Legal
Privacy
Last updated September 26, 2026
Parallel plans and executes work on your behalf, which means it handles information about your goals, your projects and sometimes the people you contact. This page explains exactly what is collected, why, and what is deliberately never stored.
01Who is responsible for your data
The data controller is Jose Manuel Sánchez-Cervera Rodríguez, tax number 28755774R, with address at Calle Medina Azahara 4, 41807 Espartinas (Sevilla), España, who provides Parallel under that trade name. For anything about your data, write to info@velorastudio.agency.
02What we collect
Only what the product needs to function. There is no advertising network and no data sale.
- Account information: your email address, display name and authentication identifiers.
- Profile information you provide during onboarding: occupation, interests, available time and working preferences.
- Your profile photo and nickname, if you add them. The photo is stored as a public file with an address nobody can guess, so that it can be shown in the product.
- Mission content: objectives, constraints, plans, agent configurations, deliverables and approval decisions.
- What your agents handle in the applications you connect (for example the email they send through Gmail or the events in your calendar), only to the extent a mission needs it.
- Billing details when you pay: name, email, country and, if you give one, a company tax number. The card is handled by Stripe.
- What you write to support, and the replies.
- Usage records: which Parallel Actions were consumed, by which mission and agent, and when.
- Technical records: standard server logs, retained briefly for reliability and abuse prevention.
- Records of what you accept: the version of the terms when you sign up, your request for the service to start at once when you pay, and full access if you turn it on.
03What we never log
Some categories are excluded from logging by design, not by policy alone. This is a rule in the codebase, applied wherever agents run.
- Credentials for connected services. Where real integrations exist, tokens are held encrypted and are never displayed again after saving.
- The contents of personal documents you upload, beyond what an agent needs in the moment to produce its output.
- Prompt text classified as sensitive by the permission layer.
- Your card details. You enter them in Stripe's payment form and they never reach Parallel.
04What we use it for, and on what legal basis
Every use has a legal basis under article 6 of the GDPR:
- Providing the service you signed up for: generating plans, agents and reports and running the work you authorise. Basis: performance of the contract.
- Charging, invoicing and keeping the accounts. Basis: performance of the contract and compliance with tax obligations.
- Emailing you about your own missions (an approval waiting, a finished report). They are part of the service, and you can turn them off with one click from any of them or in Settings. Basis: performance of the contract.
- Keeping the service secure, preventing abuse and fixing errors. Basis: legitimate interest in protecting the service and the people who use it.
- Keeping a record of what you accepted, so that it can be proved if needed. Basis: legal obligation and legitimate interest.
- Knowing which channel you arrived from, only if you accepted the measurement cookie. Basis: your consent, which you can withdraw at any time.
05What we do not do
- We do not send you promotional emails. Every email from Parallel is about your account or your missions.
- We do not sell your data or share it with advertisers.
- We do not take decisions about you based solely on automated processing that have legal effects on you.
- We do not train AI models with your data.
06AI processing
Generating a plan or an agent team involves sending mission context to a language model provider. Only the information required for that specific operation is sent, and structured output is validated against a strict schema before it is stored or shown.
Some of the AI providers Parallel uses (Groq, NVIDIA, OpenRouter, Google Gemini and Ollama) are used on free plans. Their terms may allow them to keep what they receive for a time or to use it to improve their services. If a mission involves information you do not want to leave Parallel under those conditions, do not include it.
When no model provider is configured, Parallel runs a deterministic offline planner instead. In that mode nothing leaves the deployment, and generated output is labelled as simulated.
07Who we share it with
Only with the providers that help us run Parallel (hosting, database, payments, email, web search and AI models), which process your data on our behalf and only for that. The full list, with what each one does and where, is on the subprocessors page.
The applications you connect (Gmail, GitHub, Notion…) are not our providers: they work for you. Parallel sends them what your agents do in your name, with the permissions you granted, and they process it under their own terms.
We only give data to a public authority when the law requires it.
08Transfers outside the European Economic Area
Our database is in the European Union (Ireland), but several providers, such as the application hosting and the AI models, process data in the United States. In those cases the transfer has to rely on one of the safeguards of the GDPR: an adequacy decision (such as the EU-US Data Privacy Framework, for certified companies) or the European Commission's standard contractual clauses. If you want to know which one applies to a specific provider, write to us and we will tell you.
09Storage and retention
Data is stored in Postgres with row-level security: every row is owned by a user and queries execute as that user.
- While your account is open, we keep what you store in it.
- Missions you delete disappear from your account at once and are erased for good when you close your account. If you want a deleted mission erased sooner, write to us.
- When you close your account, your profile, missions, agents, deliverables, files, connections and records are erased at once, your paid subscription is cancelled and the permissions you granted to connected applications are revoked.
- Our database provider keeps backups for a limited time for disaster recovery. Erased data disappears from them when they are overwritten in their normal cycle.
- Invoices and payment records are kept by Stripe and in our accounts for as long as Spanish law requires (generally four years for tax purposes and up to six for commercial records), even after you close your account.
- If an account is closed for serious abuse, we keep its email address on a block list so that it cannot sign up again, based on our legitimate interest in protecting the service.
- Technical server logs are kept briefly, for reliability and security.
10Your rights
You have the right to access your data, correct it, erase it, object to or restrict its processing, receive it in a portable format and withdraw any consent you gave, without affecting what was done before.
You can delete your account yourself in Settings, Account. To get a full copy of your data, or for anything else, write to info@velorastudio.agency. We will reply within one month.
If you think we have not handled your data properly, you can file a complaint with the Agencia Española de Protección de Datos (AEPD) (https://www.aepd.es) or with the data protection authority of your country.
11Minimum age
You must be at least 14 to use Parallel, which is the age at which Spanish law lets you consent to the processing of your data (article 7 of Organic Law 3/2018). If you live in a country where that age is higher, the higher one applies. To take out a paid plan you must be of legal age or have the permission of your parent or guardian.
12Google user data
Connecting a Google account is optional and is always initiated by you. Parallel only ever requests the narrowest scope that the connected capability needs, and each one is used for a single, stated purpose.
Parallel's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never sold, never used for advertising, never used to train generalised machine-learning models, and is never read by a person except with your explicit permission, to resolve a support request you raised, or where the law requires it.
- gmail.send: sending the specific message you approved, at the moment you approve it, or, if in your permission settings you have allowed agents to send email without asking, the messages they send in your name within the missions you created.
- calendar.freebusy and calendar.events: finding free time and creating the events a mission schedules.
- drive.file: limited to files Parallel itself creates or that you explicitly open with it. The rest of your Drive stays invisible to Parallel.
- Disconnecting a Google account in Settings revokes the token immediately and deletes the data obtained through it.
13Record of full access
If you turn on full access, we keep the date and time, the version and language of the risk text you accepted, the text itself, and the IP address and browser you did it from. We process this to be able to prove your consent (performance of the contract and our legitimate interest), it cannot be edited afterwards, and it is deleted when you close your account.
When you sign up we also record the version of the terms you accepted, and when you pay, your request for the service to start at once, with the text you saw and the payment it refers to. These records cannot be changed and are erased when you close your account.
14Cookies
Parallel only uses the cookies it needs to work, plus one optional cookie to measure campaigns that is only set if you accept it. The cookie policy lists them all.
15Security
We apply reasonable technical and organisational measures: every row in the database belongs to one person and only they can read it, credentials for connected applications are stored encrypted, and access to production is restricted. No system is invulnerable; if a breach ever affected your data, we would tell you and the authority as the law requires.
16Changes
If we change this policy in a way that matters, we will tell you in the product before it applies. The date at the top is the version in force.
17Contact
For any question about this policy or your data, write to info@velorastudio.agency. You can also use the contact form.
Parallel wrote this document to explain, as plainly as it can, how the service handles your data and your money. If something is unclear, or you think we are not doing what it says, write to info@velorastudio.agency.