Privacy Policy
This is an informative translation of a document governed by Spanish law. In the event of any discrepancy, the Spanish version shall prevail. This Privacy Policy describes how LATENT SERVICES processes the personal data of individuals who visit the Site, contract its services or use the private platform app.latent.services, including data that may be visible during remote assistance sessions. Please read it carefully before contracting a service or authorizing remote access to your computer.
1. Data controller
The data controller for personal data collected through the Site and the platform is:
- Controller: [RELLENAR: razón social o nombre del titular]
- Tax ID (NIF/CIF): [RELLENAR]
- Address: [RELLENAR]
- Contact email for data protection matters: vaultdevelopment@proton.me
- Data Protection Officer: no DPO has been appointed as it is not mandatory, given the nature and volume of the data processing activities carried out (Art. 37 GDPR).
2. Data collected through the website
Through the Site and the private platform we may collect the following categories of data, depending on user interaction:
- Contact and account data: name, surname, email address, and where applicable a password (securely managed through Auth.js) when the user creates an account or signs in.
- Billing data: name or company name, address and, where applicable, tax ID (NIF/CIF), necessary for issuing invoices and managed by LATENT and by Stripe as the payment processor.
- Contract data: service contracted, date, order status, communications related to the service.
- Payment data: managed directly by Stripe. LATENT does not store complete card numbers or security codes at any time.
- Aggregated and anonymous technical browsing data collected by Plausible Analytics and Vercel Speed Insights (see section 8 and the Cookie Policy), which do not allow individual user identification.
- Support data: content of messages the user sends through support or contact channels.
3. Data potentially visible during remote access
Providing the optimization service requires, in most cases, that a LATENT technician remotely accesses the client's desktop using Tailscale, Sunshine and Moonlight (see section 9). During that session, the technician views and, if the client authorizes it, controls the client's computer desktop in real time.
It is important for the client to understand that, during remote access, the technician may incidentally see any information present on the computer screen, including but not limited to: the desktop wallpaper and icons, open windows and applications, content of running programs, file and folder names, open emails, open documents, images or videos being played, system notifications, and, if visible on screen due to the client's oversight, credentials, passwords or other sensitive information.
LATENT expressly recommends that the client, before starting any remote access session, close email sessions, password managers, banking or payment applications, and any documents or windows of a personal or confidential nature that are not necessary for the service. This recommendation is also reiterated during the contracting process.
4. Commitment not to copy or retain personal data from the client's computer
LATENT expressly commits that, during and after any remote access session:
- The technician will not copy, download, transfer or extract files, documents, photographs, emails, browsing history or any other personal data from the client's computer, unless strictly necessary to diagnose or resolve the issue that is the subject of the contracted service and the client has given express authorization.
- The technician will not take screenshots, video recordings or session logs containing the client's personal data, unless there is a separate and specific consent from the client for this purpose (for example, for technical documentation of the service itself or incident resolution).
- The technician will not deliberately access personal documents, photographs, emails, messaging conversations or passwords of the client that are not necessary for the provision of the contracted service, even if they are visible during the session.
- Any information seen incidentally during the session is treated as confidential and will not be retained, communicated or used for any purpose other than the provision of the service.
This commitment does not exempt the client from taking the reasonable precautions described in section 3 above and in the Terms and Conditions, given that LATENT cannot absolutely control what information becomes visible on screen during the session.
5. Technical files created during the service
As part of providing the service, the technician may create technical files on the client's computer such as configuration files, optimization scripts, tool profiles (for example, LatencyMon, CapFrameX, Process Lasso or HWiNFO) and diagnostic log files.
These technical files contain only operating system configuration parameters, Windows registry values, and performance settings; they do not contain personal data of the client. They are stored on the client's computer (local folder) and, when the service requires it, in an internal LATENT repository. They are kept for 1 year after the completion of the service, after which they are deleted.
The client may request at any time information about the technical files generated during their service, as well as their deletion, through the channels indicated in section 12 of this policy.
6. Legal bases for processing
LATENT processes personal data on the following legal bases, depending on the specific purpose:
- Performance of a contract (artículo 6.1.b RGPD): to manage account registration, service contracting, billing and communication necessary to provide the service.
- Specific consent (artículo 6.1.a RGPD): for remote access to the client's computer, which is requested expressly, informedly and separately during the checkout process before each session, and for any data processing that exceeds what is strictly necessary for contract performance.
- Legal obligation (artículo 6.1.c RGPD): to comply with tax, accounting and billing obligations.
- Legitimate interest (artículo 6.1.f RGPD): for aggregated and anonymous statistical analysis of Site usage through Plausible Analytics, which does not allow individual user identification and is carried out without cookies or prior consent in accordance with applicable regulations.
7. Purposes of processing
Personal data is processed for the following purposes:
- Managing registration and access to the customer account on the platform.
- Processing the contracting, payment and billing of services.
- Providing the contracted remote diagnostic and optimization service.
- Handling inquiries, issues and support requests.
- Complying with legal, tax and accounting obligations.
- Preparing aggregated and anonymous usage statistics of the Site to improve its operation.
- Preventing fraud and ensuring platform security.
8. Recipients and data processors
To provide the service, LATENT uses the following third-party providers, who act as data processors pursuant to Article 28 of the GDPR or, where applicable, as independent controllers for processing they carry out on their own behalf:
- Stripe: processes payments made on the platform. Stripe acts as a data processor (and, for certain purposes such as fraud prevention, as an independent controller) with respect to payment and billing data. Headquarters: United States (with European entity Stripe Payments Europe, Ltd. in Ireland). Transfer mechanism: Standard Contractual Clauses (SCCs) and EU-U.S. Data Privacy Framework.
- Vercel: hosts the Site and the platform, and processes the technical data necessary to serve pages and applications. Acts as a data processor. Headquarters: United States. Transfer mechanism: Standard Contractual Clauses (SCCs) and Data Privacy Framework.
- Plausible Analytics: self-hosted instance used to obtain aggregate, anonymous website usage statistics, without cookies or individual user identification. [RELLENAR: ubicación del servidor donde se aloja la instancia].
- Prisma Postgres: database where account data, orders, and billing information are stored. Acts as managed storage infrastructure. [RELLENAR: región del servidor de base de datos].
- Tailscale: provides the private network infrastructure (encrypted tunnel) used during remote access sessions. See section 9 for a detailed explanation of its operation. Headquarters: United States / Canada. Transfer mechanism: [RELLENAR: verificar si Tailscale está adherido al DPF o aplica CCT].
- Resend: transactional email provider used to send order confirmations, notifications, and service-related communications. Headquarters: United States. Transfer mechanism: Standard Contractual Clauses (SCCs) and Data Privacy Framework.
LATENT does not sell or share personal data with third parties for advertising or marketing purposes. Data is only communicated to the providers indicated to the extent necessary for service provision, and always under the corresponding data processing agreements.
9. Technical operation of remote access tools
Tailscale creates a virtual private network (mesh VPN) between the client's and the technician's computers. The data connection is established, whenever network configuration allows, directly and with end-to-end encryption (peer-to-peer) between both computers. Tailscale's coordination servers process only the metadata necessary to establish the connection (device identifiers and public keys), but do not have access to the content of the remote access session, which remains end-to-end encrypted.
Sunshine and Moonlight are open-source tools that manage the video streaming and remote desktop control through the tunnel created by Tailscale. Both tools run locally on the technician's and client's computers, do not send data to third-party servers outside the established connection, and do not collect or store information about the session content.
Consequently, the visual and control content of the remote access session does not pass through LATENT servers or third parties other than Tailscale's coordination infrastructure, which — as noted — does not have access to the encrypted session content.
10. International data transfers
Some of the providers used by LATENT are located or process data outside the European Economic Area, which constitutes an international transfer of personal data:
- Stripe, Vercel, and Resend: may involve transfers to the United States. These transfers are covered by Standard Contractual Clauses approved by the European Commission and the providers' adherence to the EU-U.S. Data Privacy Framework.
- Tailscale: may involve transfers to the United States or Canada. [RELLENAR: verificar mecanismo de transferencia aplicable — confirmar adhesión al DPF o existencia de CCT firmadas].
- Plausible Analytics: [RELLENAR: si la instancia está autoalojada en la Unión Europea, no existe transferencia internacional; indicar la ubicación del servidor].
The user may request additional information about the safeguards applied to these transfers by contacting LATENT through the contact channels indicated in section 1.
11. Data retention periods
Personal data will be retained for the following periods:
- Account data: for as long as the user maintains an active account on the platform and for 2 years following account deletion, unless a prior deletion request is made.
- Billing and accounting data: for the legally required period under tax and commercial law, currently 6 years under Article 30 of the Spanish Commercial Code and 4 years under Article 66 of the General Tax Law.
- Technical files and service logs: for 1 year from the completion of the service.
- Support communications: for 1 year from the last communication.
- Data processed on the basis of consent (e.g., remote access authorization): until the completion of the service for which consent was given, unless they must be retained for an additional period to comply with legal obligations or for the establishment, exercise or defense of claims.
After the indicated periods, data will be securely deleted or anonymized, unless there is a legal obligation for additional retention.
12. Data subject rights
The user may exercise at any time the following rights recognized by the GDPR and the LOPDGDD:
- Access: know what personal data is being processed.
- Rectification: request the correction of inaccurate or incomplete data.
- Erasure: request the deletion of their data when, among other reasons, they are no longer necessary for the purposes for which they were collected.
- Objection: object to the processing of their data in certain circumstances, particularly when processing is based on legitimate interest.
- Restriction of processing: request the restriction of processing of their data in certain situations.
- Data portability: receive their data in a structured, commonly used and machine-readable format, or request their direct transmission to another controller, where technically feasible.
- Withdraw consent: at any time, without affecting the lawfulness of processing based on consent prior to its withdrawal.
These rights may be exercised by sending a request to vaultdevelopment@proton.me, accompanied by a copy of a document proving the applicant's identity.
The user also has the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), through its electronic headquarters (www.aepd.es), if they consider that the processing of their personal data does not comply with applicable regulations.
13. Security measures
LATENT implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including but not limited to: encryption of communications via HTTPS/TLS, end-to-end encryption in remote access sessions through Tailscale, secure credential management via Auth.js, access controls to the platform and database, and periodic system updates.
Access to personal data by LATENT staff is limited to what is strictly necessary for the performance of their duties.
14. Security incident management
In the event of a personal data security breach that poses a risk to the rights and freedoms of data subjects, LATENT will notify the Spanish Data Protection Agency within a maximum of 72 hours from becoming aware of it, in accordance with Article 33 of the GDPR, and will communicate the incident to affected users when the risk to their rights and freedoms is high, in accordance with Article 34 of the GDPR.
15. Data Protection Officer
No Data Protection Officer has been appointed, as, given the nature and volume of the data processing activities carried out, appointment is not mandatory under Article 37 of the GDPR and Article 34 of the LOPDGDD. For any queries regarding data protection, the user may contact the controller at the address indicated in section 1.
16. Changes to this policy
LATENT may modify this Privacy Policy to adapt it to legislative, jurisprudential developments or changes in the services or providers used. Modifications will be published on this same page indicating the update date. The user is advised to review this policy periodically.
See also: Legal Notice · Cookie Policy · Terms and Conditions