Privacy policy
1. Data controller
- Controller: Pixel Labs Solutions SLU
- Spanish Tax ID (CIF): B22907570
- Address: C/ Trinidad Grund 21, 6-81, 29001 Málaga
- Email: info@certificacionens.eu
2. Purposes of processing
At CertENS we process the personal data you provide for the following purposes:
- To respond to requests for information, quotes or commercial contact submitted through the contact form or by email.
- To manage the contractual relationship and provide the services you engage.
- To comply with applicable legal obligations (tax, accounting, etc.).
- To send commercial communications about our services, provided you have given your consent.
3. Legal basis
- Consent of the data subject: for handling contact-form requests and sending commercial communications.
- Performance of a contract: when you engage any of our services.
- Compliance with legal obligations: retention of tax and accounting information.
- Legitimate interest: to improve our services and prevent fraud.
4. Retention period
Data is kept for as long as necessary to fulfil the purpose for which it was collected and to determine any resulting liabilities. Applicable legal retention periods in tax, commercial and labour matters will apply.
5. Recipients
We do not transfer your data to third parties unless legally required. We do engage duly contracted data processors that provide services necessary for our activity (hosting, transactional email, cloud productivity tools), always with appropriate safeguards under the GDPR. The main processors are:
- Resend, Inc. (transactional email) — USA, under Standard Contractual Clauses.
- Cloudflare, Inc. (Turnstile anti-bot protection and CDN) — USA, under Standard Contractual Clauses.
6. Rights of the data subject
You can exercise at any time your rights of access, rectification, erasure, objection, restriction of processing and portability, as well as withdraw consent, by emailing info@certificacionens.eu with the subject "Data protection" and proof of identity. If you consider that your request has not been properly addressed, you may file a complaint with the Spanish Data Protection Agency (www.aepd.es).
7. Security
We apply the technical and organisational measures appropriate to the risk. As an ENS consultancy, we apply in our own systems measures analogous to those of Annex II of Royal Decree 311/2022: encryption in transit and at rest, access control, activity logging and staff training.