Privacy Policy
This policy explains how the company operating ifxtools, incorporated in Spain and subject to EU data-protection law, handles the personal data of visitors and contacts. It applies wherever you are in the world.
Regulatory framework
The General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679 — is the European Union's primary data-protection law. It applies to any organisation that processes the personal data of people located in the EU or EEA, regardless of where the organisation itself is based. It gives individuals enforceable rights over their data and requires organisations to be transparent about how they use it.
The Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD) is the Spanish national law that complements and implements the GDPR within Spain. Because the company operating ifxtools is incorporated and headquartered in Barcelona, Spain, both instruments apply to all data it processes.
1. User information
Who is the controller of your personal data?
The company operating ifxtools (referred to below as "we", "us" or "the Company") is the data controller — the entity that determines the purposes and means of processing your personal data. We are incorporated in Spain and process personal data in accordance with Regulation (EU) 2016/679 of 27 April (GDPR) and the Organic Law 3/2018 of 5 December (LOPDGDD).
Why do we process your personal data?
To respond to the requests you make and to maintain a commercial relationship with you. The planned processing operations are:
- Arranging and delivering the diagnostic run, capability evaluation or conversation you request through the contact form on this site.
- Responding to queries, requests or any other type of request you make through the contact methods available on this site.
- Maintaining a commercial relationship in connection with the products and services described on this site.
Why can we process your personal data?
Because the processing is lawful according to article 6 of the GDPR:
- Your consent: when you submit the contact form to request a diagnostic run or a conversation.
- Our legitimate interest: to process and respond to the requests you make of us.
How long will we keep your personal data?
Your personal data is stored for no longer than necessary to fulfil the purpose or purposes of the processing, or as long as legal prescriptions require its custody. When the purpose is no longer necessary, the data is erased with appropriate security measures to ensure its anonymisation or complete destruction.
To whom do we disclose your personal data?
No communication of personal data to third parties is foreseen, except where required by legal obligation, where necessary for the development and execution of the purposes of the processing, or to our service providers with whom the Company has signed the confidentiality and data-processing contracts required by current privacy regulations.
What are your rights?
Your rights are:
- Right to withdraw consent at any time.
- Right of access, rectification, portability and erasure of your data, and the limitation of or objection to its processing.
- The right to file a claim with the Spanish Supervisory Authority (www.aepd.es) if you consider that the processing does not comply with current legislation.
To exercise these rights, contact the Company through the contact page on this site.
2. Compulsory or optional nature of the information provided
By entering your personal data in the fields of the contact form, you accept expressly, freely and unequivocally that this data is necessary to meet your request.
The Company indicates which data is necessary to provide the service you request. Where such data is not provided, we cannot guarantee that the information and services provided will match your needs.
You guarantee that the personal data provided to the Company is true, and you are responsible for communicating any changes to it.
3. Security measures
The Company complies with the provisions of the GDPR and LOPDGDD for the processing of the personal data for which it is responsible, and observes the principles described in Article 5 of the GDPR: data is processed lawfully, fairly and transparently, and is adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.
In practical terms: access to personal data is restricted to authorised personnel; data in transit is encrypted; retention periods are enforced; and any data breach that meets the GDPR notification threshold is reported to the AEPD within 72 hours.
4. Cookies and similar technologies
This site does not use third-party advertising or analytics cookies. It does not embed advertising-network trackers, and it does not build a profile of your browsing.
The site may use strictly-necessary technologies required for it to function and to honour a choice you have made — for example, storing a preference locally in your browser. Under Article 5(3) of the ePrivacy Directive, strictly-necessary technologies do not require consent.
For the full disclosure, see the Cookies Policy at /cookies/. You can clear any cookie at any time using your browser's standard privacy controls. If web analytics are introduced in the future, this policy and the Cookies Policy will be updated before they are enabled, and any technology that requires consent will be gated behind a consent banner.
5. Server access logs
The site is served through a content-delivery network. Standard access logs record, per request: the request timestamp, the visitor's IP address, the requested URL, the HTTP status code, the size of the response, the referring URL, the user-agent string and the viewer's country derived from the IP. No cookies are recorded in these logs.
The lawful basis for this processing is Article 6(1)(f) of the GDPR — the Company's legitimate interest in operating the site reliably, detecting abuse and security incidents, and measuring aggregate traffic. No automated decision-making is performed on the basis of these logs.
Logs are retained for a bounded period proportionate to the operational-telemetry purpose, after which they are deleted automatically. They are stored within the European Union and are not shared with third parties, except where a legal obligation requires disclosure to a competent authority.