Brimlo · autonomo.space
Privacy Policy
How Brimlo processes personal data under the GDPR and Spanish LOPDGDD.
Last updated: 6 September 2026
Service provider / data controller
- Trade name
- Brimlo
- Legal name
- Individual Entrepreneur VADIM CHIBISOV
- Legal form
- Individual Entrepreneur
- Identification number
- 300476991
- Country of registration
- Georgia
- Registration date
- 16 July 2026
- Registering authority
- LEPL National Agency of Public Registry, Ministry of Justice of Georgia
- Registry extract ref.
- Application / extract reference B26396947
- Registered address
- Georgia, Tbilisi, Gldani district, Niko Ketskhoveli street, N 16, entrance 1, floor 10, apartment N58
- Operational establishment in the EU
- Spain — Brimlo is managed and operated on an ongoing basis from Spain
- vadim.c@autonomo.space
- Website
- https://autonomo.space
1. Scope and roles
This policy applies to autonomo.space, the Brimlo workspace and related Brimlo communications. The Brimlo operator identified in the Legal Notice is the controller for account, security, billing, support, website analytics and service-operation data. When a professional user stores personal data about their own customers, suppliers or other contacts in invoices, expenses, documents or integrations, that user is normally the controller and Brimlo processes those records on the user's behalf as processor under the Brimlo Data Processing Agreement (DPA).
2. Data we process
Account and contact data: email, authentication identifiers, language and account settings. Professional and tax-profile data: activity, IAE/CNAE context, tax regimes, dates and other configuration entered by the user. Accounting and business records: invoices, expenses, customers, suppliers, tax identifiers, countries, transaction metadata, attachments and supporting documents. Integration data: records imported or synchronized from services the user connects, including Amazon Selling Partner API where enabled. AI data: prompts, conversation context and documents the user chooses to submit to AI features. Technical and security data: IP address, user agent, timestamps, authentication and security logs. Usage/analytics data and advertising identifiers are processed only as described in the Cookie Policy and, where required, after consent. Support and correspondence data are processed when the user contacts us.
3. Purposes and legal bases
We process data to create and operate the account, provide invoices, accounting workflows, tax estimates, integrations, support and AI features (performance of contract, Art. 6(1)(b) GDPR); secure the service, prevent abuse, diagnose faults and improve reliability (legitimate interests, Art. 6(1)(f)); comply with tax, accounting, fraud-prevention and lawful-authority obligations applicable to us (legal obligation, Art. 6(1)(c)); and operate optional analytics, session replay, advertising measurement or marketing communications where consent is required (consent, Art. 6(1)(a)). Consent can be withdrawn at any time without affecting earlier lawful processing.
4. Data about customers and suppliers
Users must have a lawful basis and provide any required notices before entering third-party personal data into Brimlo. Brimlo does not determine the user's purposes for customer/supplier records. For those records Brimlo acts as processor and follows the user's documented instructions, subject to the DPA and applicable law.
5. AI processing
When the user invokes an AI feature, Brimlo sends the prompt and only the context needed for that request to contracted AI infrastructure/model providers. Users should avoid submitting special-category or unnecessary personal data and must have authority to process any third-party data they submit. AI outputs can be incorrect and are not a substitute for a gestor, tax adviser, lawyer or public authority. Brimlo does not make solely automated decisions that produce legal or similarly significant effects on users.
6. Recipients and subprocessors
Data is disclosed only where needed to provide or protect the service, including hosting/database/authentication/storage providers, AI infrastructure and model providers, email/support infrastructure, and user-selected integrations. With consent, analytics providers may include Google Analytics and Smartlook; marketing measurement may include Meta Pixel and Meta Conversions API. Connected Amazon data is exchanged with Amazon only when the user authorizes that integration. We may also disclose data when legally required. We do not sell personal data.
7. International transfers
Some providers may process data outside the EEA. Where Chapter V GDPR requires safeguards, we rely on an applicable adequacy decision, the European Commission's Standard Contractual Clauses or another lawful transfer mechanism and supplementary measures where appropriate.
8. Retention
Account and workspace data is kept while the account is active. After account deletion, user content is deleted or anonymized within the operational deletion cycle and backups age out under their normal retention schedule, unless a legal hold applies. Billing, tax and transaction records that Brimlo itself is legally required to retain are kept for the applicable statutory period. Security and support records are retained only as long as reasonably necessary for the relevant purpose. Consent records are retained to demonstrate the user's choices. Where a precise period cannot be stated, we use necessity, legal limitation periods and security requirements as retention criteria.
9. Your GDPR rights
Subject to the GDPR and LOPDGDD, data subjects can request access, rectification, erasure, restriction, portability and objection, and can withdraw consent. Requests can be sent to the contact email in the Legal Notice. We may need to verify identity. Users also have the right to complain to the Agencia Española de Protección de Datos (AEPD) at aepd.es or another competent supervisory authority.
10. Cookies and tracking
Optional analytics, personalization and marketing technologies are controlled through the cookie panel. Accepting Terms or creating an account does not constitute cookie consent. Users can reject optional cookies and can reopen Cookie settings at any time from the site or workspace.
11. Security and incidents
We apply technical and organizational controls appropriate to the risk, including transport encryption, access controls and least-privilege practices. No system is risk-free. Where a personal-data breach triggers GDPR notification duties, Brimlo will notify the competent authority and/or affected data subjects as required and will assist business customers where Brimlo acts as processor.
12. Changes
We may update this policy when the product, providers or law changes. The current version and effective date are published here. Material changes affecting registered users will be communicated through the service or by email where appropriate.
