Privacy and data protection policy
Here you will find what we do and do not do with your personal data on this website.
This policy explains how personal information is processed and protected for those who interact through this website.
Please read all sections of the Legal Notice, the Cookie Policy, and this Privacy Policy before using this website.
In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and Organic Law 3/2018, of December 5, on the Protection of Personal Data and the guarantee of digital rights, you are informed that, by accepting this Privacy Policy, you give your express, informed, free, and unambiguous consent for the data you provide, which is subject to the security, technical, and organizational measures required under current regulations, to be processed by the owner as data controller.
Data controller
The data controller is the owner of the site and domain:
Controller identity: Setel Kode S.L.
Trade name: Setcode.
Tax ID (NIF): B67288852
Address: Pintor Gimeno, 13 bajos. 08022 Barcelona.
Email:
Purpose of processing: What will we use your data for?
All data provided to this website or its staff is included in a record of personal data processing activities, created and maintained under the responsibility of the owner, and is essential for providing the requested services, informing users, or resolving any queries raised.
Our policy is not to create profiles of the users of our services.
Lawful basis for processing: Why do we need your data?
- Contractual relationship: This applies when you purchase one of our products or contract one of our services.
- Legitimate interest: To handle queries and claims you raise with us and to manage the collection of amounts owed.
- Consent: If you are a user of our website, by checking the box on the contact form, you authorize us to send you the communications necessary to respond to your query or request for information.
Retention: How long will we keep your data?
We will only retain personal data for as long as necessary to achieve the purposes for which it was collected. In determining the appropriate retention period, we consider the risks involved in the processing, as well as our contractual, legal, and regulatory obligations, our internal data retention policies, and our legitimate business interests as described in this Privacy Notice and Cookie Policy.
In this regard, personal data will be retained, duly blocked, once the relationship has ended, for the statute-of-limitations period applicable to any actions that could arise from the relationship maintained with the data subject.
Once blocked, the data will be inaccessible and will not be processed except to make it available to public authorities, judges, and courts, to address any liabilities arising from the processing, as well as for the exercise or defense of claims before the Spanish Data Protection Agency.
The data retention period varies depending on the service contracted. In any case, it will be the minimum necessary, and may be retained for up to:
- 4 years: Law on Infractions and Sanctions in the Social Order (obligations regarding affiliation, registration, deregistration, contributions, salary payments, etc.); Articles 66 et seq. of the General Tax Law (accounting books, etc.).
- 5 years: Article 1964 of the Civil Code (personal actions without a special time limit).
- 6 years: Article 30 of the Commercial Code (accounting books, invoices, etc.).
- 10 years: Article 25 of the Law on the Prevention of Money Laundering and Terrorist Financing.
Security: How will we protect your data?
We are committed to using and processing personal data while respecting its confidentiality, in line with its intended purpose, and to fulfilling the obligation to store it and implement all measures necessary to prevent alteration, loss, unauthorized processing, or access, in accordance with current data protection regulations.
This website includes a security certificate. This is a protocol that ensures your data travels intact and securely; that is, the transmission of data between a server and the web user, and vice versa, is fully encrypted.
We do not guarantee the absolute inviolability of the Internet, nor, therefore, the absence of data breaches through fraudulent access by third parties.
Regarding the confidentiality of processing, we ensure that anyone authorized to process personal data (including our staff, collaborators, and service providers) is subject to an appropriate duty of confidentiality (whether contractual or statutory).
Recipients: Who do we share your data with?
Some tools used on this website to manage data are contracted from third parties. To provide services strictly necessary for carrying out our activity, we share data with providers under their respective privacy terms.
External service providers (for example, where applicable, payment processing services, order processing, analytics, marketing campaign management, website management, email distribution, and other similar service providers) so that they can carry out business functions on our behalf.
The web development and maintenance company or the hosting company may have access to this website. These companies have signed a service agreement requiring them to maintain the same level of privacy applied to the processing carried out on this website.
Any international data transfer resulting from the use of tools or service providers will be avoided but, in any case, will be subject to the Privacy Shield framework, which ensures that American software companies comply with European data protection policies regarding privacy, secrecy, and data security.
Aside from the above, we do not share personal data with anyone, except for public or private entities to which we are legally obligated to do so. For example, tax law requires us to provide the Tax Agency with certain information on economic transactions exceeding a certain amount.
Should we need to disclose personal information to other entities beyond the cases mentioned, we will first request your permission through clear options that allow you to decide.
International transfers: Where might we send your data?
We will not carry out international transfers of personal data for any of the purposes indicated.
Your rights: What rights can you exercise as a data subject?
You have the right to obtain confirmation as to whether we are processing your personal data, and you may also:
- Request access to your personal data.
- Request its rectification or erasure.
- Request its cancellation.
- Request limitation of its processing.
- Object to its processing.
- Request data portability.
You may exercise these rights free of charge at any time by contacting us through this website.
If you have given consent for a specific purpose, you have the right to withdraw it at any time, without affecting the lawfulness of the processing based on consent prior to its withdrawal.
Protection of rights: Where can you file a complaint?
If you believe your rights have not been respected by us, you may file a complaint with the Spanish Data Protection Agency, through any of the following means:
- Electronic office: https://www.aepd.es
- Postal mail: Agencia Española de Protección de Datos, C/ Jorge Juan, 6, 28001, Madrid
- Phone: 901 100 099 and 912 663 517
Filing a complaint with the Spanish Data Protection Agency is free of charge, and the assistance of a lawyer or attorney is not required.
There is a form available for exercising your rights, which you can request by email, or you may use the forms provided by the Spanish Data Protection Agency or by third parties.
These forms must be electronically signed or accompanied by a photocopy of your national ID document.
If you are represented by someone else, they must attach a copy of their ID document or sign the form with their electronic signature.
Forms may be submitted in person, by post, or by email to the controller's address.
Accuracy and truthfulness of data
You are solely responsible for the truthfulness and accuracy of the data you provide to us, and you release us from any liability in this regard.
You guarantee and are responsible, in any case, for the accuracy, validity, and authenticity of the personal data provided, and you undertake to keep it duly updated. You agree to provide complete and correct information in the contact or subscription form.
Revocability
Consent given, both for the processing and the disclosure of data, may be revoked at any time by notifying us under the terms established in this Policy for exercising your ARCO rights (access, rectification, cancellation, objection). This revocation shall under no circumstances be retroactive.
Breach notification and reporting
We implement security measures appropriate to the level of risk to protect personal information against loss, misuse, unauthorized access, disclosure, alteration, and destruction, taking into account the risks involved in the processing and the nature of the personal information.
However, if we determine that your data has been misappropriated, exposed through a security breach, or improperly acquired by a third party, we will inform you immediately of such security breach, misappropriation, or improper acquisition.
Updates: What changes may be made to this Privacy Policy?
We reserve the right to modify this policy to adapt it to new legislation or case law, as well as to industry practices that may affect compliance with it.