Data protection

Privacy policy

What personal data we collect on this website, how we use it, with whom we share it and how you can control it. Information provided in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

Last updated: September 9, 2026

01

Data controller

Data controller
InformationDetails
ControllerNUMANTICA PROTECTION, S.L.
Tax identification number (N.I.F.)B93931103
AddressCalle Princesa, 31, planta 2, puerta 2, 28008 Madrid, España
Privacy contactprivacidad@numantica.com [provisional]

We have not appointed a data protection officer, as none of the circumstances set out in Article 37 of the GDPR or Article 34 of the LOPDGDD applies [provisional]. You can send any privacy enquiry to the address above.

02

The data we process

We process only the data you voluntarily provide and the strictly technical data generated by your browsing:

  • Demo and sales contact forms: full name, professional email address, company, job title (optional) and the content of your message.
  • Callback requests: country calling code, phone number and email address.
  • Technical browsing data: IP address, date and time, pages requested, device type and browser, recorded by our hosting provider for security and operational purposes.
  • Audience measurement: page visited, referring website, country, device type, browser and operating system, processed in aggregate by Plausible Analytics without cookies. The IP address is used temporarily to distinguish visits within a single day and is not stored.

We do not process special categories of data or ask you for sensitive information. Please do not include third-party personal data or confidential information in the free-text message field.

03

Purposes and legal bases

Purposes, legal bases and retention periods
PurposeLegal basisRetention
Handle your request for a demonstration, information or callback, and maintain commercial contact before a potential contract.Taking steps at the data subject's request prior to entering into a contract (Article 6(1)(b) GDPR).While handling your request and for up to 2 years after the last contact. [provisional]
Send you information about our services related to your enquiry.Legitimate interest in commercial communication with professional contacts who have requested information (Article 6(1)(f) GDPR), with the right to object at any time.Until you object or request to unsubscribe.
Protect the website against unauthorised access, fraud and abuse.Legitimate interest in the security of our systems (Article 6(1)(f) GDPR).Technical logs: up to 12 months. [provisional]
Measure website audience in aggregate to understand which content is viewed and improve it.Legitimate interest in understanding website use (Article 6(1)(f) GDPR), through processing that does not install cookies or identify individuals.IP addresses are not stored. Aggregate statistics are retained while the website is operating.
Comply with legal obligations and respond to requests from competent authorities.Compliance with a legal obligation (Article 6(1)(c) GDPR).The periods prescribed by applicable law.

04

How long we retain data

We retain your data for the periods set out above. After those periods, the data is deleted or appropriately blocked, remaining available exclusively to judges, courts, the Public Prosecutor’s Office or the competent public authorities for the limitation period applicable to potential liabilities arising from the processing. It is then deleted.

05

Who can access your data

We do not sell your data or share it with third parties for commercial purposes. Access is limited to providers supplying services to us as data processors, under a signed contract in accordance with Article 28 of the GDPR [provisional]:

  • Cloudflare, Inc. — website hosting, content delivery network, storage and protection against attacks.
  • Plausible Insights OÜ (Estonia) — cookie-free website audience measurement, with data hosted on servers in the European Union.

We may also disclose data to competent public authorities where required by law, and to legal or accounting advisers subject to confidentiality duties where necessary to defend our rights.

06

International transfers

Our hosting provider is a US entity that may process data outside the European Economic Area. These transfers are based on the standard contractual clauses approved by the European Commission and, where applicable, the provider’s certification under the EU–US Data Privacy Framework, together with supplementary technical measures such as encryption in transit and at rest. Our audience measurement provider processes data exclusively in the European Union, so it does not involve international transfers. You can request a copy of the safeguards applied by writing to privacidad@numantica.com [provisional].

07

Your rights

You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability at any time. You may also withdraw consent without affecting the lawfulness of earlier processing. To do so, write to privacidad@numantica.com [provisional] or to Calle Princesa, 31, planta 2, puerta 2, 28008 Madrid, España, specifying the right you wish to exercise. We may ask you to prove your identity if we have reasonable doubts about it.

We will respond within one month, which may be extended by a further two months if the request is particularly complex. If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan, 6, 28001 Madrid — www.aepd.es).

08

Automated decisions

We do not make decisions based solely on automated processing of your data that produce legal effects concerning you or similarly significantly affect you. Our product’s automated analysis of images and listings applies to assets and content published by our clients under a separate service agreement, in which Numantica acts as a data processor.

09

Information security

We apply appropriate technical and organisational measures to protect your data against destruction, loss, alteration or unauthorised access. These include TLS encryption for communications, access control based on the principle of least privilege and periodic reviews of our providers. If a security breach poses a risk to your rights, we will inform you in accordance with Articles 33 and 34 of the GDPR.

10

Children

This website is intended for professionals and businesses, not children. We do not knowingly collect data from anyone under 14. If we discover that we have received a child’s data without authorisation from their legal representatives, we will delete it immediately.

11

Changes to this policy

We may update this policy to reflect legal, technical or service changes. We will always publish the current version on this page with its update date. If changes are substantial, we will notify you through the contact details you have provided. Please also consult our legal notice and cookie policy.