privacy policy
how we handle your personal data.
This policy explains what personal data we collect, how we use it, who we share it with, and your rights under GDPR.
Who we are
With Pilar S.L. ("Pilar", "we", "us") is a Spanish limited liability company registered at Plaça de la Fira, 1, 08261 Cardona, Barcelona, Spain, with Spanish tax identification number [NIF to be added after incorporation].
We operate the Pilar financial wellbeing platform, provided to individual employees through their employers or, in future, via direct subscription.
Data Protection Officer: [email protected]
General privacy inquiries: [email protected]
What personal data we collect
We collect what we need to operate the service. Nothing more.
Identity data
- —Name and email address (required for account creation)
- —Employer name (required to associate you with the correct workspace)
- —Optional profile information you choose to add (role, tenure, other demographic information relevant to peer benchmarking)
Financial data (only if you choose to add it)
- —Account balances and holdings from CSV bank statements you upload
- —Transaction descriptions and categorisations
- —Assets you record (property, pension, other investments)
- —Stated financial goals and plans
Behavioural data
- —Course chapters started, completed, and time spent
- —Wellbeing score progression over time
- —NPS ratings you submit
Technical data
- —Session logs (login times, device type, general location)
- —Application error logs (for debugging)
- —IP addresses (retained for security purposes only)
How we use your personal data
We use your data to:
- —Provide the Pilar service to you personally
- —Show you insights about your own finances (privately, only to you)
- —Generate aggregated, anonymised reports for your employer (see Section 04)
- —Improve our educational content and product
- —Communicate with you about service updates, security, and administrative matters
- —Meet legal and regulatory obligations
We do not sell your personal data to anyone. We do not use your data to train third-party AI models. We do not share your data with your employer at an individual level.
What your employer sees and does not see
Your employer never sees your individual financial data or personal Pilar activity.
This separation is architectural, not policy-based. See our Trust page for the full technical detail.
Your employer sees:
- —Total number and percentage of employees who have activated their account
- —Aggregate engagement metrics (average sessions per month, course completion rates)
- —Aggregate wellbeing score movement over time
- —Anonymous NPS responses
- —Content performance data (which chapters are completed most)
- —Aggregate opt-in demographic breakdown
Your employer never sees:
- —Your individual financial accounts, balances, transactions, income, savings, debts, or net worth
- —Your individual wellbeing score or NPS response
- —Your individual session activity, content history, or specific completions
- —Any aggregate report below a minimum group size (to prevent re-identification)
- —Any identification information linking behavioural or financial data to you personally
Legal basis for processing
Under GDPR Article 6, we process your personal data on the following legal bases:
- —Consent (Article 6(1)(a)): for optional data you choose to add (financial accounts, demographic information)
- —Contract performance (Article 6(1)(b)): for essential data needed to provide the service (identity, account credentials)
- —Legal obligation (Article 6(1)(c)): for tax, accounting, and regulatory record-keeping
- —Legitimate interest (Article 6(1)(f)): for security monitoring, service improvement, and fraud prevention
Where processing is based on consent, you may withdraw that consent at any time through your account settings or by writing to [email protected]. Withdrawal does not affect the lawfulness of processing before withdrawal.
How long we keep your data
While your account is active
Personal profile and financial data are retained for as long as you have an active account.
When you deactivate
If your employer contract ends or you leave the organisation, your personal data is automatically anonymised 90 days after deactivation unless you migrate to a personal subscription or object to anonymisation.
If you delete your account
Full account deletion, requested via account settings or [email protected], is completed within 30 days. You will receive email confirmation.
Anonymised aggregate data
May be retained indefinitely for product improvement and academic research. Anonymised data cannot be linked back to you.
Your rights
Under GDPR, you have the right to:
- —Access the personal data we hold about you
- —Correct inaccurate or incomplete data
- —Delete your data ("right to be forgotten")
- —Restrict or object to certain processing
- —Receive your data in a portable format
- —Withdraw consent where processing is based on it
- —Lodge a complaint with a data protection authority
To exercise any of these rights, contact [email protected]. We respond within 30 days.
You may also lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, aepd.es).
How we protect your data
All personal data is encrypted at rest (AES-256) and in transit (TLS). Sensitive fields carry additional field-level encryption.
Full technical details on encryption, authentication, incident response, and security audits are on our Trust page.
Changes to this policy
We may update this policy to reflect changes in our practices or legal requirements. Material changes will be notified to you by email at least 30 days before they take effect.
The current version of this policy is always available at withpilar.com/legal/privacy. The date at the top indicates when the policy was last updated.