: an identifier each installation reports, the machine name, the
operating system and the version of the software.
- Your subscription and billing: plans, terms, orders, invoices, payments and credit
balances.
- Your messages: support conversations, and the emails and notifications we send you.
- An audit trail of significant actions, which records who did what and when.
2. What we do not hold
We do not hold your trading data. Your products, your customers, your suppliers, your prices and your sales live in your shop's own database, on your own equipment.
When you ask for a live report, your shop builds a summary and sends it to us so your browser can be shown it. It is held in memory for a few minutes and then discarded. There is no table behind it and no copy is kept.
Where a backup is stored with us, it is encrypted on your equipment before it is sent, with a password we never receive. We hold bytes we cannot read.
3. Why we hold it
To provide the service you have bought: to issue licences, to run your subscription, to invoice you, to support you, and to keep a record of what was done for the periods the law requires.
4. Who else sees it
Only the providers we need in order to run the service, and only what they need:
- payment providers, to take a payment you have chosen to make;
- email, SMS and messaging providers, to deliver messages you have asked for;
- electronic invoicing providers, where your country requires one and you have configured
it;
- hosting and infrastructure providers, who hold the systems the service runs on.
We do not sell your data, and we do not share it for anybody else's marketing.
5. How long
Account, subscription and billing records are kept while you are a customer and afterwards for as long as tax and commercial law requires. The audit trail is kept for the same reason. Live reports are kept for minutes.
One period is set rather than derived, and the terms of service state it in full: a backup held with us survives ninety days past the day payment was due, and is then deleted.
The invoices we issue you are our own accounting records as well as yours, so they are kept for at least as long as the law requires of us and are downloadable throughout. Documents your own shop issues never reach us at all, so there is nothing here for us to keep or to delete.
6. Your rights
You may ask what we hold about you, ask for it to be corrected, and ask for it to be deleted where we are not required to keep it. Ask through the support area of the portal.
7. Security
Access is limited to the staff who need it. Sensitive values are encrypted. Actions that matter are recorded in the audit trail. No system is perfectly secure, and we do not claim otherwise.
8. Changes
The current version of this policy, and the date it took effect, are always published here.
9. Contact
Questions about this policy can be sent through the support area of the customer portal.
This policy is published in Spanish and in English. The Spanish version is the one that governs; the English is provided so that it can be read.