Legal notice, privacy and cookies
This page brings together the three pieces of information that Spanish and European law requires to be published: the identification of the owner of the site, how we process personal data and the use of cookies. It is written to be read, not to put you off.
Legal notice and terms of use
In compliance with article 10 of Ley 34/2002, of 11 July, on information society services and electronic commerce (Spain’s Law 34/2002 on Information Society Services, LSSI-CE), the following details are made available to the user.
This website is informational and corporate. No products or services are sold through it, there is no purchase or payment process, and it is not directed at consumers within the meaning of Real Decreto Legislativo 1/2007 (Royal Legislative Decree 1/2007). All contracting is formalised by means of a written proposal and contract between businesses.
The platforms dsacompliance.net y dsacore.com are separate sites, with their own terms of service, privacy policy and cookie policy. What is stated here does not replace them.
1.1 · Purpose
This legal notice governs access to, browsing of and use of this website. The mere use of the site confers the status of user and implies full acceptance of these terms in the version published at the time of access. If you do not agree with them, we ask you not to use the site.
1.2 · Conditions of access and use
Access is free of charge, except for the connection cost charged by your provider. The user undertakes to use the site in accordance with the law, good faith and these terms, and in particular not to:
- Carry out unlawful activities, activities harmful to the rights of third parties or activities contrary to public order.
- Introduce or distribute programs, viruses, malicious code or any element capable of damaging the systems of the owner or of third parties.
- Attempt to access restricted areas without authorisation, alter the data, circumvent security measures or interfere with the operation of the site.
- Use automated means of mass extraction of contents (scraping) or use the contents to train artificial intelligence systems without express written authorisation.
- Impersonate third parties or provide false data in the forms.
1.3 · Intellectual and industrial property
All the contents of this site—texts, photographs, graphics, illustrations, iconography, screenshots, diagrams, source code, graphic design, navigation structure and the selection and arrangement of contents—are owned by DSA Nexus, S.L. or by third parties who have authorised their use, and are protected by Real Decreto Legislativo 1/1996 (Royal Legislative Decree 1/1996), approving the consolidated text of the Spanish Intellectual Property Act, and by the applicable national and international legislation.
The names DSA Nexus, DSA Core y DSA Compliance, together with their logotypes and icon marks, are distinctive signs of the company. Their use without authorisation is prohibited.
The user is authorised to view the contents and to print or download a copy for personal and private use. Their reproduction, distribution, public communication, transformation or exploitation for commercial purposes is not authorised without prior written consent.
The trade marks and logos of third parties appearing on the site—in particular those of clients—belong to their respective owners and are displayed with their authorisation, for the sole purpose of identifying completed projects. Their presence does not imply sponsorship or endorsement by those owners.
1.4 · Screenshots and demonstration data
The DSA Core and DSA Compliance screens reproduced on this site correspond to demonstration environments. The names of individuals and companies, amounts, addresses, vehicle registration numbers, identifiers and any other data appearing in them are fictitious and do not correspond to real clients or to identifiable individuals. The figures shown do not constitute results, promises or guarantees of performance.
1.5 · Links
This site may contain links to third-party pages. DSA Nexus does not control their contents or their policies and accepts no liability whatsoever for them; the link does not imply any relationship, collaboration or endorsement. If you find a link to unlawful or inappropriate content, you can report it to us at hola@dsanexus.com and we will remove it with due diligence.
Links to the home page are permitted provided that the site is not reproduced within another one (framing), that our trade marks are not used beyond what is necessary to identify the destination, that no false or inaccurate statements are made about the company and that no non-existent relationship is suggested.
1.6 · Exclusion of warranties and liability
DSA Nexus uses reasonable means to ensure that the information published is accurate and up to date, but does not guarantee the absence of typographical errors or the completeness of the contents, which are informational in nature and do not constitute legal, technical or financial advice. Any decision taken on the basis of these contents is the responsibility of the user.
Nor is the availability and uninterrupted continuity of the site guaranteed. DSA Nexus is not liable for damage arising from interruptions, viruses, failures of the network or of the user’s equipment, or from use of the site contrary to these terms, except in those cases in which the law imposes liability on a mandatory basis.
1.7 · Modifications and term
DSA Nexus reserves the right to modify at any time the presentation, configuration and contents of the site, as well as these terms, and to suspend or cancel the service, without prejudice to what has been agreed in contracts with clients. Previous versions are archived and may be requested in writing.
1.8 · Partial invalidity
If any clause of this legal notice were declared null or ineffective, the remainder will retain full validity, and the affected clause will be replaced by another which, being valid, pursues the same purpose.
1.9 · Applicable law and jurisdiction
These terms are governed by Spanish law. For any matters that may arise in relation to the site, and these being relationships between businesses or professionals, the parties expressly submit to the Courts and Tribunals of Madrid, waiving any other jurisdiction that might correspond to them. If the user has the status of consumer, the jurisdiction established on a mandatory basis by consumer protection legislation shall apply.
Privacy policy
Prepared in accordance with Reglamento (UE) 2016/679, General de Protección de Datos (Regulation (EU) 2016/679, the General Data Protection Regulation, GDPR), and with Ley Orgánica 3/2018, de Protección de Datos Personales y garantía de los derechos digitales (Spain’s Organic Law 3/2018 on Data Protection, LOPDGDD).
Among other things, our business is making it possible for our clients to demonstrate that they comply. It would be inconsistent not to apply the same standard to ourselves.
The data you provide to us when you contact us, book a session or engage our services is processed at our own decision and for our own purposes. Everything described in this policy refers to that role.
The data a client enters into DSA Core or DSA Compliance remains theirs: they decide what it is for. We process it solely on their behalf, following their instructions, under the processing agreement of article 28 of the GDPR, without using it for our own purposes or disclosing it to anyone. That relationship is governed by that agreement, not by this policy.
2.1 · Data controller
DSA Nexus, S.L., with NIF B06995476 and registered office at Calle Gerardo Cordón, 11, puerta C, planta 4 — 28017 Madrid (Spain). Contact email for data protection matters: privacidad@dsanexus.com.
DSA Nexus has not appointed a Data Protection Officer, since none of the circumstances of article 37 of the GDPR or of those listed in article 34 of the LOPDGDD (Spain’s Organic Law 3/2018 on Data Protection) apply to its activity as data controller. There is, however, an internal privacy officer who handles the requests received at the address indicated and acts as the point of contact with the Spanish Data Protection Agency (AEPD). This decision is reviewed periodically and will be updated in this policy if the evolution of our processing activities so requires.
2.2 · Processing activities
For each activity, the purpose, the legal basis that legitimises it, the categories of data processed and the retention period are set out below.
2.3 · Recipients and data processors
We do not sell or transfer personal data to third parties for commercial purposes. In order to provide the service we use suppliers that act as data processors, under a contract compliant with article 28 of the GDPR, with a duty of confidentiality and a prohibition on use for their own purposes:
- Hosting and infrastructure provider for the site and for the platforms.
- Email and corporate productivity suite provider.
- Web analytics and advertising measurement provider, on the terms of section 3.
- Tool for sending communications, where applicable.
- Electronic signature provider.
- Accounting, tax and employment advisers, and auditing where legally required.
You can request the up-to-date list of processors, with their identity and location, by writing to privacidad@dsanexus.com.
In addition, the data may be disclosed to the tax authorities, to the Social Security authorities, to banks for the management of collections and payments, and to Courts, Tribunals and Law Enforcement Agencies where there is a legal obligation to do so.
2.4 · International transfers
Our main infrastructure is hosted in the European Union. Some providers of productivity, analytics and advertising measurement tools may involve access to data from third countries, mainly the United States. In such cases the transfer relies on one of the mechanisms of Chapter V of the GDPR:
- The European Commission adequacy decision of 10 July 2023 on the EU-U.S. Data Privacy Framework, where the provider is certified under that framework.
- The standard contractual clauses approved by Implementing Decision (EU) 2021/914, supplemented by a transfer impact assessment and additional technical measures such as encryption and pseudonymisation.
You can obtain a copy of the safeguards applied by requesting it at the address indicated.
2.5 · Your rights
You may exercise the following rights, recognised in articles 15 to 22 of the GDPR, at any time:
To exercise them, simply write to privacidad@dsanexus.com stating the right you wish to exercise. We may ask you to prove your identity only if there are reasonable doubts as to who is making the request. We will reply within one month of receipt, extendable by a further two months for complex requests, informing you of the extension. Exercising them is free of charge.
If you consider that we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD) (C/ Jorge Juan, 6, 28001 Madrid — www.aepd.es), without prejudice to any other administrative or judicial action. We would be grateful for the opportunity to resolve it first.
2.6 · Automated decisions, profiling and artificial intelligence
On this website no automated decisions are taken and no profiles are created that produce legal effects or significantly affect you, within the meaning of article 22 of the GDPR.
On our platforms we use artificial intelligence features with explicit limits: they assist a person—drafting, classifying, summarising or proposing—but they do not decide on their own, and any action with consequences is subject to human validation and logged together with its author. This is what we call AI with guardrails, and it is a design decision, not a statement of intent.
We do not use the data of our clients or that of the users of this site to train general-purpose artificial intelligence models, whether our own or those of third parties. The systems used correspond to the limited or minimal risk categories of Reglamento (UE) 2024/1689, de Inteligencia Artificial (Regulation (EU) 2024/1689, the Artificial Intelligence Act), and where the interaction takes place with an automated system, this is disclosed.
2.7 · Security measures
We apply the appropriate technical and organisational measures required by article 32 of the GDPR, taking into account the state of the art and the risk of the processing: encryption of communications and of data at rest, access control by role and least privilege, strong authentication for administrative access, audit logging of relevant operations, verified backups, separation of environments, vulnerability management and periodic review of the effectiveness of the measures.
In the event of a personal data breach entailing a risk to rights and freedoms, we will notify the Spanish Data Protection Agency (AEPD) within seventy-two hours in accordance with article 33, and the affected data subjects without undue delay in accordance with article 34, where the risk is high.
2.8 · Obligation to provide the data
The data marked as mandatory in our forms is necessary in order to handle your request; if you do not provide it, we will not be able to do so. The rest is voluntary and only helps to prepare the conversation better. The data provided must be truthful and up to date, and we ask you to inform us of any change.
2.9 · Minors
The services on this site are aimed exclusively at professionals and companies. We do not knowingly collect data on children under fourteen. If we detect that data on a minor has been provided without the consent of the holder of parental authority or guardianship, we will delete it.
2.10 · Operations in Latin America
When we provide services to clients established in Latin America, in addition to the GDPR the local legislation of the relevant country applies, and the processing complies with it: Chile —Ley 19.628 and Ley 21.719—, Brazil —Ley 13.709, the LGPD—, Colombia —Ley 1581/2012—, Peru —Ley 29733—, Ecuador —Ley Orgánica de Protección de Datos Personales (Organic Law on the Protection of Personal Data)— and Argentina —Ley 25.326—. Where they overlap, we apply the standard that is most protective of the data subject.
2.11 · Modifications
This policy may be updated in order to adapt it to regulatory or case-law changes or to changes in our activity. The version in force is the one published on this page, with the date indicated at the beginning. If the modification substantially affects processing based on your consent, you will be informed individually.