Privacy Policy
How boveDAM collects, uses, and protects your information.
Last updated: June 16, 2026
This Privacy Policy explains how boveDAM ("we", "us", "our") handles personal information when you use our website https://bovedam.com, the application at https://app.bovedam.com, and the public brand portals we host (together, the "Service").
boveDAM is operated by Daniel Benitez Correa (RFC: BECD920908LP9), an individual sole proprietor (persona física con actividad empresarial) based in Zapopan, Jalisco, Mexico, who acts as the data controller responsible for your personal information. We serve users worldwide, so this policy is written to meet Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP), the EU/UK General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA/CPRA).
1. Information we collect
We collect only what we need to run the Service:
Information you provide
- Account data — your name, email address, password (stored only as a salted hash, never in plain text), and your preferred language.
- Workspace and billing data — your plan, subscription status, and, when you subscribe, the billing details you give our payment processor (see “Who we share with”). We never see or store your full card number.
- Content you upload — the files, logos, colors, typography, brand guidelines, and descriptions you add to your portals. This may include the personal data of others if you choose to include it; you are responsible for having the right to upload it.
- Communications — messages you send us by email or support channels.
Information we collect automatically
- Usage and download events — when an asset is downloaded we record the asset, the time, and the workspace. To respect privacy, the visitor IP address is stored only as a one-way HMAC (keyed) hash — we cannot recover the original IP from it.
- Technical data — IP address, browser/device information, and request metadata processed by our infrastructure and security providers (e.g. for rate-limiting, fraud prevention, and uptime).
- Cookies — strictly necessary cookies that keep you signed in, protect against CSRF, and remember your language. We do not use advertising or cross-site tracking cookies. See “Cookies”.
2. How we use your information
- To provide, operate, and maintain the Service and your portals.
- To process subscriptions, trials, payments, and invoices.
- To secure the Service — authentication, rate-limiting, abuse and fraud prevention, and incident investigation.
- To communicate with you about your account, security, billing, and material changes to the Service.
- To comply with legal obligations and enforce our Terms of Service.
We do not sell your personal information, and we do not use your uploaded content to train artificial-intelligence models.
3. Legal bases (GDPR)
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract — to provide the Service you signed up for.
- Legitimate interests — to secure, improve, and protect the Service (balanced against your rights).
- Legal obligation — to meet tax, accounting, and other legal requirements.
- Consent — where we ask for it (for example, optional communications); you may withdraw consent at any time.
5. International data transfers
We and our sub-processors operate in several countries, so your information may be processed outside your country of residence, including in Mexico, the United States, and the European Union. Where required, transfers are protected by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
6. How long we keep information
We keep your information for as long as your account is active and as needed to provide the Service. After a subscription ends, your content enters a grace period before it is locked and ultimately deleted (see the Terms of Service). We retain limited records longer where required for legal, tax, or security purposes. You can ask us to delete your account and data at any time.
7. How we protect information
We apply technical and organizational measures appropriate to the risk, including:
- Encryption in transit (HTTPS/TLS) across the Service.
- Passwords stored only as salted hashes; private files served through expiring signed URLs.
- Download-event IP addresses stored only as one-way hashes.
- Rate-limiting and anti-abuse protection on sensitive endpoints, and least-privilege access controls.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
8. Your rights
Mexico (LFPDPPP) — ARCO rights
You may request Access to your data, Rectification of inaccurate data, Cancellation (deletion), or Opposition to certain processing, and you may limit the use or disclosure of your data. Submit requests to hello@bovedam.com.
European Union / United Kingdom (GDPR)
- Access, rectification, and erasure ("right to be forgotten").
- Restriction of, or objection to, processing.
- Data portability.
- Withdrawal of consent, and the right to lodge a complaint with your local data-protection authority.
California (CCPA/CPRA)
- The right to know what personal information we collect and how we use it.
- The right to delete and to correct your personal information.
- The right to opt out of "sale" or "sharing" — note we do not sell or share your personal information.
- The right not to be discriminated against for exercising your rights.
To exercise any right, email us at hello@bovedam.com. We will verify your request and respond within the timeframe required by applicable law.
10. Children
The Service is intended for professional use and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the date above and, where appropriate, notify you. Your continued use of the Service after changes take effect means you accept the updated policy.
12. Contact us
For any privacy question or to exercise your rights, contact the data controller, Daniel Benitez Correa, at hello@bovedam.com.