← Back to home

Privacy Policy

Last updated: 20 May 2026 · GDPR (EU 2016/679) compliant

1. Data controller

The controller of your personal data is Pau Serrano García (sole trader / autónomo), NIF 48059727P, registered at Carrer Orient, 4, 25318 Les Puelles (Lleida), Spain, contact email hello@hmilibrary.com.

2. What data we collect

CategoryDataWhen
AccountEmail, name, password (hashed), optional companyOn sign-up
BillingVAT/Tax ID, billing address, card data (processed by Stripe — we never see it)On subscribing
UsageSymbols downloaded, date/time, truncated IP addressWhile using the app
Functional storageSession token, preferred languageDuring the session

3. Why we use your data

4. Legal basis

5. Who we share your data with

Your data is stored and processed by the following sub-processors:

ProviderPurposeLocation
Supabase Inc.Database & authenticationEU (eu-central-1, Frankfurt)
Stripe Payments EuropePayment processingEU (Ireland) / US (DPF + SCCs)
Cloudflare Inc.Static hosting & CDNGlobal (with SCCs)
Google LLCOAuth (sign-in with Google), optionalUS (with SCCs)

We do not sell or rent your data to third parties for commercial purposes.

6. Retention

7. Your rights

As a data subject, you have the right to:

To exercise any of these rights, email hello@hmilibrary.com with "GDPR" in the subject. We respond within 30 days at most.

If you believe processing does not comply with the law, you may lodge a complaint with your local data protection authority — in Spain, the Spanish Data Protection Agency (AEPD).

8. Security

We apply appropriate technical and organisational measures: encryption in transit (TLS 1.3), encryption at rest, role-based access control, audit logs, encrypted backups. Passwords are stored as bcrypt hashes — never in plain text.

9. Minors

HMI Library is aimed at professionals and does not knowingly collect data from minors under 16. If you believe a minor has provided us data, contact us and we will delete it.

10. Changes to this policy

If we update this policy we will notify you by email to the address associated with your account at least 15 days in advance when the changes affect material rights.