Last updated: 25 July 2026
This policy explains how [COMPANY LEGAL NAME] ("CasaReel", "we") processes personal data when you use casareel.io and app.casareel.io, in accordance with the EU General Data Protection Regulation (GDPR). Data controller: [COMPANY LEGAL NAME], [REGISTERED ADDRESS], Spain — hello@casareel.io.
Account data: name, email address, language preference, and — if you sign in with Google — the identifiers Google shares with us. Organisation data: organisation name, branding (logo, colours), members and roles. Content: property photos, property details and generated videos. Billing data: subscription plan, invoices, billing address and VAT number — processed by Stripe; we never see or store card numbers. Technical data: log and usage data needed to run and secure the Service.
We process data to provide the Service (contract performance), to bill you (contract and legal obligation), to secure and improve the Service (legitimate interest), and to communicate with you about the Service (contract; marketing only with your consent).
We use a small number of processors to run the Service: cloud hosting and database (Supabase), static-site hosting (Netlify), payments (Stripe), authentication (Google, if you choose Google sign-in), and AI video-generation providers that process the photos you submit solely to produce your videos. Processors are bound by data-processing agreements. Where data leaves the EU/EEA, transfers rely on adequacy decisions or standard contractual clauses.
We keep your data while your account exists. After account deletion we delete or anonymise personal data within 30 days, except invoicing records we must keep under Spanish tax law and minimal logs kept for security. You can delete individual photos and videos at any time in the app.
You have the right to access, rectify, erase, restrict, object to processing of, and port your personal data, and to withdraw consent at any time. Write to hello@casareel.io. You may also lodge a complaint with the Spanish supervisory authority (AEPD, aepd.es).
Data is encrypted in transit, access is role-based and limited to what each organisation's members may see, and payment data is handled exclusively by Stripe (PCI-DSS certified).
We will announce material changes to this policy by email or in the app before they take effect.