Última actualización: 11 July 2026
This policy explains how we process personal data on the coordinat.io platform and the coordinat Guard browser extension, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
coordinat.io is a product brand of OWIUS TECHNOLOGIES, S.L. References in this document to "coordinat.io" are understood as referring to that company as the controller.
coordinat.io acts in a dual role depending on the data:
| Data category | Purpose | Legal basis |
|---|---|---|
| Account data (name, work email, hashed password, organization, role) | Create and manage the account, authenticate access, provide the service | Performance of contract (Art. 6.1.b) |
| Usage and log data (AI requests, model used, cost, audit trails, data-protection events) | Provide governance, cost control, audit and security features | Contract and legitimate interest (Art. 6.1.b, 6.1.f) |
| Content sent to AI (prompts, files, responses) | Process the user request through the gateway to the chosen AI provider | Processed as processor, on behalf of the customer |
| Billing data (plan, payments) | Manage the subscription and meet tax obligations | Contract and legal obligation (Art. 6.1.b, 6.1.c) |
| coordinat Guard extension data (see section 8) | Detect sensitive data and give the organization visibility of external AI usage | Processed as processor, on behalf of the employer |
| Commercial contact data (forms, website chat) | Handle enquiries and information requests | Consent and legitimate interest (Art. 6.1.a, 6.1.f) |
coordinat.io is a governance layer: the content a user submits is routed to the relevant AI provider (see section 6). We apply data-loss-prevention (DLP) controls that may warn, anonymize or block sensitive data according to the organization's policy. We do not use customer content to train our own models, nor do we share it with third parties beyond the AI provider needed to fulfil the request.
Some AI providers may process data outside the EEA; in that case processing relies on appropriate safeguards (EU standard contractual clauses). The current list of sub-processors is available to customers on request at privacidad@coordinat.io. We do not sell personal data.
You may exercise the rights of access, rectification, erasure, objection, restriction and portability, and withdraw consent, by writing to privacidad@coordinat.io. If the processing is carried out by your organization (for example, Guard extension data or AI content), address your request to your company as controller; we will help route it. You may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
Guard analyses, locally, the text you are about to send on public AI sites (ChatGPT, Claude, Gemini, Copilot, Perplexity, DeepSeek) to detect sensitive data (national ID, tax ID, IBAN, cards, emails, keys) and, depending on policy, warn, anonymize or block the submission. This analysis happens entirely on your device.
If you sign in with your corporate account, Guard syncs your organization's policy and records usage events. By default each event contains only: the AI tool used, the timestamp and the type of data detected (e.g. "national ID"), linked to your account. The content of your messages is not recorded, unless your organization's administrator explicitly enables the option to store an excerpt. Without a connected account, the extension sends no data to any server.
When a company deploys Guard, the company is the controller and must inform its staff of the recording in accordance with employment and data-protection law. coordinat.io acts as processor.
We apply technical and organizational measures to protect data: encryption in transit, encryption of credentials and sensitive secrets, role-based access control, per-organization isolation and audit logs.
We may update this policy to reflect legal or service changes. The current version will be published on this page with its update date.