Data controller: Gextiona Interproducción, S.L.
Version 2.0 · Last updated: January 1, 2026
qartalia is an information society service owned by Gextiona Interproducción, S.L. This Privacy Policy informs you, prior to registration and in a concise, transparent and intelligible manner, about the processing of the personal data collected through the platform.
By ticking the acceptance box —which will not be pre-ticked— and completing registration, the user declares that they have read and understood this Policy. Where a specific processing activity is based on consent, such consent will be obtained in a specific, informed and unambiguous manner through a clear affirmative action, and may be withdrawn at any time without affecting the lawfulness of processing prior to withdrawal.
The controller of the personal data collected through qartalia is:
Considering the nature, scope and purposes of the processing, the controller has assessed that the circumstances requiring the designation of a Data Protection Officer do not apply. Nonetheless, the user may address any data protection query to privacy@qartalia.com.
qartalia processes the following categories of data, always applying the principles of data minimisation and purpose limitation:
It is expressly noted that the IP address is regarded as personal data for the purposes of data protection law.
Data is processed for the purposes set out below, each with its legal basis:
Processing based on legitimate interest has been subject to the required balancing test, information on which the user may request. No profiling, personalised advertising or transfer of data to third parties for commercial purposes is carried out.
Data is kept only for as long as necessary for the stated purposes and, thereafter, duly blocked during the legally applicable limitation periods:
To provide the service, the controller relies on providers that process data on its behalf, with which it has entered into the corresponding data processing agreement:
Each processor is contractually obliged to process data solely on the controller's instructions, to ensure confidentiality and to apply appropriate security measures. Processors only engage sub-processors with the controller's authorisation and under the same obligations.
The use of Resend involves a transfer of data to the United States. This transfer is based on Resend's certification under the EU–US Data Privacy Framework, for which the European Commission adopted an adequacy decision on 10 July 2023. As an additional safeguard, Resend incorporates into its processing agreement the Standard Contractual Clauses approved by the European Commission.
Hosting with Hostinger is located in the Netherlands, within the European Economic Area, and therefore does not constitute an international transfer.
qartalia does not make decisions based solely on automated processing, including profiling, that produce legal effects on the user or similarly significantly affect them.
The controller does not send commercial communications by electronic means unless the user has previously consented or there is a prior contractual relationship concerning similar products or services. In any event, the user may object to receiving them easily and free of charge in each communication.
The platform uses only the strictly necessary technical cookies required for its operation. The use of any other cookies will require the user's informed consent and will be detailed in the Cookie Policy, available separately.
qartalia is a service aimed at professionals and businesses and is not intended for minors. In the field of information society services, in Spain the processing of minors' data based on consent is only lawful from the age of 14; below that age, the consent of those holding parental authority or guardianship is required.
The user may exercise the following rights at any time:
To exercise these rights, simply write to privacy@qartalia.com, indicating the right you wish to exercise. The controller will respond within a maximum of one month, extendable depending on complexity. If you consider that your rights have not been properly addressed, you may lodge a complaint with the Agencia Española de Protección de Datos (Spanish Data Protection Agency; C/ Jorge Juan, 6, 28001 Madrid; electronic office: sedeagpd.gob.es), without prejudice to any other administrative or judicial remedy.
More information at:
Legal basis: Rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21) and automated decisions (Art. 22) of the GDPR; withdrawal of consent (Art. 7(3) GDPR). Means and time limit for exercise: Art. 12 GDPR and Arts. 12 to 18 LOPDGDD. Right to lodge a complaint with the supervisory authority: Art. 77 GDPR and Art. 37 LOPDGDD.
The controller applies appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
In the event of a security breach entailing a risk to people's rights, the controller will notify the supervisory authority and, where appropriate, the affected individuals.
The controller may update this Policy to adapt it to regulatory or service changes. Material changes will be communicated by appropriate means and, where applicable, new consent will be requested. The date of the latest version appears in the header.
The data processing described is governed by Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 (LOPDGDD) and Spanish Law 34/2002 (LSSI-CE), as well as by the other applicable Spanish and European Union legislation.