Privacy Policy
Last updated 7 October 2026
What personal data Folio collects, why, who sees it, and the rights you have over it under the EU General Data Protection Regulation (GDPR) and Spain's data protection law (LOPDGDD).
- 1. Who is responsible for your data
- 2. What we collect
- 3. Why we use it, and on what basis
- 4. AI processing
- 5. Company verification
- 6. Who can see your data
- 7. Transfers outside the EU
- 8. How long we keep it
- 9. Your rights
- 10. Security
- 11. Age
- 12. Cookies
- 13. Changes to this policy
1. Who is responsible for your data
The controller of your personal data is [TO FILL: legal name of the operator] ([TO FILL: NIF/CIF]), [TO FILL: registered address], Madrid, Spain. For anything about your data, write to [TO FILL: privacy email, e.g. privacy@folio.app].
2. What we collect
| Data | Examples | Where it comes from |
|---|---|---|
| Account | Name, email, password (stored hashed), whether you're a student or a client. Students also confirm an IE University email, which becomes the email they sign in with | You, when you sign up |
| Signing up or in with LinkedIn, connecting GitHub | Name, email, profile picture link, account ID; your GitHub username | LinkedIn or GitHub, when you connect them |
| Student profile | Photo, programme and year, links, CV, the strengths we read from your CV, certificates from other courses (with their links or uploaded copies), PayPal email for payouts | You |
| Client profile | Company name, website, tax ID (CIF), description, logo, files and verification documents | You |
| Projects and applications | Briefs, pitches, interviews, milestones, deliveries and files, requested changes | You and the other side of the project |
| Messages | Chat messages and attached files | You and the people you talk to |
| Credentials | Rating, review, signatures (drawn), dates | The client and the student |
| Payments | Amounts, payment status, PayPal transaction IDs, your PayPal email. We never see card or bank details | You and PayPal |
| Technical | IP address, browser, sign-in times, error logs | Your device, automatically |
3. Why we use it, and on what basis
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Running your account and the service: profiles, applications, projects, messages, credentials | Contract (6.1.b) |
| Taking, holding, releasing and refunding payments | Contract (6.1.b) |
| Verifying clients before their projects go live, and preventing fraud and abuse | Legitimate interest in a safe marketplace (6.1.f) |
| Confirming that students study at IE University, by emailing their IE address | Contract (6.1.b): Folio is for IE students |
| Reading your CV with AI to show your strengths and match projects | Contract (6.1.b), as a feature you choose by uploading a CV |
| Drafting a brief from a client's idea with AI | Contract (6.1.b) |
| Keeping payment and accounting records | Legal obligation (6.1.c) |
| Service emails (confirming your email, important changes) | Contract (6.1.b) |
| Security, debugging and keeping Folio running | Legitimate interest (6.1.f) |
We don't sell your data, show ads, or use it for marketing without asking you first.
4. AI processing
When you upload a CV, its text is sent to Google's Gemini service to pick out your fields and skills. When a client describes a project idea, that text is sent to Gemini to draft a brief. Google processes this for us as a service provider and doesn't use it to train its models. The results are suggestions shown to you; no decision about you is made by AI alone. You can object to the CV analysis by not uploading a CV or by asking us to delete it.
5. Company verification
We check every company that wants to post projects, in two stages. This protects students from fake or fraudulent offers and makes sure we deal with someone who can act for the company.
| When | What we ask for | What we check |
|---|---|---|
| Before the company can publish | Legal name, CIF, website and description; optionally the founder's LinkedIn (connected, or a profile link) | Against public records (for example the company registry and the website) that the company exists and the person is real |
| Before the company's first payment | Company registry extract (nota simple); ID of the representative (DNI, NIE or passport) | The company's legal details and who can represent it, and that the person signing up is that representative |
A student startup (an IE student's own startup that isn't registered yet) has no CIF or registry extract. Instead we ask for the founder's IE email, which we write to once to confirm the founder is an IE student, and before the first payment only the founder's ID. The IE email isn't shown to students or anyone else, and is kept and deleted like the documents below.
- Legal basis: our legitimate interest in keeping the marketplace safe from fraud (GDPR art. 6.1.f), and taking the steps you ask for before entering into our contract (art. 6.1.b).
- Who sees them: only you and Folio's review team. Documents are stored in a private storage area that other users, including students, can't open. Students only see your company name, logo, description and the verified badge.
- What we don't do: we don't share them with anyone else, use them for marketing, or make the verification decision automatically. A person reviews every company.
- Where: with our database and storage provider, Supabase ([TO FILL: Supabase region, e.g. EU (Frankfurt)]), encrypted in transit and at rest.
- How long: while your company account is open, so we can re-check details if something changes or a dispute comes up. When you close the account, they're deleted within 30 days, unless we need them to deal with a legal claim already under way.
- Your control: you can replace or remove the documents yourself until your first payment. After that, ask us at [TO FILL: privacy email, e.g. privacy@folio.app] to see, correct or delete them.
- Progress records: we note when each verification step is completed (for example when the details were filled in or the documents uploaded), to see where companies get stuck and make the process easier.
7. Transfers outside the EU
Some providers above are based in the United States or may process data there. Where that happens, the transfer is covered by the EU–US Data Privacy Framework or by the European Commission's Standard Contractual Clauses. Ask us for a copy of the safeguards.
8. How long we keep it
- Your account and profile: while your account is open. When you close it, we delete it within 30 days (backups roll over within a further 30 days).
- Company verification documents: while the company account is open, then deleted within 30 days of closing it (see Company verification).
- Credentials: deleted with the student's account, after which the verification link stops working.
- Projects, messages and files you share with another user: kept while either side's account is open, so the other side keeps their record, then deleted.
- Payment records: kept for 6 years, as Spanish commercial and tax law requires.
- Technical logs: up to 90 days.
9. Your rights
You can ask us to:
- give you a copy of your data, or send it to you in a portable format;
- correct it (you can also edit most of it on your profile);
- delete it, or restrict how we use it;
- stop using it where we rely on legitimate interest.
Email [TO FILL: privacy email, e.g. privacy@folio.app] from the address on your account. We reply within one month. If you're unhappy with how we handle your data, you can complain to the Spanish data protection authority, the AEPD, or the authority where you live.
10. Security
Data is encrypted in transit, passwords are stored hashed, files such as CVs and documents are private and only shared through short-lived links, and database rules limit each user to their own data. No system is perfect: if a breach affects you, we'll tell you and the authorities as the law requires.
11. Age
Folio is for people aged 18 and over. We don't knowingly collect data from anyone younger; if we learn we have, we delete it.
13. Changes to this policy
If we change how we use your data in a significant way, we'll tell you by email or in Folio before it applies. The date at the top shows the current version.