Saltar al contenido

Legal

Privacy policy

Information on the processing of personal data under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Act 3/2018 on Data Protection and Digital Rights (LOPDGDD).

Last updated: August 2026

1. Data controller

Controller
Fesnorix Digital Infrastructure.
Address
Paseo de Recoletos 10, 28001 Madrid, Spain.
Privacy contact
privacy@fesnorix.com
Data Protection Officer
You may contact the DPO at privacy@fesnorix.com.

2. Data processed and purposes

Contact form
Name, email, company and message content, to handle your enquiry and maintain the commercial or service relationship.
Ethics channel (whistleblowing)
Report content and, where applicable, the reporter's identity, to manage reports under Spanish Act 2/2023 on the protection of persons reporting regulatory breaches.
Recruitment
CV data provided voluntarily, to assess applications.
Browsing
Technical and usage data collected via cookies and similar technologies, as described in the Cookie Policy.

3. Legal basis

  • Consent (art. 6.1.a GDPR) for informational communications and non-essential cookies.
  • Performance of a contract or pre-contractual measures (art. 6.1.b GDPR) for service delivery and commercial requests.
  • Compliance with legal obligations (art. 6.1.c GDPR), including tax, accounting and Act 2/2023 obligations for the ethics channel.
  • Legitimate interest (art. 6.1.f GDPR) in systems security, fraud prevention and service improvement.

4. Retention periods

Data is kept for the duration of the relationship and thereafter for the applicable statutory limitation periods (generally up to 6 years for commercial matters and 4 years for tax matters). Ethics channel reports are kept only as long as needed to decide on their admissibility and, in any case, no longer than three months from receipt, unless retained as evidence of the system's operation. Applications are kept for a maximum of one year.

5. Recipients and international transfers

Data is not shared with third parties except where legally required. Providers acting as processors (hosting, email, support and analytics tools) may access data under agreements signed pursuant to article 28 GDPR.

Where a provider is located outside the European Economic Area, transfers rely on a European Commission adequacy decision or on Standard Contractual Clauses with supplementary measures.

6. Your rights

You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw consent, by writing to Fesnorix Digital Infrastructure, Paseo de Recoletos 10, 28001 Madrid, Spain, or to privacy@fesnorix.com, stating the right exercised and attaching proof of identity.

You may also lodge a complaint with the Spanish Data Protection Agency (www.aepd.es, C/ Jorge Juan 6, 28001 Madrid) if you believe your rights have not been properly addressed.

7. Information security

Fesnorix applies appropriate technical and organisational measures (encryption in transit and at rest, role-based access control, activity logging, backups, monitoring and periodic audits) to ensure a level of security appropriate to the risk, as required by article 32 GDPR.

All activity carried out in Fesnorix private environments and systems is monitored, recorded and subject to periodic audits.

8. Accuracy of data

You warrant the accuracy of the data provided and undertake to notify any changes. If you provide third-party data, you must inform those individuals of this policy beforehand.