qartalia ← Back to home

Privacy policy

Last updated: 24 de mayo de 2026
Privacy Terms Cookies
ES CA GL EN FR IT DE

Privacy Policy of qartalia

Data controller: Gextiona Interproducción, S.L.

Version 2.0 · Last updated: January 1, 2026

Information notice and acceptance

qartalia is an information society service owned by Gextiona Interproducción, S.L. This Privacy Policy informs you, prior to registration and in a concise, transparent and intelligible manner, about the processing of the personal data collected through the platform.

By ticking the acceptance box —which will not be pre-ticked— and completing registration, the user declares that they have read and understood this Policy. Where a specific processing activity is based on consent, such consent will be obtained in a specific, informed and unambiguous manner through a clear affirmative action, and may be withdrawn at any time without affecting the lawfulness of processing prior to withdrawal.

1. Data controller

The controller of the personal data collected through qartalia is:

  • Identity: Gextiona Interproducción, S.L.
  • Tax ID (CIF): B-87967592.
  • Registered office: Madrid, 28002 – Francisco Silvela 110, 2º
  • Contact email: privacy@qartalia.com.

2. Data Protection Officer (DPO)

Considering the nature, scope and purposes of the processing, the controller has assessed that the circumstances requiring the designation of a Data Protection Officer do not apply. Nonetheless, the user may address any data protection query to privacy@qartalia.com.

3. Personal data we process

qartalia processes the following categories of data, always applying the principles of data minimisation and purpose limitation:

  • Account data: name, email address, password (stored encrypted using bcrypt), assigned role and the company you belong to.
  • Usage data: log of logins (date, time and IP address) and log of the actions carried out in the application (creation, modification or deletion of content).
  • Operational data: the commercial information that the user enters (products, materials, formulas, costings, price lists, etc.). As a general rule this does not constitute personal data in the strict sense when it relates to the business, but it is processed with the same level of protection.

It is expressly noted that the IP address is regarded as personal data for the purposes of data protection law.

4. Purposes and legal bases of processing

Data is processed for the purposes set out below, each with its legal basis:

  • Provision of the service (basis: performance of the contract): to allow you to use qartalia, authenticate you and preserve your work.
  • Technical communications (basis: performance of the contract): welcome emails, password recovery and critical service notices.
  • Platform security (basis: legitimate interest): detection of anomalous access and audit logging for incident investigation.
  • Compliance with legal obligations (basis: legal obligation): meeting accounting and tax obligations and responding to requests from competent authorities.

Processing based on legitimate interest has been subject to the required balancing test, information on which the user may request. No profiling, personalised advertising or transfer of data to third parties for commercial purposes is carried out.

5. Retention periods

Data is kept only for as long as necessary for the stated purposes and, thereafter, duly blocked during the legally applicable limitation periods:

  • Account and operational data: for the duration of the contract and, thereafter, blocked during the limitation periods for legal, tax and accounting claims —up to six years under the Commercial Code and, in tax matters, for the four-year limitation period under the General Tax Act—.
  • Audit log (usage data): 180 days.
  • Password recovery tokens: 30 minutes, purged 24 hours after use.
  • Login attempt log: 24 hours.

6. Recipients and processors (sub-processors)

To provide the service, the controller relies on providers that process data on its behalf, with which it has entered into the corresponding data processing agreement:

  • Resend (transactional email delivery) — United States.
  • Hostinger (web hosting and database) — Netherlands (European Union).

Each processor is contractually obliged to process data solely on the controller's instructions, to ensure confidentiality and to apply appropriate security measures. Processors only engage sub-processors with the controller's authorisation and under the same obligations.

7. International data transfers

The use of Resend involves a transfer of data to the United States. This transfer is based on Resend's certification under the EU–US Data Privacy Framework, for which the European Commission adopted an adequacy decision on 10 July 2023. As an additional safeguard, Resend incorporates into its processing agreement the Standard Contractual Clauses approved by the European Commission.

Hosting with Hostinger is located in the Netherlands, within the European Economic Area, and therefore does not constitute an international transfer.

8. Automated decisions and profiling

qartalia does not make decisions based solely on automated processing, including profiling, that produce legal effects on the user or similarly significantly affect them.

9. Commercial communications

The controller does not send commercial communications by electronic means unless the user has previously consented or there is a prior contractual relationship concerning similar products or services. In any event, the user may object to receiving them easily and free of charge in each communication.

10. Cookies and similar technologies

The platform uses only the strictly necessary technical cookies required for its operation. The use of any other cookies will require the user's informed consent and will be detailed in the Cookie Policy, available separately.

11. Minors

qartalia is a service aimed at professionals and businesses and is not intended for minors. In the field of information society services, in Spain the processing of minors' data based on consent is only lawful from the age of 14; below that age, the consent of those holding parental authority or guardianship is required.

12. Your rights

The user may exercise the following rights at any time:

  • Access to their data —you may use the “Export my data” button in your profile—.
  • Rectification of inaccurate data.
  • Erasure where the data is no longer necessary —you may use “Request account deletion” in your profile—.
  • Restriction of processing in the cases provided for by law.
  • Objection to processing based on legitimate interest.
  • Portability of your data to another controller (JSON format, via export).
  • Withdrawal of consent at any time, where processing is based on it, without retroactive effect.
  • Not to be subject to automated decisions with legal or similar effects.

To exercise these rights, simply write to privacy@qartalia.com, indicating the right you wish to exercise. The controller will respond within a maximum of one month, extendable depending on complexity. If you consider that your rights have not been properly addressed, you may lodge a complaint with the Agencia Española de Protección de Datos (Spanish Data Protection Agency; C/ Jorge Juan, 6, 28001 Madrid; electronic office: sedeagpd.gob.es), without prejudice to any other administrative or judicial remedy.

More information at:

Legal basis: Rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21) and automated decisions (Art. 22) of the GDPR; withdrawal of consent (Art. 7(3) GDPR). Means and time limit for exercise: Art. 12 GDPR and Arts. 12 to 18 LOPDGDD. Right to lodge a complaint with the supervisory authority: Art. 77 GDPR and Art. 37 LOPDGDD.

13. Security measures

The controller applies appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of communications via the HTTPS/TLS protocol.
  • Passwords stored encrypted with bcrypt; never stored in plain text.
  • Strict per-company isolation: each client's data is only accessible to its authorised users.
  • Daily encrypted backups, retained for 14 days.
  • Audit log of all critical actions.
  • Automatic lockout after failed login attempts.

In the event of a security breach entailing a risk to people's rights, the controller will notify the supervisory authority and, where appropriate, the affected individuals.

14. Changes to this policy

The controller may update this Policy to adapt it to regulatory or service changes. Material changes will be communicated by appropriate means and, where applicable, new consent will be requested. The date of the latest version appears in the header.

15. Applicable law

The data processing described is governed by Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 (LOPDGDD) and Spanish Law 34/2002 (LSSI-CE), as well as by the other applicable Spanish and European Union legislation.

Legal sources and references

  • Regulation (EU) 2016/679 (GDPR). General Data Protection Regulation.
  • Spanish Organic Law 3/2018 (LOPDGDD). Protection of personal data and guarantee of digital rights.
  • Spanish Law 34/2002 (LSSI-CE). Information society services and electronic commerce.
  • Commission Implementing Decision (EU) 2023/1795. Adequacy of the EU–US Data Privacy Framework (10 July 2023).
  • Commission Implementing Decision (EU) 2021/914. Standard Contractual Clauses for international transfers.
  • Spanish Commercial Code (Royal Decree of 22 August 1885). Art. 30 (retention of accounting records).
  • Spanish General Tax Act 58/2003. Arts. 66 to 70 (tax limitation periods).
  • Agencia Española de Protección de Datos (AEPD). Supervisory authority and guidance (cookies, duty to inform).
← Back to home