Legal
Privacy policy
Last updated: July 2026
1. Data controller
In compliance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPD-GDD), we inform you that the controller responsible for processing your personal data is:
- Legal name: THRAX BIEITO INGENIERIA INFORMATICA SL (hereinafter, "THRAX")
- Tax ID (CIF): B24784175
- Address: Carrer Joan Vidal i Jumbert 10, 08403 Granollers (Barcelona)
- Email: [email protected]
- Phone: 644 836 122
THRAX does not have a Data Protection Officer (DPO), as it is not required to under article 37 GDPR. For any queries regarding the protection of your data, you can write to us at [email protected].
2. Data we collect and purpose
Through this website's contact form we collect the following personal data:
- First and last name — to identify you and personalise communication. Name is required.
- Email address — to respond to your enquiry. Required.
- Phone number — to contact you if necessary. Optional.
- Message — to understand the reason for your enquiry and address it. Required.
Main purpose: to manage enquiries received through the form and respond to requests for information. We do not use this data to build profiles or for advertising purposes.
Additionally, the web server hosting this site records the IP address, date and time of the request, the page requested and the browser used in its activity logs. This is a technical record necessary for the operation and security of the service, whose legal basis is the legitimate interest of THRAX (art. 6.1.f GDPR). These logs are not cross-referenced with form data and are not used to identify visitors.
3. Legal basis for processing
The legal basis for processing the form data is the consent of the data subject (art. 6.1.a GDPR): by ticking the acceptance box and submitting the form, you expressly consent to the processing of your data for the stated purpose.
You can withdraw your consent at any time by writing to [email protected], without affecting the lawfulness of processing carried out prior to its withdrawal.
4. Retention period
Data collected through the form will be kept for a maximum period of 6 months from receipt of the enquiry, unless a legal obligation requires a longer retention period, or the enquiry leads to a business relationship, in which case the periods in section 8 will apply.
Once this period has elapsed, the data will be securely deleted.
5. Recipients and data processors
Your data will not be shared with third parties except where legally required.
Form data is passed to THRAX's internal enquiry management system. Reply emails are sent using the SMTP service of DonDominio (Nominalia Internet SL), a Spanish provider with servers located in Spain.
No international data transfers outside the European Economic Area take place.
6. User rights
Under the GDPR and the LOPD-GDD, you may exercise the following rights:
- Access: find out what personal data of yours we process.
- Rectification: request the correction of inaccurate or incomplete data.
- Erasure: request the deletion of your data when it is no longer necessary.
- Restriction: request that processing be restricted in certain circumstances.
- Objection: object to the processing of your data.
- Portability: receive your data in a structured, commonly used format.
To exercise any of these rights, send an email to [email protected] stating which right you wish to exercise and attaching a copy of your ID document or equivalent.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD):
- Website: www.aepd.es
- Address: C/ Jorge Juan, 6, 28001 Madrid, Spain
- Phone: +34 900 293 183
7. Security measures
THRAX has adopted the technical and organisational measures necessary to guarantee the security of your personal data and prevent its alteration, loss, unauthorised processing or access, taking into account the state of the art, the nature of the data and the risks to which it is exposed. The site is served entirely over an encrypted connection (HTTPS).
8. Customers, invoicing and SEPA direct debits
We process data of clients and/or their representatives (identification and contact details, address, and banking data such as IBAN; and, where applicable, tax ID) to manage the business relationship, provide the service, handle invoicing, collect payment via SEPA direct debit, and manage incidents and refunds.
- Legal basis: performance of a contract or application of pre-contractual measures (art. 6.1.b GDPR) and compliance with legal obligations (art. 6.1.c GDPR).
- Recipients: financial institutions and banks involved in payment collection; public authorities where legally required.
- Retention: for the duration of the business relationship and, thereafter, for the legal retention periods applicable to commercial and accounting documentation (generally 6 years from the last accounting entry, unless special periods apply).
- Rights: access, rectification, erasure, objection, restriction and portability, and the right to lodge a complaint with the AEPD (www.aepd.es).
9. Cookies
This site uses one strictly necessary first-party cookie to remember your cookie choice. Full details, including the categories reserved for analytics and marketing (currently with no active tool), are in the Cookie Policy.