privacy policy

how we handle your personal data.

This policy explains what personal data we collect, how we use it, who we share it with, and your rights under GDPR.

01

Who we are

With Pilar S.L. ("Pilar", "we", "us") is a Spanish limited liability company registered at Plaça de la Fira, 1, 08261 Cardona, Barcelona, Spain, with Spanish tax identification number [NIF to be added after incorporation].

We operate the Pilar financial wellbeing platform, provided to individual employees through their employers or, in future, via direct subscription.

Data Protection Officer: [email protected]

General privacy inquiries: [email protected]

02

What personal data we collect

We collect what we need to operate the service. Nothing more.

Identity data

  • Name and email address (required for account creation)
  • Employer name (required to associate you with the correct workspace)
  • Optional profile information you choose to add (role, tenure, other demographic information relevant to peer benchmarking)

Financial data (only if you choose to add it)

  • Account balances and holdings from CSV bank statements you upload
  • Transaction descriptions and categorisations
  • Assets you record (property, pension, other investments)
  • Stated financial goals and plans

Behavioural data

  • Course chapters started, completed, and time spent
  • Wellbeing score progression over time
  • NPS ratings you submit

Technical data

  • Session logs (login times, device type, general location)
  • Application error logs (for debugging)
  • IP addresses (retained for security purposes only)
03

How we use your personal data

We use your data to:

  • Provide the Pilar service to you personally
  • Show you insights about your own finances (privately, only to you)
  • Generate aggregated, anonymised reports for your employer (see Section 04)
  • Improve our educational content and product
  • Communicate with you about service updates, security, and administrative matters
  • Meet legal and regulatory obligations

We do not sell your personal data to anyone. We do not use your data to train third-party AI models. We do not share your data with your employer at an individual level.

04

What your employer sees and does not see

Your employer never sees your individual financial data or personal Pilar activity.

This separation is architectural, not policy-based. See our Trust page for the full technical detail.

Your employer sees:

  • Total number and percentage of employees who have activated their account
  • Aggregate engagement metrics (average sessions per month, course completion rates)
  • Aggregate wellbeing score movement over time
  • Anonymous NPS responses
  • Content performance data (which chapters are completed most)
  • Aggregate opt-in demographic breakdown

Your employer never sees:

  • Your individual financial accounts, balances, transactions, income, savings, debts, or net worth
  • Your individual wellbeing score or NPS response
  • Your individual session activity, content history, or specific completions
  • Any aggregate report below a minimum group size (to prevent re-identification)
  • Any identification information linking behavioural or financial data to you personally
06

Who we share data with

We use subprocessors to operate the service. Full list, roles, and data protection agreements are published on our Trust page.

We do not sell your data. We do not share your individual data with your employer, marketing partners, or any third party outside our subprocessor list.

We may disclose your data if required by law (court order, criminal investigation), in which case we will notify you unless legally prevented from doing so.

07

How long we keep your data

While your account is active

Personal profile and financial data are retained for as long as you have an active account.

When you deactivate

If your employer contract ends or you leave the organisation, your personal data is automatically anonymised 90 days after deactivation unless you migrate to a personal subscription or object to anonymisation.

If you delete your account

Full account deletion, requested via account settings or [email protected], is completed within 30 days. You will receive email confirmation.

Anonymised aggregate data

May be retained indefinitely for product improvement and academic research. Anonymised data cannot be linked back to you.

08

Your rights

Under GDPR, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Delete your data ("right to be forgotten")
  • Restrict or object to certain processing
  • Receive your data in a portable format
  • Withdraw consent where processing is based on it
  • Lodge a complaint with a data protection authority

To exercise any of these rights, contact [email protected]. We respond within 30 days.

You may also lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, aepd.es).

09

How we protect your data

All personal data is encrypted at rest (AES-256) and in transit (TLS). Sensitive fields carry additional field-level encryption.

Full technical details on encryption, authentication, incident response, and security audits are on our Trust page.

10

Changes to this policy

We may update this policy to reflect changes in our practices or legal requirements. Material changes will be notified to you by email at least 30 days before they take effect.

The current version of this policy is always available at withpilar.com/legal/privacy. The date at the top indicates when the policy was last updated.