Privacy Policy
Contents↓
Version of 4 October 2026.
1. Who processes your data
The controller of personal data is Health Informatic Security System, S.L., NIF ESB86739125. For data protection questions: contacts@layers.md.
Data Protection Officer (DPO): not appointed; write to contacts@layers.md with any data protection question.
2. Data We Collect
Website Visitors
The layers.md website does not set cookies and does not use analytics counters, advertising pixels or web beacons. Your browser (localStorage) keeps only the theme and language you choose and your answer to the consent request — categories, version and date; they are not sent to our server. You can change your decision in “Cookie settings” in the site footer.
Fonts, scripts, images and videos are served from our own server; browsing the site sends no data to third parties. See Cookies.
Like any web server, the site server receives your IP address and browser details to deliver the page and records them in a technical log to protect against attacks and to find faults.
The app.layers.md application
The Layers web application uses the following services to analyse usage and find errors:
- Google Tag Manager — visit and in-app activity statistics; these services use cookies;
- Sentry — error reports and a recording of the interface session used to reproduce them. Conversations with the AI assistant are masked in the recording.
Analytics (Google Tag Manager) and Sentry session recording are turned on only with your consent. The app asks for it on your first visit; the “Accept” and “Reject” buttons carry equal weight, and these services are not loaded until you answer. You can change your choice at any time in the app’s “Cookie settings”. Error reports without session recording rely on legitimate interest (section 3).
Layers Users
When you register for Layers, we collect:
- Name
- Email Address
- IP Address
- Browser type and language
- Internet service provider
- Operating system
This data is used to create your account and provide you access to the Layers platform. We also process payment information (credit card number, cardholder name) for paid users strictly for the purpose of processing your payments.
Responses to Technical Inquiries — For any technical inquiries, we may ask for the name and email address you provided during registration. This data helps us address your questions and troubleshoot any issues.
Is providing data required
Your name and email address are needed to conclude and perform the contract: an account cannot be created without them. Payment details are needed only for paid plans. Technical details (IP address, browser, operating system) are sent by your browser automatically with every request. Consent to analytics is voluntary: refusing has no consequences.
3. Purposes and legal bases
We process data only for the purposes below and on the stated legal bases (Art. 6 GDPR):
| Purpose | Data | Legal basis |
|---|---|---|
| Purpose: Account and operation of the platform | Data: name, email, workspace data | Legal basis: contract — Art. 6(1)(b) |
| Purpose: Payments, invoices and accounting | Data: payment details, invoices | Legal basis: contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) |
| Purpose: Service security, server logs | Data: IP address, browser details, request times | Legal basis: legitimate interest: protection against attacks and abuse — Art. 6(1)(f) |
| Purpose: Sentry error reports (without session recording) | Data: technical error data, IP address, browser | Legal basis: legitimate interest: a working product — Art. 6(1)(f) |
| Purpose: Analytics (Google Tag Manager) and Sentry session recording | Data: cookies, device identifiers, in-app actions | Legal basis: consent — Art. 6(1)(a) |
| Purpose: AI features | Data: your request and the material needed to answer it | Legal basis: contract — Art. 6(1)(b) |
| Purpose: Sign-in with Google, Google Drive | Data: Google account data within the permissions you grant | Legal basis: contract — Art. 6(1)(b) |
| Purpose: Answering requests and support | Data: name, email, correspondence | Legal basis: contract — Art. 6(1)(b); legitimate interest — Art. 6(1)(f) |
Where the basis is legitimate interest, we have balanced it against your rights and interests. You can object to such processing (section 10).
4. Use of Google User Data
Our platform may interact with Google services, and we ensure full compliance with Google's Limited Use requirements. Specifically, we only access, use, store, and share Google user data as outlined below:
- We use your Google account information to facilitate login to the Layers platform.
- We only use Google user data for providing necessary platform functions (e.g., authentication, file sharing, or integrations).
- We do not share Google user data with any third party except as required to operate our service.
Note: Your use of Google data is governed by the permissions you provide when linking your Google account to our platform. We do not access any Google user data without explicit consent.
5. In-Product Privacy Notifications
When you register for Layers, we show links to this policy and the User Agreement and ask for your consent to data processing.
When a feature sends data to an external service (for example, signing in with Google or connecting Google Drive), the access request is shown at the moment you connect it.
6. Who We Share Your Data With
We share data only with providers that process it on our behalf and under a contract (Art. 28 GDPR):
- Hosting of the website and platform — a data centre in the EU;
- Payment processing — a payment provider;
- Language model providers (OpenAI, OpenRouter) — only when you use AI features: they receive your request and the material needed to answer it;
- Analytics and error monitoring: Google Tag Manager — only with your consent; Sentry;
- Google — if you sign in with Google or connect Google Drive.
Meeting recordings
If a meeting participant starts a recording, it is stored in the workspace. Meeting transcripts and summaries are produced with a language model provider.
Self-hosted server
If Layers is installed on your organisation’s server, work data (tasks, pages, files, messages, meeting recordings) is stored on that server, and your organisation is the controller of that data. External providers (such as language model providers) are used only to the extent your administrator has connected them.
7. Transfers outside the EEA
Some recipients are located outside the European Economic Area. Such transfers take place only with the safeguards of Chapter V GDPR:
- United States — OpenAI, OpenRouter, Sentry, Google: the European Commission adequacy decision on the EU-US Data Privacy Framework for certified recipients (Art. 45 GDPR); for others, the standard contractual clauses adopted by Commission Decision 2021/914 (Art. 46(2)(c) GDPR);
You can request a copy of the safeguards at contacts@layers.md. References: Data Privacy Framework list, Commission Decision 2021/914.
8. Retention periods
We keep data no longer than needed for its purpose (Art. 5(1)(e) GDPR):
- account and workspace data — while the account is active; after the account is deleted, within 30 days, and from backups within 35 days;
- invoices and accounting records — 6 years (Art. 30 Código de Comercio; tax limitation period 4 years, Art. 66 Ley General Tributaria);
- server logs — 90 days;
- Sentry error reports and session recordings — 90 days;
- analytics data — 14 months;
- support correspondence — 5 years after the request is closed (general limitation period, Art. 1964 Código Civil);
- AI requests at the language model provider — no longer than 30 days (OpenAI API retention policy);
- meeting recordings and transcripts — until they are deleted in the workspace.
9. How We Protect Your Data
We use industry-standard security measures, including encryption and secure servers, to protect your personal data. Access to your personal data is restricted to authorized personnel only.
10. Your Rights Under GDPR
In accordance with the GDPR, you have the following rights regarding your personal data:
Right of Access:
You have the right to request information about the personal data we process about you.
Right to Rectification:
You have the right to request the correction of inaccurate personal data.
Right to Erasure ("Right to be Forgotten"):
You have the right to request the deletion of your personal data under certain conditions.
Right to Restrict Processing:
You can request the restriction of the processing of your personal data in specific situations.
Right to Data Portability:
You can receive your personal data in a structured, machine-readable format or ask us to transmit it to another controller.
Right to Object:
You can object to processing based on our legitimate interest (section 3): server logs and error reports.
Right not to be subject to automated decisions:
You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects for you.
Right to withdraw consent:
Where processing is based on consent (analytics and session recording in the app), you can withdraw it at any time as easily as you gave it — in the app’s “Cookie settings” or by writing to contacts@layers.md. Withdrawal does not affect the lawfulness of processing before it (Art. 7(3) GDPR).
Automated decisions:
We do not make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects for you (Art. 22 GDPR).
How to exercise your rights:
Write to contacts@layers.md. We will reply within one month (Art. 12(3) GDPR). You also have the right to lodge a complaint with a data protection supervisory authority — in Spain, the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid — or with the authority in your country.
11. Changes to this policy
The version date is shown at the top. We will notify registered users of material changes in advance by email or in the app.