Privacy Policy
Blockema ("Blockema," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Excel and CSV data validation platform and related services (the "Service").
Last updated: August 22, 2026
1. Data Controller
The data controller responsible for your personal data is:
Blockema
Barcelona, Spain
Email: hello@blockema.com
2. Information We Collect
2.1 Account Information
When you create an account, we collect your name and email address.
2.2 Payment Information
Payments are processed by Polar.sh. We do not store your credit card number, CVV, or full payment card details on our servers. Polar.sh handles payment processing in accordance with PCI DSS standards. We retain a transaction record including your name, email, and transaction details as required for accounting and tax purposes.
2.3 Files You Upload
You may upload Excel and CSV files for validation. The handling of these files depends on the validation mode you choose:
- Browser-based validation: Your files are processed entirely in your browser using client-side JavaScript. Your file data never leaves your device and is never transmitted to our servers.
- Server-based validation: Your files are uploaded to our servers for processing. We process the file to perform the requested validation and return the results. Files are stored temporarily on our servers for the duration of the validation process and are permanently deleted within 24 hours of processing, unless a longer retention period is required.
2.4 Usage Data
We automatically collect certain information when you access or use the Service, including:
- IP address
- Browser type and version
- Operating system
- Pages visited and features used within the Service
- Date and time of access
- Referring URL
2.5 Cookies and Similar Technologies
We use cookies and similar technologies to operate the Service and improve your experience. We use:
- Essential cookies: Required for the Service to function properly, including authentication and session management.
- Analytics cookies: To understand how users interact with the Service and to improve its functionality.
We comply with the LSSI-CE (Ley 34/2002, de 11 de julio, de servicios de la sociedad de la información y de comercio electrónico) regarding cookie use. You can manage your cookie preferences through your browser settings.
3. Legal Basis for Processing
We process your personal data under the following legal bases under the General Data Protection Regulation (EU) 2016/679 ("GDPR"):
-
Performance of a contract (Article 6(1)(b) GDPR): Processing your account information, files, and usage data as necessary to provide the Service you have requested.
-
Consent (Article 6(1)(a) GDPR): For analytics cookies and optional communications. You may withdraw consent at any time.
-
Legitimate interest (Article 6(1)(f) GDPR): For improving the Service, ensuring security, preventing fraud, and complying with legal obligations. We balance our legitimate interests against your rights and freedoms before processing.
4. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process validation requests and return results
- Process payments through Polar.sh
- Send transactional emails, including account notifications and validation results, via Resend
- Respond to your inquiries and provide customer support
- Detect, prevent, and address technical issues and security threats
- Analyze usage patterns to improve the Service
- Comply with legal obligations
5. Information Sharing and Disclosure
5.1 Service Providers
We share information with third-party service providers who perform services on our behalf, including:
- Polar.sh — payment processing
- Resend — transactional email delivery
Each service provider is bound by a Data Processing Agreement (DPA) that requires them to process your data only on our instructions and in compliance with applicable data protection laws.
5.2 Legal Obligations
We may disclose your information if required to do so by law or in response to valid requests by public authorities, including to meet national security or law enforcement requirements.
5.3 No Sale of Personal Data
We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
6. Your Rights
Under the GDPR and the Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD), you have the following rights:
- Right of access (Article 15 GDPR) — Request a copy of the personal data we hold about you.
- Right to rectification (Article 16 GDPR) — Request correction of inaccurate or incomplete data.
- Right to erasure (Article 17 GDPR) — Request deletion of your personal data.
- Right to restriction of processing (Article 18 GDPR) — Request limitation of how we process your data.
- Right to data portability (Article 20 GDPR) — Receive your data in a structured, commonly used, machine-readable format.
- Right to object (Article 21 GDPR) — Object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent (Article 7(3) GDPR) — Withdraw consent at any time where processing is based on consent.
- Right not to be subject to automated decision-making (Article 22 GDPR) — Not be subject to decisions based solely on automated processing, including profiling.
To exercise any of these rights, please contact us at hello@blockema.com.
If you are in the European Union and believe your data protection rights have been infringed, you have the right to lodge a complaint with your local supervisory authority. You may also contact the Agencia Española de Protección de Datos (AEPD) at https://www.aepd.es.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption in transit (TLS), access controls, and regular security assessments.
While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the Internet or method of electronic storage is 100% secure.
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Account information: Retained for the duration of your account. Deleted within 30 days of account deletion.
- Payment records: Retained for 7 years as required by Spanish tax law.
- Uploaded files (server-based): Deleted within 24 hours of processing.
- Usage data: Retained for up to 12 months in anonymized form.
- Cookies: See Section 2.5 for cookie-specific retention periods.
9. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, to ensure your data receives an adequate level of protection.
10. Children's Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without verification of parental consent, we will take steps to delete that information promptly. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at hello@blockema.com.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically for any changes.
12. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Blockema
Barcelona, Spain
Email: hello@blockema.com