RuumRuum
SolutionsProductPricingDemo
Log inTry Ruum
Back to home

Privacy Policy

Version 1.0 · Last updated: 21 June 2026

On this page
  • 1. Data controller
  • 2. Who this Policy applies to
  • 3. Data we process
  • 4. Purposes, legal bases and retention (GDPR table)
  • 5. Aggregated, anonymised data and market intelligence
  • 6. Artificial intelligence
  • 7. Recipients and processors
  • 8. International transfers
  • 9. Retention periods
  • 10. Rights of users
  • 11. Automated decisions and profiling
  • 12. Minors
  • 13. Security
  • 14. Changes to this Policy

This Policy explains how Ruum processes the personal data of the people who use the Service, in accordance with Regulation (EU) 2016/679 (GDPR), Organic Law 3/2018 (LOPDGDD) and the applicable electronic communications regulations.


Table of contents

  1. Data controller
  2. Who this Policy applies to
  3. Data we process
  4. Purposes, legal bases and retention (GDPR table)
  5. Aggregated, anonymised data and market intelligence
  6. Artificial intelligence
  7. Recipients and processors
  8. International transfers
  9. Retention periods
  10. Rights of users
  11. Automated decisions and profiling
  12. Minors
  13. Security
  14. Changes to this Policy

1. Data controller

  • Controller: Daniel Gil Alegre (self-employed) — NIF/NIE 71364447R
  • Address: Calle Ramón Menéndez Pidal 7, 09002 Burgos (Spain)
  • Privacy email: privacy@ruum.es
  • Data Protection Officer (DPO): not appointed in the current phase. Its appointment will be assessed if the nature, scope or purposes of the processing require it under Art. 37 GDPR.

2. Who this Policy applies to

This Policy applies to:

  • Professional users: people who create an account and use Ruum (account holders, members of a company, collaborators).
  • The professional user's clients and third parties: people whose data the user enters into Ruum (e.g. end clients of a quote). With respect to this data, the professional user acts as controller and Ruum as processor (see the DPA).
  • Quote recipients: people to whom a quote is shared for viewing, acceptance or rejection. If they have the status of consumer, the Terms for quote recipients also apply to them.
  • Leads and visitors: people who request information, a demo or leave their data in forms.

3. Data we process

Depending on how you use the Service, we may process:

  • Identity and account: first and last name, email address (and its verification status), phone (and its verification status), password (always stored encrypted using hash functions, never in plain text), roles, avatar, language, time zone, onboarding status and audit metadata (creation, modification and deactivation dates).
  • Professional profile: specialties, the business's digital maturity and stated needs.
  • Company / company account: trade or corporate name, description, logo, contact details, tax and operating address, geographic coordinates and placeId (if you use autocomplete), tax data (NIF/CIF/VAT, currency, billing address), legal form, size, project volume, unit system and margin policies.
  • Team and collaboration: emails of invited people, roles, invitation status, invitation relationships and access permissions.
  • Clients and third parties: name, email, phone, NIF/CIF, corporate name, type (individual/company), internal notes, role in the project, change-request messages, viewing/acceptance/rejection dates, verification codes (stored encrypted using hashing).
  • Projects and works: reference, name, description, notes, status, priority, dates, type of property and intervention, year of construction, area, address and coordinates, spaces, elements and measurements.
  • Quotes and costs: reference, name, commercial status, cost and price totals, chapters, line items, resources (materials, labour, machinery, subcontractors, services, management), units, quantities, unit costs and version history.
  • Marketing and leads: name, email, phone, professional role, team size, projects managed, stated frustrations/motivations, source (Meta, web or others), UTMs, campaign/ad/form identifiers, commercial status, tags, follow-up notes and import data.
  • Communications: transactional emails, in-app notifications and (in the future) SMS and push notifications. Includes one-time codes (OTP), new-device notices, verifications and invitations.
  • Security and technical logging: IP address, user agent, device fingerprint (hash), session and trusted-device tokens, OTP audit logs, business events and error logs.
  • Analytics and observability: product usage and error diagnostics data, and data stored on your device (cookies and local storage), as detailed in the Cookie Policy.

4. Purposes, legal bases and retention (GDPR table)

Data categoryPurposeLegal basisRetentionProcessors / subprocessorsCurrent / Planned
Identity and accountCreate and manage the account; authenticationPerformance of the contract (Art. 6(1)(b))While the account is active; after deactivation, deletion within the period in clause 9Neon, Render, VercelCurrent
Professional profilePersonalise the Service and onboardingPerformance of the contract (Art. 6(1)(b))Life of the accountNeon, RenderCurrent
Company / company accountManage the company and collaborationPerformance of the contract (Art. 6(1)(b))Life of the accountNeon, Render, Google Maps/Places (autocomplete)Current
Tax and billing dataBilling, accounting and tax obligationsLegal obligation (Art. 6(1)(c))Up to 6 years (Commercial Code; tax regulations)Neon, RenderCurrent
Team and collaborationInvitations, roles and permissionsPerformance of the contract (Art. 6(1)(b))Life of the accountNeon, Render, Mailjet (invitations)Current
Clients and third parties of the userManage the user's clients and quotesInstruction of the professional user (Art. 28); legitimate interest of the professionalAccording to the professional user's instructionsNeon, RenderCurrent
Projects and worksCore of the Service: project managementPerformance of the contract (Art. 6(1)(b))Life of the accountNeon, Render, Google Maps/PlacesCurrent
Quotes and costsCore of the Service: creating quotesPerformance of the contract (Art. 6(1)(b))Life of the accountNeon, RenderCurrent
Sharing quotesAllow viewing/accepting/rejecting quotesPerformance of the contract; legitimate interest (Art. 6(1)(f))Life of the account or until the link is revokedNeon, Render, MailjetCurrent
Marketing and leadsAcquisition and commercial follow-upConsent (Art. 6(1)(a))24 months from the last interaction; afterwards deleted or anonymisedMailjet, Meta (lead source)Current
Transactional communications (OTP, verifications, notices)Security and provision of the ServicePerformance of the contract; legitimate interest in security (Art. 6(1)(f))As long as necessary; OTP audit logs up to 12 monthsMailjetCurrent
Security and technical logging (IP, UA, fingerprint, tokens, audit)Security, fraud prevention and integrityLegitimate interest (Art. 6(1)(f)); legal obligation where applicableUp to 12 monthsRender, Neon, MaxMind GeoLite2Current
Product analyticsUnderstand usage and improve the ServiceConsent (Art. 6(1)(a))Provider's default retentionPostHogCurrent
Error diagnosticsDetect and fix errorsLegitimate interest (Art. 6(1)(f))Provider's default retention (approx. 90 days)SentryCurrent
Aggregated market intelligenceAggregated reports and trends (incl. marketing to third parties)Prior explicit consent (Art. 6(1)(a)); after anonymisation, outside the scope of the GDPRPersonal data: until consent is withdrawn. Anonymised aggregates: indefiniteNeon, RenderCurrent / Planned
Documents and files (photos, plans, contracts)Document management of the projectPerformance of the contract (Art. 6(1)(b))Life of the accountNeon, Render, file storagePlanned / Partial
Payments and subscriptionsCharging for plans (Stripe Checkout, PayPal, card, SEPA, Apple Pay, Google Pay, Bizum; manual invoicing for Enterprise)Performance of the contract; legal obligation (Art. 6(1)(b) and 6(1)(c))Up to 6 years (tax data)Stripe, PayPalPlanned
AI featuresAssistance, classification, suggestionsConsent or legitimate interest depending on the featureDepending on the feature; see the AI PolicyOpenAI, Anthropic, Google (models), under DPAPlanned
Template marketplaceIntermediate the exchange of templatesPerformance of the contract (Art. 6(1)(b))Life of the accountNeon, Render, payment gatewaysPlanned

The items marked as Planned describe features that are not yet active in production; this Policy will be updated and, where appropriate, consent will be obtained before activating them.


5. Aggregated, anonymised data and market intelligence

Ruum wants to generate, from the platform's activity, aggregated and anonymised statistics about the sector (trends by area, by product or material type, by company type, evolution of aggregated costs, etc.) and, where applicable, to market aggregated reports to third parties (manufacturers, distributors, wholesalers, retailers, insurers, developers, construction companies and other actors in the sector).

It is essential to distinguish two concepts:

  • Personal or confidential data: identifies or may identify a person or company (name, client data, individual quotes, exact prices of a specific company). It is never sold, transferred or exposed in an identifiable manner.
  • Aggregated and anonymised data: statistics calculated over many participants, from which the elements that allow identifying a person or company have been removed. Once truly anonymised, they cease to be personal data and fall outside the scope of the GDPR.

Ruum's binding commitments on market intelligence:

  1. Prior consent (opt-in). The use of your data to feed aggregated market intelligence is disabled by default and is only carried out if you give your explicit consent. You can withdraw it at any time from your account settings or by writing to privacy@ruum.es.
  2. Statistical aggregates only. Individual record-level data, complete quotes, named company or client information, individual exact prices or private documents are never marketed or shared.
  3. Minimum aggregation threshold. No data referring to fewer than 5 companies or projects is published for each analysed combination; in areas or niches with few participants, the threshold is raised to 10. Combinations below the threshold are suppressed, to prevent re-identification.
  4. Prevention of re-identification. Reasonable techniques are applied to prevent the singling out, linking and inference of specific persons or companies.
  5. Withdrawal of consent. If you withdraw your consent, we will stop using your data for new aggregates. Reports already anonymised and published cannot be reversed, given that they no longer contain personal data and cannot be linked to you.

The anonymisation methodology and the thresholds described are subject to professional review.


6. Artificial intelligence

The artificial intelligence features (classification of chapters and line items, information extraction, content generation, conversational assistant, suggestions and semantic search) are not yet generally integrated in production. Their operation, the models used and the applicable safeguards are described in the AI Policy, which you must be aware of and, where appropriate, consent to before use.


7. Recipients and processors

Ruum does not sell your personal data. To provide the Service, Ruum relies on providers that act as processors and process data on Ruum's behalf following its instructions and under contract (Art. 28 GDPR). The updated list, with its purpose and location, appears in the Subprocessors Annex.

In addition, data may be communicated to public authorities where there is a legal obligation.


8. International transfers

Ruum prioritises hosting data in the European Union (mainly in Frankfurt where possible). Some providers may process data outside the European Economic Area. In such a case, those transfers are covered by valid mechanisms under the GDPR, such as adequacy decisions, the EU-US Data Privacy Framework or standard contractual clauses (SCC). The detail by provider appears in the Subprocessors Annex.


9. Retention periods

  • Active account: as long as the account exists.
  • After account deactivation: data is marked for deletion immediately and physically deleted within a maximum of 90 days.
  • Backups: backups are kept for a limited period (approx. 7–30 days) and overwritten on a rotating basis.
  • Unconverted leads: 24 months from the last interaction.
  • Tax and billing data: for the applicable legal periods (up to 6 years).
  • Security logs and OTP audit: up to 12 months.
  • Analytics and diagnostics: according to the providers' default retention.

10. Rights of users

You may exercise, free of charge, the rights of access, rectification, erasure, objection, restriction of processing, portability and not to be subject to automated decisions, as well as withdraw the consent given, by writing to privacy@ruum.es or to the controller's postal address, proving your identity.

  • Portability: you may request a copy of your data in a structured and commonly used format. Ruum allows quotes to be exported in PDF and, soon, in structured formats such as JSON.
  • If you consider that your data is not being processed correctly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD), www.aepd.es.

When the data has been entered by a professional user (you are their client or third party), Ruum will forward your request to that professional user, who is the controller.


11. Automated decisions and profiling

Ruum may carry out basic commercial segmentation of leads (commercial status, tags) for follow-up purposes. These processing operations do not produce legal effects or significantly affect you in a similar way. No automated decisions with legal effects are taken without human intervention. Future AI features will be governed by the AI Policy.


12. Minors

Ruum is aimed exclusively at professionals and companies and is not designed for or directed at persons under 18 years of age. We do not knowingly collect data from minors. If a company authorises access for a worker aged 16 or 17 legally entitled to work, that company, as the account holder, is responsible for that access and its lawfulness. If we detect data from a minor collected improperly, we will delete it.


13. Security

Ruum applies technical and organisational measures to protect data (among others, hashing of passwords and codes, encryption in transit, access control and audit logs). The detail appears in the Security Policy.


14. Changes to this Policy

Ruum may update this Policy to reflect legal or Service changes. The version in force is the one published on the site, with its update date. If the changes are substantial, you will be informed by reasonable means.

On this page

  • 1. Data controller
  • 2. Who this Policy applies to
  • 3. Data we process
  • 4. Purposes, legal bases and retention (GDPR table)
  • 5. Aggregated, anonymised data and market intelligence
  • 6. Artificial intelligence
  • 7. Recipients and processors
  • 8. International transfers
  • 9. Retention periods
  • 10. Rights of users
  • 11. Automated decisions and profiling
  • 12. Minors
  • 13. Security
  • 14. Changes to this Policy
Ruum

One workspace for your construction projects — budgets, projects and client communication, finally in one place.

Product
SolutionsProductPricingDemo
Legal
Legal NoticePrivacy PolicyCookie PolicyTerms and Conditions of UseAll legal documents
Company
Log inTry Ruum
Contact
info@ruum.es+34 634 630 020Burgos, Spain
© 2026 Ruum. All rights reserved.
Privacy PolicyTermsCookies