EnrikeBack to Enrike ↗
Legal
Terms of ServicePrivacy PolicyLegal NoticeCookie PolicyData Processing Agreement

Questions?enrike@higuera.ai

Data protection

Privacy Policy

This policy explains how Higuera Ex Machina SL handles personal data when you visit Enrike, create an account, purchase a plan, contact us, or use the enrichment service.

Last updated: 30 July 2026

1. Data controller

Controller
Higuera Ex Machina SL
Tax ID (NIF)
B21770680
Address
C/Escultor Llimona 15, 08031, Barcelona, Spain
Privacy contact
enrike@higuera.ai

2. Our roles

Higuera is controller for website visits, accounts, billing, support, service communications, security, usage metering, abuse prevention, and the shared enrichment cache described below.

When a business customer submits personal data for enrichment, Higuera processes the request and produces the result on that customer’s behalf as a processor. The customer is responsible for its legal basis, notices, instructions, and use of the result. Our Data Processing Agreement applies to that processing.

3. Personal data and sources

  • Account and profile data: business email, authentication identifiers, name, location, age, company, industry, company size, plan, and preferences you provide.
  • Billing data: plan, subscription status, Stripe customer and subscription identifiers, payment status, and invoice-related records. Stripe handles full payment-card details.
  • Usage and security data: API-key records, request type and channel, pseudonymised input and rate-limit hashes, counts, timestamps, IP-derived security signals, logs, and diagnostics.
  • Support data: messages and information you send when requesting help or exercising rights.
  • Submitted data: business email addresses, postcodes, optional country hints, and rows selected from spreadsheets.
  • Enrichment data: public professional, company, and location information, plus inferred role, location, language, gender, age, salary, demographic, and related contextual estimates.

We collect data from you, your organisation, service and payment providers, technical interactions with Enrike, local postcode datasets, public websites and search results, and model or research providers used to produce an enrichment.

4. Purposes and legal bases

PurposeLegal basis
Create accounts; provide lookups, files, API access, support, and billingContract performance
Authenticate users, protect credentials, prevent abuse, troubleshoot, and maintain reliabilityLegitimate interests in operating a secure service and, where applicable, legal obligation
Measure plan usage, enforce limits, improve performance, and reuse the shared cacheContract performance and legitimate interests in efficient service delivery
Manage invoices, accounting, tax, disputes, and regulatory requestsLegal obligation and legitimate interests
Send transactional and requested service communicationsContract performance or legitimate interests
Send optional promotional communicationsConsent or the existing-customer exception where legally available; you may opt out at any time

Where we rely on legitimate interests, we assess the necessity and impact of the processing and apply safeguards such as pseudonymisation, access controls, limited retention, and user rights.

5. How enrichment works

Enrike combines the submitted email or postcode with local data, public-web research, search results, and model-generated analysis to return structured context. For company emails, this can include researched company information and estimates about a likely person. For postcodes, it can include municipality, region, population, and income context.

Results are probabilistic estimates, not verified facts.

Enrike does not itself make decisions that produce legal or similarly significant effects. Customers must review results and must not use them as the sole basis for employment, credit, insurance, housing, eligibility, or other high-impact decisions.

6. Files, API requests, and cache

CSV and XLSX files are parsed in the user’s browser. The original file is not intentionally uploaded or stored as a file by Enrike. Values in the selected email or postcode columns are sent as individual enrichment requests, and the completed spreadsheet is generated for download in the browser.

Raw lookup values are not stored in the service database as usage or cache keys. Enrike uses SHA-256 hashes for those records, and cached result objects omit the submitted input. The input is nevertheless processed transiently by the application and relevant research providers to produce the result.

Successful email enrichment results may be held in the shared cache for four calendar months. Postcode results may be held for twelve calendar months. Cache hits still count toward plan usage.

7. Providers and recipients

We use the following categories of provider to operate Enrike:

  • Supabase: authentication, profiles, database, API-key records, usage records, and cache.
  • Google Cloud: application hosting, API execution, edge security, and operational logs.
  • OpenRouter and routed model or retrieval providers: model inference and web-assisted enrichment; the configured retrieval provider may include Exa.
  • Brave Search: optional fallback public-web research.
  • Stripe: checkout, subscriptions, invoices, payment security, and the customer portal.
  • hCaptcha: signup security and bot prevention.

Providers process data under their contracts and applicable data-protection terms. We may also disclose data when required by law, to protect users or the service, in a corporate transaction, or on your instructions. We do not sell personal data.

8. International transfers

Some providers or their infrastructure may process data outside the EEA. Where required, we rely on an adequacy decision, the European Commission’s Standard Contractual Clauses, or another valid transfer mechanism, with supplementary measures where appropriate.

9. Retention

  • Account and profile data is kept while the account is active and for a limited period afterwards where needed for support, disputes, security, or legal obligations.
  • Email enrichment cache entries expire after four calendar months; postcode entries expire after twelve calendar months.
  • Usage, security, and diagnostic records are retained only as long as reasonably needed for limits, integrity, incident response, and disputes.
  • Billing, tax, and accounting records are retained for applicable statutory periods.
  • Provider backups and logs are deleted through ordinary rotation cycles unless a legal hold applies.

10. Your rights

Subject to applicable law, you may request access, rectification, erasure, restriction, or portability; object to processing based on legitimate interests; and withdraw consent at any time without affecting earlier processing.

Send requests to enrike@higuera.ai. We may verify your identity. If a customer submitted your data, we may direct your request to that customer where it is the controller. You may lodge a complaint with the Spanish Data Protection Agency (AEPD) or your local supervisory authority.

11. Security

We use proportionate technical and organisational safeguards, including access controls, encryption in transit, protected server credentials, encrypted API-key storage, row-level database controls, pseudonymised lookup and rate-limit keys, logging controls, and rate limiting. No service can guarantee absolute security. You must keep passwords and API keys confidential.

12. Business users, changes, and contact

Enrike is intended for business and professional use and is not directed to children. We may update this policy when the service, providers, or legal requirements change. Material changes will be communicated through the service or by another appropriate method. Questions can be sent to enrike@higuera.ai.

© 2026 Higuera Ex Machina SLC/Escultor Llimona 15, 08031, Barcelona, Spain