Saltar al contenido
Legal information

Legal notice, privacy and cookies

This page brings together the three pieces of information that Spanish and European law requires to be published: the identification of the owner of the site, how we process personal data and the use of cookies. It is written to be read, not to put you off.

Last updated: 25 August 2026 Version 2.0
Section 2

Privacy policy

Prepared in accordance with Reglamento (UE) 2016/679, General de Protección de Datos (Regulation (EU) 2016/679, the General Data Protection Regulation, GDPR), and with Ley Orgánica 3/2018, de Protección de Datos Personales y garantía de los derechos digitales (Spain’s Organic Law 3/2018 on Data Protection, LOPDGDD).

Among other things, our business is making it possible for our clients to demonstrate that they comply. It would be inconsistent not to apply the same standard to ourselves.

First of all, because hardly anyone tells the two apart
We are the controller of the data on this website and of our commercial relationship

The data you provide to us when you contact us, book a session or engage our services is processed at our own decision and for our own purposes. Everything described in this policy refers to that role.

We are the processor of the data our clients host on the platforms

The data a client enters into DSA Core or DSA Compliance remains theirs: they decide what it is for. We process it solely on their behalf, following their instructions, under the processing agreement of article 28 of the GDPR, without using it for our own purposes or disclosing it to anyone. That relationship is governed by that agreement, not by this policy.

2.1 · Data controller

DSA Nexus, S.L., with NIF B06995476 and registered office at Calle Gerardo Cordón, 11, puerta C, planta 4 — 28017 Madrid (Spain). Contact email for data protection matters: privacidad@dsanexus.com.

DSA Nexus has not appointed a Data Protection Officer, since none of the circumstances of article 37 of the GDPR or of those listed in article 34 of the LOPDGDD (Spain’s Organic Law 3/2018 on Data Protection) apply to its activity as data controller. There is, however, an internal privacy officer who handles the requests received at the address indicated and acts as the point of contact with the Spanish Data Protection Agency (AEPD). This decision is reviewed periodically and will be updated in this policy if the evolution of our processing activities so requires.

2.2 · Processing activities

For each activity, the purpose, the legal basis that legitimises it, the categories of data processed and the retention period are set out below.

Enquiries and discovery session
Purpose
To handle your request, prepare and hold the session, and send you the conclusion in writing.
Legal basis
Performance of pre-contractual measures at the request of the data subject (art. 6.1.b) and, for a purely informational enquiry, your consent (art. 6.1.a).
Data
Identification data, professional contact details, company, job title and the content of your message.
Retention
One year from the last contact, or until you request erasure. If it leads to a contract, it moves to the following activity.
Client management and provision of services
Purpose
To formalise and perform the contract, provide the service and the support, invoice and manage collection.
Legal basis
Performance of the contract (art. 6.1.b) and compliance with legal accounting, tax and invoicing obligations (art. 6.1.c).
Data
Identification and contact details of the contact persons, invoicing data and data on the contractual relationship.
Retention
For the duration of the relationship and, thereafter, six years in accordance with article 30 of the Código de Comercio (Spanish Commercial Code) and four years for the purposes of tax limitation (art. 66 of the Ley General Tributaria, Spain’s General Tax Act), blocked and accessible only upon official request.
Commercial communications
Purpose
To send you publications, regulatory alerts and news about our services and platforms.
Legal basis
Your express consent (art. 6.1.a). If you are already a client, the prior relationship in respect of similar services, in accordance with article 21.2 of the LSSI (Spain’s Law 34/2002 on Information Society Services).
Data
Name, email address and company. Delivery and opening data for the mailing, for statistical purposes.
Retention
Until you withdraw your consent or object. Every mailing includes a simple and free means of unsubscribing.
B2B commercial prospecting
Purpose
To contact the contact persons of companies whose profile corresponds to our activity, in order to present our services.
Legal basis
Legitimate interest (art. 6.1.f), these being professional contact details within the framework of article 19.1 of the LOPDGDD (Spain’s Organic Law 3/2018 on Data Protection), following a documented balancing of that interest against your rights.
Source
Publicly and professionally accessible sources: the company’s own website, public registers, directories and professional networks. You are informed at the first contact, in accordance with article 14.
Retention
One year from the contact, or immediate erasure if you object. Simply replying to the email to ask for it is enough.
Applications and selection processes
Purpose
To assess your application for the profiles we are looking for.
Legal basis
Your consent when you send us your application (art. 6.1.a) and pre-contractual measures (art. 6.1.b).
Data
Those contained in the CV and those provided in the interviews. We ask you not to include special categories of data under article 9; if you do include them, we will delete them.
Retention
One year, unless you request erasure before then. Once that period has elapsed, it is deleted with no need for notice.
Security and technical access logging
Purpose
To ensure the security of the site, prevent abuse and diagnose incidents.
Legal basis
Legitimate interest in information security (art. 6.1.f), taking into account recital 49 of the GDPR.
Data
IP address, date and time, resource requested, response code and user agent, logged by the server.
Retention
Twelve months, unless they must be kept for longer in order to investigate a specific security incident.

2.3 · Recipients and data processors

We do not sell or transfer personal data to third parties for commercial purposes. In order to provide the service we use suppliers that act as data processors, under a contract compliant with article 28 of the GDPR, with a duty of confidentiality and a prohibition on use for their own purposes:

  • Hosting and infrastructure provider for the site and for the platforms.
  • Email and corporate productivity suite provider.
  • Web analytics and advertising measurement provider, on the terms of section 3.
  • Tool for sending communications, where applicable.
  • Electronic signature provider.
  • Accounting, tax and employment advisers, and auditing where legally required.

You can request the up-to-date list of processors, with their identity and location, by writing to privacidad@dsanexus.com.

In addition, the data may be disclosed to the tax authorities, to the Social Security authorities, to banks for the management of collections and payments, and to Courts, Tribunals and Law Enforcement Agencies where there is a legal obligation to do so.

2.4 · International transfers

Our main infrastructure is hosted in the European Union. Some providers of productivity, analytics and advertising measurement tools may involve access to data from third countries, mainly the United States. In such cases the transfer relies on one of the mechanisms of Chapter V of the GDPR:

  • The European Commission adequacy decision of 10 July 2023 on the EU-U.S. Data Privacy Framework, where the provider is certified under that framework.
  • The standard contractual clauses approved by Implementing Decision (EU) 2021/914, supplemented by a transfer impact assessment and additional technical measures such as encryption and pseudonymisation.

You can obtain a copy of the safeguards applied by requesting it at the address indicated.

2.5 · Your rights

You may exercise the following rights, recognised in articles 15 to 22 of the GDPR, at any time:

Access
To know what data we process and obtain a copy.
Rectification
To correct data that is inaccurate or complete data that is incomplete.
Erasure
To have us delete the data when it is no longer necessary.
Restriction
To have us keep the data without processing it, while a dispute is resolved.
Portability
To receive the data in a structured format or have it sent to another controller.
Objection
To object to processing based on legitimate interest and to prospecting.
To withdraw consent
At any time, without this affecting the lawfulness of the previous processing.
Automated decisions
Not to be subject to decisions based solely on automated processing.

To exercise them, simply write to privacidad@dsanexus.com stating the right you wish to exercise. We may ask you to prove your identity only if there are reasonable doubts as to who is making the request. We will reply within one month of receipt, extendable by a further two months for complex requests, informing you of the extension. Exercising them is free of charge.

If you consider that we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD) (C/ Jorge Juan, 6, 28001 Madrid — www.aepd.es), without prejudice to any other administrative or judicial action. We would be grateful for the opportunity to resolve it first.

2.6 · Automated decisions, profiling and artificial intelligence

On this website no automated decisions are taken and no profiles are created that produce legal effects or significantly affect you, within the meaning of article 22 of the GDPR.

On our platforms we use artificial intelligence features with explicit limits: they assist a person—drafting, classifying, summarising or proposing—but they do not decide on their own, and any action with consequences is subject to human validation and logged together with its author. This is what we call AI with guardrails, and it is a design decision, not a statement of intent.

We do not use the data of our clients or that of the users of this site to train general-purpose artificial intelligence models, whether our own or those of third parties. The systems used correspond to the limited or minimal risk categories of Reglamento (UE) 2024/1689, de Inteligencia Artificial (Regulation (EU) 2024/1689, the Artificial Intelligence Act), and where the interaction takes place with an automated system, this is disclosed.

2.7 · Security measures

We apply the appropriate technical and organisational measures required by article 32 of the GDPR, taking into account the state of the art and the risk of the processing: encryption of communications and of data at rest, access control by role and least privilege, strong authentication for administrative access, audit logging of relevant operations, verified backups, separation of environments, vulnerability management and periodic review of the effectiveness of the measures.

In the event of a personal data breach entailing a risk to rights and freedoms, we will notify the Spanish Data Protection Agency (AEPD) within seventy-two hours in accordance with article 33, and the affected data subjects without undue delay in accordance with article 34, where the risk is high.

2.8 · Obligation to provide the data

The data marked as mandatory in our forms is necessary in order to handle your request; if you do not provide it, we will not be able to do so. The rest is voluntary and only helps to prepare the conversation better. The data provided must be truthful and up to date, and we ask you to inform us of any change.

2.9 · Minors

The services on this site are aimed exclusively at professionals and companies. We do not knowingly collect data on children under fourteen. If we detect that data on a minor has been provided without the consent of the holder of parental authority or guardianship, we will delete it.

2.10 · Operations in Latin America

When we provide services to clients established in Latin America, in addition to the GDPR the local legislation of the relevant country applies, and the processing complies with it: Chile —Ley 19.628 and Ley 21.719—, Brazil —Ley 13.709, the LGPD—, Colombia —Ley 1581/2012—, Peru —Ley 29733—, Ecuador —Ley Orgánica de Protección de Datos Personales (Organic Law on the Protection of Personal Data)— and Argentina —Ley 25.326—. Where they overlap, we apply the standard that is most protective of the data subject.

2.11 · Modifications

This policy may be updated in order to adapt it to regulatory or case-law changes or to changes in our activity. The version in force is the one published on this page, with the date indicated at the beginning. If the modification substantially affects processing based on your consent, you will be informed individually.

Section 3

Cookie policy

Prepared in accordance with article 22.2 of Ley 34/2002 (Spain’s Law 34/2002 on Information Society Services, LSSI), with the Guidance on the use of cookies of the Spanish Data Protection Agency (AEPD) and with the guidelines of the European Data Protection Board.

This site uses measurement cookies, and only if you accept them

On your first visit you will see a notice with Accept and Decline at the same level. Until you answer, no measurement cookie is installed and no identifier is sent to any third party. If you decline, the site works exactly the same: there is no cookie wall. You can change your mind at any time from «Cookie preferences», in the footer.

We use them for two things: to learn which pages are useful, and to check whether our search ads bring the right people. We do not build advertising profiles and we do not personalise ads with your data: the advertising personalisation permission stays denied at all times, including for those who accept. There are no social networks or third-party pixels on this site.

3.1 · What cookies are

A cookie is a small file that a website stores on your device when you visit it, and which makes it possible to remember information about that visit. Article 22.2 of the LSSI extends the same regime to any other form of storage or retrieval of data on the user’s equipment, such as local storage, session storage, web beacons or device fingerprinting.

Except for those strictly necessary to provide the service requested, their use requires informed, freely given, specific and unambiguous consent, given before installation and revocable at any time.

3.2 · Cookies used on this site

This is the complete list. None is installed before you accept, except the last one, which is precisely the one that remembers your answer and is exempt from consent because it is strictly necessary.

Name
Owner
Purpose
Type
Duration
_ga
Google Ireland Ltd.
Analytics. Distinguishes visitors from one another in order to count visits and page views (Google Analytics 4).
Third-party · analytics
24 months
_ga_0XPKYV4PXP
Google Ireland Ltd.
Analytics. Maintains the session state in this site’s measurement property.
Third-party · analytics
24 months
_gcl_au
Google Ireland Ltd.
Advertising measurement. Makes it possible to attribute to an ad the visit that ends in a form submission.
Third-party · advertising
90 days
_gcl_aw
Google Ireland Ltd.
Advertising measurement. Keeps the ad click identifier so we know which campaign brought the enquiry. Installed only if you arrive from one of our ads.
Third-party · advertising
90 days
dsa_origensession storage
DSA Nexus, S.L.
Advertising measurement. Keeps, for the duration of the visit, where you came from — campaign and, where applicable, click identifier — so it can be attached to the form you choose to send. It is what later lets us know which campaign brought a real client.
First-party · advertising
The session
dsa_consentimiento
DSA Nexus, S.L.
Technical. Remembers your answer to the notice and its date, so we do not ask you again. Exempt from consent.
First-party · technical
12 months
List closed as at 25 August 2026. Should we add any other, it would appear here before being activated.

3.3 · Third-party services that receive your IP address

In addition to the above, there are communications with third-party servers that receive your IP address and the technical data of the request, with or without cookies involved.

Google Fonts

The fonts of the site are requested from Google’s servers (Google Ireland Limited / Google LLC), which receive the IP address in order to serve the files. No cookies are installed and the information is not used for advertising purposes.

Legal basis: legitimate interest in the correct presentation of the site. Available alternative: hosting the fonts on our own server, which would make this communication disappear.

Google Analytics and Google Ads

The measurement tag is downloaded from Google’s servers (Google Ireland Limited / Google LLC), which receive your IP address. With your permission denied the tag still loads but writes no cookies and no identifiers: it only sends an anonymous, stateless signal, which is what allows the result to be estimated without measuring you.

Legal basis: your consent (art. 22.2 LSSI and art. 6.1.a GDPR), revocable at any time. It may involve a transfer to the United States, covered by the EU-US adequacy framework and by standard contractual clauses.

3.4 · How we ask for consent

These are the rules we apply, and which you can check for yourself in the notice:

  • A notice on the first visit, with accept and decline equally visible and accessible at the same level: same size, same contrast, same number of clicks.
  • Nothing is installed before consent is obtained, other than what is strictly necessary.
  • A single permission, for a single purpose: to measure. Advertising personalisation is neither offered nor enabled, because we do not use it.
  • No cookie walls: access to the site is not conditional on acceptance, and declining degrades nothing.
  • You may withdraw consent at any time as easily as it was given, from «Cookie preferences» in the footer.
  • We renew the request at most every twelve months, and also whenever the scope of what is asked changes: if the text changes, you are asked again even if you had already answered.
  • Every decision is recorded with its date and the version of the text accepted, which is what serves as evidence in an inspection.

3.5 · How to control cookies in your browser

Regardless of the above, you can configure your browser to block or delete cookies from any site. Here are the official instructions:

Blocking cookies across the board may degrade the operation of other sites. Not on ours: the only thing that happens is that we stop measuring.

3.6 · Updating of this policy

We review this policy whenever we introduce a technical change to the site and, in any case, annually. The date of the last review appears at the beginning of the page. We recommend that you consult it on each relevant visit.

Any questions about any of these three sections?

Write to privacidad@dsanexus.com for data protection matters, or to hola@dsanexus.com for anything else. A person replies.

DSA Nexus

Process consulting and custom software engineering for mid-sized companies in Spain and Latin America.

Based in Madrid · Projects in Spain and Latin America
Services
Platforms
Company
DSA Nexus S.L. © 2026. All rights reserved. · ISO 9001:2015 certified by LRQA