Privacy Policy
1) Identity of the Data Controller
In accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (General Data Protection Regulation, hereinafter the “GDPR”), Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights (hereinafter the “LOPDGDD”), and other applicable data protection regulations, Users are hereby informed that the entity responsible for the processing of their personal data is: iPronics Programmable Photonics, S.L. (hereinafter, “iPronics”) having its registered office at C. del Convent dels Carmelites 2, entresuelo, 46010 Valencia, Spain, Tax Identification Number (NIF): B40630733 and email address: info@ipronics.com. iPronics acts as Data Controller pursuant to Article 4(7) GDPR, determining the purposes and means of the processing of personal data.
2) Scope and Acceptance of the Privacy Policy
This Privacy Policy governs the collection and processing of personal data obtained through the website https://ipronics.com and its subdomains (hereinafter, the “Website”). Access to and use of the Website implies that the User has read, understood, and accepted this Privacy Policy. If the User does not agree with its terms, they must refrain from using the Website.
3) Categories of Personal Data Processed
a) Personal Data Provided Directly by Users
iPronics may process personal data voluntarily provided by Users through forms, communications, or other means, including:
- Identification data: full name
- Contact data: email address
- Content data: information included in messages, inquiries, or communications
b) Personal Data Collected Automatically
iPronics may collect certain data automatically when Users access or interact with the Website, including:
- Internet Protocol (IP) address
- Device type, operating system, and browser type
- Date, time, and duration of visits
- Pages viewed and navigation patterns
- Referring URLs
Such data may be collected through cookies or similar technologies, as described in the Cookie Policy.
c) Exclusion of Special Categories of Data
Users are expressly prohibited from providing special categories of personal data as defined in Article 9 GDPR (including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health data, or data concerning sexual orientation or criminal convictions).
If such data is inadvertently provided, it will be deleted without undue delay unless a valid legal basis exists for its processing.
4) Principles Governing the Processing of Personal Data
iPronics processes personal data in accordance with the principles established in Article 5 GDPR, namely:
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimization
- Accuracy and updating
- Storage limitation
- Integrity and confidentiality
- Accountability
iPronics ensures that personal data is processed only to the extent necessary and appropriate for the purposes described in this Policy.
5) Purposes of Processing
Personal data will be processed for the following purposes:
a) Management of User Inquiries: To receive, process, and respond to requests, inquiries, or communications submitted by Users.
b) Provision and Improvement of Services: To manage the operation of the Website, improve usability, optimize performance, and develop new functionalities.
c) Security and Fraud Prevention: To ensure the security of the Website, prevent unauthorized access, detect fraudulent activity, and protect the integrity of systems and data.
d) Statistical Analysis and Research: To analyze user behavior and usage patterns in an aggregated and anonymized manner in order to improve services and content.
e) Sending of Commercial Communications: To send marketing or promotional communications to Users where they have provided prior explicit consent or where permitted under applicable law. Users may withdraw their consent at any time.
f) Compliance with Legal Obligations: To comply with legal, regulatory, or judicial obligations applicable to iPronics.
6) Legal Basis for Processing
The processing of personal data is carried out under the following legal bases:
a) Consent (Article 6(1)(a) GDPR): where Users have explicitly provided consent
b) Performance of a contract or pre-contractual measures (Article 6(1)(b) GDPR)
c) Compliance with legal obligations (Article 6(1)(c) GDPR)
d) Legitimate interests of iPronics (Article 6(1)(f) GDPR): including security, fraud prevention, and improvement of services
Where processing is based on legitimate interest, iPronics ensures that such interest does not override the fundamental rights and freedoms of the User.
7) Recipients of Personal Data
Personal data may be disclosed to:
a) Internal Recipients: Authorized employees, collaborators, or representatives of iPronics who require access for the fulfillment of their duties, subject to confidentiality obligations.
b) Data Processors: External service providers acting on behalf of iPronics, including providers of IT services, hosting services, analytics services, and professional advisors. All processors are contractually bound in accordance with Article 28 GDPR to:
- Process data only on documented instructions
- Ensure confidentiality
- Implement appropriate security measures
- Not use data for their own purposes
c) Legal and Regulatory Authorities: Public authorities, courts, or regulatory bodies where disclosure is required by law or necessary for the defense of legal claims.
8) International Data Transfers
Where personal data is transferred outside the European Economic Area, iPronics ensures that appropriate safeguards are implemented, including:
a) Standard Contractual Clauses approved by the European Commission
b) Adequacy decisions adopted by the European Commission
9) Data Retention Periods
a) Personal data will be retained for as long as necessary to fulfill the purposes for which it was collected and to comply with applicable legal obligations. Once the purpose has been fulfilled, data will be:
- Deleted, or
- Blocked and retained only for the purpose of complying with legal obligations and defending against potential claims
b) Retention periods are determined based on:
- Nature and sensitivity of the data
- Purpose of processing
- Legal requirements
10) Security Measures
iPronics implements appropriate technical and organizational measures in accordance with Article 32 GDPR to ensure a level of security appropriate to the risk, including:
- Access control systems
- Data encryption where appropriate
- Monitoring and detection systems
- Regular evaluation of security measures
- Confidentiality obligations for personnel
Notwithstanding the above, Users acknowledge that absolute security cannot be guaranteed.
11) Personal Data Breaches
In the event of a personal data breach, iPronics shall:
- Notify the competent supervisory authority without undue delay, where required by Article 33 GDPR
- Notify affected Users where the breach is likely to result in a high risk to their rights and freedoms, in accordance with Article 34 GDPR
12) Rights of Data Subjects
Users may exercise the following:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to object to processing
- Right to data portability
- Right to withdraw consent at any time
- Right not to be subject to automated individual decision-making
Requests may be submitted to: info@ipronics.com. iPronics may require proof of identity to process requests. Requests will be processed within the time limits established by applicable legislation.
13) Right to Lodge a Complaint
Users have the right to lodge a complaint with the competent supervisory authority: Agencia Española de Protección de Datos (AEPD)
14) Obligations and Responsibilities of Users
Users guarantee that:
- The personal data provided is accurate, complete, and up to date
- They have the legal right to provide such data
- They will not provide data of third parties without authorization
Users shall be solely responsible for any damage resulting from the provision of false or unlawful data.
15) Processing of Data of Minors
The Website is not intended for individuals under eighteen (18) years of age. iPronics does not knowingly collect personal data from minors. If such data is identified, it will be deleted without undue delay.
16) Changes to the Privacy Policy
iPronics reserves the right to modify this Privacy Policy at any time, particularly to adapt it to legislative or regulatory developments or to instructions issued by supervisory authorities. Users will be informed of significant changes where required by applicable law.
17) Applicable Law and Jurisdiction
This Privacy Policy shall be governed by Spanish law. Any disputes arising from its interpretation or application shall be submitted to the competent courts in accordance with applicable legislation, including consumer protection rules where applicable.