Skip to content
SolvTako SolvTako
Español

Privacy Policy

How SolvTako, as data controller, processes your personal data: what we collect, for which purposes and legal bases, for how long, and the rights available to you.

Version: 2026-09-01 · Effective date: 2026-09-01 · Last updated: 2026-09-01 · support@solvtako.com

1. Data controller and contact

The controller is SolvTako, S.L. (Sociedad de Responsabilidad Limitada), Spanish Tax ID (NIF) B88978887, with registered office at Avenida Ribados 14, Block B, Staircase 2, Door C, 15670 Culleredo, A Coruña, Spain. SolvTako, S.L. operates the SolvTako website and application, a marketplace that connects people and organisations seeking local services with independent providers offering them.

For privacy questions and to exercise rights, write to privacy@solvtako.com. For general support, use support@solvtako.com.

2. Scope and people covered

This policy applies to people who visit the website, create or use a personal or organisation account, act as requesters or providers, publish content, exchange messages, manage an organisation, purchase a subscription or contact support.

SolvTako is the controller for processing needed to operate the Platform. Local services are agreed directly between users; a provider receiving data to perform their own service may act as an independent controller for that use and must meet their own obligations.

3. Sources of data

We obtain data directly from you, from your activity on the Platform, from an organisation administrator who adds you or manages licences, from other users when they interact with or report you, and from providers involved in authentication, app distribution, subscriptions, notifications, security and support.

If you sign in with Google or Apple, we receive the data you authorise and that is needed to link or create your account, normally an identifier, email address and, when provided, name. We do not receive your Google or Apple account password.

4. Account, authentication and organisations

We may process your name, alias, email address, internal and federated identifiers, language, account status, roles, preferences, access records and information needed to verify a session. Email sign-in credentials are handled by the identity service.

We also process your date of birth. It is necessary data: SolvTako is open only to people aged 18 or over, and the date of birth is what allows that minimum age to be checked. We do not show your date of birth or your age to other users.

For organisation accounts, we also process the organisation name and details, membership, administrative roles, invitations and licence assignments. The organisation administrator can view and manage the member information needed according to product permissions.

5. Mandatory and optional data

Data identified as mandatory in each form is required to create or protect an account, publish an offer or request, provide the requested feature or validate a subscription. If you do not provide it, we may be unable to create the account or provide that particular feature.

Additional profile data, precise device location, push notifications, marketing communications and other features identified as optional are voluntary unless a justified reason is expressly stated. Refusing them does not prevent use of basic features that do not depend on that data. A territorial location or address may still be required for a listing, request, search or organisation function that inherently depends on location, but granting precise device-location access is not required because manual selection or entry provides an alternative. A phone number or address is mandatory only in a flow that marks it as required for that specific purpose.

6. Profiles, listings and images

We process information you add to your profile, such as a photo or avatar, biography, languages, skills and availability, as well as offers or requests you publish, their categories, descriptions, images, terms, indicative prices and status.

We may technically analyse images and text to remove unnecessary metadata, detect contact details, unlawful content, fraud or breaches, and support moderation. You must not publish third-party personal data or material for which you lack rights.

7. Location and geolocation

We process addresses or locations you enter, coordinates, search or service radiuses and geocoding results to save locations, calculate distance and show relevant results. If you permit device location, we use it for the feature you request and you can withdraw permission through your operating system.

The public interface displays an approximate location or distance, not the exact saved address. However, a location, description or message may allow others to infer more information; avoid sharing more data than needed.

8. Messaging, reputation, support and moderation

We process messages between users, ratings, references, reports, blocks, moderation decisions and communications with support. We may review reported content and related evidence to investigate fraud, safety risks, rights infringements or breaches of the terms.

Where someone notifies allegedly illegal content we additionally receive the data they provide in the notice: their name and email address where required, the indicated location of the content, the explanation of why they consider it illegal, and the good-faith confirmation. We use that data to acknowledge receipt, assess the notice, take and substantiate the decision, communicate it to those affected, and demonstrate compliance with our legal moderation duties. We also record the decision, its ground, the reviewer, the dates and whether an automated system was involved.

We do not disclose the identity of a person who submits a notice to the affected user unless strictly necessary and legally required. A notice may be communicated to competent authorities where a legal obligation applies or where there is a threat to the life or safety of a person. The allegedly illegal material does not need to be attached, and we ask that it is not sent.

9. Subscriptions and in-app purchases

Apple App Store and Google Play manage billing and the payment method. We receive and process product and transaction identifiers, store, store country when supplied, subscription status and validity, enabled entitlements, restorations and events needed to validate the purchase. We do not receive your full card number.

Personal accounts and organisations may have different plans. For organisations, we also process the assignment of entitlements or licences to members.

10. Notifications, technical data, analytics and diagnostics

If you enable push notifications, we process the device token, platform, preferences and information needed to deliver and technically measure the notification. You can withdraw permission through your operating system and adjust available preferences.

We process IP address, device type and version, operating system, language, app version, technical identifiers, access dates, usage events, security logs, performance, errors and diagnostics. We use first-party analytics to understand usage and may use observability and diagnostic providers. We do not use this data for behavioural advertising.

11. Purposes

We process data to:

  • Register, authenticate, protect and administer personal and organisation accounts.
  • Publish and search offers or requests, calculate proximity and facilitate contact and messaging.
  • Display profiles, reputation and content according to service options and features.
  • Send operational communications, requested notifications and periodic summaries of new matching opportunities related to your active listings or searches, which you can disable at any time from your notification settings without affecting the rest of the service.
  • Validate subscriptions, restore purchases and assign features or licences.
  • Handle support, rights requests, complaints and legal communications.
  • Prevent fraud, abuse and unauthorised access; moderate content and preserve supplied evidence.
  • Measure, maintain, debug and improve service reliability and usability.
  • Comply with legal obligations and valid authority requests.
  • Establish, exercise or defend legal claims.

12. Visible information and disclosures

Depending on how you configure and use the Platform, others may see your public name or alias, avatar, professional information, listings and images, prices and terms, availability, approximate location, ratings and references. A message recipient sees its content and associated profile data. We do not make your sign-in email, exact saved address or credentials public.

We may disclose data to an organisation administering your membership; to the recipient of an interaction; to Apple or Google to validate and manage purchases; and to authorities, courts, advisers, auditors or potential acquirers where there is a legal basis and this is necessary. We do not sell personal data.

13. Providers and subprocessors

To provide the Platform, we use specialised identity and authentication, infrastructure and hosting, storage, database and cache, content delivery network, security, email and notification, app distribution and purchase, mapping and geocoding, support, fraud prevention, moderation, technical analytics and observability providers.

The primary production environment of SolvTako —the main infrastructure and storage systems of the service— is configured to operate in the United States, and that is its primary location from launch.

Data handled by that primary environment is received, stored and processed in the United States. Certain categories of data may also, or instead, be processed directly by the providers described below in other locations.

This is a hosting and processing location, not an additional commercial market: SolvTako, S.L., established in Spain, remains the data controller regardless of where hosting technically runs, and Panama remains the initial commercial market.

The primary location does not by itself determine where everything else sits. Regardless of it:

We therefore assess and document each access and each onward transfer separately, restricting them to their purpose and to the permissions required: the primary location is not a sufficient answer for any of them.

If we move the primary infrastructure or the primary storage systems to another country, we will update this policy and its stated location before the change takes effect, and will inform you in accordance with the changes section.

Where a provider processes data for SolvTako, S.L., activation must be subject to the contract, instructions, security measures, subprocessors and transfer mechanism required by law. Some providers act as independent controllers for their own operations, particularly app stores and identity providers, under their own privacy information.

  • the content delivery network serves public files from edge locations around the world;
  • the app stores, federated identity providers and the push notification service process data on their own infrastructure, in several countries;
  • the email, map or tile, diagnostics and observability, and support providers process data in the locations each of them determines under its contract, which need not coincide with the primary location;
  • certain providers and subprocessors may access information from other countries to provide support, maintain security, operate the service or comply with legal obligations.

14. Retention, deletion and restriction

We keep each category only for as long as needed for its purpose and afterwards for periods required by a legal obligation or needed to establish, exercise or defend claims. A deadline for answering a rights request is not a general technical deletion deadline.

When you request deletion, the account becomes unavailable and an asynchronous technical process begins. Ordinary data is deleted or anonymised and access under SolvTako, S.L.'s control is revoked. As part of the process, an encrypted legal-evidence snapshot may be isolated, separate from ordinary use and accessible only to authorised personnel, limited to information relevant to documenting operations, complying with legal obligations, preventing serious fraud, or establishing, exercising or defending legal claims. A legal hold pauses deletion only for affected data and only while its basis remains.

Backups that may contain deleted data stay outside ordinary use and are overwritten or expire under their lifecycle. If a copy is restored for continuity, deletion requests must be reapplied. Periods used in development environments do not by themselves become production retention commitments.

CategoryRetention criterion
Account, profile and organisationWhile the account or relationship is active; then deleted or anonymised through the deletion workflow, except for justified restriction
Listings, images and owned assetsWhile active or needed for the service; then removed and deleted according to the workflow and technical lifecycle
Messages, ratings and interactionsWhile needed for the conversation, third-party integrity, safety or claims; they may be anonymised when an account closes
Subscriptions and transactionsWhile managing the purchased entitlement and for applicable tax, accounting, consumer, anti-fraud or claims periods
Push tokens and session identifiersUntil revoked, expired, detected as inactive or the account is deleted, as applicable
Technical logs, analytics and moderation evidenceFor limited windows set according to security, debugging, fraud prevention and applicable limitation periods, with restricted access
Notices of allegedly illegal content, moderation decisions and their auditable recordFor as long as needed to handle the notice and, afterwards, for the time needed to demonstrate compliance with our legal moderation duties, handle a review or complaint and defend claims; a submitter's contact details are kept only while needed to send the acknowledgement and the decision and to evidence them
Rights requests and supportWhile handled and for the period needed to evidence the response and defend claims

15. Security and incidents

We apply technical and organisational measures proportionate to risk, including access control, separation of duties, encryption in transit, secrets protection, and encryption of data or evidence where required. We review logs and limit staff and provider access to what is necessary. No system provides absolute security.

If a personal data breach occurs, we will assess and document it and notify authorities and affected people where and within the period required by applicable law.

16. Children

SolvTako is intended exclusively for people aged 18 or over. A person under 18 may not create an account or offer or request services. If we reasonably believe an account belongs to a child, we may suspend it, request verification and delete their data, subject to strictly necessary legal retention. A legal representative may contact privacy@solvtako.com.

17. Application of the GDPR and Spanish law

SolvTako, S.L. is established in Spain. Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 therefore apply to processing in the context of that establishment, including where a user is outside the European Union. Mandatory local-market provisions are added where relevant through specific annexes.

19. International transfers and processing location

The GDPR applies to these processing activities because they are carried out in the context of the activities of SolvTako, S.L., established in Spain, regardless of where collection, storage or processing technically takes place.

The primary production environment and the primary storage systems of the service are configured to operate in the United States. Data handled by the primary production and storage systems is received, stored and processed in the United States; it does not need to be stored first in primary systems in the European Economic Area.

For the purposes of Chapter V of the GDPR, the international transfer arises because SolvTako, S.L., as a controller subject to the GDPR, makes the data available to separate organisations established outside the European Economic Area. It does not depend on the physical route, or on the data having been stored in Europe first.

Besides the primary hosting, international transfers also arise in processing involving delivery of public content from edge locations worldwide, the app stores, federated identity providers, push notifications, and any email, mapping, diagnostics, observability or support provider operating outside the European Economic Area.

Nor does the primary location by itself determine where copies, redundancy, telemetry, support or subprocessors are located, so we assess access and onward transfers separately.

Where the GDPR applies, each transfer relies on an adequacy decision applicable to the specific recipient or on the appropriate safeguards of Article 46, such as Standard Contractual Clauses approved by the European Commission, together with the assessment and any supplementary technical and organisational measures required.

Two distinct things should not be confused. A provider being situated in a given country tells you the **location** of the processing; the **transfer mechanism** is a separate question that depends on the specific receiving entity, the service contracted, and its certification or contractual commitments. An adequacy decision covers only the recipients within its scope and, where it requires certification, only entities that are in fact certified and for as long as they remain so. Being established in a country covered by an adequacy decision does not automatically make a provider an adequate recipient.

The specific safeguards depend on the provider, service, receiving entity and relevant processing activity. Selecting a provider or merely having a contract does not replace assessment of the applicable transfer mechanism, any supplementary measures that may be needed, or onward transfers.

You may request further information about international transfers or a copy of the applicable safeguards by contacting privacy@solvtako.com.

20. Data protection rights

Subject to the GDPR, you may request access, rectification, erasure, restriction, portability and objection; withdraw consent; and not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. You may also give instructions on the destination of your data in circumstances recognised by Spanish law.

Write to privacy@solvtako.com and identify the account, right and information needed to locate the data. We will request additional proof of identity only where there are reasonable doubts, and unnecessary documents should not be sent.

21. Response period and complaints

We will answer a rights request without undue delay and generally within one month of receipt. This may be extended by up to two further months because of complexity or number of requests; we will explain the extension and reasons within the first month. These periods govern the response to the right and do not promise that every technical deletion will finish within one month.

You may complain to the Spanish Data Protection Agency (AEPD), at www.aepd.es, or to the supervisory authority of your habitual residence, place of work or place of the alleged infringement in the European Union.

22. Automated decisions and ordering

We do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you. Search and ordering may consider category, text, location or distance, availability, relevance and recent activity to present results; they do not decide whether you contact or contract with another person. If this changes to significant profiling, we will provide the required information and safeguards before activation.

23. Additional provisions applicable in Panama

This annex applies to users in Panama and processing subject to Law 81 of 26 March 2019 on Personal Data Protection and Executive Decree 285 of 28 May 2021.

Law 81 applies to SolvTako because Article 2(4) of Executive Decree 285 extends its scope to processing carried out in the course of a commercial activity, over the Internet or any other electronic or digital medium, directed at the Panamanian market. It therefore does not depend on the databases being in Panamanian territory or on the controller being domiciled in Panama.

This annex supplements, and does not replace, the general policy or the framework applicable to SolvTako, S.L. because it is established in Spain. If rules conflict, the mandatory rule providing the protection required in the specific case will be preserved.

25. Rights and periods in Panama

You may exercise access, rectification, cancellation, objection and portability and revoke consent where processing relies on it. Send the request to privacy@solvtako.com with enough information to identify the account and right; we may request proportionate verification where there are reasonable doubts.

Requests for access or information will be handled within no more than ten business days. Erroneous, inaccurate, misleading or incomplete data will be corrected within five business days following the request. Requests for erasure, objection, blocking or portability will be handled in accordance with the time limits and procedures established by Law 81 of 2019 and Executive Decree 285 of 2021.

26. Transfers and processing outside Panama

SolvTako does not host your data in Panama. The primary production environment and the primary storage systems of the service are configured to operate in the United States, and certain providers process data in other countries, as detailed in the general providers section. Data is collected, received, stored and processed directly outside Panama, without first being stored in the country: the international transfer arises from making the data available to recipients established outside Panama, not from a prior physical journey.

These transfers are lawful under Article 33 of Law 81. The condition we rely on principally is item 9: the transfer is necessary for the maintenance and performance of the legal relationship between SolvTako, S.L. and you, since without hosting, authentication, notifications, app stores and support the service cannot be provided to you. Item 2 may apply in addition, where the receiving country or body offers an equivalent or higher level of protection, as may item 13, where processing is covered by contractual clauses containing data-protection mechanisms consistent with Law 81, and item 1, where you have consented for a specific feature.

Where processing involves confidential, sensitive or restricted data originated or stored in Panama, Article 5 of Law 81 also applies: we require whoever hosts or holds them to meet protection standards equal to or higher than those of the Law, without prejudice to the exceptions the Law itself provides, including the necessity of the transfer to conclude or perform a contract in your interest.

In accordance with Article 25 of Law 81 and Article 14 of Executive Decree 285, we inform you of the international nature of the processing, its purpose and the categories of data and recipients; we require confidentiality, security and onward-transfer safeguards; and we maintain the register of transfers to third parties provided for in Article 31 of Law 81, available to the National Authority for Transparency and Access to Information on request. You may request further information from privacy@solvtako.com and complain to ANTAI through the channels described below.

Nor will we transfer or communicate your personal data once seven years have elapsed since the legal obligation to retain them ended, unless you expressly request otherwise, in accordance with Article 28 of Law 81.

27. Automated decisions in Panama

Under Article 19 of Law 81, you have the right not to be subject to a decision based solely on automated processing of your data that produces negative legal effects or impairs a right.

We do not take decisions of that kind. We process Content, including images, for safety, abuse prevention and compliance with these rules. In that context we may use automated tools and human review, depending on the type of content and the case; human review is part of our moderation process for already published content, including removals, restrictions and suspensions.

Nor does the ordering of search results decide for you: it presents results according to the parameters described in the Terms and produces no legal effects on you.

28. Notification of security breaches in Panama

In accordance with Article 37 of Executive Decree 285, if we become aware of a security breach that represents a risk to the protection of your personal data, we will notify the control authority and the affected individuals within seventy-two hours of becoming aware of the incident.

The notification will be written in clear and plain language and will state the nature of the incident, the personal data compromised, the corrective actions taken immediately, recommendations on measures you can take to protect your interests, and the means available to obtain further information.

29. Complaint to ANTAI

If you believe we have not properly handled your request, you may complain to the National Authority for Transparency and Access to Information (ANTAI), Panama's competent personal data protection authority, through the channels published at www.antai.gob.pa. This right does not limit other available administrative or judicial remedies.

30. Changes and current information

We will publish the current version, its effective date and material changes. Where a change materially affects purposes, legal bases, recipients, main location, transfers or rights, we will inform you by an appropriate means and request new consent or acknowledgement where legally required.

Prior versions and evidence of the version displayed or acknowledged may be retained on a restricted basis to demonstrate compliance and defend claims.

31. Privacy contact

To ask about this policy, exercise rights or report a possible privacy incident, write to privacy@solvtako.com. For general support, use support@solvtako.com. This version takes effect on 2026-09-01.