At AIRON TEAM SL we take privacy seriously. This policy explains, transparently and in accordance with articles 13 and 14 of Regulation (EU) 2016/679 (GDPR), what personal data we process through this website, for what purpose and legal basis, for how long, with whom we share it and what rights you have.
1. Data controller
- Controller: AIRON TEAM SL (hereinafter, 'AIRON')
- NIF/CIF: [PENDIENTE_CIF_NIF]
- Address: Plaza Mayor 1A, Valladolid, 47001, España
- Privacy contact: info@airon.team (subject: 'Data protection')
Data Protection Officer (DPO): a DPO has not been appointed as none of the cases of mandatory appointment under article 37 GDPR apply. Nevertheless, you may address any question relating to your data through the contact email indicated.
2. Applicable regulations
This processing is governed, among others, by:
- Regulation (EU) 2016/679, General Data Protection Regulation (GDPR).
- Organic Law 3/2018, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
- Law 34/2002, on information society services and electronic commerce (LSSI-CE).
- The guidelines and interpretative criteria of the Spanish Data Protection Agency (AEPD) and the European Data Protection Board (EDPB).
3. Origin and categories of data
We process only the data that you voluntarily provide to us through the site's forms (contact, demo request or newsletter subscription) and the technical data derived from your browsing. We do not obtain data from external sources nor do we process special categories of data (art. 9 GDPR).
- Identification and contact data: name, email, company and position or telephone, if you provide them.
- Enquiry data: the content of the message, the demo request or the information you decide to include.
- Subscription data: subscription email and, where applicable, interaction data with the mailings (opening, click), if enabled.
- Technical data: IP address, device and browser type and usage data, where a valid legal basis exists.
4. Purposes, legal bases and retention
4.1 Handle contact or demo requests
- Purpose: manage your enquiry and maintain pre-contractual communications.
- Legal basis: application of pre-contractual measures at your request (art. 6.1.b GDPR) and/or legitimate interest in handling enquiries (art. 6.1.f GDPR).
- Retention: during the management of the request and any relationship that may arise from it; afterwards, blocked during the limitation periods of any potential liabilities.
4.2 Sending of the newsletter and informational communications
- Purpose: send you content, news and communications about AIRON.
- Legal basis: your express consent (art. 6.1.a GDPR), which you can withdraw at any time without affecting the lawfulness of the prior processing.
- Retention: until you withdraw consent or unsubscribe; after that, we block your data to demonstrate compliance.
4.3 Site usage analytics
- Purpose: aggregate measurement to improve content, experience and performance.
- Legal basis: your consent (art. 6.1.a GDPR and art. 22.2 LSSI-CE) when non-exempt cookies or tracking technologies are used. Check the current status in the Cookie Policy.
- Retention: according to the periods of the analytics provider that, where applicable, is implemented.
4.4 Security and legal compliance
- Purpose: ensure the security of the site and meet legal obligations.
- Legal basis: legitimate interest in security (art. 6.1.f GDPR) and compliance with legal obligations (art. 6.1.c GDPR).
5. Automated decisions and profiling
This website does not make automated decisions that produce legal effects or that significantly affect you in a similar way (art. 22 GDPR), nor does it carry out profiling for that purpose. The AIRON platform contracted by our clients is governed by its own service agreement and maintains, by design, human supervision and approval in sensitive actions.
6. Recipients and data processors
We do not disclose your data to third parties, except by legal obligation. To provide the service we rely on providers that act as data processors, under a contract in accordance with article 28 GDPR:
- Resend — Management of demo and contact requests. Privacy policy.
- Mailchimp — Management of subscriptions and newsletter mailings. Privacy policy.
- Analytics — Aggregate measurement of site usage and performance. The final provider will be inventoried in the Cookie Policy when it is activated.
Hosting and technical infrastructure providers necessary to operate the site may also access the data as processors.
7. International transfers
Some of our providers (for example, Resend and Mailchimp) are located in or may process data in the United States, outside the European Economic Area. In such cases we require adequate safeguards in accordance with Chapter V of the GDPR, such as adherence to the EU-US Data Privacy Framework when the provider is certified, or the Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914) together with supplementary measures where necessary. You may request information about such safeguards through the contact email.
8. Rights of data subjects
You may exercise, free of charge, the following rights:
- Access: to know what data of yours we process.
- Rectification: to correct inaccurate or incomplete data.
- Erasure ('right to be forgotten'): to request that we delete it where appropriate.
- Restriction: to restrict the processing in certain cases.
- Objection: to object to processing based on legitimate interest.
- Portability: to receive your data in a structured format or have us transmit it to another controller.
- Withdrawal of consent at any time, without retroactive effects.
- Not to be subject to automated decisions with legal or significant effects.
To exercise them, write to us at info@airon.team indicating the right you wish to exercise; we may request documentation proving your identity. We will respond within a maximum period of one month, extendable to two months in complex cases (art. 12 GDPR).
9. Complaint before the supervisory authority
If you consider that the processing does not comply with the regulations, you may file a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid, or through its electronic headquarters: www.aepd.es. Beforehand, you may contact our privacy email to try to resolve the matter.
10. Security measures
We apply the appropriate technical and organisational measures (art. 32 GDPR) to ensure a level of security appropriate to the risk, including the encryption of communications (HTTPS/TLS), access control according to the principle of least privilege, pseudonymisation where appropriate, backups and the periodic review of the effectiveness of these measures.
11. Security breaches
In the event of a data security breach that poses a risk to your rights, we will notify the AEPD within a maximum period of 72 hours (art. 33 GDPR) and, where it entails a high risk, we will also communicate it to you without undue delay (art. 34 GDPR).
12. Minors
The forms on this site are aimed at persons over 14 years of age (art. 7 LOPDGDD). If we detect data of a minor without the required authorisation, we will delete it.
13. Obligation to provide the data
The data marked as mandatory in each form are necessary to handle your request; if you do not provide them, we will not be able to manage it. The rest of the data are voluntary.
14. Changes to this policy
We may update this policy to reflect regulatory, technical or operational changes. The version in force will always be the one published on this page, with its date of last update.