Data controller
Quevedo Tech Group, S.L. is the controller of personal data processed through nubyron.com. You can contact us at rgpd@nubyron.com or at our registered address.
Scope and applicable principles
This policy applies to data provided or generated through nubyron.com and its associated channels: enquiries, professional communications, contracts, applications and relationships with clients, suppliers or partners. It is supplemented by specific notices in forms, proposals or contracts.
We process data under Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 (LOPDGDD) and other applicable rules.
- Lawfulness, fairness and transparency: each processing activity has a legal basis and is explained clearly.
- Purpose limitation: we use data for specified, explicit and legitimate purposes.
- Data minimisation and accuracy: we request only adequate information and seek to keep it up to date.
- Storage limitation: we do not retain data longer than necessary.
- Integrity, confidentiality and accountability: we apply proportionate controls and review compliance.
Data we process
We process the data you provide when contacting us, requesting information or applying for a position. The form sends your details to our server and uses Resend to deliver your enquiry to our team and send you a confirmation. We use Cloudflare Turnstile to verify requests and prevent automated submissions. The application does not save form content in a database; the enquiry is retained in the email services used to handle it.
- Identity and contact details, such as your name, email and phone number.
- Professional, business or technical information included in an enquiry.
- CV, experience, professional profile and other information included in a job application.
- Minimum technical data generated when serving the site, such as server security logs.
- Financial, billing and transaction data where a contractual relationship exists.
- Communications, stated preferences and documents needed to provide or assess a service.
Source and required information
We normally obtain data directly from you or the organisation you represent. It may also come from someone referring an opportunity, public professional sources, or providers and partners where there is a legitimate basis. We will disclose the source where required by law.
Required information allows us to process or answer a request. Without it, we may be unable to reply, prepare a proposal, formalise a service or assess an application. Do not include sensitive categories that are not necessary.
Purposes and legal bases
- Answering enquiries and preparing proposals: steps requested before entering a contract or our legitimate interest in responding to professional communications.
- Managing contracted services: performance of a contract and compliance with legal obligations.
- Managing applications: consent and, where applicable, steps prior to a possible employment relationship.
- Protecting the website and preventing misuse: our legitimate interest in maintaining service security and availability.
- Managing supplier and partner relationships: contract performance, pre-contract steps and legitimate interest in organising the professional relationship.
- Meeting accounting, tax, employment or regulatory duties: compliance with a legal obligation.
- Sending service communications: consent where required or legitimate interest in an existing professional relationship, with a right to object at any time.
Automated decisions and profiling
We do not make decisions with legal or similarly significant effects based solely on automated processing, nor create commercial profiles through this site. If this changes, we will explain the logic, significance, consequences and safeguards before processing begins.
Recipients and providers
We do not sell or disclose personal data for commercial purposes. Providers helping us with hosting, email, communications or support may access it under confidentiality and data protection obligations.
We may also disclose data where required by law, requested by a competent authority, or necessary to establish, exercise or defend legal claims.
- Hosting, infrastructure, email and communication providers.
- Advisers, auditors, financial institutions and professionals bound by confidentiality.
- Public authorities, courts and law enforcement where legally required.
- Authorised technical collaborators where needed for the contracted service.
International transfers
Some technology providers may provide services from outside the European Economic Area. Where this occurs, we apply GDPR safeguards such as an adequacy decision or Standard Contractual Clauses, together with any necessary supplementary measures.
Retention periods
We retain data for as long as needed for its purpose and then for any period required to meet legal obligations or potential liabilities. Enquiries that do not lead to a contractual relationship are normally reviewed and deleted within 12 months. Applications are retained during the selection process and, with permission, for up to 12 months for future opportunities.
- Contracts and billing: during the relationship and applicable statutory retention and limitation periods.
- Enquiries and unaccepted proposals: normally up to 12 months after the last interaction.
- Applications: during the process and for up to 12 additional months where appropriate and authorised.
- Technical logs: the minimum period needed to prevent, investigate and document incidents.
- Where a legal duty or claim requires retention, information may be restricted and used only for that purpose.
Your rights
You may request access, rectification, erasure, objection, restriction and portability, and withdraw consent without affecting prior lawful processing. Write to rgpd@nubyron.com and state the right you wish to exercise. We will only request additional information to verify your identity where reasonable doubts exist.
- If you believe processing does not comply with the law, you may lodge a complaint with the Spanish Data Protection Agency (aepd.es).
- Exercising your rights is free. We normally respond within one month; where requests are complex or numerous, the period may be extended by two further months and we will tell you within the first month.
- You may act directly or through a representative. If we do not act on the request, we will explain why and identify the available complaint routes.
- You may also object to automated individual decisions, although we do not currently carry out this type of processing.
Security measures
We apply reasonable technical and organisational measures to preserve the confidentiality, integrity and availability of information, reviewing them as risks and services evolve.
These measures may include access control, strong authentication, encryption where appropriate, backups, activity logging, vulnerability management, confidentiality and incident response.
No internet-connected system can guarantee absolute security. If a breach poses a risk to individuals, we will assess it and notify the authority or affected people where required.
Children
Our professional services are not aimed at children under 14 and we do not knowingly request their data. Anyone below that age must not provide information without a legal guardian’s authorisation. If we identify improper collection, we will delete the data as soon as possible.
Changes to this policy
We will update this policy when our processing, providers or applicable obligations change. The current version and update date will always be available on this page.
