Last updated 27 September 2026
Privacy
What is stored, why, and how to get it back or have it deleted. No advertising, nothing sold on, and one script counting visits to the public pages.
What is stored about you
Three things, and nothing else.
Your account: the name and the email address you signed up with, and your password kept as a hash that cannot be read back.
Your work: the lists, companies, branches, contacts, calls and notes you type in or import. Nothing on that list comes from anywhere but you. An email draft you write or save for a company is kept until you clear it, delete the company or mark it DO_NOT_CONTACT, and puertafria never sends it.
Your sign-ins: while a session is open, the server keeps the session token, its expiry, the IP address it was opened from and the browser it was opened in. That is how a stolen session is spotted.
To count how much the app is used, the date of each sign-in and of each day you come back is kept, with no IP address and no browser; a failed sign-in keeps only a keyed fingerprint of the address typed.
To keep the service safe, a dated record is kept of each sign-up, sign-in and sign-out; of each failed sign-in, as the keyed fingerprint of the address typed and nothing else; of each API key created, revoked, or used after it stopped working; of each import, with its row counts, and each export, with which file; of each list created or deleted; of each plan change; and of a suspension of the account, with its reason. API calls are counted per key per day, with whether they came from the MCP server or another client, and are not stored one by one. None of it holds an IP address or a browser.
When you contact us
The contact form stores the name, the email address, the phone number if you gave one, the message, and which of the two languages you wrote from.
It is read to answer you and for nothing else. Say the word and it is deleted once the exchange is over.
The data you bring
A prospect list is data about other people, usually business contacts. You decide what goes in it and what it is used for, so that list is yours to answer for.
puertafria holds it for you and does nothing with it: it is never read for another purpose, never mixed with anybody else. Each account sees only its own lists.
A company marked DO_NOT_CONTACT stays out of the queue for good and is never handed back to you as a call to make.
How long it is kept
Your account and your work stay while the account exists. Ask for the account to go and it goes, with everything under it.
Sessions expire on their own. Messages from the contact form are kept until the conversation is done.
Those records and the daily API counts are deleted after 180 days. Failed sign-in fingerprints are deleted after 30 days.
Taking it with you
Every list exports to CSV from inside the app, whenever you want, without asking anybody. The file re-imports into a spreadsheet or back into puertafria unchanged.
That is the honest version of portability: nothing is held hostage.
Your rights
You can ask to see what is held, to have it corrected, to have it deleted, to get a copy, or to object to it being held at all. Write in and it is done, at no cost.
If the answer does not satisfy you, you can complain to the data protection authority where you live. In Spain that is the Agencia Española de Protección de Datos, aepd.es.
What is never done
- Nothing is sold, rented or handed to an advertiser.
- Nobody is profiled, scored or decided about by a machine.
- Your prospect list is never used to build anybody else's.
Changes
This page changes when the software does. The date at the top says when it last did.
How the public pages are measured
The landing page and these notices load a script from Cronitor, which counts visits and times how quickly the pages render. It runs on the public half only. No screen behind a sign-in loads it, so no list, company, contact or note is ever measured.
Cronitor receives the address of the page, the site you arrived from, your browser and its language, your screen width, your connection type and any campaign tags in the link you followed. The rest of the query string is not sent. As with any server a browser contacts, they see the address you connect from.
It sets no cookie and stores no identifier in your browser. Add ?cronitor_rum_disable to the address of any page here and it stops, for as long as that browser keeps the note it leaves. Nothing on these pages knows who you are: an account exists only on the other side of the sign-in.
Who is responsible for this site
These details are still being filled in. Until then, write to us and a person will answer.
- Name
- puertafria
- Hosting
- IONOS SE, Germany
- hola@puertafria.es