Privacy Policy
In compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).
01. Data Controller Information
Entity Name: Zertifier
Registered Headquarters: Cornellà del Terri — Girona (Catalonia, Spain)
Contact Telephone: +34 972 40 04 29
General Contact Email: info@zertifier.com
Privacy & Data Protection Officer: privacy@zertifier.com
02. Principles Applied to Data Processing
In processing your personal data, Zertifier strictly observes the foundational principles set forth in Article 5 of the GDPR:
- Lawfulness, fairness & transparency: We will always require your explicit consent for specific purposes communicated beforehand with absolute transparency.
- Purpose limitation: Personal data is collected exclusively for explicit, legitimate, and specified purposes.
- Data minimization: We request strictly the minimum information necessary to provide our digital infrastructure services.
- Integrity and confidentiality: Data is processed ensuring adequate security, cryptographic encryption, and protection against unauthorized or unlawful processing.
03. Categories of Data We Collect
Depending on how you interact with our website and services, we may process:
04. Purposes & Legal Basis of Processing
| Purpose | Legal Basis (GDPR) | Retention Period |
|---|---|---|
| Responding to contact requests, meetings, and business queries | Explicit consent (Art. 6.1.a) & pre-contractual steps (Art. 6.1.b) | Duration of the inquiry or commercial relationship + 3 statutory years |
| Provision of enterprise trust services and pilot platforms | Performance of a contract (Art. 6.1.b) | Duration of the contract + legal obligations (tax and corporate laws) |
| Platform security, fraud prevention, and server integrity | Legitimate interest (Art. 6.1.f) & legal obligation (Art. 6.1.c) | Standard server logs retained up to 12 months |
05. Recipients & International Transfers
Zertifier does not sell, rent, or trade your personal data to third parties under any circumstances.
Your data may be accessed only by trusted technological service providers acting as Data Processors (such as EU-based cloud hosting providers, IT infrastructure maintainers, and security audit tools), strictly bound by Data Processing Agreements (DPA) under Art. 28 GDPR. If any international transfer occurs outside the European Economic Area (EEA), it is executed under European Commission Adequacy Decisions or Standard Contractual Clauses (SCCs).
06. Your Rights under the GDPR
You hold the following enforceable rights regarding your personal data at all times:
How to exercise your rights:
Send a written request with the subject line "Data Protection Rights" accompanied by proof of identity to privacy@zertifier.com or info@zertifier.com. We will respond within one month without charge.
If you consider that your rights have not been appropriately addressed, you have the right to lodge a complaint with the competent supervisory authority: Agencia Española de Protección de Datos (AEPD) — www.aepd.es.