StorageIdol is a platform that automates the operation of self-storage facilities: 24/7 phone service, WhatsApp, arrears recovery and a KPI dashboard. Processing personal data is part of the service, so it is worth explaining exactly how we do it.
This is a courtesy translation. The Spanish version of this policy is the one that applies and prevails in case of any discrepancy. The section numbers and anchors are the same in both, so you can cross-reference them.
01Data controller
The personal data collected through this website and in the course of our business relationship is processed by:
- Trading name
- StorageIdol
- ai@storageidol.com
- Website
- storageidol.com
- Activity
- Development and operation of automation software for self-storage facilities and storage spaces
The full registration details —legal name, tax identification number and registered office— will be published in this very section. Until then you can request them at ai@storageidol.com and we will provide them in writing.
Any question relating to data protection is handled at ai@storageidol.com, which is also the contact address for exercising your rights.
02Scope of this policy: when we are the controller and when we are a processor
This distinction is the key to understanding the rest of the document, so it comes first.
We are the data controller
When we decide the why and the how: the data of whoever fills in the
form on this site, of whoever tries the
instant demo at
demo.storageidol.com, of our customers and their contact
people, of invoicing, of support and of our marketing communications.
All of that is governed by this policy.
We are a data processor
When a self-storage facility subscribes to the platform, the data of its end customers (whoever calls, whoever writes on WhatsApp, whoever rents a unit or has an outstanding fee) is processed on behalf of and following the instructions of that facility, which is the data controller. Our role is governed by the data processing agreement under Article 28 of the GDPR that we sign with each customer, not by this policy.
If you are a customer of a self-storage facility and want to exercise your rights over a call, a message or your rental contract, contact the facility you signed with. If you write to us, we will forward your request to that controller without undue delay and confirm it to you.
If what you used is the instant demo, it is the other way round: we are the controller. There is no customer behind that demo, so there is nobody to forward your request to and we handle it directly — what it processes, on what basis and for how long is in section 06, and how to exercise your rights in section 11.
For information purposes, this policy describes which categories of data we process as a processor, because we believe that anyone evaluating the platform has the right to know before signing.
03Personal data we process
3.1 · Data you give us
- "Request information" form: name, email address, company, phone number and, optionally, the management software you currently use.
- Communications: the content of the emails, messages and calls we exchange with you, including the notes from the discovery meeting.
- Contractual relationship: details of the company, of the contact people and of the account's authorised users, as well as billing and payment details.
Along with the form submission we also record the date and time of the submission and the address of the page it was sent from. We do not ask for or need special categories of data (Article 9 of the GDPR).
3.2 · Technical data on the website
This site is served as a set of static pages. It embeds no advertising pixels and no tracking cookies. We do measure how many visits it receives, with a tool that writes nothing to your device and does not identify you: it is explained in full in section 07. The only piece of code that runs on our server is the one that receives the "Request information" form and records it in our CRM: it does not store your IP address or your browser details, and it sends the CRM only what is listed in section 08. The only technical data processed is:
- Connection data (IP address, request headers, user agent, timestamp), processed by our hosting and CDN provider to serve the page, protect it against abuse and keep security logs.
- IP address and browser details sent to Google when the site's fonts are loaded, as explained in section 07.
- Aggregated audience-measurement data (page visited, referring link, device and browser type, country and load time), sent to Cloudflare without identifying you and without any persistent identifier, as explained in section 07.
The instant demo at demo.storageidol.com is a separate
page and does process more data than this: what you give it, the
website address you submit, the transcript of the conversation and
the encrypted fingerprints we use to prevent abuse. They are
described, one by one, in section 06.
3.3 · Data we process on behalf of our customers
As a processor, and only to the extent the customer configures it, the platform may process:
- Phone number, caller ID and call metadata (time, duration, outcome, queue).
- Audio recordings and transcripts of the calls answered or placed by the voice agent.
- WhatsApp messages and other text channels, with their metadata.
- Rental contract and unit details: holder, reference, amount, payment status, incidents, collection history.
- Identification and contact details of the facility staff who use the dashboard.
The contract prohibits the customer from entering health data, data revealing ideology, religion, racial origin or sexual orientation, biometric data for the purpose of unique identification, full payment card numbers or copies of identity documents into the platform, unless the technical and legal framework for doing so has been expressly agreed in writing.
04Purposes and legal bases
Every processing operation we carry out as a controller has a specific purpose and a legal basis under Article 6(1) of the GDPR:
| Purpose | Legal basis |
|---|---|
| Handling your request for information, calling you and preparing a proposal | Performance of a contract or pre-contractual measures at the data subject's request (art. 6(1)(b)) |
| Managing the contractual relationship: onboarding, configuration, support, incidents | Performance of the contract (art. 6(1)(b)) |
| Invoicing, accounting and tax obligations | Compliance with a legal obligation (art. 6(1)(c)) |
| Sending marketing communications about StorageIdol to customers and to those who have requested information | Legitimate interest in promoting our own products and services similar to those already requested or contracted (art. 6(1)(f), in connection with art. 21.2 of Spain's LSSI). In all other cases, consent (art. 6(1)(a)) |
| Security of the platform and the site, fraud and abuse prevention, access logs | Legitimate interest in protecting our systems and the data entrusted to us (art. 6(1)(f)) |
| Improving the product from aggregated or anonymised usage data | Legitimate interest in developing and maintaining the service (art. 6(1)(f)) |
| Responding to requests from authorities and bringing or defending claims | Legal obligation (art. 6(1)(c)) and legitimate interest (art. 6(1)(f)) |
You may object at any time to processing based on legitimate interest and withdraw your consent where that is the applicable basis, without affecting the lawfulness of the processing carried out beforehand. Every marketing communication includes an unsubscribe link, and writing to us is enough to stop receiving them.
As a processor, the purpose and legal basis are determined by the customer acting as controller; we only act on its documented instructions.
The instant demo has its own table of purposes and bases in section 06, because it introduces two processing operations that do not appear above and that rest on your consent: calling you by phone and contacting you afterwards.
05Voice agents, artificial intelligence and call recording
The platform handles calls and messages through an automated system based on language and speech models. That demands three explicit commitments.
Transparency
The caller is informed at the start of the conversation that they are speaking with an automated StorageIdol system and, when the call is recorded, that it is being recorded and for what purpose. The announcement is configurable by the customer, who must ensure it is correct and complete under its applicable law. A transfer to a person can be requested at any time.
No automated decisions with legal effects
The system informs, books, schedules, sends reminders and prepares collection actions, but it does not make automated decisions that produce legal effects —terminating a contract, enforcing an eviction, listing someone in a debtors' register, refusing a rental— without human intervention by the customer. Sensitive actions require approval in the dashboard.
Model training
We do not use the content of our customers' calls, transcripts or messages to train general-purpose artificial intelligence models, whether our own or third parties'.
The model providers we integrate are contracted with training on customer data disabled. Product improvement work is done on aggregated or anonymised usage data —from which it is not reasonably possible to re-identify a person— and always within what the contract with the customer allows.
Voice recordings are treated as sensitive personal data from a risk standpoint, even though they are not biometric data: we do not use them to uniquely identify anyone, nor do we build voice models from them.
Section 06 explains how these three commitments apply to the instant demo, where the controller is us and not a customer.
06The instant demo with your own website
At demo.storageidol.com you can try the agent with your
own business's details: you type in your website address and your
contact details and, within seconds, you are talking to an agent that
already knows your facility's name and the cities it operates in. It
is a separate page from this site and processes more data than it
does, so it is explained separately. Here we are the data
controller: there is no customer behind it, and this section
is the information Article 13 of the GDPR obliges us to give you at
that moment.
6.1 · What happens, step by step
- We read your website. An automated process downloads the home page of the address you typed and, if needed, a couple more pages linked from it —never more than four requests— and extracts a business profile: name, cities, services, opening hours, pricing hints and the phone number the website itself publishes.
- We classify whether it is a self-storage facility. First with a keyword check. Only when that check is inconclusive —around one in five addresses— is the website text sent to a language model from Anthropic (United States) for classification. It receives website text and nothing from the form: not your name, not your email, not your phone number. And we do not keep the text of your page: of it we retain only a cryptographic fingerprint and its length.
- You talk to the agent in the browser. The conversation is transcribed. No audio is recorded: the demo agents are configured without recording, so what remains of that conversation is the transcript and not the sound.
- We check that the phone number is yours. Before calling we look up the line type and send you an SMS with a code. The code is generated and checked by the verification provider (Twilio): we do not see it and do not store it anywhere.
- We call you, if you have authorised it. An automated agent calls the number you provided and verified and, during the call, hands you over to a second agent. It is also transcribed and likewise not recorded.
- We control abuse and cost. The demo is open to anyone and every use costs real money, so we keep counters per IP address, email, domain and phone number. Those counters do not store the value: they store a keyed, encrypted fingerprint of each one, which serves to count and to block but not to read.
A good share of self-storage facilities are run by a sole trader, so the name or phone number a website publishes may be both company data and personal data. That is why we do not treat the profile we extract from your website as purely corporate information: it has its own retention period in section 10.
6.2 · Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Running the demo: reading and classifying the website you indicate and preparing a personalised agent from it | Pre-contractual measures taken at your request, since you are the one requesting the demo (art. 6(1)(b)) and, where not pre-contractual, legitimate interest in fulfilling that request (art. 6(1)(f)) |
| Calling you by phone for the telephone part of the demo | Your consent, given through a specific checkbox that is not pre-ticked (art. 6(1)(a)) |
| Checking by SMS that the number provided is yours before calling it | Legitimate interest (art. 6(1)(f)) and, in particular, the legitimate interest of a third party: the person that number would belong to if someone had typed it by mistake or on purpose |
| Preventing abuse of an open feature and controlling its cost | Legitimate interest in protecting the service, its availability and its cost (art. 6(1)(f)) |
| Contacting you commercially after the demo | Your consent, through a separate checkbox independent of the previous one (art. 6(1)(a)) |
| Understanding how the demo itself performs: how many are started, how many completed and where they are abandoned | Legitimate interest in measuring and improving the service (art. 6(1)(f)). After twenty-four months the record kept no longer contains personal data |
6.3 · The two permissions are separate
The form has two independent checkboxes, neither of them pre-ticked: "I authorise StorageIdol to call me on the number provided to run the demo" and "I want to receive marketing information". The first is the only thing that allows the call; the second does not condition any part of the demo. You may tick one, both or neither, and withdraw either without affecting the other or the lawfulness of the processing carried out beforehand.
To withdraw them, just write to ai@storageidol.com or use the unsubscribe link in any marketing communication we send you.
We keep proof of that consent: the version of the text you were shown, a cryptographic fingerprint of that exact text, the date and time, an encrypted fingerprint of the IP address, the browser it was sent from and the moment the phone number was verified. It is the set that serves as evidence —a date without the text proves nothing— and it is also the reason that evidence survives the deletion of the rest of your data: it is what shows that both the processing and the deletion itself were lawful.
6.4 · What we do not do with the demo
- We do not train models with it. Neither your conversation with the agent, nor its transcript, nor the text of your website is used to train artificial intelligence models, our own or third parties'.
- We do not build advertising profiles or cross-reference this data with third-party data to segment you.
- We do not disclose the data to anyone beyond the providers in section 08, who process it on our behalf and on our instructions.
The automated classification of your website has a single effect: if it does not look like a self-storage facility's, we may not offer you the demo. It affects no contractual relationship and produces no other effect on you, and if you think it got it wrong, write to us and a person will review it.
The conversation is at all times with an automated system, not with a person, and the retention periods for all of the above are in section 10.
07Cookies and local storage
Neither this site nor the demo sets analytics, advertising or profiling cookies, which is why you will not see a consent banner. We do measure audience, but with a tool that writes nothing to your device —no cookie and no local storage—, so on that side there is nothing to consent to; it is described below, under "Cookieless audience measurement". There are cookies: a few, all strictly necessary for security, all from our CDN provider and all exempt from the prior-consent requirement. We name them one by one below, because "no banner" does not mean "no cookies": it means the ones there are do not require your permission.
The cookies there may be, by name
All of them are set by Cloudflare, which hosts this site and protects both pages against abuse; none is set by StorageIdol. We say "may" because they depend on which protection is active at any given time and on the anti-bot check (Turnstile) that protects the demo form.
| Cookie | Purpose | Where |
|---|---|---|
__cf_bm |
Telling human traffic from automated traffic (bot management) | storageidol.com and demo.storageidol.com |
cf_clearance |
Recording that the anti-bot check has already been passed, so it is not repeated on every request | demo.storageidol.com |
cf_chl_rc_i · cf_chl_rc_ni · cf_chl_rc_m |
Internal diagnostics of the challenge platform that serves that anti-bot check | demo.storageidol.com |
Cloudflare publishes the full list of its cookies and the purpose of each, and states that they are strictly necessary to provide the requested service. None of them measures audience, builds profiles or serves advertising.
Why no banner is needed
Article 22.2 of Spain's LSSI requires consent to store information on your device, but expressly exempts whatever is strictly necessary to provide a service you have requested; the Spanish Data Protection Agency's Guide on the use of cookies places security cookies and abusive-traffic detection cookies within that exemption. The three rows above are exactly that, and there are no others. With no non-exempt cookie in place, there is nothing to consent to and a banner would offer no real choice.
It is a specific exemption, not a broad reading: if one day we set a cookie that does not fit it, it will appear in the table above and we will ask for your consent before setting it.
The demo session uses no cookies
The identifier your browser uses to follow a demo in progress is not stored in any cookie, nor in local storage, nor in the page address: it lives only in the tab's memory, and if you reload, the demo ends. That is deliberate —that identifier is what authorises a real phone call to a real number, and the less time and the fewer places it exists, the better.
Browser local storage
When you submit the form on this site, the page saves a copy of the
request in your browser's local storage, under the key
storageidol_leads, so it is not lost if the connection
fails at that moment. That copy stays on your device, we do not read
it remotely, and you can delete it by clearing the site's data from
your browser settings.
Cookieless audience measurement
To know how many visits the site receives and which pages are read we
use Cloudflare Web Analytics. It works with a script
downloaded from static.cloudflareinsights.com that sends
the measurement to cloudflareinsights.com, so your IP
address and your browser's basic details are sent to Cloudflare, Inc.
What is measured is aggregated: the page visited, the referring link,
the device and browser type, the country and how long the page takes
to load.
It sets no cookie and uses no local storage, and Cloudflare states that it does not fingerprint visitors from the IP address, the user agent or any other data. With no persistent identifier, we cannot follow you across visits or across sites. That is why this measurement falls outside Article 22.2 of the LSSI —it stores no information on your device— and requires no banner. If you would rather avoid it, you can block that domain in your browser: the page works exactly the same.
Fonts served by Google
The site's fonts are loaded from Google's servers
(fonts.googleapis.com and fonts.gstatic.com),
which means your IP address and your browser's basic details are
sent to Google Ireland Limited and may be transferred to Google LLC in
the United States. Google sets no cookies when serving fonts. If you
would rather avoid it, you can block those domains in your browser:
the page remains perfectly readable with your system fonts.
08Recipients, processors and sub-processors
We do not sell personal data, do not pass it to advertising intermediaries and do not share it with third parties for their own commercial purposes. We disclose it only to the providers we need to deliver the service, all of them bound by a data processing agreement with confidentiality and security obligations.
| Provider | Purpose |
|---|---|
| Cloudflare (US, with storage in the EU) | Hosting of this site, content delivery network, protection against abuse, the anti-bot check (Turnstile) on the demo form and the cookieless audience measurement described in section 07. The platform's call recordings are stored in its object storage service, in a bucket pinned to European Union data centres |
| Attio (US) | Customer relationship management (CRM) system. Receives and keeps the "Request information" form submissions: name, email address, company, phone number, the management software you indicate, the submission date and the address of the page it was sent from |
| Google (Google Workspace) | Email and internal office tools. Receipt and logging of demo requests —name, email, phone number, company and website— |
| Google Fonts | Font service for the website |
| ElevenLabs (US) | Conversational voice agents: speech recognition, speech synthesis, language understanding and conversation transcription, with training on our data disabled. In the demo it receives your voice, the transcript, your company's name and yours and, if you authorise the call, your phone number |
| Twilio (US) | Numbering and carriage of the agent's calls and messages. In the demo it also receives your phone number to check the line type and to send you the SMS with the verification code |
| Supabase (Ireland, EU) | Managed database where the platform's and the demo's information is stored |
| Anthropic (US) | Automated classification of the text of the website you submit in the demo. It receives nothing you type into the form: not your name, not your email, not your phone number |
| Hosting and infrastructure providers in the EU | Servers on which the platform's services run |
| Advisory, accounting and payment providers | Invoicing, accounting and tax compliance |
The named, up-to-date list of the platform's sub-processors, with their location and function, is provided to customers in the relevant annex of the data processing agreement, together with the procedure for prior notice of changes and the right to object. If you are evaluating StorageIdol and want to see it before signing, write to us.
In addition, we may disclose data to law enforcement, courts, tribunals and competent authorities where there is a legal obligation, and to our legal advisers where necessary to bring or defend claims. In the event of a merger, acquisition or transfer of a line of business, the data could be transferred to the acquirer, which would be bound by this same policy.
09International data transfers
Everything we store ourselves —the database and the platform's call recordings— is in the European Union. Even so, several of the providers in the previous section are US entities or may access the data from outside the European Economic Area, and it is worth naming which:
- ElevenLabs (United States) processes the voice and the transcript of the agent's conversations, including the two in the demo.
- Twilio (United States) processes phone numbers and call metadata and, in the demo, the line check and the verification SMS.
- Anthropic (United States) receives the text of the website you submit in the demo, and nothing you type into the form.
- Attio (United States) receives and keeps the "Request information" form submissions: your name, your email, your company, your phone number and the management software you indicate.
- Google and Cloudflare are entities with a US parent: the former provides our email and office tools and serves the fonts; the latter protects and delivers the site, runs the code that receives the form and stores the recordings in a bucket pinned to the European Union.
In all those cases, the transfer is covered by:
- The European Commission's adequacy decision of 10 July 2023 on the EU–US Data Privacy Framework, where the importer is certified under it.
- The Standard Contractual Clauses approved by the European Commission (Decision 2021/914), where it is not.
- The supplementary measures resulting from the transfer impact assessment: encryption in transit and at rest, minimisation of the data exported, access control and the provider's commitment to notify requests from authorities.
You can request a copy of the applicable safeguards by writing to ai@storageidol.com.
10Retention periods
| Data | Retention |
|---|---|
| Requests for information that do not lead to a contract | Twelve months from the last contact, or sooner if you request erasure |
| Customer and contractual relationship data | For the term of the contract and, afterwards, blocked for the statutory limitation periods and the accounting and tax retention periods (up to six years under the Spanish Commercial Code and tax law) |
| Billing data | The periods imposed by commercial and tax law |
| Call recordings and transcripts | The period the customer acting as controller configures in its account, as agreed in the data processing agreement. At the end of the contract they are returned or deleted on its instructions |
| Instant demo request and session | Twenty-four months. Afterwards the name, email, phone number and website provided are deleted, and the record survives without any data identifying anyone, so the funnel figures still add up |
| Proof of consent for the demo (text version, text fingerprint and date) | Kept beyond that deletion, and also if you request erasure: it is the proof that the processing and the erasure itself were lawful |
| Phone verification by SMS | Thirty days |
| Profile extracted from the analysed website | Ninety days; seven days if the website turned out not to be a self-storage facility's; one hour if the read failed. Nothing of the page text is kept |
| Demo anti-abuse counters (encrypted fingerprints of IP, email, domain and phone) | Seven days, except for a block in force, which is kept for as long as it lasts —deleting it sooner would amount to lifting it |
| Demo transcripts | At ElevenLabs (United States), ninety days. In our systems, the retention period of the demo environment, which is deleted in the scheduled automatic clean-up. There are no audio recordings, because the demo is not recorded |
| Technical and security logs | As long as needed for their security purpose, as a rule no more than twelve months |
| Aggregated or anonymised usage data | No time limit, as it does not allow any person to be identified |
"Blocked" means the data is set aside and accessible only to respond to requests from judges, courts, the Public Prosecutor or the supervisory authorities, under Article 32 of Spain's LOPDGDD.
The exact retention period of demo transcripts in our own systems will be published in this very table. Until then you can ask us for it at ai@storageidol.com and we will state it in writing, and at any time you can ask us to delete yours without waiting for any period to elapse.
11Your rights
You may exercise the following rights at any time:
- Access — to know what data of yours we process and obtain a copy.
- Rectification — to correct inaccurate or incomplete data.
- Erasure — to ask us to delete it when it is no longer necessary or there is no basis to process it.
- Restriction — to ask us to suspend processing while a dispute is verified.
- Objection — to object to processing based on legitimate interest and, in any case and without having to give a reason, to marketing communications.
- Portability — to receive your data in a structured, commonly used format, or to have us transmit it to another controller.
- Withdrawal of consent — where processing is based on it, with no retroactive effect.
- Not to be subject to automated individual decisions with legal effects or that significantly affect you.
To exercise them, write to ai@storageidol.com stating the right you wish to exercise. We may ask you to prove your identity if there is reasonable doubt. We will respond within one month of receipt, extendable by two further months for complex requests, in which case we will let you know.
If you have used the instant demo
Here we are the controller and there is no customer to forward your request to: we handle and resolve it ourselves. Write to ai@storageidol.com and tell us which right you wish to exercise.
We will verify your identity through a channel the record itself fixes —the email you sent or the phone number that was verified—, not by asking you for details anyone could have typed into a public form. It is a requirement in your favour: everything we hold about you could have been typed by someone else, so deleting without checking would be as serious as not deleting.
If you request erasure, the deletion covers our database, the transcript ElevenLabs keeps in the United States and the records the request created in our CRM. Only the proof of consent described in section 06 survives, without your contact details.
Objecting and erasing are different rights, and it helps to tell us which of the two you are exercising. If what you want is for us to stop contacting you, say so and we will delete nothing else. If you request erasure, we erase. And we tell you the consequence in advance, because it is real: when no trace remains, neither does the record that you asked not to be contacted, so a future mailing could not recognise and skip you. In both cases we will set out in writing, in our reply, what we did and what was kept.
If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos) (C/ Jorge Juan 6, 28001 Madrid — www.aepd.es), without prejudice to any other administrative or judicial remedy. You may also come to us first: we would rather resolve it directly.
12Information security
We apply technical and organisational measures appropriate to the risk, under Article 32 of the GDPR, including:
- Encryption of communications in transit (TLS) and encryption of data at rest.
- Role-based access control, least-privilege principle and strong authentication for administrative access.
- Logging and review of access to and operations on personal data.
- Separation of environments, backups and recovery procedures.
- Prior and contractual assessment of the providers that access data.
- Staff training and confidentiality undertakings.
No system is invulnerable, and we do not promise otherwise. If a personal data breach occurs, we will notify the competent supervisory authority within 72 hours where required, and the controllers and affected persons without undue delay under Articles 33 and 34 of the GDPR.
13Minors
StorageIdol is a service aimed exclusively at businesses and professionals. This site is not aimed at minors and we do not knowingly collect data from children under fourteen. If we find that we have received a minor's data without the involvement of the holder of parental authority or guardianship, we will delete it.
14Third-party links and services
This site may link to third-party pages and the platform may integrate with systems the customer already uses (facility management software, CRMs, payment gateways, messaging channels). We do not control those services and are not responsible for their privacy practices: once data flows out to an integration the customer has enabled, subsequent processing is governed by the relevant provider's policy. We recommend reviewing it.
15Changes to this policy
We may update this policy to reflect changes in the service, in our providers or in the law. The current version is always the one published at this address, with its last-updated date and version number in the header. If a change is material and affects processing that concerns you, we will notify you by email or through a prominent notice on the site before it takes effect.
16Contact
Privacy and exercise of rights
ai@storageidol.com
StorageIdol — Spain
The conditions of use of the service are set out in the Terms of Service.