Privacy Policy

Last updated: August 16, 2026

1. Scope of this policy

This Privacy Policy governs exclusively the processing of personal data carried out through ApisKit, at kit.apisdom.com, including its demonstration environment, user accounts and the support features available on the platform.

It does not govern other ApisDom services or purchase operations carried out outside kit.apisdom.com.

2. Data controller

The data controller is:

Juan Luis Salvador, operating under the ApisDom name.

Contact email: contacto@apisdom.com

The controller's full identification details are centralized in the ApisDom Legal Notice:

https://apisdom.com/legal#aviso

They are not reproduced again in this policy to avoid duplicating information that is already directly and permanently available in that Legal Notice.

3. What personal data is processed

Depending on how the user uses ApisKit, the following categories of data may be processed:

Account data

  • email address;
  • user identifier;
  • profile data provided by the user;
  • information needed to manage registration, authentication and session.

Support data

When the user uses the support system:

  • ticket content;
  • messages and replies;
  • attachments the user chooses to provide;
  • status and information needed to manage the request.

Demo usage data

  • demo actions used;
  • information needed to control the operation of the available features;
  • logs associated with the activity carried out within the account.

Technical and security data

When generated by the operation of the platform:

  • IP address;
  • basic device or browser information;
  • date and time of accesses or requests;
  • technical, error and security logs;
  • identifiers needed to protect accounts, sessions and the infrastructure.

ApisKit does not request banking data or payment card data through kit.apisdom.com.

4. Source of the data

The data comes from:

  • directly from the user when they create an account, modify their profile, use support or provide information;
  • automatically from the device, browser or use of the platform when needed for its operation, security or protection against abuse.

ApisKit does not acquire personal databases from third parties to complete the profiles of demo users.

5. Purposes and legal bases

The data will be processed only for the following purposes:

PurposeLegal basis
Create and maintain the accountPerformance of the Terms of Service and provision of the requested features
Authenticate the user and maintain their sessionPerformance of the Terms of Service
Allow use of the demoPerformance of the Terms of Service
Manage support tickets, messages and attachmentsPerformance of the Terms of Service and handling of the request made by the user
Protect accounts, application and infrastructureController's legitimate interest
Prevent fraud, improper access, abuse or abnormal use of the serviceController's legitimate interest
Investigate technical or security incidentsController's legitimate interest
Exercise or defend rights and claimsController's legitimate interest where applicable
Comply with legal obligationsCompliance with a legal obligation

The legitimate interest used for security processing consists of protecting ApisKit, its users, its systems, the infrastructure and the owner's rights against fraud, abuse, unauthorized access, incidents and uses contrary to the applicable conditions.

This processing will be limited to the data and time reasonably necessary for those purposes.

6. Required and optional data

The data marked as required during registration is essential to create and maintain an account.

If the user does not provide that data, it will not be possible to complete registration or use the features that require authentication.

Attachments and any additional information voluntarily added to a support ticket are optional, except for the fields essential to create and manage the request.

7. Data retention

Account data will be kept while the account remains active and, after its closure or deletion, only for the time needed to complete its erasure, comply with legal obligations or address possible liabilities.

Support data will be kept while needed to manage the request and, afterwards, for the period needed to address possible incidents, claims or liabilities related to it.

Technical and security logs will be kept for the period needed to detect, investigate and document incidents, prevent abuse and protect the infrastructure.

Where a legal retention obligation exists, the affected data may be kept blocked for the legally required period and will not be used for incompatible purposes.

Once the purpose and any applicable retention obligation have ceased, the data will be deleted or anonymized.

The same period is not artificially set for all categories of data when their purposes and retention obligations are different. The GDPR allows indicating the period or, where it cannot be determined in advance, the criteria used to establish it.

8. Recipients and providers

Personal data is not sold or rented to third parties.

To operate ApisKit, certain technology providers that supply services needed for the following may have limited access to data:

  • hosting and infrastructure;
  • authentication;
  • database;
  • storage;
  • transactional email;
  • security, technical logs or monitoring, where used.

These providers will access only the data needed to provide their respective services and will be subject to the contractual and legal obligations applicable in data protection matters.

Data may also be disclosed to judges, courts, public administrations, law enforcement or other authorities when a legal obligation or valid requirement exists.

The GDPR allows informing of the recipients or categories of recipients, so it is not necessary to turn this policy into a public inventory of the entire technical architecture.

9. International transfers

Some technology providers may provide services from countries located outside the European Economic Area or allow access to data from those countries.

When an international transfer occurs, one of the mechanisms permitted by applicable regulations will be used, as appropriate:

  • an adequacy decision by the European Commission;
  • a legally recognized transfer framework;
  • standard contractual clauses approved by the European Commission;
  • or other valid safeguards under Chapter V of the GDPR.

The Firebase infrastructure used by the platform has processing conditions that contemplate transfer mechanisms compliant with European regulations, including the Data Privacy Framework where applicable and standard contractual clauses.

The user may request additional information about the applicable safeguards by writing to contacto@apisdom.com.

10. Purchases and Polar

No sales are made and no payments are processed on kit.apisdom.com.

On this domain, ApisKit works as a presentation site and demonstration environment for the products.

Purchases are made externally through Polar Checkout.

The data needed to carry out the transaction is provided directly to Polar and is processed by that platform under its own Privacy Policy.

Stripe is the payment processor that collects the card data needed for the operation. ApisKit does not receive or store the full card data used to make those purchases.

Polar acts as reseller and Merchant of Record in the transactions carried out through its platform and is the entity with which the buyer carries out the commercial operation.

The economic conditions, taxes, delivery, withdrawal and refunds are not governed by this Privacy Policy; they correspond to the Payment Conditions.

11. Security

ApisDom applies technical and organizational measures appropriate to the risk to protect personal data against:

  • unauthorized access;
  • alteration;
  • loss;
  • destruction;
  • improper disclosure;
  • unauthorized use.

The specific security measures, internal rules, configurations, detection mechanisms and infrastructure details are not published in this policy when their disclosure is not necessary to inform the user.

No system connected to the Internet can guarantee absolute security, but the measures will be reviewed and adapted according to the risks and needs of the service.

12. User rights

The user may exercise the rights that correspond to them under data protection regulations, including:

  • access to their data;
  • rectification of inaccurate data;
  • erasure where appropriate;
  • restriction of processing;
  • objection, especially regarding processing based on legitimate interest;
  • portability, where applicable.

To exercise them, you can send a request to: contacto@apisdom.com

The request must make it possible to identify the applicant and determine which right they wish to exercise.

Additional information to verify identity will only be requested when there are reasonable doubts about it. The GDPR permits that verification and establishes, as a general rule, a period of one month to respond, extendable by a further two months when the complexity or number of requests justifies it.

The exercise of these rights is free of charge, except for the exceptional cases of manifestly unfounded or excessive requests provided for by the regulations.

13. Complaints

If the user considers that the processing of their personal data breaches the regulations, they may file a complaint with the Spanish Data Protection Agency (AEPD), without prejudice to any other remedy legally available to them.

The right to complain to a supervisory authority is part of the information expressly required by Article 13 of the GDPR.

14. Cookies

The use of cookies and equivalent technologies is governed exclusively by the ApisKit Cookie Policy.

That information is not reproduced here.

15. Changes to this Privacy Policy

This Policy may be updated when the features of ApisKit, the processing carried out, the providers used or the applicable legal obligations change.

The current version will be the one published on this page and will indicate the date of its last update.

When a change legally requires additional information or the user’s consent, the appropriate procedure will be applied before carrying out the new processing.