Trimestria

Privacy policy

Version 1.1, in force from 28 September 2026

This translation is provided for your convenience. Only the Spanish version is legally binding. Read the Spanish version

This policy explains which personal data Trimestria processes, why, on which legal basis, for how long and how you exercise your rights, under Regulation (EU) 2016/679 (GDPR, RGPD in Spanish) and Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).

1. Who the controller is

The controller of your data is the provider of the service:

  • Provider: Lebediev Tymofii
  • NIF: Z0361888B
  • Address: Calle Valparaíso 7, 6º B, 33008 Oviedo, Asturias
  • Email: legal@trimestria.es

We have not appointed a data protection officer. Any question about your data is handled at the email address above.

2. What it covers

This policy covers the Trimestria application, at app.trimestria.es, its website, trimestria.es, which sets no cookies and runs no scripts, and the data of the accounts created in it. Trimestria is software for a self-employed person (autónomo) in Spain to keep their books and prepare their tax returns.

3. Which data we process

We process only the data needed to provide the service:

  • Account data: the nickname, the email address, the name you give us and the date you signed up. We do not keep your password, only a digest of it from which it cannot be recovered.
  • Sign-in data: the secret of the second factor, if you turn it on, stored encrypted; of your passkeys, only the public part; and the open sessions, with the date each began and was last used.
  • If you sign in with Google: the identifier of your Google account and the verified email address Google gives us. We do not receive your Google password or any other data of your Google account. Section 4 explains it.
  • The account photo, if you choose to add one: your browser cuts out a small circle and only that reaches the server, without the metadata of the file. Only you see it.
  • Data of your activity: the tax details of your business (name, NIF, region, VAT regime, IRPF method, IAE heading and start date), the income and expense entries, the invoices, your clients and suppliers, the bank statements you import, the documents you upload and the returns prepared from all of it.
  • Help requests: the text you write to us, the reply address, the language and the context of the screen you write from (the screen, the period and the modelo), never the amounts or the content of your documents.
  • Security data: to stop improper sign-in attempts we count failures by IP address, but of the address we keep only a keyed digest from which it cannot be read. We also record the actions on your account and your business (who did what and when), without keeping the values or the IP address.
  • Your preferences: language, theme and interface mode.

When you record data about other people, such as your clients or suppliers, you are the one who decides to process it. We process it on your behalf, as a processor, under the conditions of section 6 of the Terms of service.

4. Google user data

Signing in with Google is optional. When you choose it, Trimestria asks Google only for the openid and email permissions, the basic ones for signing in, and receives from Google:

  • the identifier of your Google account, which tells us it is the same Google account each time;
  • the email address of your Google account and whether Google has verified it; we accept only a verified address;
  • when you confirm a sensitive action with Google, the time you last signed in to Google, which is used for that check and not kept.

We do not ask Google for your name, your photo, your contacts, your emails, your files, your calendar or any other data of your Google account, and we never receive your Google password. Google’s answer is read once, at sign-in: we keep no Google access or refresh token, so Trimestria cannot reach your Google account afterwards.

We use this data only to create your account, to sign you in, to bind or unbind your Google account in Settings and to confirm it is you before a sensitive action. If you create your account with Google, the verified address also becomes the email address of your account.

The identifier and the address are kept with your account while your Google account stays bound to it, together with the date it was bound and the date it was last used. Unbinding it in Settings, Security, which is possible when the account has another way in, deletes them at once, and they are deleted with your account when it is deleted. A sign-up with Google that is not finished expires after fifteen minutes and is deleted afterwards.

We do not sell this data or transfer it to anyone, except to IONOS, which stores it for us as the hosting provider (section 6), and to authorities when a law obliges us. We do not use it for advertising, or to develop, improve or train artificial intelligence or machine learning models. Nobody reads it, except to help you when you ask, to keep the service secure, or when the law requires it.

Trimestria’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

5. Why we process it and on which legal basis

  • To provide the service: create and keep your account, keep your books, calculate and prepare your returns and store your documents. Legal basis: the performance of the contract you accept when you sign up (article 6.1.b GDPR).
  • To protect the service and your account: detect improper sign-in attempts, check that a new password is not on public lists of breached passwords (the check runs on our own server) and record the actions on the account. Legal basis: our legitimate interest in the security of the service (article 6.1.f GDPR).
  • To answer your help requests and the exercise of your rights. Legal basis: the performance of the contract and compliance with legal obligations (article 6.1.b and 6.1.c GDPR).
  • To keep what the law requires to be kept and to be able to prove what we did if a claim arises. Legal basis: compliance with legal obligations and our legitimate interest (article 6.1.c and 6.1.f GDPR).
  • To send you the emails of the service itself, such as confirming your address or recovering access. Legal basis: the performance of the contract. We send no advertising.

We do not sell your data, show advertising or build commercial profiles. We take no automated decisions with legal effects on you: the application calculates from what you record, but reviewing and filing a return is your decision. Today we use no artificial intelligence to process your data; if that changes, we will say so here first.

6. Who else processes your data

We disclose your data to no third party unless the law requires it. These take part in providing the service:

  • IONOS, the hosting provider: the application, the database, the documents and the backups are on a server of theirs in their data centre in Logroño (Spain). It acts as a processor.
  • Google, only if you choose to sign in with Google: Google identifies you and gives us back the identifier and the email address. In that step Google processes your data as a controller, under its own privacy policy, and may do so outside the European Economic Area.
  • Sending email: today the application sends no email. When it starts to, we will use Amazon Simple Email Service, from Amazon Web Services, in its Spain region, and we will say so here first.
  • The Spanish Tax Agency (Agencia Estatal de Administración Tributaria): today the application files nothing with the AEAT; you file your returns yourself. If we later offer filing from the application, data will be sent only when you instruct it.
  • Authorities, judges and courts, when a law obliges us to disclose data to them.

Apart from what is said about Google, your data is stored and processed in Spain, within the European Union.

7. How long we keep it

  • Account data, for as long as the account exists.
  • The books of your activity, six years from the last entry, as article 30 of the Spanish Commercial Code (Código de Comercio) requires.
  • The documents and data that support a return, four years from the end of the period to file it, which is the limitation period of article 66 of the General Tax Law (Ley General Tributaria), or longer if that period is interrupted.
  • The record of actions, for as long as what it proves is kept and, after that, for as long as a claim about it can be brought.
  • The photo, until you remove it or the account is closed. Removing it deletes it for good.
  • A session open in a browser lasts at most 30 days.
  • Help requests, for as long as needed to answer them and settle any matter that arises from them.
  • Backups are kept for fourteen days.

If you ask us to delete your account, we close it and delete what no law requires us to keep. What must be kept is blocked, as article 32 of the LOPDGDD provides: it is used only to meet legal obligations or deal with claims, and it is deleted when its period ends. We will tell you what remains and until when.

8. Your rights

At any time you can ask us for:

  • Access: to know which of your data we process. In Settings, Your data shows what we hold about you and about your business.
  • Rectification: to correct inaccurate data. You can correct most of it yourself in the application.
  • Erasure: to delete your data, within the limits of the section above.
  • Restriction: to stop using your data while a claim about it is being resolved.
  • Portability: to receive your data in a structured format. In Settings, Your data you can download a file with the data of your business, in CSV and JSON tables, together with your original documents.
  • Objection: to stop processing your data based on our legitimate interest, unless there are compelling legitimate grounds or we need it for a claim.

Write to us at legal@trimestria.es from the address of your account, or from Help inside the application. We will answer within one month, which may be extended by two further months if the request is complex, as article 12 GDPR provides. Exercising your rights is free.

If you are not satisfied with our answer, you can lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es, calle Jorge Juan 6, 28001 Madrid).

9. How we protect your data

The connection is encrypted. Passwords are stored with a slow hashing algorithm, and those found in known breaches are refused. You can protect your account with a second factor or with passkeys. Each account can read only its own data, and every access of the support team to an account is recorded, with its reason, in Settings, Who reached your account.

10. Cookies and storage in your browser

We use only what is strictly necessary for the application to work, so we do not need your consent (article 22.2 of Law 34/2002, LSSI):

  • The session cookie, __Host-trimestria_session, which keeps you signed in. It lasts at most 30 days.
  • The cookie __Host-trimestria_google, only while you sign in with Google. It lasts a few minutes.
  • In the storage of your browser we keep your preferences (language, theme, mode and side panel), your recent searches, whether this device holds a passkey or you signed in with a password, to suggest the way in, and whether you have already closed a notice. All of this stays in your browser.

We use no analytics or advertising cookies.

11. Minors

The service is meant for adults who carry on an economic activity and is not directed at anyone under 18.

12. Changes to this policy

If we change this policy, we will publish the new version here with its date. If the change is significant, we will let you know in the application before it applies.