Privacy policy
This policy explains what data we process when you use Gestise, what for, and what you can ask of us.
Last reviewed: 2026-07-27
Who processes your data
Gestise is the controller of the account and billing data of the service.
For the data you load into the system — your clients, your employees, your documents — we act as processor: it is yours, and we only handle it to provide the service.
What we collect
Account data: name, email, phone, company and language. Needed to create and keep your access.
Usage data: technical access logs (date, IP, browser) that let us detect misuse and debug failures.
Billing data: plan, amounts and payment status. Card details are handled by the payment gateway; we do not store them.
What you load: the contents of your ERP. We do not use it for anything other than serving you.
What we use it for
To deliver the service you contracted, bill it, answer you when you write to support, and meet the legal and tax obligations that apply to us.
We do not sell personal data, nor pass it to third parties for their advertising.
Who we share it with
With the providers needed to operate: cloud hosting, payment gateway and email delivery. Each one handles only what its function requires.
With an authority, when a rule or a court order requires it.
How long we keep it
Your account data, for as long as you hold an active subscription.
When the account closes, we keep what accounting and tax rules require and delete the rest.
You can export your data before closing the account; write to us and we will show you how.
Your rights
You can request access, rectification, erasure, restriction, objection and portability of your data.
Write to privacidad@gestise.com and we will answer. If our answer does not satisfy you, you can turn to your data protection authority.
Security
We encrypt traffic, isolate each company's data and log access. No system is infallible: if a breach affects you, we will tell you.