Effective date: 20.10.2025
Your privacy matters to us. This Policy explains how we collect, use, share, and protect personal data in compliance with the EU GDPR (2016/679) and Spanish LOPDGDD (3/2018).
Controller: LOS SHAULOV S.L. (CIF B75591339), Av. Pau Casals 13, Suite 4-4, 08021 Barcelona, Spain.
Compliance contact: info@losshaulov.com
Data Protection Officer (DPO): info@losshaulov.com
Supervisory authority: AEPD (Agencia Española de Protección de Datos).
Merchant-of-Record role: LOS SHAULOV S.L. acts as the seller/merchant-of-record for our group’s digital products (e.g., SEOMA, MoodBoss).
We use vetted processors under Data Processing Agreements (hosting, email, storage, analytics, payments, e-signature, compliance tools). Some services are provided under license and services agreements with ONERY Overseas Ltd. (BVI). A current vendor register is available on request.
Identity & contact: name, email, phone, company, role.
Account & billing: purchase history, invoices, payment metadata (we do not store full card numbers).
Usage/telemetry: device, logs, IP, app/web analytics (see Cookie Policy).
Support & forms: messages, attachments, timestamps.
Compliance (KYB/KYC/AML): corporate docs, IDs/passports and proof of address of representatives/UBOs, sanctions/AML statements, bank letters.
Provide and improve services; customer support — Art.6(1)(b) contract; Art.6(1)(f) legitimate interests.
Merchant-of-Record operations (billing, fraud prevention) — Art.6(1)(b)/(f).
Legal & compliance (tax, AML/CFT, audits) — Art.6(1)(c) legal obligation.
Communications (service notices) — Art.6(1)(b)/(c).
Marketing (news, updates) — Art.6(1)(a) consent (only if you opt-in).
Analytics — Art.6(1)(a) consent for non-essential cookies; Art.6(1)(f) for necessary security logs.
Tax/accounting: 6–10 years (as required by law).
KYB/KYC/AML records: up to 10 years (or longer if legally required).
Contracts/support: typically 6 years.
Marketing: until consent is withdrawn.
We delete or anonymize data when no longer necessary.
We share data with processors listed above solely for the purposes stated here, and with banks/PSPs, auditors, or authorities when legally required. We do not sell personal data.
Where data is transferred outside the EEA/UK, we use EU Standard Contractual Clauses (SCCs) or other safeguards permitted by GDPR, plus additional measures where appropriate.
You have the right to access, rectify, erase, restrict processing, object to processing, and data portability. Where processing is based on consent, you may withdraw it at any time (this does not affect prior lawful processing). You can also lodge a complaint with AEPD.
Requests: info@losshaulov.com (or info@losshaulov.com).
We use cookies and similar technologies. See our Cookie Policy for details and consent choices. Non-essential cookies are disabled until you opt in.
We apply organizational and technical measures appropriate to risk (encryption in transit/at rest where applicable, access controls, logging, least-privilege). No method is 100% secure.
We may update this Policy from time to time. The latest version is published on this page with the effective date at the top.