This English version is provided for convenience. The Spanish version is the legally binding text.
Executive summary
We only collect the data needed to provide our services. We don't sell or share your data with third parties. You can exercise your rights at any time.
1. Data controller
Data controller: Verasens
Contact for exercising your rights: [email protected]
The data controller's full identification details will be published here as soon as company registration is complete. The rights of access, rectification, erasure and the other rights provided for in GDPR can already be exercised at the email address above.
2. Data we collect
Contact forms
When you contact us through our forms, we collect:
- First and last name
- Email address
- Phone number (optional)
- Company name
- Message or enquiry
Radar service
For the cybersecurity scan we collect:
- Company domain
- Email address (to send the report)
- Technical scan data (ports, certificates, DNS, etc.)
Browsing data
We automatically collect:
- IP address
- Browser type
- Pages visited
- Time on site
- Technical and preference cookies
3. Purposes of processing
Handling enquiries
Purpose: Respond to your enquiries and provide information about our services
Legal basis: Consent and legitimate interest
Retention: 3 years from the last contact
Service delivery
Purpose: Deliver the services you have contracted (audits, scans, etc.)
Legal basis: Performance of a contract
Retention: For the term of the contract and 6 years after it ends
Analytics and improvement
Purpose: Analyse website usage to improve the experience
Legal basis: Legitimate interest
Retention: 2 years (aggregated and anonymised data)
4. Data sharing
We don't sell or share your data with third parties for commercial purposes.
We only share data with third parties in the following cases:
- Service providers: Email marketing, hosting, analytics (under confidentiality agreements)
- Legal obligations: When required by the competent authorities
- Protection of rights: To defend our legitimate rights
5. International transfers
Some of our providers may be located outside the European Economic Area. In those cases, we make sure appropriate safeguards are in place through standard contractual clauses approved by the European Commission.
6. Your rights
As a data subject, you have the right to:
Access
Know what data we hold about you
Rectification
Correct inaccurate data
Erasure
Request the deletion of your data
Portability
Receive your data in a structured format
Objection
Object to the processing of your data
Restriction
Restrict processing
7. Security measures
We apply appropriate technical and organisational measures to protect your personal data:
- SSL/TLS encryption on all communications
- Data access restricted to authorised staff only
- Encrypted backups
- Periodic security audits
- Staff training in data protection
8. Contact and exercising your rights
To exercise your rights or resolve any questions about how your data is processed, you can contact us:
You can also lodge a complaint with the AEPD (Spain's data protection authority) (www.aepd.es).
9. Updates
We may update this privacy policy from time to time. We'll notify you of any significant changes by email or through a notice on the website.