In this section, we inform users and interested parties of all matters concerning the processing of their personal data, thereby complying with the applicable data protection regulations, in particular, Regulation (EU) 2016/679 of 27 April on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter, “GDPR”).
This Privacy Policy applies to the data processing carried out by About FI Europe, S.L. (hereinafter, “Centinel”) through the website https://centinel.finance (hereinafter, the “Website”), through its platform, and integrations with third-party services, including Google services via OAuth.
We recommend that you read it carefully before using the Website and/or providing your data to Centinel. If you have any questions, you can contact us via email: support@centinel.finance
Who is responsible for the processing of your personal data?
Your personal data will be processed by the company About FI Europe, S.L. (“Centinel”), with Tax Identification Number (NIF) B75926840, and whose contact details are as follows:
What requirements must you meet to provide us with your personal data?
2.1 Minimum age
To provide us with your personal data, you must be at least 14 years old and/or have sufficient legal capacity to use this Website.
2.2 Accuracy
When you provide us with your data to use our services, you guarantee that the information and data provided are true, accurate, up-to-date, and that they belong to you and not to third parties.
You must also notify us of any changes to the data provided and are in any case responsible for the accuracy and truthfulness of the data supplied at all times.
2.3 Age and identity verification
At Centinel, we reserve the right to verify your age and identification information at any time, if necessary, including by requesting an official identification document or equivalent procedure. If fraud is detected or there is reasonable suspicion that you are under the required age, we may delete, temporarily deactivate, and/or cancel your account.
What data processing activities do we carry out, and what are their main characteristics?
Below, we explain how we process your personal information and provide you, in detail, with all relevant information regarding your privacy.
3.1 When you contact us through our communication channels or request a demonstration of our services
3.2 When you access and use our services
3.3 Data processing for Google service integrations (Gmail and Google Drive)
If you choose to connect your Gmail and/or Google Drive account to Centinel, we will access and process specific types of data solely for the purpose of automating the extraction and organization of invoices. This functionality is entirely optional and only activated with your explicit authorization through Google’s OAuth 2.0 consent flow.
Under the GDPR, the processing of Gmail and Google Drive data is based on your explicit consent (Article 6(1)(a) GDPR), which is obtained via Google’s OAuth authorization mechanism. You may withdraw your consent at any time, as detailed below.
A. Data access from Gmail and Google Drive
Once you authorize access, we may collect the following data from your Gmail or Google Drive account.
We do not access, process, or store any emails that do not meet invoice-related criteria. We do not access your entire inbox. Our access is scoped, filtered, and restricted solely to fulfill the invoice-processing feature you have opted into. All access to Google Drive is purpose-limited and restricted to the folders and files necessary to perform invoice export and publishing operations.
B. Data usage from Gmail and Google Drive
The Gmail and Google Drive data is used exclusively to support our automated invoice management feature. Specifically, we may detect invoice-related emails in your Gmail inbox; extract structured data from invoice attachments (e.g. invoice number, date, supplier, due amount); generate accounting entries, reports, or suggestions based on invoice content; store extracted invoice information in your Centinel account for your internal financial operations; and export and publish processed invoices (in PDF or CSV format) to your Google Drive.
We do not use Gmail or Google Drive data for marketing, advertising, profiling, or any purpose unrelated to invoice automation.
C. Data sharing from Gmail and/or Google Drive data
We do not make any additional disclosures beyond those generally indicated in section 04. In this regard, we may use service providers for the delivery of certain ancillary services who act as Data Processors.
D. Data storage and protection
For Gmail: Centinel does not store your entire Gmail inbox or unrelated messages. However, for invoice-related emails that are identified and approved for processing, we may store extracted invoice information (e.g. invoice number, amount, issue date, supplier) and minimal metadata (e.g. sender, subject line, email date) in your Centinel account.
For Google Drive: Centinel uses your Google Drive to export and organize processed invoice documents (e.g. PDFs or CSVs). We do not store Drive files in our systems. However, we may retain file or folder references (such as Google Drive file IDs or directory names) and metadata necessary to manage invoice publishing and prevent duplication. We do not read or store unrelated Drive file contents.
Centinel protects Gmail and Google Drive data in accordance with industry best practices. Data is encrypted in transit using TLS and encrypted at rest with AES-256 or equivalent standards. Access is strictly limited by role-based controls and subject to the principle of least privilege. All administrative and system access to user data is logged, monitored, and periodically reviewed. We maintain continuous monitoring and incident response procedures to detect and address threats, and we regularly review and update our security measures to remain compliant. See further detail in section 07.
E. Data retention and deletion
All Gmail and/or Google Drive data will be processed during the duration of the contractual relationship between the parties. Once that period ends, Centinel will retain the data in a blocked state for the periods established by law to handle any potential liabilities and to demonstrate compliance with our obligations.
You may disconnect Gmail and Google Drive at any time, in which case we will delete all Gmail and Google Drive derived data associated with your account within thirty (30) days, unless retention is required by applicable law.
F. Human access policy
Centinel personnel do not access your Gmail and/or Google Drive data unless you have explicitly requested support and provided consent for access; it is necessary to investigate abuse, fraud, or a security incident; or it is required by a valid legal obligation or enforceable government request. All access is monitored, logged, and subject to strict confidentiality and access control policies.
G. Compliance with the Google API Services User Data Policy
Centinel’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. This means:
3.4 Your rights
As with all personal data processed by Centinel, you have the right to access, rectify, erase, restrict, and object to the processing of your Gmail and/or Drive derived data. You may also request data portability or lodge a complaint with the relevant data protection authority. To exercise these rights, please contact us at support@centinel.finance.
3.5 Browsing the Website (cookies)
We use cookies and other tracking and tracing tools on this Website to collect information about how users interact with the Website. For more information on the processing carried out through these tracking tools, please visit our Cookie Policy.
To whom do we disclose your personal information?
In general, Centinel does not communicate your data to third parties. However, in addition to the specific disclosures indicated in section 03, we inform you of the general disclosures we may make, which apply to all data processing activities previously mentioned and are based on the corresponding legal grounds.
We also inform you that this Privacy Policy only refers to the collection, processing, and use of personal data by Centinel. Access to third-party websites, platforms, or services that you may access through links on our Website or platform are subject to their own privacy policies, over which we have no control. Therefore, before providing any personal information to such third parties, we recommend that you carefully review their Privacy Policies.
Are your personal data transferred to third countries outside the European Economic Area?
We may use service providers located in countries outside the European Economic Area (“EEA”). The location of these companies outside the EEA implies the existence of an international transfer of your personal data, which could result in a lower level of protection than that provided by European regulations. Nevertheless, at Centinel, we apply safeguards to ensure that such transfers do not result in a lower level of protection for your personal data.
Accordingly, we only enter into agreements with service providers located outside the EEA when they have a valid mechanism in place to lawfully carry out international transfers. This includes:
As a result, using these providers does not result in a lower level of protection than would be obtained by using providers located within the European Union.
What are your rights as a data subject?
You may exercise the rights granted to you by law in relation to the processing of your personal data by contacting us via email at support@centinel.finance.
We will resolve any rights-related requests as soon as possible, and in any case, within the maximum time period established by applicable regulations from the time we receive your request. In some cases, we may need to request a copy of your identity document or other identification if necessary to verify your identity.
How do we guarantee the confidentiality of your information?
The security of your personal data is a priority for us. For this reason, Centinel has implemented all necessary security measures to ensure the effective use and processing of the personal data provided by the user, safeguarding the privacy, confidentiality, and integrity of the data, and using the necessary technical means to prevent alteration, loss, unauthorized access, or processing of your data, according to the state of the art at all times.
Accordingly, we comply with recommended security standards to protect your data. However, it is impossible to fully guarantee the security of your data due to the inherent nature of the Internet and the possibility of malicious actions by third parties that are beyond our control.
We are committed to acting swiftly and diligently if the security of the data is compromised or endangered, and to informing you about such events if relevant.
Changes to this policy
Centinel may modify the content of this Privacy Policy at any time, especially when legislative, jurisprudential, or regulatory changes by competent authorities occur that affect the data processing carried out by Centinel.
Any modification will be published on the Website and/or on our platform, and, if relevant, we will notify you of the changes through the available communication channels or means. The modifications will become effective at the time of their publication, unless otherwise stated.
We recommend that you review this Privacy Policy periodically to stay informed about how your personal data is processed and protected, as well as to understand your rights.
This Privacy Policy was last modified on 8 March 2025.