Privacy policy
Last updated: 7 October 2026
At Briox Baker we take your privacy seriously. This website is an informational site: it does not sell online, it has no cart or registration, and does not install cookies. Here we explain, clearly, what data we process and what your rights are, in accordance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD).
Orders are placed in our ordering app, which has its own section: section h.
1. Data controller
Controller Briox Baker Corporate, S.L.
NIF B70830583
Registered office Rúa Fieira 1, 15220 Ames (A Coruña), Spain
Tax address Calle Oliveiras 100, puerta A2, Pol. Ind. Novo Milladoiro, 15895 Ames (A Coruña), Spain
Email marketing@brioxbaker.com
2. What data we process and for what purpose
a) Browsing the site — anonymous analytics, no cookies
To know how many people visit the website and what content is of interest, we use our own analytics without cookies. We generate a irreversible daily fingerprint from your IP address, browser and a key that changes every day: we do not store your IP and that fingerprint does not make it possible to identify you or to know whether you have come back another day. We record in aggregate form the page visited, the type of device, the source (if you come from another website) and an approximate location (country/city) provided to us by our provider. If the page shows a technical error, we record its message. On every page we also measure how long you keep it in view, how far down you scroll, which buttons you tap, which videos you watch and whether you accept or reject the cookie notice; in the catalogue, which pages you look at; in the pallet calculator, the numbers you try; and on forms, in addition, which fields you have filled in and whether you get an error, never what you type. It is not possible to identify you with this data.
Legal basis: legitimate interest (art. 6.1.f GDPR) in measuring the use of the site anonymously.
b) If you contact us
If you write to us by email, WhatsApp or through the App, we will process the data you provide (name, email, telephone, content of your message) for the sole purpose of dealing with your request and, where applicable, managing the business relationship.
Legal basis: your request and/or the performance of a contractual relationship (art. 6.1.b GDPR).
c) Measurement of our advertising
When you carry out a specific action on the website (for example, send the contact form, clicking to download the App or contacting us via WhatsApp), we may send to Meta Platforms (Facebook/Instagram) a conversion event to measure the effectiveness of our campaigns. Your contact details (email and telephone) always travel encrypted (pseudonymised with SHA-256). Together with them, and only so that Meta can recognise the event, we transmit some unencrypted technical data: your IP address and the browser (user-agent). Under no circumstances do we send your name, email or telephone in clear text.
Only if you accept cookies, we also load in your browser the Meta pixel: it tells Meta that you have visited a page and, in the catalogue and on the product pages, which bun you are looking at and whether you tap to place an order, to measure our ads and show them to the people who actually come in to look. It uses the cookies _fbp y _fbc (90 days). If you reject it, it is not loaded, and if you withdraw your consent, they are deleted.
If you reach the site from a Meta ad, the address carries a click identifier. We use it to know which ad works, and we handle it in two different ways:
- During your visit, it travels in the address of the pages you go through and is sent with the form if you write to us. Nothing is stored on your device, so it does not require your consent.
- Beyond your visit, only if you accept it in the notice that appears on arrival: it is then stored in your browser for 90 days —Meta’s attribution window— to recognise the ad even if you come back another day. If you refuse, nothing is stored and anything from before is erased.
In addition to your email and phone number, we send Meta your hashed first and last name (SHA-256), which improve the recognition of the event. You can change your decision whenever you want from the cookie policy.
Legal basis: legitimate interest in evaluating our advertising. You can object by writing to us at marketing@brioxbaker.com.
d) Access to brand material (/material)
The brand material is for press, customers and distributors. To enter, you just need to type an email address. We process: your email, the name or company if you give it to us, how many times you have entered and when the last time was, y which files you download —the latter associated with an internal identifier, never with your email within our event log—. We also store the login attempts, to detect abuse and solve access problems.
The first time you enter, your email also goes to our internal customer system, so we know who uses the material and can get in touch with you about it or about Briox Baker. We do not send you anything automatically just because you entered.
When you enter, your browser stores a signed pass so you do not have to type your email every time. It is not an advertising cookie and it is not used to track you across other websites: it is strictly necessary for the service you have requested, which is why it does not require prior consent.
Legal basis: preparing a business relationship and our legitimate interest in knowing who uses the material and in being able to contact you about it (art. 6.1.b and 6.1.f GDPR). You can object, ask us to remove your access and delete this data by writing to marketing@brioxbaker.com.
Retention: for as long as the access lasts and up to 12 months after the last entry.
d bis) Presentation for distributors (/socios)
Anyone who types their email at the entrance can enter, as can the people we invite. We process: your email; if we invite you, also your name and that of your company (we enter them ourselves when we invite you), the language, when you enter and what you watch: how far into the video you get, whether you finish it, whether you open the demo panel and how long you spend in it, with the city and type of device that the connection gives, approximately.
When you enter, your browser stores a session cookie that lasts as long as your access (48 hours). It is strictly necessary for the service you have requested: it is not for advertising and does not require prior consent. This page has no Meta pixel and no Clarity recording.
Legal basis: preparing a business relationship and our legitimate interest in knowing whether the presentation has been useful to you (Art. 6.1.b and 6.1.f GDPR). You can object or request deletion by writing to marketing@brioxbaker.com.
Recipients: Cloudflare, where it is stored (and its cdnjs service, from which your browser downloads the video player), and Resend, which sends the invitation email when we invite you.
Retention: 12 months from your last access; after that, it is deleted automatically.
e) If you apply for a job (/personal)
When you send your application we process your name, your phone number, the shift you choose, how you get to work, whether you have worked before on a production line or in a factory and your CV. The CV is kept in private storage, accessible only from our internal panel: it has no public address and no one outside the selection process can see it.
We only accept PDF, JPG or PNG files, and we check that the file really is of that type before storing it. It is never opened inside the browser: it is downloaded.
To help us sort the applications, an artificial intelligence tool (Claude, by Anthropic) reads the CV and summarises your experience and where you live. It decides nothing: it rules no one out, and every application is reviewed and decided by a person. From that reading we only keep the summary, never the text of the CV.
Legal basis: your consent given expressly by ticking the box, and pre-contractual measures taken at your request (art. 6.1.a and 6.1.b GDPR). You can withdraw it whenever you want by writing to marketing@brioxbaker.com, without this affecting the lawfulness of the processing carried out before.
Retention: one year from the moment you send the application. After that period the record and the CV are deleted automatically, without you having to ask. If you want us to delete it sooner, write to us.
Recipients: no one outside Briox Baker, except the providers that help us as data processors: Cloudflare, where it is stored, and Anthropic, which reads it to sort the applications. Your CV is not shared with third parties and is not used for advertising.
f) How the website is used — Microsoft Clarity, only with your permission
If you accept cookies, we use Microsoft Clarity to see how people browse the website: where they tap, how far down they scroll and at what point they leave a form (heatmaps and recordings of the visit). What you type in the forms stays hidden: we can see that someone is typing, not what.
Legal basis: your consent (art. 6.1.a GDPR). If you do not accept, Clarity is not loaded. You can withdraw it whenever you want from the cookie policy, and doing so deletes its cookies.
g) If you write to us on WhatsApp or Instagram
When you contact us via WhatsApp (Meta's WhatsApp Business API) or via Instagram direct messages to our accounts (Spain, Portugal, France), we process your name or username, your phone number (on WhatsApp), the language of your message, what you write, the photos and audio messages you attach (audio messages are automatically transcribed into text with an artificial intelligence tool), and whatever you tell us about your business (venue, city, what you cook). If you write to us from a button on the website, your first message ends with a short reference in square brackets (for example [REF:ES-SEL-ORG]) which says which page and which ad you come from; it does not say who you are.
Replying to you is Lucía (Lucie in French, Lúcia in Portuguese), an assistant powered by artificial intelligence. She introduces herself as an AI when she greets you and admits it if you ask (AI Act, art. 50). She does not make decisions with legal effects about you (art. 22 GDPR): she informs and recommends, but you place the order on the website or talk to a person from our team. Lucía hands the conversation over to a person when needed: if there is a complaint, a large order, or if you ask for it.
If you leave the conversation halfway through, we may send you a single reminder within the following 24 hours. We will not send you any further commercial communications via WhatsApp outside that conversation unless you give us your express consent to do so.
Legal basis: pre-contractual measures taken at your request (art. 6.1.b GDPR) to answer your questions and help you choose and order, and legitimate interest (art. 6.1.f GDPR) for the 24-hour reminder. Any later commercial communications, only with your consent.
Retention: while we remain in contact and, afterwards, for the time needed to handle any claims. You can ask for them to be deleted whenever you want.
Recipients / processors: Meta Platforms Ireland Limited (WhatsApp and Instagram), OpenAI Ireland Limited (processing in the United States under standard contractual clauses; OpenAI is not in the Data Privacy Framework), Anthropic Inc. (United States, standard contractual clauses; backup if OpenAI fails), Supabase Inc. (database hosted in London, United Kingdom: a country with an EU adequacy decision), and Telegram FZ-LLC (internal alerts to the team with your name and your question, without phone numbers or emails; it may process data outside the EEA). The AI providers do not use these conversations to train their models: this is the default condition of their business services.
Your rights: in addition to the usual rights, you can ask at any time to speak to a person instead of the AI assistant.
h) If you use our ordering app
This applies to the Briox Baker app and its web version, pedidos.brioxbaker.com, where accounts are created and orders are placed.
What data: Identity data (first name and surname) and contact data (email, phone). Tax and company data (company name and VAT/tax number, needed for invoicing). Delivery addresses. Data about your orders (products, quantities, amounts, dates, coupons and Briox Coins). Notification identifier (your device token) if you turn notifications on. Technical usage data (IP address, access logs, technical device identifier) and aggregated, anonymous activity data for the shop’s «live» statistics (visits and purchases in real time, without profiling you individually).
What we do not process: We do not store your payment card details (Redsys handles them in its secure environment). The app does not access your precise location, camera, contacts or photo gallery, unless you expressly choose to upload an image.
Purposes and legal basis: Creating and managing your account and processing and delivering your orders → performance of the contract. Issuing invoices and meeting accounting and tax obligations → legal obligation. Managing Briox Coins, providing support and improving the service (including aggregated statistics) → legitimate interest. Sending you push notifications → your consent (can be withdrawn from the device).
Recipients / processors: We do not sell your data. The providers needed to deliver the service process it on our behalf, with the appropriate safeguards: Supabase (infrastructure, database, authentication and real time, hosted in the European Union); Redsys and the bank (payment processing); Holded (issuing invoices); Resend (sending the service emails: access code, order confirmation and invoices); and, for notifications, Expo together with Apple (APNs) and Google (FCM). Also the app stores (Apple App Store and Google Play) when you download or update the app. When your order is served through the distributor in your area, we pass on the data needed for delivery (name or company name, address, contact phone and order contents).
Retention: We keep your account data while it is active. If you delete it, we remove your access and your personal account data. Orders and invoices are kept for the periods required by commercial, accounting and tax law (generally, several years), after which they are deleted or anonymised.
Your rights: You can delete your account directly from Account › My details, or write to us at marketing@brioxbaker.com. If you believe we have not handled your data properly, you can complain to the supervisory authority: in Spain, the Agencia Española de Protección de Datos (AEPD, www.aepd.es); in Portugal, the Comissão Nacional de Proteção de Dados (CNPD, www.cnpd.pt).
Security and breaches: We apply technical and organisational measures to protect your data (encryption in transit, role-based access control, separate environments). If a security breach puts your rights at risk, we will notify the competent authority within 72 hours, and you when appropriate.
International transfers: Your database is hosted in the European Union. Some notification services (Apple, Google) may involve processing outside the European Economic Area; in that case it is carried out with the safeguards provided for in the GDPR (standard contractual clauses or other valid mechanisms).
Minors: The app is aimed at professionals and businesses (over 18). It is not intended for minors and we do not knowingly collect data from minors.
3. Recipients of the data
We do not sell your data. The following may access it, as processors or providers necessary for the service:
- Cloudflare, Inc. — hosting of the site and of the anonymous analytics.
- Meta Platforms, Inc. — only the pseudonymised conversion events described above.
- Microsoft Corporation (Microsoft Clarity) — only if you accept cookies, the browsing data described in section f.
- Supabase, Inc. — hosting of our internal customer system, where the website contacts and the emails in section d arrive.
- OpenAI Ireland Limited / Anthropic Inc. — only for the WhatsApp and Instagram conversations described in section g.
- Telegram FZ-LLC — only for the internal alerts described in section g.
- Supabase, Redsys, Holded, Resend, Expo, Apple and Google — only if you use the ordering app, as explained in section h.
We may also disclose data where there is a legal obligation.
4. Retention
Analytics data is kept in aggregate and anonymous form. Data arising from your contact is kept for as long as the relationship lasts and, thereafter, for the periods legally required to address possible liabilities.
The job applications and CVs are kept for one year from when they are sent and are then deleted automatically.
5. International transfers
Our providers (Cloudflare, Meta, Microsoft, OpenAI, Anthropic and Telegram) may process data outside the European Economic Area. In that case, the transfer is covered by appropriate safeguards, such as the Standard Contractual Clauses approved by the European Commission.
6. Your rights
At any time you can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, by writing to marketing@brioxbaker.com and indicating the right you wish to exercise. If you consider that we have not handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
7. Minors
This site is not directed at minors and we do not knowingly collect their data.
8. Changes to this policy
We may update this Privacy Policy to reflect legal or operational changes. We will publish the current version on this page with its update date.
Informational document in accordance with the regulations in force on the date indicated. It does not constitute legal advice.