Behemoth

Privacy Policy

What data we process, in which role in each case, what we use it for, and how to exercise your rights.

In effect from 2026-09-01

1. The two roles

Behemoth processes two sets of personal data that must not be confused, because the party responsible for each is a different one. This distinction governs everything that follows.

Account data is the data that identifies the Customer and the users the Customer authorizes: company identification, contact details, credentials, and billing information. With respect to that data, Nephilim Systems LLC acts as controller and determines the purposes of the processing within what this Policy describes.

The data the Customer uploads to the system about its own customers, suppliers, and employees is a different matter. With respect to that data, the controller is the Customer: it decides what to upload, for what purpose, and for how long. Nephilim acts solely as processor and processes that data only in order to provide the service and following the Customer’s instructions, on the terms of the Data Processing Addendum.

Accordingly, Nephilim does not use the data the Customer uploads for purposes of its own, does not combine it across different customers, and does not exploit it commercially.

2. What data we collect

As controller, we collect the following account data:

  • Company identification: legal name, trade name, and address.
  • Tax identification: the taxpayer number or equivalent applicable in the Customer’s jurisdiction.
  • Contact details: email address, telephone number and, where the Customer provides one, a messaging channel.
  • Administrator user data: name, email address, job title, and access credentials.
  • Billing data: the plan contracted, payment history, and the data the payment processor returns to us in order to reconcile the charge.

We also collect technical data generated by the use of the system itself:

  • The IP address from which access takes place.
  • Access and activity logs: date, time, operation performed, and the user who performed it.
  • Session cookies necessary to keep the session signed in.

We do not collect sensitive account data, nor do we request information that is not necessary in order to provide the service and bill for it.

3. What we use it for

We use account data for the following purposes, and for no other:

  • To provide the service: create and maintain the account, enable the modules of the plan contracted, and allow access by the authorized users.
  • To bill: issue and collect the subscription, reconcile payments, and keep the accounting record of the relationship.
  • To provide support: handle inquiries and incidents and communicate operational notices, version changes, and scheduled maintenance.
  • Security and fraud prevention: detect unauthorized access, abuse of the platform, and uses that infringe the Acceptable Use Policy.
  • To comply with legal obligations: retain the records that applicable law requires and respond to requests from a competent authority.

We do not use the data for behavioral advertising or to build profiles producing legal effects on individuals.

4. Who we share it with

We share data only with the providers that make the service possible and that act as our subprocessors. Each of them, the service it provides, the data it accesses, and the place where it processes that data are set out in our Subprocessor List, which is published and kept up to date.

All of those providers are contractually bound to process the data only on our instructions, to maintain confidentiality, and to apply security measures equivalent to our own.

We do not sell personal data. We do not transfer, rent, or exchange it with third parties for advertising, marketing, or audience-building purposes. Nor have we done so in the past.

We disclose data outside that circle only where an order of a competent authority requires it, where it is necessary in order to bring or defend a legal claim, or where the Customer expressly instructs us to do so.

5. International transfers

The infrastructure that supports Behemoth — compute, database, file storage, and transactional email — operates in the United States of America.

By contracting for the service, the Customer understands and accepts that account data, and the data it uploads to the system, is stored and processed there, regardless of the country from which it operates.

Where the law applicable to the Customer requires a formal mechanism for that transfer, we put it in place by means of the contractual clauses that correspond, at the Customer’s request.

6. How long we keep it

We retain account data for as long as the subscription is active.

After cancellation, the data remains available during the export window set by the Refund and Cancellation Policy, and is deleted when that period expires.

We retain for longer, and solely for that purpose, those records that a legal, accounting, or tax obligation requires us to keep, and those necessary in order to defend a legal claim for as long as it has not lapsed.

7. Your rights

With respect to account data, any individual identified in it may exercise the rights the law affords them, and in particular:

  • Access: obtain confirmation of whether we process their data, and a copy of it.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: request its deletion where it is no longer necessary or where the processing lacks a legal basis.
  • Portability: receive their data in a structured, commonly used format.
  • Objection: object to the processing on grounds relating to their particular situation.
  • Restriction: request that the processing be restricted while a dispute over the data is resolved.

For those to whom the law affords it, there is also the right not to have their personal data sold. That right requires nothing to be exercised against us: as stated above, we do not sell personal data in any case.

These rights are exercised by writing to the contact channel published in the footer of this site, identifying the data subject and the right invoked. We respond within thirty calendar days of the request. If the request is complex or requires additional verification, we say so within that same period, together with the estimated response date.

Exercising these rights is free of charge. Every individual also retains the right to lodge a complaint with the supervisory authority that has jurisdiction over them.

8. Data of end customers

If your data appears in Behemoth because a company that uses the system uploaded it — on account of a purchase, the engagement of a service, or an outstanding debt with that company, for example — that company is the controller of that data, not Nephilim.

In that case, the rights of access, rectification, erasure, portability, objection, and restriction are exercised against that company, which is the party that decided to collect the data and the party able to act on it.

Nephilim assists that company with reasonable tools and information so that it can handle the request within the applicable time limit. If a request of this kind reaches us directly, we forward it to the company concerned and inform the person who submitted it.

9. Security

We apply technical and organizational measures proportionate to the risk of the processing:

  • Encryption in transit by means of TLS in all communication with the service, and encryption at rest of the database and the file storage.
  • Isolation between customers at the database level: every record belongs to one customer, and the engine prevents — by policy, and not merely by application code — a query from reaching another customer’s data.
  • Permission-based access control: each user sees and operates only what their role and permissions allow, and the Customer administers that assignment.
  • Audit logging: every creation, deletion, and modification is recorded together with the user who performed it and the moment at which it occurred.
  • Periodic backups, and verification that they can be restored.

No system is invulnerable. If a security incident affecting personal data occurs, we notify it without undue delay in accordance with the Data Processing Addendum.

10. Minors

Behemoth is a management tool aimed at companies and professionals. It is not intended for minors, and we do not deliberately collect account data belonging to minors.

If we detect that an account has been created in the name of a minor, we close it and delete the associated data.

11. Changes to this Policy

We may modify this Policy. Every change is published on this page with a new version and effective date, and is notified to the Customer within the system.

A material change requires the Customer’s acceptance in order to continue using the service. The record of that acceptance — version, date, and origin — is stored in our systems.

12. Language

The Spanish version of this Policy is the binding one. This English version is provided as a courtesy translation; in the event of any discrepancy, the Spanish text prevails.

13. Contact

Nephilim Systems LLC — Behemoth. The contact channels and the mailing address appear in the footer of this site.

Any request to exercise rights, any question about this Policy, and any report of a privacy incident is directed to that same channel.