Privacy Policy
Last updated: March 18, 2026
1. Introduction and Data Controller
NEXOFLUX is committed to protecting your privacy. The person responsible for the processing of your data is NEXOFLUX, located in Madrid and email [email protected]. This policy complies with the GDPR (EU 2016/679) and LOPDGDD.
2. Purpose and Collected Data
We collect contact and billing data to manage your contractual relationship, send you technical information about our platforms (Verifactu) and, if you consent, commercial newsletters.
3. Legitimation
The legal basis for processing is your consent, the execution of a contract and compliance with legal obligations (accounting, taxation, Verifactu).
4. Conservation
The data will be kept for the duration of the commercial relationship or for the years necessary to comply with legal obligations.
5. Recipients
Data will not be transferred to third parties except for legal obligation or providers necessary for the service (hosting, technical support).
6. Your Rights
You have the right to access, rectify, delete, oppose, limit processing and request portability of your data by sending an email to [email protected]. You also have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) or your local supervisory authority if you consider that the processing of your personal data infringes Regulation (EU) 2016/679.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, in accordance with Article 32 of the GDPR.
8. International Transfers
We do not make international data transfers outside the European Economic Area. All data is stored on servers located within the EU.
9. Breach Notification
In the event of a personal data breach that affects your data, we will notify you without undue delay and in accordance with Article 33 of the GDPR. The notification will include information on the nature of the breach, categories of data affected, and measures taken.
10. Data Protection Officer
In accordance with Article 37 of the GDPR, we are not required to designate a Data Protection Officer (DPO) since our processing is not massive or of sensitive data. Nevertheless, you can exercise your rights by contacting [email protected]