1. Data controller
- Controller
- Fesnorix Digital Infrastructure.
- Address
- Paseo de Recoletos 10, 28001 Madrid, Spain.
- Privacy contact
- privacy@fesnorix.com
- Data Protection Officer
- You may contact the DPO at privacy@fesnorix.com.
Legal
Information on the processing of personal data under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Act 3/2018 on Data Protection and Digital Rights (LOPDGDD).
Last updated: August 2026
Data is kept for the duration of the relationship and thereafter for the applicable statutory limitation periods (generally up to 6 years for commercial matters and 4 years for tax matters). Ethics channel reports are kept only as long as needed to decide on their admissibility and, in any case, no longer than three months from receipt, unless retained as evidence of the system's operation. Applications are kept for a maximum of one year.
Data is not shared with third parties except where legally required. Providers acting as processors (hosting, email, support and analytics tools) may access data under agreements signed pursuant to article 28 GDPR.
Where a provider is located outside the European Economic Area, transfers rely on a European Commission adequacy decision or on Standard Contractual Clauses with supplementary measures.
You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw consent, by writing to Fesnorix Digital Infrastructure, Paseo de Recoletos 10, 28001 Madrid, Spain, or to privacy@fesnorix.com, stating the right exercised and attaching proof of identity.
You may also lodge a complaint with the Spanish Data Protection Agency (www.aepd.es, C/ Jorge Juan 6, 28001 Madrid) if you believe your rights have not been properly addressed.
Fesnorix applies appropriate technical and organisational measures (encryption in transit and at rest, role-based access control, activity logging, backups, monitoring and periodic audits) to ensure a level of security appropriate to the risk, as required by article 32 GDPR.
All activity carried out in Fesnorix private environments and systems is monitored, recorded and subject to periodic audits.
You warrant the accuracy of the data provided and undertake to notify any changes. If you provide third-party data, you must inform those individuals of this policy beforehand.