PRIVACY POLICY
Last update: 02/12/2025
WHO IS THE DATA CONTROLLER?
NOMAD US, S.L.
TAX ID NO.: B-22759153
Registered Office: Av. Diagonal, 640 6 Pta. A, 08017 Barcelona
E-mail: info@getpodo.com
If you wish to contact us regarding your Personal Data, you may do so at the address indicated above.
The Data Controller will be alternatively referred to as “PÔDO”, the “Controller”, “Platform” or “we”.
INTRODUCTION
PÔDO owns the domain www.getpodo.com of this website or the Web App and any other software developed, operated and/or maintained by PÔDO (hereinafter the “Platform”).
PÔDO's Privacy Policy is hereby made available to the User (hereinafter also referred to as “User”, “Stakeholder” or “you”) in order to describe the personal information we collect, the purpose for which we use it and, in general, the processes and ways in which we treat it during the course of the use and/or the Platform by Users (both registered and unregistered depending on the treatments) during their navigation through the Platform.
PÔDO may make this Privacy Policy available to the User in different languages. In such case, this English version shall prevail in the event of a conflict of interpretation.
PROCESSING OF PERSONAL DATA ON BEHALF OF OUR CUSTOMERS:
When the Platform is integrated by our end customers as part of their business activity under a service contract, the Platform will process the personal data that such customer makes available to us for the provision of services on behalf of such customers, acting in the capacity of Processor.
In such case, the referred customer will be the Responsible for the processing of the personal data that it shares with, or that it enters on the Platform.
The processing of personal data by PÔDO as Data Processor shall not be governed by this Privacy Policy, but by the provisions of the contract for the provision of services between the Platform and the end customer, in accordance with the instructions and purposes specified therein, as well as in the specific Data Processing Agreement and the privacy policy of the end customer that integrates our services, in compliance with current legislation on data protection.
PROCESSING AND PURPOSES FOR WHICH WE PROCESS YOUR DATA AS DATA CONTROLLERS
Treatments that we carry out as Data Controllers:
Functionality of the website
Purpose: to allow the use and navigation through the website by users ensuring the proper functioning, allow updates and technical maintenance, improve the navigability, security and performance of the same.
Categories of data processed:
User Platform Usage Data and application and device data; including the following: browsing and usage data, IP address, usage preferences, visits made, language, device information, browser type, gender, language, device type and operating system, approximate location on region and country access; as well as cookies where applicable; and anonymized statistical data.
Similarly, if the User arrives at the Platform through an external source (such as, for example, through a link from a third-party website or social network), the Controller will collect statistical and anonymous information about the source from which the visitor came in order to better understand how Users discover and reach the Platform and/or to improve the company's marketing and positioning strategies.
Stakeholder Categories: Registered and unregistered users who use the Platform.
Method of collection: shared by the User through navigation through the Platform environment.
Basis of legitimacy: our legitimate interest in ensuring the proper, up-to-date operation and ensuring the improvement and security of the Platform and Users, and in knowing the origin and source from which the User originates; or the consent of the User otherwise (e.g., with respect to cookies that are not necessary to ensure the operation of the Platform).
Retention period: Usage Data will be retained for a maximum of 1 year months from the date of collection. After this period, the data will be deleted unless required by a public authority. Anonymized statistical data may be stored indefinitely as it does not contain personal data.
Platform security and fraud prevention
Purpose: We collect and analyze data from the Data Subject to ensure the security of our Users, prevent fraud, and conduct timely investigations and make use of the information for possible claims in our own interest or in the interest of third parties. This treatment includes:
Traffic data collection: We collect information about visits to our website, including IP addresses, browser type, pages visited, time spent, and other navigational data.
Behavioral Pattern Analysis: We use analysis tools to identify unusual or suspicious patterns of behavior that may indicate fraud attempts or unauthorized access.
Threat Detection: We implement intrusion and other threat detection systems that analyze traffic in real time to identify and block malicious activity.
Identity Verification: We use traffic data to verify the identity of Users to ensure that transactions and accesses are legitimate.
We maintain detailed logs of access and activity on our website to perform security audits and respond quickly to any incidents.
Collaboration with authorities: In case of detecting fraudulent or suspicious activities, we may collaborate with the competent authorities by providing the information necessary for the investigation in compliance with a legal obligation.
These processes allow us to protect the integrity of our website and the security of our Users, ensuring a safe and reliable digital environment.
Categories of data processed: Browsing and usage data, IP address, access logs, failed login attempts and suspicious activity, device information, browser type, device type and operating system, approximate location on region and country access.
Stakeholder Category: Users who make use of the Platform.
Method of collection: shared by the User when browsing the Platform.
Applicable legitimate basis: Fulfillment of legal obligations in relation to access and activity registration. The treatment will be based on the legitimate interest of the Responsible to investigate, detect, prevent and prosecute fraud, protect their interests or those of third parties; as well as to defend their interests against possible claims for breach of contract or applicable regulations by Users and to ensure the proper and secure operation of the Platform, Users and third parties.
Retention period: Access and activity records will be retained for 1 year. After this period, the data may be blocked for the periods provided by law to comply with regulatory obligations and legal statute of limitations if we believe there may be a risk of receiving a claim.
Provision of contracted services:
Purpose:
The processing is carried out in order to ensure the provision of Platform services that allow Users to manage booth reservations through the Platform.
The treatment will include the management of requests, mandates or previous managements and during the contracting and the one to make communications on the operative one of the service.
Likewise, data processing will be carried out to ensure registration, authentication on the Platform and to manage payments, among other derivative processing to ensure the provision of services and execute the contract.
If consent is obtained and the User configures it on his/her device, he/she will be able to receive notifications on his/her device. Likewise, communications may be exchanged with the User through instant messaging applications such as WhatsApp, in the event that the customer contacts the Platform by such means or expressly consents thereto. In this case, the treatment will also be governed by the privacy policy of the WhatsApp provider.
Likewise, in the event that the User decides to use the cafeteria services through the Platform, the User's data and orders placed may be shared with VISIONAIRE US, a company of the NOMAD US, S.L. group that provides such service. The User will be informed of the privacy policy of the company through the Platform.
Likewise, our application uses technology provided by AKILES TECHNOLOGIES S.L. to enable the functionality of opening and closing booths through smart locks, being able to process identification and technical data strictly necessary (for example, access credentials, user ID, opening logs) to ensure the contracted service.
Categories of data processed:
Registration data: User name and password, as well as first and last name and gender.
Contact information: including e-mail address and telephone number.
Professional data: information on professional category.
Service usage data: including reservations made, check-in and check-out times, opening logs, conversations with customer service through any of the contact channels, and any other data generated through the use of the services.
Billing information: Identification data, Tax Identification Number and fiscal address.
Payment data: For the realization of payments will be enabled services of external payment gateway providers, such as Stripe. In this case, the User will share the data directly to that provider, and PÔDO will only receive a confirmation of payment, User identification data, as well as the last 4 digits of the card and CVV code.
Location: the User may voluntarily activate the geolocation option so that the Platform can display the nearest Booths. You can deactivate this function at any time in the corresponding section of the Platform and/or your device.
In case of registration on the Platform from Apple or Google, certain personal data associated with the Google or Apple account will be shared with PÔDO automatically (such as the avatar/image, email and name and surname of the User).
Biometric data: Although the User can enable login through facial face detection, such as “Face ID”, such functionality is enabled through your device or mobile terminal. PÔDO does not store biometric data, you will only receive confirmation from your terminal or device provider that the User is authenticated.
Stakeholder Categories: Registered users who make use of the Platform's services.
Method of collection: directly from the data subject when using the Platform. We may also receive information about payment confirmation from payment gateway service providers or companies that integrate the services within their business activity and for which we act as data processors.
Basis of legitimacy: the processing is necessary for the performance of a contract to which the data subject is a party or for the implementation, at the request of the data subject, of pre-contractual measures.
Retention period: for the duration of the provision of services and, after its termination, your data may be blocked for the periods provided by law to comply with regulatory obligations, including tax, commercial and anti-money laundering regulations, as well as for the period of statutory limitations.
Sending of commercial communications:
Purpose: Sending commercial communications, offers, promotions, or similar, of the products offered by the Responsible, according to the different possibilities:
Communications by e-mail: Sending of promotions and/or offers to the User's e-mail address. The User may object to receiving commercial communications at any time by contacting the email address of the Responsible or, where appropriate, through the enabled option included in the email itself,
Push“ notifications: Sending of promotions and/or offers to the Users” device when they voluntarily configure it and with their consent. Users may stop receiving this type of notifications by configuring their device to do so.
Communications from third parties: Users may receive communications from third parties only when they have previously given their express consent. You may withdraw your consent at any time through the contact addresses of the Responsible.
Personalized communications: the sending of personalized communications according to the interests and preferences of the Users will require the prior consent of the same, and may be withdrawn at any time.
If the User wishes to stop receiving commercial communications, he/she may oppose or withdraw his/her consent at any time by contacting the Responsible Party through his/her postal address, e-mail or through the channels enabled for the different means of communication.
Categories of data processed:
Identifying data: User name.
contact information: e-mail.
data related to the User's preferences, if any.
Stakeholder Category: Users who use the Platform or consent to receive communications.
Method of collection: directly from the User.
Registered users or clients of PÔDO: directly from the Interested Party through their registration on the Platform.
Non-registered users: directly from the data subject through registration in forms, newsletters, and the like.
Basis of legitimacy:
In relation to registered Users or customers: it will be based on the legitimate interests of the Controller in informing Users about contracted or similar products and relevant information, and unless the User objects to such processing.
In relation to Users with whom you do not have a contractual relationship: prior consent will be required.
Consent will also be required for both registered and unregistered Users for the sending of push notifications, personalized communications, and third party communications, until the withdrawal of consent, opposition or account deletion by the User.
Retention period: the data will be processed until the User withdraws his/her consent. Once this period has expired or consent has been withdrawn, the data may be blocked for the legally prescribed periods in order to comply with applicable regulatory obligations and legal statutes of limitation.
Resolution of queries made by the User
Purpose: To ensure communication by Users with the Responsible for customer service inquiries, complaints, or other similar, through any of the contact points of the Responsible including forms, electronic or postal addresses or others made available to the User.
Categories of data processed: identification data, namely name and surname and contact data, including e-mail address and/or telephone number.
Stakeholder Categories: User who formulate the consultation.
Method of obtaining directly from the Users, when they contact directly with the Responsible or through external suppliers subcontracted for this purpose.
Basis of legitimacy: consent of the Users or legitimate interest of the Responsible to answer a query after having received the request.
Retention period: once the purpose for which the data was collected has been achieved, the data will be kept for a maximum period of 24 months, unless for reasons of legitimate interest or legal statute of limitations, the data is required to be kept for a longer period.
Commercial prospecting: contracting of Services:
Purpose: To allow interested parties to contact PÔDO to request a meeting or a trial of the platform, and to collect basic contact information to manage requests made through the website) to display products, commercial offers and manage the possible contracting of services by potential customers.
Data categories: identification data (name and surname; corporate contact data (including e-mail address, telephone number); professional data (job title or position).
Method of collection: Directly from the User when he/she fills in the contact form.
Stakeholder Categories: Data of the Stakeholders who wish to contract the Services or a trial version.
Basis of legitimacy: the processing is necessary for the performance of a contract to which the Data Subject is a party or for the implementation, at his request, of pre-contractual measures; as well as the consent of the Data Subject when he gives his consent by clicking through a form, where appropriate.
Retention period: for the duration of communications with the data subject to fulfill the purposes and, after their termination, for 18 months, or until the data subject revokes his/her consent or objects to the processing. Subsequently, the data may be blocked for the periods provided for by law in order to comply with regulatory obligations, including tax, commercial and anti-money laundering regulations, as well as for the period of time prescribed by law.
Internal analysis and development
Purpose: The Responsible Party may collect and process statistical and anonymized usage data to analyze the behavior and use of the Platform, browsing patterns, gender, language, functionalities used by the User in order to improve the user experience, optimize functionalities, and analyze usage trends; in order to develop new tools or services, etc.
Data categories: Anonymous data on Platform usage, browsing patterns, and functionalities used.
Stakeholder Categories: Registered users and visitors to the Platform (in anonymized format).
Basis of legitimacy: Legitimate interests in analyzing anonymous, statistical and aggregated information to offer improved products and services to Stakeholders and to develop new products.
Method of collection: data shared by the User in connection with the use of the Services.
Retention period: in order to fulfill the stated purpose, the data may be stored and kept indefinitely, always in a dissociated or anonymous form, so that the data subjects cannot be identified.
WHERE DOES YOUR DATA COME FROM?
As a general rule, unless otherwise specified in other sections of this Policy, all data comes from the Data Subject, either by browsing or using the Platform or through a communication made by the User by any of the means made available to him/her.
TO WHOM DO WE DISCLOSE YOUR INFORMATION?
In general, the Responsible will not communicate the User's Personal Data to third parties, except when the provision of a service implies the need for a contractual relationship and such communication is strictly necessary for the management and maintenance of the relationship between the User and the Responsible and/or for the fulfillment of the purposes described in this Policy.
In such cases, the communication will be carried out only for the time strictly necessary to allow the achievement of such purposes, and always in accordance with the principles of the General Data Protection Regulation, through the implementation of appropriate technical and organizational measures to ensure the security and confidentiality of Personal Data. Such measures include the execution of the corresponding data processing contracts with each supplier, which establish obligations equivalent to those assumed by the Controller in terms of data protection. At the end of the provision of the service, the suppliers shall return or delete the Personal Data in accordance with the provisions of such contracts.
In this sense, and exclusively to enable the operation of the Platform and the fulfillment of the purposes described, the Controller may communicate the Personal Data to the following recipients:
Providers of essential services, including computer and technology services, payment gateway, cloud storage, communications delivery, authentication and security services, analytics services, among other similar services that are necessary to ensure the purposes.
Suppliers to whom, if applicable, we subcontract the physical booths or the management thereof.
Smart lock service providers, such as AKILES TECHNOLOGIES S.L.
Cafeteria service providers.
Public authorities, by court order or by legal requirement.
Companies and/or consultants that help us in the management of our services and in the fulfillment of our purposes.
Companies and professional consultants that provide services to the Controller to facilitate the management of the Platform and compliance with its legal, contractual or administrative obligations, such as legal advice, accounting, technical or IT security services.
You may request additional information about the communications made to the Controller through any of the contact points indicated in this Policy.
DO WE TRANSFER DATA TO THIRD COUNTRIES OR INTERNATIONAL ORGANIZATIONS (“TTI”)?
As a general rule, no transfers of Personal Data to third countries or international organizations (“TTI”, hereinafter) are made.
However, in order to ensure the purposes, TTI may be made to our service providers are essential to ensure the purpose for which they were collected, regardless of the fact that PÔDO does not perform such TTI directly, but by the providers.
In such case, the Platform shall choose service providers that comply with the applicable regulations and shall adopt the contractual, technical and organizational measures necessary to ensure an adequate level of protection of personal data in accordance with the applicable regulations (including, where appropriate, the subscription of standard contractual clauses approved by the European Commission or equivalent mechanisms).
In such case, the Controller shall contract with suppliers that comply with the GDPR and by applying some of the safeguards provided for in art. 44 GDPR et seq. to ensure an adequate level of security of the processing of Personal Data, including the adequacy decision (list of countries based on an adequacy decision) or by means of European Commission Standard Contractual Clauses (“STCs”, hereinafter).
The following is a list of suppliers to whom TTI could be performed, as indicated above:
AKILES TECHNOLOGIES S.L,
Microsoft Ireland Operations Limited (Microsoft 365), for the management of internal and external email communications. Although Microsoft Location has its data center within the European Union, its group companies or external suppliers may be located in the U.S. In such a case, TTIs will be carried out through EU TTIs.
Mailgun Technologies, Inc: For bulk mailing and telemarketing services. Although the server is located in Europe, since the headquarters is located in the United States, international data transfers may take place. TTIs may be carried through the implementation of appropriate security safeguards in compliance with the GDPR, through its certification and adherence to the EU-US Data Privacy Framework (link) and through EU TTIs (link).
WhatsApp Ireland Limited WhatsApp. Electronic communication services with Users. TTIs may be made outside the EEA to its parent company Meta Platforms Inc. and group companies (such as WhatsApp LLC) are located in the U.S. TTIs will be made through EU TCTs.
For more information about international data transfers and the specific safeguards applied, you can contact us through the contact details indicated in this Privacy Policy.
DO WE PROCESS SPECIAL CATEGORIES OF PERSONAL DATA?
The Data Controller shall not request or process data of “special category of personal data”, meaning data revealing ”racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data intended to uniquely identify a natural person, data concerning health or data concerning the sex life or sexual orientation of a natural person”, in accordance with Articles 9 and 10 of Regulation (EU) n. 2016/679.
However, in the event that the user decides to share such information, such processing will be carried out in accordance with the user's consent.
TREATMENT MODALITY
The processing of the data provided is based on the principles of lawfulness, transparency, purpose limitation and conservation, data minimization, accuracy, integrity and confidentiality, and will be carried out, in any case, subject to the provisions in this regard in the EU Regulation 2016/679 and Organic Law 3/2018 of December 5, 2018, on the Protection of Personal Data and guarantee of digital rights.
In particular, the processing may be carried out using paper, IT and telematic tools, also in accordance with the provisions of Article 29 of EU Regulation 2016/679 and, in any case, with appropriate means to ensure its security and confidentiality in accordance with the provisions of Article 32 of the same EU Regulation No. 2016/679.
AUTOMATED DECISIONS:
As part of the User's participation in the monthly sweepstakes organized by the Platform, it is informed that an automated decision-making process is applied for the selection of the winner, in accordance with Article 22 of Regulation (EU) 2016/679 (GDPR).
This process is carried out by means of a computer algorithm that automatically randomly assigns a winner among the Users that make up the Top 100 of the Monthly Ranking of their region, giving each of them a 1 % probability of being awarded a prize. Inclusion in the ranking is based on the User's activity, in particular the publication of reviews and the score obtained according to criteria established by the Platform.
This treatment does not produce significant legal effects nor does it affect the User in a similar way, since its only consequence is of a promotional and recreational nature, consisting of the possible obtaining of a prize.
However, in compliance with the GDPR, the User is informed that he/she has the right to: Obtain human intervention by the Controller; express their point of view; and challenge the automated decision taken by the system.
COOKIES:
PÔDO does not currently collect cookies or other similar or analogous tracking technologies. If these are used in the future, the interested parties will be duly informed. You can access the cookie policy through the website.
RETENTION OF YOUR PERSONAL DATA
As a general rule, the Controller will keep your Personal Data only for the time necessary for the purpose for which it was originally collected, and for the maximum periods indicated in each of the processing operations referred to in this Policy.
Conservation periods according to the type of data, purposes and applicable regulations:
Contractual documentation
Documentation associated with the contracts with
Customers
Code of Commerce
6 years (From
termination of the
contractual relationship)
Platform and web users
Identification data, contact information, addresses, email, etc.
RGPD and LOPDGDD
5 years or unless they expressly request deletion.
Traffic data
User ID, IP Address, Phone Number, Date and access logs, etc.
LSSI
12 months
Cookies
Cookies and/or similar
LSSI, Data Conservation Law.
18 months
Internal analysis and development.
Anonymized data
Art. 4.1) RGPD.
Recital 26 RGPD
Indefinite
Statutory limitation period
Generic application
Art. 1.967 Code
Civil
5 years
Once the aforementioned periods have elapsed, the data will be automatically deleted, without prejudice to its subsequent retention blocked when necessary for the fulfillment of certain obligations, by legal provisions or responsibility, or requests and/or orders issued by the Public Administrations and/or Control Authorities, for some of the reasons indicated in the previous sections.
In relation to anonymous and statistical information, the Controller shall apply as described in Recital 26 of the GDPR, which states the following: “Therefore the data protection principles should not apply to anonymous information, i.e. information which does not relate to an identified or identifiable natural person, nor to data rendered anonymous in such a way that the data subject is not, or is no longer, identifiable”. Consequently, this Regulation does not affect the processing of such anonymous information, including for statistical or research purposes.
WHAT ARE YOUR DATA RIGHTS?
In accordance with the GDPR, the Data Subject has the following rights in relation to his or her Personal Data:
access to your data, which you can also consult in the «my data» section,
rectification of your data, because we also want to make sure that your information is accurate and up to date,
deletion of your data,
limitation of the processing of data concerning you,
opposition to the processing of your data, when the legitimacy for the processing of your data is our legitimate interest,
withdrawal of your consent to the processing of your data, where the legitimation for the processing of your data is your consent, and
portability of your data, when the legitimacy for the processing of your data is your consent or the execution of a contract.
To exercise his or her rights, the Data Subject may contact the Controller through the addresses designated in this Policy.
In addition, the Data Subject has the right to file a complaint with the Spanish Data Protection Agency (AEPD) if he/she has doubts or is not satisfied with the exercise of his/her rights or the processing that we carry out, whose contact details are:
Spanish Data Protection Agency -Spain- (AEPD).
Calle Jorge Juan, 6 // C.P.: 28004 - Madrid
Telephone service: +34 901 100 099 // +34 91 266 35 17
https://www.aepd.es