This page explains who runs FICO, what personal data we collect, and what we do with it. It covers everything: this website, the members' area at app.ficoworking.com, and the FICO mobile apps. They are one service run by one data controller, so there is one policy rather than a different answer on each screen.

Who we are

This site and the FICO coworking space are operated by Christian Campoli, NIE Y8479494Y, at Calle Prudencio Morales 73, 35009 Las Palmas de Gran Canaria, Spain. You can reach us at info@ficoworking.com or +34660443986. We are the data controller for the data described below.

What we collect, and why

The only personal data this website collects is what you type into the contact form: your name, your email address, your message, and the topic you select. We use it for one purpose — to read your enquiry and reply to it. The legal basis is Article 6(1)(b) GDPR: steps taken at your request before entering into a contract. If your message isn't about becoming a member, the basis is our legitimate interest in answering people who write to us (Article 6(1)(f)).

Your message is stored in this site's database and also delivered to our own inbox. We keep enquiries for 12 months after our last contact with you, and then delete them automatically. If your enquiry turns into a membership, the resulting account data is handled separately under that relationship.

When you have a member account

The members' area at app.ficoworking.com is part of the same service and the same data controller — this policy covers it too, which is why there is one policy and not two. What we hold there is what running a coworking membership requires:

  • Your account. Your first and last name, your email address, an optional phone number, and your password — which is stored only as a cryptographic hash, so nobody at FICO can read it.
  • Your bookings and credits. The desks and phone-booth slots you book, the dates and times, your credit balances, and a ledger of every credit granted, spent and refunded. We keep this for as long as you are a member: it is the record of what you have paid for and used, and it is what an account balance is made of.
  • Your sessions. When you sign in we record the IP address and browser your session was opened from. Signing out ends the session and removes it.
  • Community directory. Your name is shown to other signed-in members only if you switch that on. It is off by default, the directory sits behind the login, and it is never published publicly. You can switch it off again at any time.

The legal basis for all of this is Article 6(1)(b) GDPR — performance of your membership contract. Without it we cannot give you an account, take a booking, or tell you what your balance is.

We do not use social logins. You sign in with an email address and a password you chose, so no other company is told when or whether you use FICO.

If you have come to us as a guest

If you have used FICO without registering — a day pass bought at the desk, or a place at an event booked for you — our staff may have created a record holding your name and, if you gave one, your email address, so that your visit and any credits could be tracked. If you later register with the same email address, that record becomes your account rather than a second one, and your earlier history carries over. The basis is Article 6(1)(b) where you bought something, and our legitimate interest in keeping accurate records of who has used the space otherwise. The rights below apply to these records exactly as they do to accounts.

Payments

Card payments are taken by Stripe, and the card itself never reaches us: you enter it on Stripe's own payment form and Stripe holds it. What we store is an identifier that lets us ask Stripe about your past payments — not a card number, and nothing we could charge on our own. Stripe issues your receipts; we generate none, and hold no copy. Stripe acts as our processor and, for the card data, as a controller in its own right under its own privacy policy.

Some things are paid for off the platform — a weekly or monthly membership arranged with us directly, or a day pass paid at the desk. In those cases no card data reaches either us or Stripe, and what we keep is the record that the payment was made.

How long we keep it

  • Contact-form enquiries: 12 months from our last contact with you, then deleted automatically.
  • Member accounts, bookings and credit records: for as long as you are a member, and afterwards only where we are required to keep them — principally Spanish tax and accounting law, which obliges us to retain records of transactions for several years after the financial year they belong to. Once no obligation remains, we delete or anonymise them.
  • Sessions: removed when you sign out or the session expires.

Where your data is

Our servers are in the European Union, and so are our hosting and email providers. Stripe is established in Ireland and may process payment data outside the EU under the safeguards set out in its privacy policy. We make no other international transfers.

Children

FICO membership is for adults. We do not knowingly create accounts for anyone under 18, and if we learn that we have, we delete the account and its data.

Automated decisions

We make none. Nothing about your membership — what you are charged, what you may book, whether the door opens — is decided by profiling or by an algorithm acting on its own.

Cookies and tracking

This website sets no cookies at all. It runs no advertising pixels and no social media trackers, and nothing here stores or reads information on your device beyond what you actively send us — so there is nothing for you to consent to, and we don't show a cookie banner.

We do measure how the site is used, with Rybbit — software we run on our own server rather than a service that collects on our behalf. It records the page you viewed, the site that linked you here, and your rough location, browser and device type. It sets no cookies and does not keep your IP address. As a visitor to this website, your visit becomes a number in a count, and nothing about it identifies you.

The members' area at app.ficoworking.com is a separate application. Once you sign in there, it sets a single session cookie that keeps you logged in — strictly necessary for a service you have explicitly requested, so it is exempt from the consent requirement, and it is not used for advertising. Unlike the public website, the members' area does attribute your usage to your member account rather than counting it anonymously: because you are already signed in there, we record your name and role against your activity in the app (which pages you use, how often), the same way we would if we simply read our own server logs while you were logged in. This is used only to understand how the space and app are used, never for advertising or profiling, and never leaves our own server.

Who else sees your data

We do not sell, rent or share your personal data. It is handled only by the providers who run this site's infrastructure on our behalf — our hosting provider and our email delivery provider — who act as data processors under contract and may not use your data for their own purposes. Our analytics adds no one to that list: we run it ourselves, so the measurements stay on our own server and are never sent to an analytics company.

Your rights

You have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to how we use it, and to receive it in a portable format. To exercise any of these, email info@ficoworking.com — we will respond within one month.

To delete your account and the data attached to it, see how to request deletion. That page explains what we can remove immediately and what tax law obliges us to keep for a while longer.

If you believe we have handled your data improperly, you can complain to the Spanish data protection authority, the Agencia Española de Protección de Datos, at aepd.es.

Changes to this policy

If we start collecting anything new, we will update this page before doing so, and add a consent banner if the law requires one.