Privacy Policy
At Genloox privacy is a right, not an option. Here we explain clearly and completely how we handle your personal data.
1 Data controller
In accordance with the GDPR (EU) 2016/679 and applicable national data protection law, the controller of the personal data collected through this website is:
| Name | Genloox |
|---|---|
| Activity | Software development company — web and mobile applications, CRM, technology consulting and digital services |
| Address | Doctor Severo Ochoa, 136. Pol. Ind. Torrehierro, Spain |
| Phone | +34 671 27 85 34 |
| Contact email | genlooxtech@gmail.com |
| Website | genloox.com |
2 Data we collect
2.1 Contact form
- First and last name.
- Email address.
- Phone number (optional).
- Subject and message content.
- IP address and browser User-Agent (for anti-spam security).
2.2 Contractual relationship (clients)
- Identification data: name, surnames, ID/tax number, company name.
- Professional contact data: email, phone, postal address.
- Financial data: bank details for invoicing and payment management.
- Professional data: job title, department, company.
2.3 Management panel (software users)
When Genloox develops or manages platforms for its clients that include user accounts, only the minimum data necessary for authentication and use of the service is processed (email, name, hashed password, role, access log). In these cases Genloox acts as Data Processor (see clause 10).
2.4 Browsing data (analytics)
- Pages visited, session time, device and browser.
- Anonymised IP address.
- Conversion data (CTA clicks, form submissions).
This data is collected via analytics cookies after obtaining consent (see clause 7).
2.5 Data we do NOT collect
Genloox does not collect special categories of data (health, political ideology, religious beliefs, ethnic origin, biometric data, etc.) through its usual channels. If a specific project requires processing such data, we will inform you and obtain the additional safeguards required by the GDPR.
3 Purposes and legal bases
| Purpose | Legal basis (art. 6 GDPR) |
|---|---|
| Handling enquiries and information requests received via the contact form, email or phone. | Legitimate interest (6.1.f) / Consent (6.1.a) |
| Managing the contractual relationship: formalisation, execution, invoicing and collection of contracted services. | Performance of a contract (6.1.b) |
| Compliance with legal obligations: accounting, taxation, invoice retention as required by tax regulations. | Legal obligation (6.1.c) |
| Sending commercial communications and news about Genloox services to clients or contacts who have expressed interest. | Consent (6.1.a) / Legitimate interest for existing clients |
| Statistical analysis of website behaviour to improve user experience (web analytics). | Consent (6.1.a) |
| Fraud prevention, IT security and protection of Genloox systems. | Legitimate interest (6.1.f) |
4 Retention periods
Personal data will be retained for the minimum period necessary for each purpose:
| Type of data | Retention period |
|---|---|
| Contact enquiries without subsequent engagement | 2 years from the last interaction |
| Client data (contracts, projects, communications) | Duration of contract + 5 years (civil limitation) or 10 years if legally required |
| Invoices and tax data | 10 years (Tax Administration requirements) |
| Web analytics data (cookies) | Depending on cookie type; maximum 2 years |
| Access and security logs | 90 days, unless an active incident investigation is ongoing |
| Commercial communications data (newsletter) | Until consent is withdrawn |
After these periods, data will be deleted or irreversibly anonymised.
5 Recipients and international transfers
5.1 Internal recipients
Only Genloox staff with a legitimate need to access data in order to provide the contracted service will have access to your data.
5.2 Data processors (suppliers)
Genloox may share data with third-party providers acting as data processors, with whom the appropriate data processing agreement (art. 28 GDPR) has been signed. These may include, depending on the project:
- Hosting and server providers (e.g. Hostinger, OVH, AWS, DigitalOcean).
- Web analytics tools (e.g. Google Analytics with IP anonymisation enabled).
- Transactional email platforms (e.g. own SMTP, Mailgun).
- Payment gateways (e.g. Stripe, PayPal) for payment processing.
- Project management and internal communication tools restricted to the Genloox team.
5.3 International transfers
Some providers may be located outside the European Economic Area (EEA). In such cases, Genloox ensures that transfers are made with appropriate GDPR safeguards: European Commission adequacy decisions, standard contractual clauses or recognised certification frameworks.
5.4 No sale of data
Genloox never sells, rents or transfers personal data to third parties for their own commercial purposes.
6 Your rights
Under the GDPR, you may exercise the following rights at any time:
Obtain confirmation of whether Genloox is processing your data and receive a copy.
Correct inaccurate or incomplete data relating to you.
Request deletion of your data when, among other reasons, it is no longer necessary for the purposes for which it was collected.
Object to the processing of your data when the legal basis is legitimate interest or for direct marketing purposes.
Request suspension of the processing of your data in certain circumstances (e.g. while a challenge is being verified).
Receive your data in a structured, commonly used and machine-readable format and transmit it to another controller.
Withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
Not be subject to decisions based solely on automated processing that produce significant legal effects.
6.1 How to exercise your rights
You can exercise any of these rights by sending a request to genlooxtech@gmail.com, stating your full name, the right you wish to exercise and, if possible, a copy of your identity document. We will respond within a maximum of one month from receipt (extendable by two more months in complex cases).
6.2 Complaint to the supervisory authority
If you believe that the processing of your data does not comply with the GDPR, you have the right to lodge a complaint with the competent supervisory authority. In Spain: www.aepd.es.
7 Cookies and similar technologies
The Genloox website uses first-party and third-party cookies. The types used are described below:
| Type | Purpose | Legal basis | Duration |
|---|---|---|---|
| Technical / strictly necessary | Basic website functionality: session, security, language preference. | Legitimate interest / technical necessity | Session or up to 1 year |
| Analytics | Statistical analysis of web traffic (page views, source, session time). Anonymised data. | Consent | Up to 2 years |
| Preferences | Remember user preferences (e.g. language, theme). | Consent | Up to 1 year |
When you first access the website, a consent banner is shown in accordance with applicable regulations. You can manage or revoke your consent at any time from the site cookie settings or from your browser preferences.
For more information on how to disable cookies in major browsers, visit the help pages of Chrome, Firefox, Safari or Edge.
8 Data security
Genloox applies appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of communications via TLS/HTTPS across all web environments.
- Password storage using secure hash algorithms (bcrypt/Argon2).
- Data access restricted by roles and the principle of least privilege.
- Regular backups and disaster recovery procedures.
- Access monitoring and anomaly detection in systems.
- Regular security updates for software and dependencies.
- Periodic team training on security and privacy best practices.
8.1 Data breach notification
In the event of a security breach that poses a risk to the rights and freedoms of data subjects, Genloox will notify the supervisory authority within a maximum of 72 hours of becoming aware of it, and affected individuals without undue delay, in accordance with art. 33 and 34 GDPR.
9 Children's data
Genloox services are aimed at businesses and professionals. Genloox does not knowingly collect personal data from children under 14. If we detect that we have collected data from a child without verifiable parental consent, we will delete it immediately.
If you are a parent or guardian and believe your child has provided us with personal data, please write to us at genlooxtech@gmail.com.
10 Data processing agreement (Genloox clients)
When Genloox develops or maintains digital platforms for its clients involving the processing of personal data of third parties (end users, the client's customers, employees, etc.), Genloox acts as Data Processor and the contracting client as Data Controller.
In such cases:
- A Data Processing Agreement in accordance with art. 28 GDPR will be signed prior to the start of the project, setting out the controller's instructions, applicable security measures, authorised sub-processors and procedures for breaches and rights requests.
- Genloox will only process data in accordance with the documented instructions of the controller (client) and will not use it for its own purposes.
- Genloox will assist the controller in fulfilling its GDPR obligations (responding to rights requests, impact assessments, breach notifications).
- Upon termination of the contract, Genloox will return or destroy the personal data processed on behalf of the client, unless legally required to retain it.
11 Social media
Genloox maintains profiles on various social media platforms (LinkedIn, Instagram, etc.). The processing of data of people who interact with those profiles (followers, comments, direct messages) is subject to the privacy policies of each platform, which are joint controllers with Genloox.
Genloox uses information from its social media profiles exclusively to:
- Respond to enquiries and messages received through those platforms.
- Publish content about Genloox services and projects.
- Statistical analysis of publication reach using the native analytics tools of each network.
We do not collect or export follower data outside the platforms themselves, except in the case of direct conversions (e.g. a contact who writes via LinkedIn and with whom a business relationship begins, at which point the purposes in clause 3 apply).
12 Policy changes
Genloox reserves the right to update this Privacy Policy to reflect regulatory changes, case law or changes in its own activities. Any changes will be published on this page with the new update date.
For substantial changes affecting consent-based processing, Genloox will notify data subjects by email or via a prominent notice on the website and will request renewal of consent where necessary.
We recommend you review this page periodically. The version in force is the one published at genloox.com/privacy with the last updated date shown at the top of the document.
13 Contact & DPO
For any query, rights request or complaint relating to the processing of your personal data, you may contact Genloox through the following channels:
+34 671 27 85 34
Doctor Severo Ochoa, 136
Pol. Ind. Torrehierro, Spain
genloox.com/contact