Skip to content
Data protection

Privacy Policy

What data we collect on www.corexia.es, what we use it for, who we share it with and how you can control it.

Last updated: August 2026

Data controller

The controller of the personal data collected through this site is Daniel Sentamans Lorente, holder of Spanish ID (DNI) 20856927K, trading under the business name Corexia, with registered tax address in Valencia (Spain) and contact email info.corexia@gmail.com.

This policy applies to www.corexia.es and complies with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on Data Protection and the guarantee of digital rights (LOPDGDD). We are not required to appoint a data protection officer: for any privacy matter, the channel is info.corexia@gmail.com.

Data we collect

We only process the data you voluntarily provide through the contact form:

  • Name, required so that we can address you.
  • Email address, required so that we can reply.
  • Phone and company, optional fields you fill in only if you want to.
  • Service of interest and the content of the message you write.
  • The site language you sent the form from.

The server also records technical connection data such as IP address and browser, which we use to limit the number of submissions per IP and curb abuse of the form. We do not request special categories of data (health, beliefs, racial origin or others) and the site is not aimed at children under 14. Your cookie and light or dark theme preferences are stored in your browser's local storage and are not sent to any server; the details are in our Cookie Policy.

Purpose of processing

We use your data solely to:

  • Reply to the enquiry or quote request you send us.
  • Keep in touch during the stage before a possible contract and, if we reach an agreement, throughout the service.
  • Meet the tax and accounting obligations tied to the commercial relationship, where one exists.
  • Protect the site against automated submissions and abuse of the form.
  • Measure site traffic in aggregate in order to improve it.

We do not build profiles or make automated decisions with legal effects on you, and we do not send marketing communications to anyone who has not requested them. Nor do we use your data for purposes other than those you provided it for.

Legal basis for processing

Each processing operation rests on one of these legal bases:

  • Consent (art. 6.1.a GDPR): by sending the form you agree that we process your data in order to reply.
  • Pre-contractual measures and performance of a contract (art. 6.1.b GDPR): when the enquiry leads to a quote or to the provision of a service.
  • Legitimate interest (art. 6.1.f GDPR): site security, prevention of form abuse and statistical traffic measurement.
  • Legal obligation (art. 6.1.c GDPR): retention of invoices and tax records where a commercial relationship exists.

Providing the data marked as required is necessary for us to assist you: without it we cannot reply to your enquiry. Optional fields may be left blank with no consequence whatsoever.

Retention period

We keep the messages we receive for as long as the conversation lasts and, afterwards, for a maximum of two years in case you get back in touch. If we end up working together, the data relating to the contractual relationship is kept for its entire duration and, once ended, for the applicable statutory limitation periods, which in commercial and tax matters reach six years.

Technical server logs are kept for the period set by the hosting provider, for security and diagnostic purposes. Once those periods elapse, the data is deleted or irreversibly anonymised.

Recipients and data processors

We do not sell or transfer your data. To run the site we rely on providers acting as data processors, under a processing agreement in line with article 28 GDPR:

  • Vercel Inc. — website hosting and traffic analytics through Vercel Analytics and Speed Insights, which measure visits in aggregate and without advertising cookies.
  • Resend, Inc. — sending and delivering the emails generated by the contact form, and storing them temporarily so that failed deliveries can be diagnosed.
  • Corporate mailbox provider, where the messages from the form are received and archived.

Vercel Inc. and Resend, Inc. are based in the United States: those international transfers rely on the European Commission's standard contractual clauses and on the EU-US Data Privacy Framework. This site does not use Google Analytics or Google advertising tags; the links to our Google business profile lead to a third-party service with its own privacy policy. Beyond the above, we would only disclose data to public authorities, law enforcement or the courts where legally required.

Your rights

The GDPR grants you the following rights over your data, and you may exercise them at any time and free of charge:

  • Access: find out what data of yours we process and for what purpose.
  • Rectification: correct data that is inaccurate or incomplete.
  • Erasure: ask us to delete it once it is no longer necessary.
  • Objection: ask us to stop processing it on grounds relating to your particular situation.
  • Restriction: ask us to limit its use while a claim is resolved.
  • Portability: receive your data in a structured, commonly used format.
  • Withdrawal of consent, without affecting the lawfulness of processing carried out beforehand.

To exercise them, write to info.corexia@gmail.com stating which right you wish to exercise and proving your identity. We will reply within one month at the latest. If you believe your request has not been handled properly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).

Data security

We apply technical and organisational measures proportionate to the risk of the processing: HTTPS encryption of communications, validation and sanitisation of everything submitted through the form, a submission limit per IP address, request origin checks, restricted access to the mailbox receiving the messages, and regular updates of the site dependencies.

No system is infallible. Should a security breach occur that poses a high risk to your rights, we would inform you without undue delay and notify the Spanish Data Protection Agency in accordance with articles 33 and 34 GDPR.

Changes to this policy

We may update this policy to reflect regulatory changes, new site features or a change of providers. The version in force is always the one published on this page, with the last updated date shown above.

If a change materially affects how your data is processed, we will announce it visibly on the site before applying it. For any question about this policy, write to info.corexia@gmail.com.