Privacy Policy
Last updated: 2026-09-29
At Horus we process your personal data in accordance with the EU General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 on Personal Data Protection (LOPDGDD).
1. Data controller
- Owner: Isaac Hernández Miranda
- Tax ID (NIF): 54577035J
- Address: Rambla Francesc Macià 31, Terrassa (Barcelona), Spain
- Contact email: support@joinhorus.com
- Website: https://joinhorus.com
To exercise your data protection rights or any privacy enquiry, write to the email above. We respond within 30 days.
2. Data we collect
2.1 Account data
- Email, full name and, optionally, agency name
- Password (stored hashed with bcrypt; never in plain text)
- Sign-up date and last login
2.2 Usage data
- IP address and browser user-agent
- Audit logs: critical actions (login, plan changes, team management)
- Basic technical metrics to detect errors and fraud
2.3 Content you upload
- Files: raw video footage, thumbnails, invoices, attachments
- Text: titles, descriptions, briefs, comments, tags
- Data about your team and clients (names, emails, roles, payments)
2.4 Payment data
We do not store your card. Payments are processed by Stripe, who processes card data in its own environment. Horus keeps customer and subscription identifiers, plan, payment status, tax details and necessary receipts. It does not store the full card number or CVV.
3. Purposes
- Provide the Service and grant you access to your account
- Bill the plan you contracted
- Send required transactional emails (alerts, receipts)
- Maintain security and prevent abuse
- Comply with legal obligations (tax, judicial requirements)
We do not sell your project content or use it to train AI models or for advertising. With your separate consent, analytics and advertising tools may receive data about visits to public pages, as described in the cookie policy. We do not send those tools files, project names or private dashboard URLs.
4. Legal basis for processing
- Performance of a contract (GDPR art. 6.1.b): account, service usage, billing.
- Legal obligation (GDPR art. 6.1.c): tax invoicing, judicial requirements.
- Legitimate interest (GDPR art. 6.1.f): security, fraud detection, technical logs.
- Consent (GDPR art. 6.1.a): non-essential cookies (separate analytics, advertising and support-chat choices).
5. Providers and data access
Horus serves adult professionals, businesses and consumers. We are the controller for accounts, billing and security; personal data hosted on a customer's behalf must be covered by an Article 28 GDPR processing arrangement. Providers may act as processors or independent controllers depending on the service.
- Hetzner: production application and database hosted in Germany.
- Cloudflare R2 and Turnstile: files, encrypted backups and anti-bot protection. The preferred storage location is Western Europe; this is not an EU-only processing guarantee. Contract information.
- Resend: recipients and transactional email content. It documents US storage and transfer safeguards. Resend privacy.
- Stripe: billing, payments and fraud prevention. It may act as a processor and as an independent controller depending on the operation. Stripe privacy.
- Crisp: optional support chat, including name, email, role and messages you send. Project names are not supplied automatically. Its French headquarters do not determine all processing locations. Subprocessors.
- Google: identity when you choose Google login and Drive when connected. These services are distinct from Google Analytics and Ads, which depend on your cookie choices. Google privacy.
- TikTok: optional advertising measurement on public pages, described in the cookie policy.
- Discord: notifications when you connect the integration. It receives messages and data needed to send them to the configured destination. Discord privacy.
- IONOS: contact mailboxes and email support replies. IONOS privacy.
Transfers outside the European Economic Area require applicable safeguards, such as standard contractual clauses or adequacy decisions where relevant. Ask support@joinhorus.com for information on providers and safeguards. Server location does not mean that every provider processes data exclusively in Europe.
Horus is not an end-to-end encrypted service: technical access to content may be needed for support, incident resolution or legal obligations, limited to what is necessary and to authorised personnel. This does not grant a licence to commercially exploit your files.
6. Retention periods
- Accounts and projects: while needed to provide the service. Cancelling renewal does not instantly delete the account. After a subscription ends there is a 30-day recovery period; automatic closure requires billing checks and evidenced delivery of the final warning, allowing at least 24 hours to act. Failed or unverified delivery requires review, not indefinite retention.
- Collaborations and files: access needed for other active teams is preserved. File deletion uses a queue and failures require review. Data needed for obligations or claims is separated from ordinary use.
- Invoices and receipts: for the applicable legal periods. The general four-year tax limitation period does not replace commercial retention of six years from the last accounting entry where applicable, or specific interruptions and liabilities.
- Security logs: deleted after 12 months, except limited and documented incident or legal holds. Contractual, tax and consent evidence has a separate purpose and is not removed by that task.
- Email: minimal delivery evidence for 90 days and delivery events for 30 days, without copying the message body. Accepted billing outbox jobs are removed after 30 days; unresolved failures need review. Contractual receipts are kept separately.
- Backups: daily encrypted copies on a 30-day cycle, removed at the following daily run. They are not active data; recovery must respect applicable erasures and restrictions.
7. Your rights
You have the right to access, rectify, erase, restrict processing, object and to portability of your data. You can also withdraw consent at any time.
You can exercise portability and erasure directly from your dashboard, at Profile → Security → Danger zone:
- Download my data: exports a JSON with all the personal information tied to your account.
- Delete my account: requests closure and erasure of active data and files, subject to the checks and legal exceptions described above. An active Stripe subscription is cancelled when closure completes.
For other rights, or if you prefer email, contact support@joinhorus.com stating which right you want to exercise and from which account email. We respond within 30 days.
If you believe we don't handle your data correctly, you may lodge a complaint with the Spanish Data Protection Agency (aepd.es) or the supervisory authority in your country of residence.
8. Security
We apply reasonable technical and organisational measures:
- Passwords hashed with bcrypt
- HTTPS connections with a valid certificate
- Daily database backups, encrypted with AES-256
- Infrastructure access restricted to SSH with key
- Audit log of critical access
9. Minors
Horus is not aimed at children under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us so we can delete it.
10. Changes to this policy
We may update this policy. We will notify you by email at least 30 days in advance for material changes. The update date is always listed at the top.
11. Cookies
See our Cookie Policy.