Privacy policy
What personal data we process, for what purposes, on what legal basis, who we share it with, how long we keep it and how to exercise your rights.
Last updated: 24 September 2026
Data controller
Tarraconsulting International S.L., tax ID (NIF) B43758671, is the owner of this website and the controller of your personal data. Registered address: Carrer de Josep Maria de Sagarra, 12, 43007 Tarragona (Spain) Phone: +34 977 223 124 Email: hola@exporta.ai Exporta.ai is not required to appoint a data protection officer. For any privacy matter, write to us at the address above with the subject "Data protection".
Who this policy applies to and our role
This policy applies to the data we process as controller: website visitors, people who contact us or request a demo, registered users of the application, customers and their representatives, and people invited to an account. When a customer company stores data about its own contacts in Exporta.ai (CRM, trade fairs, notes, verification lists, messages), the customer company is the controller of those data and Exporta.ai acts as processor, in accordance with the Data processing agreement. If your data are in the CRM of an Exporta.ai customer, see the section "If you are a contact of one of our customers".
What data we process
• Account data: first name and surname, email address, password (managed by our authentication provider; we cannot see it), phone number, LinkedIn profile, profile photo and language. If you sign in with Google or Microsoft, we receive your name, email address and photo from them. • Company data: name, website, sector, country, description, products, target markets, ideal customer profiles and logo. • Billing data: plan, billing period, subscription status, credit history, tax and billing details. Card details are processed directly by Stripe; Exporta.ai does not store them. • Usage data: actions performed, credit consumption, technical and security logs (IP address, browser, date and time, request identifier), report ratings and communications with support. • Content you generate: market reports, conversations with the Xport assistant, email and LinkedIn drafts, templates, translations and files you upload. • Browsing and analytics data, only with your consent where required by law (see the Cookie policy). We do not process special categories of data (health, beliefs, etc.) and we ask you not to enter them into the platform.
Why we use them and on what legal basis
• To create and manage your account, provide the contracted service, manage credits, payments and taxes and give you support. Basis: performance of the contract (Art. 6(1)(b) of Regulation (EU) 2016/679, the General Data Protection Regulation or "GDPR") and legal accounting and tax obligations (Art. 6(1)(c)). • To send you service communications: invitations, balance or credit expiry alerts, reports ready, payment incidents, plan changes and the welcome guide during your first days. Basis: performance of the contract. • To maintain the security of the platform, prevent fraud and abuse, and audit staff access. Basis: legitimate interest (Art. 6(1)(f)) and the legal obligation to apply security measures (Art. 32 GDPR). • To analyse use of the platform in order to improve it and measure its commercial performance (which features are used, consumption by plan). Basis: legitimate interest in improving a B2B service; you may object by writing to us. • To handle enquiries and demo requests. Basis: your consent or the pre-contractual steps you ask us to take (Art. 6(1)(a) and 6(1)(b)). • To send you commercial communications about Exporta.ai: if you are a customer, on the basis of legitimate interest and in accordance with Art. 21(2) LSSI-CE; otherwise, only with your consent. You may unsubscribe at any time. • Web and product analytics by means of non-essential cookies. Basis: your consent, which you may withdraw whenever you wish. • To respond to legal requirements and to establish, exercise or defend claims. Basis: legal obligation and legitimate interest. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). Fit scores and AI suggestions are aids for the user, who makes the decision.
Artificial intelligence
Several features use third-party artificial intelligence models (market reports, tariff classification, enrichment, message drafting, the Xport assistant, voice note transcription, business card reading). To provide them, we send the model the information needed for each task, through the OpenRouter platform. Exporta.ai does not use your data or your contacts' data to train its own models, nor does it authorise providers to use them for that purpose. The full terms are set out in the Terms of use of artificial intelligence.
Customer search and contact enrichment
Exporta.ai allows its customers to search for companies and professional contact persons (name, job title, company, country, LinkedIn profile and business email or phone) in third-party commercial databases, mainly Apollo.io and FullEnrich, and to complete a contact's record with publicly available professional information. These searches are carried out at the request and on behalf of the customer, who is responsible for the use it makes of the data: it must have a legal basis (normally legitimate interest for business contacts, Article 19 of the Spanish Organic Law 3/2018 on Data Protection and Guarantee of Digital Rights, "LOPDGDD") and inform the person in accordance with Art. 14 GDPR. The data providers are responsible for their own databases. Exporta.ai does not maintain its own database of people: it stores the results in the customer's account and automatically deletes search results that the customer does not add to its CRM within 90 days. It also honours each customer's suppression lists so that anyone who has asked not to be contacted is not shown or charged for again.
If you are a contact of one of our customers
If a customer company of Exporta.ai has contacted you or holds your data in its CRM, that company is the controller and the first party you should contact. If you prefer to write to us (hola@exporta.ai), we will forward your request to the relevant company and help it to respond. If you ask not to be contacted, the company may add you to its suppression list, which stores an encrypted fingerprint (hash) of your email address and, where applicable, the data provider's identifier or your LinkedIn profile, solely to prevent you from being added again. You may also exercise your rights directly with the source data providers (including Apollo.io, FullEnrich, Icypeas and Hunter) in respect of their databases.
Who we share data with
We do not sell personal data. We share them only with providers that help us deliver the service, under data processing agreements, and with public authorities or courts where required by law. The main ones are: • Supabase (database, authentication and file storage; Ireland region, EU). • Vercel (hosting of the website and the application; Dublin region, EU). • Stripe (payments, invoicing and taxes). • OpenRouter and, through it, the providers of the AI models we use at any given time (including Google, Anthropic, OpenAI, DeepSeek and Xiaomi). • Apollo.io, FullEnrich and Dropcontact (search for companies and people and finding business email addresses). • looot.ai and, through it, Icypeas and Hunter (search for companies and people, finding business email addresses and reading public web pages). • MillionVerifier (verification of email lists you upload). • DeepL (translation of documents you upload). • Firecrawl (reading public web pages, such as exhibitor directories). • Resend (sending transactional emails) and Microsoft 365 (team email). • PostHog (product analytics; servers in the EU). • Clientify and Google Tag Manager (website analytics and attribution, only with consent; demo booking). • Google and Microsoft, if you sign in with their accounts. The full, up-to-date list of sub-processors is set out in the Data processing agreement. We may also disclose data to a potential purchaser or successor of the business, with the same safeguards, and to professional advisers bound by confidentiality.
International transfers
Platform data are hosted in the European Union. Some providers (for example, OpenRouter and the AI model providers, Apollo.io, FullEnrich, Firecrawl, Resend or Stripe) may process data outside the European Economic Area, mainly in the United States. In such cases, the transfer is based on an adequacy decision (such as the EU-U.S. Data Privacy Framework for participating companies) or on standard contractual clauses approved by the European Commission, with any supplementary measures that may be appropriate. You may ask us for more information about the safeguards applied.
How long we keep them
• Account and company data: for as long as the account is active. If you delete the account or the company, they are erased, except for what we are required by law to keep. • Billing data and accounting records: 6 years (Spanish Commercial Code, Código de Comercio) and 4 years for tax purposes (General Taxation Act, Ley General Tributaria), blocked. • Audit logs: write operations, 6 years; read operations, 12 months. • Items deleted from the CRM (bin): permanently erased after 30 days. • People search results not added to the CRM: 90 days. • A contact's automatic enrichment profile: 30 days. • Details of email verifications: 90 days (only the counts are kept). • Enquiries and demo requests: up to 18 months from the last contact. • Suppression lists: for as long as the customer's account exists, to ensure that objections are honoured. Once those periods have elapsed, the data are erased or anonymised.
Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw your consent at any time, by writing to hola@exporta.ai. We will reply within one month, which may be extended by a further two months in complex cases. Within the application, administrators can export their company's data and delete the company or the account in Settings. If you consider that we have not properly handled your rights, you may lodge a complaint with the Spanish Data Protection Agency, Agencia Española de Protección de Datos (AEPD, www.aepd.es).
Security
We apply technical and organisational measures appropriate to the risk: encryption in transit, isolation of each customer's data, access control with two-step verification, audit logs, provider management and an incident response procedure. We describe them in detail in the Information security policy.
Minors
Exporta.ai is a service for businesses and professionals. It is not directed at persons under 18 years of age and we do not knowingly process their data.
Changes to this policy
We may update this policy to reflect legal or service changes. We will publish the new version with its date and, if the changes are significant, we will notify you by email or within the application before they take effect.