Skip to content

Legal terms

Who we are, what we do with your data and what this website stores.

Three documents in one: the legal notice, the privacy policy and the cookie policy. Written to be understood, not to be skipped.

How to read this.

A legal notice is a mandatory document and it is usually written to comply, not to inform. This one tries to do both: each section first says what it means in plain language and then says what it has to say.

If you only want to know one thing, it is probably one of these three: who is behind this website, what happens to what you write in the contact form, and what this website stores in your browser. They are in that order, and the footer of any page on the site has a direct link to each one.

The law allows —and the Agencia Española de Protección de Datos, Spain's data protection authority, recommends— informing in layers: a short first layer next to the form, where the decision is made, and a full second layer, which is this page. That is why the tick-box on the form says the essentials in two lines and links here: the essentials have to fit where you sign, and the detail has to be where it can be looked up.

The twenty-seven sections run in the order in which the questions come up. Sections 1 to 10 are the legal notice: who is answerable, what you can do on the site, what it is liable for and what it isn't. Sections 11 to 21 are privacy: what data, what for, who sees it, how long it is kept and what you can demand. Section 22 is cookies. Sections 23 to 27 are what closes a document like this: accessibility, complaints, applicable law, versions and —the one that is almost never there— what is still missing from this text.

A reading warning worth giving early: this document is about THIS WEBSITE. The security and video analysis systems the group designs, installs and maintains at its clients' sites are something else, with a different controller and different documentation. Section 15 explains the difference, because it is the most frequent confusion and the one with the most consequences.

Last updated: September 2026. When this changes, the date changes.

1 · Who is answerable for this website.

Upon Group is not a company: it is the trading name of three that work together. And that matters, because which one is answerable depends on the matter.

In compliance with article 10 of Ley 34/2002, on information society services and electronic commerce, the identifying details of the entities that own this site are set out below.

That article requires the owner of a website to be identifiable without effort: name, registered address, registration details at the relevant registry, tax identification number and a direct and effective means of contact. It isn't a formality: it is what allows anyone —a client, a competitor, a public authority— to know who to complain to and where.

North Point Solution, S.L.

Owner of the website and controller of the data collected through it. CIF B66888413. Registered at the Registro Mercantil de Barcelona, volume 39233, folio 0155, sheet 341170, first entry. Registered address at Av. Martí Pujol 198, entresuelo · 08912 Badalona (Barcelona). Telephone: 902 02 70 91. Email: [email protected].

West Point Solution, S.L.

Company in the group engaged in the engineering, installation and maintenance of electronic security systems. Authorised installation company no. 3709 and registered in the RASIC. CIF: PENDING. Registration details: PENDING. Registered address: Av. Martí Pujol 198, entresuelo · 08912 Badalona (Barcelona).

Upon Solution, S.L.

Company in the group. CIF: PENDING. Registration details: PENDING. Registered address: Av. Martí Pujol 198, entresuelo · 08912 Badalona (Barcelona).

Why two of the three say "PENDING".

Because we don't have them published anywhere on the site and they are not invented. A wrong CIF in a legal notice isn't a detail: it is a false identification of the provider, which is precisely what article 10 exists to prevent.

The word "PENDING" is visible on purpose. A silent gap goes unnoticed for years; a visible marker is irritating until somebody fills it in, and that is exactly what it is supposed to do.

Who is answerable for what.

For this website —for the content published, for its maintenance and for the processing of the data collected through the form— North Point Solution, S.L. is answerable.

For engineering, installation and maintenance work on electronic security systems, the company answerable is the one that signs the corresponding contract or quotation, which is identified in that document. Anyone contracting an installation doesn't contract with "Upon Group": they contract with a specific company, with its CIF and its registered address, and that is set out in writing before work starts.

If you don't know which of the three you are dealing with, ask and you will be told. It is a reasonable question and it has a one-line answer.

Trading names.

"Upon Group" is the name under which the three companies present themselves jointly. "Infinity Neural", "IRIS Neural", "WestPoint", "Neural Pax" and the product family names —Black, Lemon, Teal, Rust, Ruby and Grey Neural— are trading names of the group's products and services.

A trading name is not a company. It appears on the website, on signage and in the technical documentation because it is useful for making yourself understood, but the party taking on obligations is always one of the three companies in the previous section.

Domain name: upongroup.com. This document refers to that domain and its subdomains. The site irisneural.com, linked from several pages, has its own legal notice and its own policy: what you read here does not apply to it.

2 · The words in this document.

Seven terms the law uses with an exact meaning and everyday speech uses with another. If you understand these seven, the rest of the document reads itself.

The names below are those of article 4 of the GDPR. They are not jargon for its own sake: each one allocates responsibilities in a different way, and confusing two of them changes who is answerable for what. That is why they are at the beginning and not in an annex.

The glossary.

  • CONTROLLER. Whoever decides what data is used for and how. It is the one in charge and the one who answers. On this website, for the form data, the controller is North Point Solution, S.L. On a camera installation at a client's premises, the controller is the client: it is the client who decides to record, what for and for how long.
  • PROCESSOR. Whoever processes the data on the controller's behalf and following its instructions, without deciding anything on their own account. The provider that hosts this website is a processor: the data passes through their servers, but it is not theirs and they cannot do what they like with it. The difference between controller and processor is not chosen by anyone out of convenience: it is determined by who actually decides.
  • DATA SUBJECT. The person the data belongs to. You, if you write to us. The law uses this odd phrase because it needed one that would work for clients, candidates, visitors and anyone else. Where this document says "data subject", you can read "you".
  • PROCESSING. Anything done with personal data: collecting it, storing it, reading it, copying it, sending it, consulting it, cross-referencing it, deleting it. Keeping an email in a mailbox is already processing. Deleting it is too. It is deliberately broad: if there were gaps, everything would escape through them.
  • PERSONAL DATA. Any information that allows a person to be identified, directly or by putting two and two together. A name, an email address, a phone number, a number plate, an image of a face, an IP address in many contexts. It does not have to state the name: it is enough that the name can be reached.
  • LEGAL BASIS. The legal reason why processing some data is allowed. The GDPR gives six and there are no more: your consent, the performance of a contract, a legal obligation, protecting somebody's life, a task carried out in the public interest, or a legitimate interest that outweighs your right for it not to happen. Without one of the six, the processing is unlawful even if it is useful, even if it is harmless and even if everybody does it.
  • CONSENT. A yes given freely, for something specific, knowing what is being accepted and without ambiguity. Carrying on browsing is not consent, a box that is already ticked is not consent, and "by using this site you accept" is not consent. And it can always be withdrawn, as easily as it was given.
  • INTERNATIONAL TRANSFER. Data leaving the European Economic Area, even if only because it is stored on a server in another country or because somebody consults it from there. It does not have to be sent in an envelope: being viewable from outside already counts. It is only lawful with specific safeguards, and section 16 says which ones.
  • PROCESSING AGREEMENT. The contract that binds a processor. Article 28 of the GDPR requires it and it has mandatory content: what data, what for, for how long, what security measures, what happens with sub-processors, what it does if there is a breach and what it does with the data at the end. Without that contract signed, handing data to a supplier is an unlawful disclosure, not a processing arrangement.
  • PROFILING. Processing data automatically in order to deduce or predict something about somebody: their interests, their creditworthiness, their behaviour, their health. Section 15 says why there is none of it on this website.

3 · Conditions of use.

What you can do on this website and what you can't. In short: read it and write to us.

Accessing and using this website implies acceptance of these general conditions. If you do not agree with any of them, do not use the site.

Access is free and requires no prior registration. There is no private area, there are no users, there are no passwords and there is nothing to buy here. Browsing does not require you to provide any personal data; the only data collected is what you decide to write in the contact form.

These conditions are general conditions in the sense of Ley 7/1998 on general contracting conditions: one party drafts them and the other accepts them as a block. That is why they are here in full, in a text you can read, print and save, and not behind a link nobody opens.

What is expected of anyone who comes in.

You undertake to use the site in accordance with the law, these conditions and good faith, and not to use it for unlawful activities, to damage the owner's systems or those of third parties, to introduce malicious code, or to attempt to access restricted areas or other users' data.

In particular, and without the list being exhaustive: do not impersonate another person on the form; do not send unlawful, insulting or unsolicited advertising content through it; do not harvest email addresses from the site in order to send commercial messages; do not manipulate request headers to hide the origin; and do not subject the site to load or penetration testing without written authorisation.

If you provide data on the form, you warrant that it is true and that, if it belongs to another person, you are entitled to give it and that person knows. It is the case most often overlooked: writing a colleague's email address "so that he gets it" is disclosing his data to a third party, and that has consequences the recipient cannot take on.

You are liable for any damage caused to the group's companies by a breach of these obligations. Put another way: if someone uses this form to attack the site or to land the company in a legal problem, the problem belongs to whoever did it.

What the owner can change.

The owner may modify, add or withdraw content, reorganise the pages and change the way they are presented, without prior notice. A website is not a closed document and freezing it benefits nobody.

That does not apply to this document. When what this page says changes, we say that it has changed and from when, and section 26 explains how. A legal notice that is modified in silence informs nobody, because there is no way of knowing what was accepted.

Access may be interrupted for maintenance, for a technical failure or because use contrary to the law or to these conditions is detected. Where reasonably possible, notice will be given beforehand.

Automated extraction, search engines and AI systems.

Mass automated extraction of the content for commercial reuse —republishing the pages, building a product or a paid service out of them— requires prior written authorisation.

Consultation and indexing by search engines and by artificial intelligence systems are expressly permitted: this site's robots.txt file authorises it explicitly, and names the AI crawlers one by one so that there is no doubt. It isn't an oversight or a concession: more and more people ask an assistant instead of searching, and a website that blocks those crawlers disappears from that conversation.

Being allowed to read doesn't mean anything is being given away. A system that cites these pages may reproduce extracts stating the source, like any other reader; what it cannot do is present them as its own or use them to offer the same services under another brand. Section 6 develops this.

Automated requests have to be reasonable. A crawler asking for hundreds of pages a second stops being a reader and becomes an overload, and at that point its access is limited.

4 · What is and what isn't an offer.

Nothing you read here is a price, or a commitment, or a guarantee that it can be done at your site. What counts is a signed quotation.

This site is informative. No products or services are sold through it, there is no basket, there are no payments and no contract is concluded electronically. That is why the prior information and confirmation obligations in articles 27 and 28 of the LSSI-CE do not apply, since those govern sites that allow contracting: here the only thing you can do is ask us to call you.

The information published —product descriptions, capabilities, case studies, detections, indicative timescales, diagrams— is explanatory in nature and does not constitute a contractual offer or a binding invitation to contract within the meaning of article 1262 of the Código Civil (the Spanish civil code). It does not in itself create any obligation for the group's companies, and the fact that a page describes a capability does not mean that capability is available at any site, with any camera and in any conditions.

Nor is it technical advice. What can be done at a particular site depends on that site: on the cameras there are, on where they are placed, on the light, on the network, on the sector's regulations and on what you want to achieve. That is said after looking at it, not before, and anyone who says it before is guessing.

What does bind: the quotation.

A quotation, a written offer or a contract are documents separate from this website. They are signed by an identified company in the group, they carry their own subject matter, their own price, their own validity period and their own particular conditions, and those are the ones that bind.

If anything said on this website contradicts what a signed quotation or contract says, the quotation or the contract prevails. This page does not apply by default to a commercial relationship: it governs the use of a website, not the provision of a service.

The particular conditions of a project may require things that do not appear here: warranties, response times, service levels, client obligations, allocation of responsibilities in data protection matters. None of that can be inferred from a website, and it should not be attempted.

A request sent through the form is not acceptance of anything. It is a contact request: it obliges us to answer it, and nothing more.

5 · Commercial communications.

None are sent today. And when they are, you will need to have said yes, not to have failed to say no.

Article 21 of the LSSI-CE prohibits sending advertising by email or by any equivalent electronic means of communication to anyone who has not requested it or expressly consented to it beforehand. It is a prohibition, not a recommendation, and a breach is penalised regardless of what the GDPR says.

There is a single exception, in paragraph 2 of that article, and it is narrower than people usually think: you may write to someone who is already a client, if the data was lawfully obtained from them in the course of that relationship, and only to offer them products or services similar to the ones they already contracted. Not a client from ten years ago, not a contact who asked for a quotation and didn't contract, and not a product with nothing to do with the one they bought.

Today, no commercial communications of any kind are sent from this website: there is no newsletter, there is no mailing list and the tick-box on the form does not subscribe you to anything. What is done with what you write is answer you.

What would happen if they were sent.

To send you commercial communications unrelated to your enquiry, consent separate from the enquiry consent would be needed: a different tick-box, not pre-ticked, saying what will be sent to you and by what means. Consent to be contacted about what you asked about is no good for sending you advertising about something else, because it is neither specific nor informed.

Every commercial message would carry, as the law requires, the word "publicidad" or "publi" in clearly identifiable form, the identity of the sender and of whoever it is sent on behalf of, and a simple, free means of objecting: a one-click link, without asking you for anyone's password and without making you justify anything.

To cancel, all you would need to do is use that link or write to [email protected] saying you don't want any more. Unsubscribing is immediate in the sense that no explanation is asked for, no three-screen "are you sure?" is offered and nothing is reactivated afterwards. The only data kept then is the minimum needed not to write to you again by mistake, which is a legitimate and separate purpose.

If you receive a commercial message from a company in the group and you don't remember consenting to it, say so. It is checked against the consent register and you are told what was found — including that nothing was found, if that is the case.

6 · Intellectual and industrial property.

Who owns what is on this website, what can be done with it and what has to be asked for first.

The texts, the design, the code, the trade marks, the logos, the images, the illustrations and the videos on this site belong to the group's companies or are used with their owner's authorisation, and they are protected by Real Decreto Legislativo 1/1996 on intellectual property, by Ley 17/2001 on trade marks and by the equivalent European legislation.

Partial reproduction of the content is permitted, citing the source and linking to the original. Any other use —full reproduction, distribution, public communication, transformation or commercial use— requires prior written authorisation.

Removing, altering or circumventing authorship notices, watermarks or the technical protection mechanisms that may accompany a piece of content is not permitted. Nor is using the group's trade marks in your own advertising, in domain names, in social media profiles or in metadata in a way that suggests there is a commercial relationship, an authorised distribution or an endorsement that does not exist.

Images, diagrams and illustrations.

A good part of the illustrations on this site are drawings: scenes built to explain what a system sees and where a camera goes. They are not photographs of clients' sites or real screen captures, and the people, the faces and the number plates that appear in them are invented. It is worth saying because an illustration that looks like a screen capture reads as evidence, and it isn't.

When an image does come from a real site, it is published with its owner's authorisation and without identifiable data of anyone unconnected. If you ever think you recognise yourself in an image on this site, say so: section 10 explains the procedure and it is dealt with.

The technical diagrams, the capability tables and the detection lists are our own work and document what the group has tested. Reproducing them without the source is presenting as your own a piece of verification work that costs time and money to do.

Third-party trade marks cited here.

This site cites trade marks, manufacturers, standards and products that do not belong to the group: camera and network equipment manufacturers, video management platforms, operating systems, ISO and UNE standards, certification bodies. Those trade marks and trading names belong to their respective owners.

They are mentioned for identifying or descriptive purposes, which is the use permitted by article 37 of the Ley de Marcas (the Spanish trade marks act): to say what equipment a system integrates with, what standard a job meets or what compatibility has been verified. It does not imply sponsorship, affiliation, representation or endorsement by those owners, except where it is expressly stated that an agreement exists and with what scope.

If you own a trade mark cited here and you consider the use goes beyond the descriptive, write to us. It is reviewed and, if you are right, the wording is changed.

Content written by a user.

Today this site has no comments, no forums, no ratings and no space where someone from outside can publish. The only thing that can be sent is the contact form, and what arrives that way goes to a mailbox, not to the website.

If a publishing space were enabled in the future, three rules would apply, and they would be stated in their place and not hidden here: whoever publishes is liable for what they publish and warrants that they have the right to do so; they grant the owner a non-exclusive, free licence to display it on the site, and only for that; and the owner may remove anything unlawful, harmful to a third party or off-topic, explaining why.

Until there is such a space, any content that looks as if a user wrote it on this website is our own content. If one day there are client testimonials published, they will be real, with permission and attributed; testimonials are not invented.

Artificial intelligence systems and this content.

This site explicitly authorises the crawlers of artificial intelligence systems to read its pages, and it does so in the robots.txt naming them one by one. The content is written in the HTML the server delivers, and not assembled afterwards by JavaScript, precisely so that they can read it: they don't run scripts.

The authorisation is to read, index and cite with attribution. That is: so that when someone asks an assistant what this group does, or whether a system can detect a particular thing, the answer can come from what is said here and not from what a third party says.

What that authorisation does not include is using the content to build a service that replaces the site without citing it, or presenting it as originating from another organisation, or reproducing whole pages as if they were its own. A search engine that summarises and links is a reader; one that republishes without a source is not.

And a useful warning for anyone arriving here from an assistant: answers generated by an artificial intelligence system from these pages are not statements by the group. If something matters —a figure, a capability, a compatibility— check it on the page or ask us.

7 · Liability and links.

What can be guaranteed and what can't. And here it is said properly, without the shouty block capitals of the original.

The owner works to keep the information on this site correct and up to date, but cannot guarantee the complete absence of errors or that the information is exhaustive for a particular case. Nothing published here constitutes a contractual offer or technical or legal advice for a particular installation: what can be done at yours depends on yours, and that is said after looking at it.

A website with a broad catalogue always has a part that is out of date: a model that went out of production, a version that changed name, a capability that improved. If you find something outdated, tell us and it gets corrected; and if a piece of information is decisive for a decision of yours, confirm it in writing before you take it.

The owner works to keep the site continuously available, but cannot guarantee that there will be no interruptions for maintenance, technical failures or causes beyond its control. No availability commitments expressed as percentages are given, because this site is not a contracted service and a figure like that could not be sustained.

To the extent the law allows, the owner is not liable for indirect damages, loss of profit or losses arising from decisions taken solely on the basis of the information published here. This limitation does not apply to wilful misconduct, to gross negligence, or to cases where the law prohibits it — in particular as against consumers, where clauses limiting the rights recognised by Real Decreto Legislativo 1/2007 are void and nothing here purports otherwise.

Links going out from this site.

This site contains links to third-party pages —among others, to irisneural.com, to the group's YouTube channels and to pages of manufacturers, standards and official bodies. The owner does not control the content or the policies of those sites and accepts no liability for them. When you follow an external link, you become subject to that site's conditions and to its privacy policy, not to this one.

The links are there to help you find information, and they do not imply that the group endorses everything on the other side, or that it sells what is offered there. It is worth taking the same care as with any other site on the internet.

If a link on this website leads to unlawful, broken or misleading content, tell us and it gets removed. Keeping dead links is carelessness, and keeping links to unlawful content is rather more than carelessness.

Links coming in to this site.

Links to this site may be created from other pages without prior authorisation, provided the link leads to the full page, does not reproduce the content inside a frame, does not suggest a commercial relationship that does not exist and does not sit alongside unlawful or harmful content.

The link may use the name of the page or of the group to identify the destination: that is descriptive use and it is legitimate. What it may not do is use the group's logos or visual identity elements as if they were those of the linking party, or present the linked content as its own.

The owner may ask for a link that breaches the above to be removed, and the fact that a link has been active for a time does not mean it has been authorised.

8 · Site security.

What is done to keep this secure, what cannot be promised and what is expected of anyone who finds a hole.

The owner applies technical and organisational measures to protect this site and the information transmitted through it, including traffic encryption by means of a TLS certificate. An architecture decision also helps: this site is served as pre-built pages, with no database behind it and no public administration area, so most of the usual attacks against a website have nowhere to get in here.

That said, no system connected to the internet is invulnerable, and the owner cannot guarantee the absolute absence of viruses, malicious code or other elements that could cause changes to your equipment, or the impossibility of unauthorised access. Anyone promising otherwise is promising something that isn't up to them.

It is worth keeping your own equipment up to date: an updated browser and a patched system prevent more problems than any clause in this document.

If you find a vulnerability.

As a user, you undertake not to take any action that compromises the security of the site: introducing malicious code, overloading the systems, bypassing protection measures or attempting to access non-public parts.

If you detect a vulnerability, we would be grateful if you told us before disclosing it, writing to [email protected] with what is needed to reproduce it. We guarantee that we will take no action against anyone who reports one in good faith, without exploiting it, without accessing third-party data beyond what is essential to demonstrate it and without making it public before it is fixed.

There is no bug bounty programme and none is promised. What is promised is to acknowledge receipt, tell you whether it has been reproduced, fix it and tell you when. And if you would rather your name appeared when it is published, it will.

9 · No licence, withdrawal of access and termination.

Three short clauses that usually go together and that all three say something similar: coming in here gives you no rights over anything, and this may cease to exist.

NO LICENCE. Access to the site grants the user no licence, assignment or right whatsoever over the content, the trade marks, the software or any other protected element, beyond the right to consult them for personal use. Nothing set out here may be interpreted as an implied assignment of intellectual or industrial property rights. Something being published and accessible does not make it free: it makes it public, which is a different thing.

REFUSAL AND WITHDRAWAL OF ACCESS. The owner reserves the right to refuse or withdraw access to the site, without prior notice and without needing to give reasons, to anyone who breaches these conditions. This power is exercised proportionately and does not affect the exercise of the rights the law grants the user, in particular those relating to their personal data: anyone whose access is blocked still has their rights of access, rectification or erasure dealt with just like anyone else.

TERM AND TERMINATION. The provision of this site's service is, in principle, of indefinite duration. The owner may terminate, suspend or interrupt the provision at any time, endeavouring to give advance notice where possible. Termination does not affect obligations already arisen or clauses that by their nature must survive, such as those on intellectual property, liability and applicable law.

If the site ceased to exist, the data collected through it does not disappear with it: it remains subject to what section 13 says about retention and to your rights in section 19, and a contact address is kept for exercising them.

10 · If you think we are infringing a right of yours.

The procedure, and it is a real one: you get an answer.

If you consider that any content on this site infringes your intellectual or industrial property rights, your right to honour, privacy or your own image, or any other right, you can tell us and we will review it.

Write to [email protected] stating: your contact details; a precise identification of the content you consider infringing and the exact address where it can be found; the reasons why you believe it infringes a right of yours; and a statement that the information you provide is truthful and that you are the rights holder or are authorised to act on their behalf.

We undertake to acknowledge receipt, review it and reply. If the complaint is well founded, the content is removed or corrected. And if it isn't, we explain why instead of not replying.

The data you give us in that communication is used only to handle it and to be able to evidence, if needed, that it was dealt with and how. That is also the reason it is kept after the matter is closed: without the file there is no way of showing that we acted with due care.

And the other way round, just in case: if a third party introduces unlawful content anywhere on the site, the owner cooperates with users, with the authorities and with law enforcement to remove or block it, in accordance with article 16 of the LSSI-CE. Removing content at the request of a competent authority is not an admission of anything: it is compliance.

11 · Privacy. What happens to your data.

In one sentence: if you write to us through the form, we keep what you write in order to answer you, and nothing else.

This section complies with articles 13 and 14 of Regulation (EU) 2016/679 —the GDPR— and with Ley Orgánica 3/2018 on data protection and the guarantee of digital rights, the Spanish data protection act. Those articles do not ask for a declaration of good intentions: they ask for eight specific pieces of information, and all eight are here, in the order the regulation lists them.

It is worth reading alongside section 2, which explains what "controller", "processor", "legal basis" and "data subject" mean. And alongside section 12, which goes into the detail of the form: what fields there are, which are mandatory and why.

What you need to know, in eight points.

  • CONTROLLER. North Point Solution, S.L., with the identifying details in section 1. Data protection contact: [email protected].
  • DATA PROTECTION OFFICER. The group companies have appointed data protection officers. You can go to them with any question about the processing of your data or the exercise of your rights: ask at [email protected] and their direct contact will be given to you. It is not published here yet because the detail is not confirmed for all three companies, and publishing the wrong address for exercising rights is blocking the exercise of those rights.
  • WHAT DATA. Only what you write in the contact form: name, email address, phone number if you give one, the subject you choose and the text of your message. Browsing the site collects no personal data, there is no user registration and no data about you is obtained from any other source: not from social networks, not from bought-in lists, not from contact enrichment services.
  • WHAT FOR. To deal with your enquiry and, where appropriate, for the sales contact afterwards related to it: calling you, arranging a visit, drawing up a quotation and following it up. It is not used to build profiles, it is not used to take automated decisions and it is not used for any purpose other than the one you wrote to us about without informing you again and, if need be, asking your permission again.
  • ON WHAT LEGAL BASIS. Your consent, which you give by ticking the box on the form (art. 6.1.a GDPR), and the legitimate interest in replying to a request you send us yourself (art. 6.1.f). If the enquiry leads to a quotation or a contract, the basis becomes the performance of that contract or the steps taken before it (art. 6.1.b), and if there is invoicing then compliance with legal, tax and accounting obligations comes in as well (art. 6.1.c). Sending marketing communications unrelated to your enquiry would need separate consent, which is not asked for today because none are sent.
  • WHO IT IS DISCLOSED TO. Nobody, unless the law requires it. The data may be processed by the technology suppliers that serve the group —hosting and email— acting as processors and with a signed processing agreement; section 14 explains what categories they are and what that contract requires of them. PENDING the public naming of those suppliers. Data is not sold, it is not passed on for third-party advertising and it is not shared with other companies in the sector.
  • FOR HOW LONG. For as long as the relationship arising from your enquiry lasts and, after that, for the limitation periods of the legal actions that may arise from it. If there is no relationship afterwards, it is deleted when the enquiry is closed. Section 13 sets out the criterion case by case, because "the time necessary" put like that tells you nothing.
  • WHAT YOU CAN DO. Access your data, rectify it, erase it, object to the processing, restrict it and request its portability, as well as withdraw your consent at any time. It is enough to write to [email protected] proving your identity. And if you think it has not been dealt with properly, you can complain to the Agencia Española de Protección de Datos (aepd.es). Section 19 explains each right, what it is for and how long the answer takes.

What the group maintains internally.

The GDPR is not complied with by a page like this alone. It also requires things that aren't visible from outside: keeping a record of processing activities, analysing the risk before starting a new processing operation and assessing its impact when that risk is high, training whoever handles data, and leaving a trail of decisions in order to be able to demonstrate them.

The group declares that it maintains that record of processing activities and carries out impact assessments where appropriate, and it has a privacy information management system certified to ISO/IEC 27701, which is precisely the standard that requires it to be reviewed periodically and submitted to external audit.

That is not a guarantee that nothing will ever happen: it is the difference between an organisation that can demonstrate what it does with data and one that would have to improvise the answer. Section 17 details the security measures, and the certificates page says what is certified, by whom and with what scope.

See the certificates

12 · The form, field by field.

It is the only place on this website where any data of yours is collected. So here it is in full: what is asked for, what is mandatory, why, and what happens to what you write.

The contact form has five fields and one tick-box. The fields marked with an asterisk are mandatory; the rest are not, and leaving them blank neither prevents you sending it nor makes the answer worse.

The fields.

  • NAME — mandatory. So we know who is being replied to and how to address them. It can be just the first name: it is not checked against any document and the surname is not needed.
  • EMAIL ADDRESS — mandatory. It is the route by which the reply comes back. Without it, the message arrives and there is no way to answer it, and a message that cannot be answered is no use to anyone. It is the only mandatory field for a purely practical reason, not a commercial one.
  • PHONE — optional. Only if you would rather be called or if what you are asking is better sorted out by talking. Not giving it has no consequence at all: the reply comes by email.
  • WHAT YOU WANT TO TALK ABOUT — optional. A selector with four options —Infinity Neural, WestPoint, IRIS Neural or something else— so that the message reaches whoever knows about it instead of going round twice. It is not commercial segmentation and it is not used to classify you: it is used to route.
  • MESSAGE — optional. The free-text field, where you say what you need. What you write there is read as it stands and it is what helps most in giving an answer that is any use.
  • CONSENT TICK-BOX — mandatory, and not pre-ticked. Ticking it is the act by which you consent to the processing. It has to be ticked by hand because article 4.11 of the GDPR requires an unambiguous indication, and a box that comes already ticked indicates nothing. It links to this page, which is the full information.

What NOT to write in the free-text field.

This is a warning, not a clause. An open text box invites you to tell everything, and there are things it is better not to tell there.

Do not include special category data: health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation, genetic or biometric data. Article 9 of the GDPR gives them reinforced protection and this form is not set up to collect them. If they arrive, they are not used for anything and they are deleted as soon as they are noticed.

Do not include passwords, access keys, credentials for any system, full card numbers or confidential documentation either. You will never be asked for any of that through a web form, and if someone asks you saying it is on our behalf, it is not on our behalf.

And think twice before writing other people's data: a colleague's name and phone number, a vehicle's number plate, an employee's or a visitor's details. If you provide them, that person has the right to know you gave them and to exercise their rights, and the one who has to inform them is you. For a technical enquiry it is almost never necessary: describing the situation is usually enough.

If what you need to send is drawings, listings or documentation with personal data inside, say so in the message and you will be pointed to a suitable way of doing it. The form doesn't accept attachments, and that is deliberate.

What happens to the message when you send it.

The content of the form is sent to a group mailbox and treated like any other email: it is read by whoever has to answer it. It is not stored in any database on this website, because this site has no database: they are pre-built pages served as they are.

Within the group, the message is accessed by the people who need access in order to reply to you —sales, technical or administration, depending on what you ask— and nobody else. Access is limited on a need-to-know basis, which is the only criterion that works.

What is NOT done with what you write: it is not added to any mailing list, it is not used to send you advertising unrelated to your enquiry, it is not disclosed or sold to third parties, it is not cross-referenced with data obtained from other sources, it is not used to build a profile of you and it is not subjected to any automated decision. If any of that changed, this page would change first and you would be asked for permission before it was applied to your data.

If you write to us directly at a group email address instead of using the form, exactly the same applies: same purpose, same time limits, same rights. The medium changes; the processing does not.

13 · How long each thing is kept.

Almost every policy says "for the time necessary", which says nothing. Here is the criterion, case by case. No invented periods: the ones we state will be stated when they are confirmed.

The governing principle is storage limitation, in article 5.1.e of the GDPR: data is kept for as long as it serves the purpose it was collected for, and after that it is deleted or anonymised. There is no single period because there is no single reason for keeping it.

And there is an intermediate step worth knowing about, because it is surprising: article 32 of Ley Orgánica 3/2018 requires data to be BLOCKED rather than deleted when it may still be needed to deal with a claim or an inspection. Blocking means setting it aside, preventing its use and leaving it accessible only to courts, authorities and one's own defence. During that period the data exists but is not used for anything else, and at the end of it it is destroyed.

Case by case.

  • AN ENQUIRY THAT GOES NOWHERE. We answer you and that is the end of it. The data is deleted when the enquiry is closed, without waiting for anything. It is not kept "in case they come back": that is a commercial purpose dressed up as filing.
  • AN ENQUIRY THAT LEADS TO A QUOTATION. It is kept while the offer is alive and for as long as anything related to it may be disputed. The criterion is the limitation period of the actions that could arise from those preliminary dealings, which is set by the Código Civil and not by us.
  • A CONTRACTUAL RELATIONSHIP. For as long as the contract lasts and, after that, for the periods that tax, accounting and civil law set for keeping the documentation and for answering for what was done. On a security installation that period includes the warranty and the maintenance, and the contract sets it.
  • CONSENT FOR MARKETING COMMUNICATIONS. Until you withdraw it. And the PROOF that you gave it —when, how and with what wording— is kept for as long as it may be required to be demonstrated, because article 7.1 of the GDPR requires it to be evidenced. If you withdraw your consent, the processing is deleted and the proof of the withdrawal is kept, which is what protects you.
  • OBJECTION TO RECEIVING COMMUNICATIONS. If you ask not to be written to, the bare minimum needed to honour it is kept: your address on a suppression list. Deleting it altogether would let you back in through the next door, which is exactly the opposite of what you asked for.
  • THE EXERCISE OF A RIGHT. When somebody exercises a right, the file —the request, the identification, the reply and the date— is kept for as long as it may be necessary to evidence that it was dealt with and how. Without that trail there is no way to show that it was complied with.
  • A COMPLAINT ABOUT SITE CONTENT. The one in section 10. The file is kept for the same reason: to be able to evidence the care with which it was handled.
  • SERVER TECHNICAL LOGS. Any web server records the IP address of whoever asks it for a page, because without it the page could not be sent back, along with the date, the page requested and the type of browser. Those logs are managed by the hosting provider, they are there for diagnostics and security, and they are not used to measure audience or to profile anyone. PENDING the identification of that provider and the retention period that applies to its logs, and until it is confirmed no number is written here.
  • AFTER ALL THAT. Secure erasure, or anonymisation if the data is still useful for something aggregated. Data that is genuinely anonymised —data from which you cannot get back to the person— is no longer personal data and stops being subject to this. Data with the name covered up but reversible is not anonymised: it is pseudonymised, and it is still personal.

14 · Who else handles your data.

No company does everything itself. Here is what kind of suppliers are involved, what contract binds them and how to find out exactly who they are.

A processor is someone who processes data on the controller's behalf following its instructions, without deciding anything on their own account. A hosting provider is one: the data passes through their machines, but it isn't theirs. The difference from a disclosure is decisive: in a disclosure the recipient decides; under a processing arrangement, they obey.

It is not a relationship you can improvise. Article 28 of the GDPR requires a written contract with mandatory content, and without that contract passing data to a supplier is not a processing arrangement: it is a disclosure of data with no legal basis.

What categories of supplier are involved.

  • HOSTING AND SITE DELIVERY. Whoever has the servers where the pages live and the infrastructure that distributes them. It is involved in everything that goes through the website, even though it has no client database to look at.
  • EMAIL AND MAILBOXES. The service where the form messages and the correspondence afterwards arrive and are stored. It is the supplier that sees the most personal data, because email is where everything piles up.
  • SITE MAINTENANCE AND DEVELOPMENT. Whoever publishes changes, corrects errors and checks that it works. It may access configuration and technical logs occasionally in the course of a specific piece of work.
  • SALES AND ADMINISTRATIVE MANAGEMENT. The tools used to follow up an offer, issue an invoice or keep the accounts, and the outside professionals involved in that, such as the accountants.
  • ONE-OFF PROFESSIONAL SERVICES. Legal advice, auditing of the certified management systems, or expert assessment in the event of an incident. They access only what is needed for their engagement and they are bound by a duty of confidentiality.

What the contract requires of them.

The processing agreement required by article 28.3 of the GDPR has to state, as a minimum: the subject matter and duration of the processing, its nature and purpose, the type of data and the categories of people affected, and the obligations of both parties.

And it requires the processor, among other things, to process the data only on documented instructions; to keep confidentiality and to ensure its staff do; to apply the security measures in article 32; not to subcontract without authorisation and to impose the same obligations on the subcontractor; to assist the controller when someone exercises a right; to give notice without delay if there is a security breach; to cooperate with audits; and to return or destroy the data at the end, keeping no copies.

That last point is the most forgotten and the one that matters most at the end of a relationship with a supplier: when you change service, the data doesn't stay where it was.

How to find out who they are.

The named, up-to-date list of the processors involved is given to anyone who asks: write to [email protected] and you will be given it, with the service each one provides and the country it provides it from.

It is not published here yet, and that is a shortcoming, not a decision: PENDING confirmation. Publishing a list of suppliers that is no longer true a month later informs worse than not publishing it; publishing it properly and keeping it up informs far better than this. The intention is the second.

Besides processors, there are recipients who are not processors and are worth naming: public authorities, the courts and law enforcement, when a rule requires information to be provided to them. That is not a voluntary disclosure and your consent is not needed, but you should know about it.

15 · Automated decisions and profiling.

There are none on this website. Not one. And since the group works on systems that analyse images, it is worth explaining very clearly where this website ends and the other thing begins.

Article 22 of the GDPR gives you the right not to be subject to a decision based solely on automated processing that produces legal effects or significantly affects you: a system refusing you credit, ruling you out of a recruitment process or closing your account without a person being involved.

No decision of that kind is taken on this website. What you write on the form is read by a person and answered by a person. There is no automatic scoring of contacts, no classification of your interest, no purchase probability calculation and nothing that decides on its own what is done with you.

Nor is any profile built. It is not recorded which pages you visit, how long you spend on each one is not measured, your sector or your job title are not inferred, and what you write is not combined with information obtained from other sources. This is not a promise of good behaviour: it is a consequence of how the site is built, with no analytics and no cookies installed, and it can be checked from any browser's developer tools.

This website and the systems that get installed are not the same thing.

The group designs, installs and maintains video surveillance, access control and image analysis systems. Those systems do process personal data, sometimes in large quantities, and some of them generate alerts from what they see. None of that happens on this website or from this website's data.

And what matters legally: at a client's site, the controller is THE CLIENT. It is the client who decides to put cameras in, where, what for, how long the images are kept, who sees them and who is informed. The legal basis, the information signs, the record of activities, the impact assessment where applicable and dealing with the rights of anyone appearing in the images are all down to them.

The group's companies act there as a supplier: they install, configure and maintain, and when in the course of that maintenance they access images or system data they do so as processors, with a processing agreement and following the client's instructions. They do not decide what is recorded or what is done with the recording.

So if you appear in the images of a system installed by the group in a car park, a factory or a hotel, and you want to exercise your rights over those images, you have to approach the owner of that site, who is the controller. If you write to us, we will tell you so and help you identify them, but we cannot decide about data that isn't ours: doing so would itself be an infringement.

This page does not document those systems. Each installation has its own, drafted by the controller, and the group company involved provides the technical information needed to do it properly.

16 · International transfers.

What it means for data to "leave Europe", why it isn't just a question of moving files, and what happens here today.

Chapter V of the GDPR governs what is needed for personal data to leave the European Economic Area. The reason is simple: data in a country without equivalent protection effectively loses the protection the law gives it here, because the safeguards don't travel with the file.

And "leaving" is understood broadly. Nothing has to be sent: a server being in another country, or a support engineer being able to look at the data from there, is already an international transfer. Remote access counts, and it is how it happens most of the time without anyone noticing.

Where there is a transfer, it is only lawful with one of these safeguards: a European Commission adequacy decision declaring that the country protects data sufficiently; standard contractual clauses approved by the Commission, together with an analysis of whether they work in practice in that particular country; binding corporate rules; or, for one-off cases, one of the exhaustive derogations in article 49, which are narrow and no use for a regular flow.

What happens today on this website.

The form data is processed within the European Economic Area. If in the future a supplier were to involve an international transfer, it will be carried out with the chapter V safeguards and it will be stated on this page before it happens, saying which supplier, to which country and with which safeguard. PENDING documentary confirmation of exactly where the hosting provider's servers are, which is the piece of information that closes this section.

There is one exception worth facing head on: the videos. When you click to play one, your browser connects to Google and that connection may involve processing of your data by Google, including a transfer outside the European Economic Area under its own safeguards and its own policy. That relationship is between your browser and Google: this document does not govern it and it cannot be governed from here.

What has been done is to make sure it doesn't happen unless you decide it. The videos are served from youtube-nocookie.com and the player doesn't load until you click. As long as you don't click, Google receives nothing from you through this website. And if you would rather not click, you miss nothing that isn't also written down.

17 · How your data is protected.

Article 32 of the GDPR does not ask for "maximum security": it asks for security proportionate to the risk. And that can be explained.

The owner applies the appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with article 32 of the GDPR. Among others: traffic encryption, need-to-know access control and periodic review of who accesses what, activity logging, backups, and processing agreements with the suppliers that process data on the owner's behalf.

To that are added the organisational measures, which are the ones that usually fail first: that access is withdrawn when someone changes role or leaves the company, that staff are trained and can recognise an attempted fraud by email, that there is a written procedure for when something goes wrong, and that it is tested from time to time that backups really can be restored.

And there is one design measure worth more than several of the above: not collecting what isn't needed. This site asks for two mandatory pieces of data, has no database, has no users and has no passwords. What doesn't exist can't be leaked, and that is minimisation in the sense of article 5.1.c, not austerity.

These measures form part of the group's information security management system, certified to ISO/IEC 27001 and complemented by ISO/IEC 27701 for privacy management. What matters about a certificate like that isn't the badge: it is that it forces you to review, to measure and to pass an external audit that can withdraw it. You can consult it on the certificates page.

See the certificates

If something breaks: security breaches.

A personal data security breach —a breach— is any incident causing the destruction, loss, alteration, unauthorised disclosure of or access to personal data. It isn't only an attack: an email sent to the wrong person, a lost laptop or a deleted backup are breaches too.

If a breach occurred that posed a risk to your rights, it will be notified to the supervisory authority within seventy-two hours of becoming aware of it, as article 33 of the GDPR requires. And where the risk is high, it will be communicated to you as well, in clear language and saying what happened, what data it affected, what is being done and what you can do.

Every breach is documented, whether it has to be notified or not. That documentation is what makes it possible to learn from what happened and what makes it possible to demonstrate, if needed, why it was decided that notification wasn't required.

18 · Consent and how to withdraw it.

A yes that can't be withdrawn isn't a yes. So here is how it is given and how it is undone.

Consent is given by actively ticking the box on the contact form. It doesn't come pre-ticked and it is not taken as given by the mere fact of browsing: article 4.11 of the GDPR requires a freely given, specific, informed and unambiguous indication, and silence is not one.

The four words in that definition are four requirements, and each one rules out a specific practice. FREELY GIVEN: access to content cannot be made conditional on your accepting processing that isn't needed to give it to you. SPECIFIC: consent for one thing is no good for another, which is why there is no single box here that accepts everything. INFORMED: you have to be able to know what you are accepting before you accept it, hence the link to this page. UNAMBIGUOUS: an act is needed, not the absence of one.

You can withdraw it at any time by writing to [email protected], as easily as you gave it and without having to explain why. Withdrawing it does not affect the lawfulness of the processing carried out before the withdrawal, and it has no consequence other than that we will stop contacting you.

The fact that consent is one of the legal bases doesn't mean it is the basis for everything. If there is a contract under way or a legal obligation to meet, withdrawing consent doesn't erase those other processing operations, because they weren't based on it. When you get an answer to a withdrawal, you will be told exactly what stops and what continues, and on what basis.

19 · Your rights, one by one.

The eight points in section 11 list them in one line. Here is what each one is for, because there are rights people ask for when they want a different one.

They are all exercised the same way and they are all free: write to [email protected] saying what you want and providing something that allows us to check it is you. No special form is needed, no reason is needed and no lawyer is needed.

The rights.

  • ACCESS (art. 15). Knowing whether your data is being processed and, if so, which data, what for, who it is disclosed to, how long it is kept and where it came from. It includes the right to a copy of that data. It is the right worth exercising first when you do not know what there is.
  • RECTIFICATION (art. 16). Correcting what is wrong or completing what is incomplete. A misspelt email address, an old phone number, a changed name.
  • ERASURE (art. 17), the so-called "right to be forgotten". Having your data deleted when it is no longer necessary, when you withdraw your consent and there is no other basis, or when it was processed unlawfully. It is not absolute: if there is a legal obligation to keep it or a claim under way, the data is blocked rather than deleted, and that is explained to you.
  • OBJECTION (art. 21). Asking for your data to stop being processed when the processing rests on a legitimate interest. If you object to processing for direct marketing purposes, there is nothing to weigh up: it stops, full stop.
  • RESTRICTION OF PROCESSING (art. 18). Asking for the data to sit still —not to be used, but not to be deleted— while it is being argued whether it is accurate or whether the processing is lawful. It is the least known right and the most useful one when there is an open disagreement: it stops the data circulating and it stops the evidence disappearing.
  • PORTABILITY (art. 20). Receiving, in a commonly used electronic format, the data you provided yourself, and asking for it to be sent to another controller where that is technically possible. It applies to what is processed on the basis of consent or of a contract and by automated means.
  • NOT TO BE SUBJECT TO AUTOMATED DECISIONS (art. 22). That a machine on its own does not decide about you when the decision really affects you. There is no such decision on this website, as section 15 explains, but the right is listed because the law lists it.
  • WITHDRAWING CONSENT (art. 7.3). At any time and as easily as it was given. It is not the same as erasure: withdrawing consent for the future and asking for what is already there to be deleted are two different requests, and they can be made together.
  • COMPLAINING TO THE AUTHORITY (art. 77). If you think it has not been dealt with properly, you can go to the Agencia Española de Protección de Datos (aepd.es), without needing to have complained to us first — although complaining here first is usually quicker. Section 24 explains the two routes.

How identity is verified, and how long the answer takes.

To deal with a right you have to be reasonably sure that the person asking is who they say they are: dealing with an impostor's erasure request would be as serious as not dealing with it at all. But the check has to be proportionate. Normally it is enough for you to write from the same email address you contacted us with, or to give details that let us find your enquiry.

A copy of your ID document is not required up front. The Agencia Española de Protección de Datos, Spain's data protection authority, has repeatedly pointed out that systematically asking for identity documentation is excessive when there are less intrusive means, and collecting a copy of an ID document in order to answer a request is collecting more data than you want deleted. Additional identification is only asked for if a reasonable doubt remains, and the reason is given.

The deadline for replying is one month from receipt, in accordance with article 12.3 of the GDPR, extendable by two further months where the request is complex or there are many of them, telling you within the first month that it is being extended and why. It is a statutory deadline and not an estimate of ours.

If the request is not granted, you are told within that same period why not and what you can do next, including the possibility of complaining to the supervisory authority or going to court. A refusal without reasons is not an answer.

If you exercise a right and your data is also processed by a processor, the instruction is passed on to them. That is why the processing agreement in section 14 includes that duty to assist: without it, an erasure would only be half done.

20 · Minors.

This site is not for minors, nothing is asked of them and age is not verified. All three things are true and all three are worth saying.

Article 7 of Ley Orgánica 3/2018 sets fourteen as the age from which a person can consent to the processing of their data on their own. Below that, the consent of whoever holds parental responsibility or guardianship is needed.

This site is aimed at professionals and organisations: security, operations, maintenance and purchasing managers. It offers nothing designed for minors, there is no content aimed at them and no data on under-fourteens is knowingly collected.

That said, we have to be honest about the limit: the age of whoever sends the form is not verified, because there is no proportionate way of doing it on an informative website and because verifying it would mean collecting far more data than is collected now. Claiming that a minor cannot get in here would simply be false.

If it is detected that data of a child under fourteen has been provided without the appropriate consent, it is deleted. And if you are a parent or guardian and you think it has happened, write to [email protected]: it is checked, you are told what there was and it is deleted without asking for further explanation.

21 · Social media and profiles.

The only thing this website links to today is the group's YouTube channels. And even so it is worth explaining what interacting on a site that isn't ours involves.

From this site there is a link to the Upon Group YouTube channel, in its Spanish version and its English version, where the case and operation videos are published. If the group opens or maintains profiles on other platforms, they will be linked from here and what this section says will apply to them.

The first thing to understand is who is answerable for what. The platform is answerable for the platform: it decides how it works, what data it collects about you, what cookies it installs, what it recommends to you and how long it keeps things. That relationship is governed by their conditions and their privacy policy, which you have to accept with them and not with us. Our role there is that of someone who publishes content and reads what people write to them.

If you follow a group profile, comment, react or send us a message that way, you are making public or accessible what you have decided should be public or accessible in your settings on that network. We see that and nothing more: we have no access to your account, to your contacts or to anything you have marked as private.

What is not done with that information: it is not extracted to add to any file, it is not cross-referenced with the form data, it is not used to build contact lists and no tracking is done of what you post elsewhere. If a commercial enquiry comes out of a conversation on a network, you are asked to continue it by email, and then what section 12 says applies as it does to any other enquiry.

Comments on the group's channels are moderated: anything unlawful, insulting, unrelated advertising or content revealing someone's personal data is removed. Removing a comment is not censoring an opinion; leaving a third party's phone number published is a problem.

Your rights over the data the platform holds are exercised with the platform, which is the one that holds it. With us you can exercise them over what we process —for example, a message you sent us that way— by writing to [email protected]. If you ask us for something that isn't in our hands, we will tell you and point you to where it is.

22 · Cookies. What this website stores in your browser.

Today, nothing that identifies you. And when that changes, you will be asked for permission first.

A cookie is a small file that a website stores in your browser. They are used for useful things —remembering that you have already accepted something, keeping a session open— and for things that require consent, such as measuring which pages are visited or building an advertising profile.

Article 22.2 of the LSSI-CE allows the use without consent only of cookies strictly necessary to provide the service you have asked for. All the rest require your prior, informed and revocable consent, and a pre-ticked box or "by continuing to browse, you accept" is not good enough.

And one point that is always forgotten: the rule doesn't only talk about cookies. It talks about storing information on a user's equipment or accessing information already stored there, by any technique. It makes no difference whether it is a cookie, browser local storage, an invisible pixel or a fingerprint built from your equipment's configuration: if it does the same job, it needs the same thing.

What there is, and what there isn't.

This website uses TWO cookies, both of them from Google Analytics, and both are only there to find out which pages get read and which don't. There are no advertising pixels, no profile is built and your browsing is not shared with anyone else.

They are not installed until you accept them. The first time you come in, a notice appears at the bottom with two buttons of the same size; until you press one, nothing from Google is loaded: not the program, not a cookie, not a single request to its servers. Closing the notice without answering, or carrying on browsing, is NOT accepting, and it is not treated here as if it were.

Refusing limits nothing. You read the whole website just the same, with all the content and all the functions. And you can change your mind whenever you want from "Change cookies", at the foot of any page: if you withdraw permission, Google is told to stop measuring and the cookies it had set are deleted, not just the program removed.

Your answer is stored in your browser's local storage, not in a cookie, and it travels to no server. It expires after two years: a "yes" from four years ago says nothing about what you want today.

What does happen, because it happens on any website, is that the server records the request: your IP address, the date, the page you asked for and the browser type. Without the IP the page couldn't be sent back to you. Those logs are for diagnostics and security, they are not used to measure audience or to profile, and they are managed by the hosting provider: section 13 says what there is and what is still to be found out about them.

The videos are the other thing to watch, and it is resolved: they are served from youtube-nocookie.com and the player doesn't load until you click on one. As long as you don't click, YouTube receives nothing from you. When you click, a connection is made to Google, which may store information in your browser under its own policy — and that is why you have to click, and why the player doesn't set itself up on its own.

Which ones they are, one by one.

Name, what it is for, how long it lasts and who installs it. Google sets both of them, and both only if you have accepted.

  • «_ga» · Google Ireland Limited · 2 years. Telling one browser from another so the same person is not counted twice. It carries no name and no email address: it is a random number.
  • «_ga_<ID>» · Google Ireland Limited · 2 years. Working out whether this visit is the same session as one a while ago. The end of the name is this site's identifier inside Analytics.

Both are from Google Ireland Limited, based in the European Union. Google may also process that data outside the European Economic Area, and for that it relies on the European Commission's standard contractual clauses. Its privacy policy explains what it does with the data, and we don't copy it here because it changes and this page would go out of date.

What has been configured, and it is worth saying because it does not come that way out of the box: measurement is asked for and NOTHING for advertising. Ad signals and personalisation are expressly denied, so Google's advertising cookies never get installed. That would need a different consent, and it is not being asked for.

You can also block or delete cookies from your browser settings, regardless of what you decide here. All current browsers let you block them completely, delete the ones already there and browse in a window that saves nothing when it closes; their own help explains how, and it changes with every version, so we don't copy instructions here that will go out of date.

If it is about your data.

For any data protection matter you can approach the data protection officer of the relevant company —ask for their contact details at [email protected]— before going anywhere else. That is their job: reviewing, mediating and correcting within the organisation.

And you can complain to the Agencia Española de Protección de Datos (aepd.es), which is the supervisory authority in Spain. It is a right under article 77 of the GDPR and you don't need to have complained to us first in order to exercise it. The complaint is submitted through their electronic office, it is free, and the Agencia can request information, open an investigation and impose penalties.

The Agencia also has a specific, urgent procedure for taking down content on the internet that seriously infringes rights, designed above all for the circulation of images without consent. It is mentioned here because it exists and almost nobody knows about it.

And in any case the judicial route remains open, in accordance with article 79 of the GDPR. Complaining to the Agencia does not close it, and going to court does not require going through the Agencia first.

If you are a consumer.

This site and the group's services are aimed at businesses, public authorities and professionals. But if you contract as a consumer —that is, for a purpose outside a business or professional activity— you have the protection of Real Decreto Legislativo 1/2007, and nothing in this document limits it. Clauses purporting to limit it would be void, and nothing here purports to.

In that case you can go to your local council's consumer services, to your regional government's consumer affairs department, or to the consumer arbitration system if both parties accept it.

Two things said because honesty requires it. First: this site publishes no adherence to any private out-of-court dispute resolution scheme or to any certified code of conduct. If one existed, it would be stated here with its link, because signing up and not saying so is no use to anyone. Second: the obligation to give information about a European online dispute resolution platform applies to sites that allow contracting online, and this one does not — no contract is concluded here, as section 4 explains.

23 · Accessibility.

This site has been audited page by page. The full statement is on its own page, with the numbers.

A website that can't be used with a screen reader, with the keyboard or with enlarged text excludes people, and that isn't a finishing detail. The 418 published pages of this site have been reviewed one by one against the WCAG 2.2 criteria at level AA.

The accessibility statement says what was measured, how, what came out and —the part that almost never gets written— what could not be checked. Full conformance with anything is not declared, because conformance is declared by whoever audits and not by whoever builds.

If you come across something you can't use, say so: that page says how, and what to tell us so it can be reproduced and fixed. There is no committed deadline, because you don't commit to one you don't know you can meet, but there is an answer.

See the accessibility statement

24 · Complaints and disputes.

Who to complain to, in what order, and what route exists for each thing. Because it isn't the same for an invoice as for a piece of data.

The first route is always the direct one, and it is the fastest: write to [email protected] telling us what has happened. Receipt is acknowledged, it is looked at and it is answered, even when the answer is that we won't do what you are asking — in which case, explaining why. An unanswered complaint is a problem that grows.

If the complaint is about an installation, a quotation or an invoice, the party to deal with is the company that signed that document, and the document itself usually says how a complaint is handled and within what period. This is a website: it doesn't replace the contract.

If it is about your data.

For any data protection matter you can approach the data protection officer of the relevant company —ask for their contact details at [email protected]— before going anywhere else. That is their job: reviewing, mediating and correcting within the organisation.

And you can complain to the Agencia Española de Protección de Datos (aepd.es), which is the supervisory authority in Spain. It is a right under article 77 of the GDPR and you don't need to have complained to us first in order to exercise it. The complaint is submitted through their electronic office, it is free, and the Agencia can request information, open an investigation and impose penalties.

The Agencia also has a specific, urgent procedure for taking down content on the internet that seriously infringes rights, designed above all for the circulation of images without consent. It is mentioned here because it exists and almost nobody knows about it.

And in any case the judicial route remains open, in accordance with article 79 of the GDPR. Complaining to the Agencia does not close it, and going to court does not require going through the Agencia first.

If you are a consumer.

This site and the group's services are aimed at businesses, public authorities and professionals. But if you contract as a consumer —that is, for a purpose outside a business or professional activity— you have the protection of Real Decreto Legislativo 1/2007, and nothing in this document limits it. Clauses purporting to limit it would be void, and nothing here purports to.

In that case you can go to your local council's consumer services, to your regional government's consumer affairs department, or to the consumer arbitration system if both parties accept it.

Two things said because honesty requires it. First: this site publishes no adherence to any private out-of-court dispute resolution scheme or to any certified code of conduct. If one existed, it would be stated here with its link, because signing up and not saying so is no use to anyone. Second: the obligation to give information about a European online dispute resolution platform applies to sites that allow contracting online, and this one does not — no contract is concluded here, as section 4 explains.

25 · Applicable law and jurisdiction.

Which law applies and which courts you go to if you have to. Short, because there is no more to it.

These conditions are governed by Spanish law. For any dispute that may arise from access to or use of this site, the parties submit to the courts of the owner's domicile, unless the applicable legislation establishes another mandatory forum — in particular, where the user is a consumer, in which case the competent court will be the one determined by law.

That proviso is not decoration. As against a consumer, a clause requiring them to litigate in the company's city is unfair, which is why it is expressly stated here that it does not apply. A consumer domiciled in Spain can be sued in the courts of their own domicile, and can sue there or where the company is.

In data protection matters the GDPR also applies, being directly applicable throughout the European Union, together with Ley Orgánica 3/2018. The competent supervisory authority is the Agencia Española de Protección de Datos.

If any clause of this document were declared void or unenforceable, the rest will remain in force, and the affected clause will be replaced by a valid one pursuing the same purpose to the extent the law allows.

This document is drafted in Spanish. If a version exists in another language and there is a discrepancy between the two, the Spanish version prevails, unless the applicable law requires otherwise in the user's favour.

26 · Validity and versions.

How a change is notified and from when it applies. Put another way: how to know which version you accepted.

This text may be updated when the regulations change, when the site's services change or when the companies' details change. The date of the last update is at the beginning of the document, in the "How to read this" section, and it is the version marker: if the date is the same, the text is the same.

A minor change —correcting a typo, clarifying a sentence, reordering a paragraph— is published and the date is updated. A substantial change —a new purpose, a new recipient, switching on analytics cookies, a change of controller— is announced on the site itself before it is applied, and not retrospectively: the new version governs from the moment it is published, not backwards.

And there is one case where notice isn't enough. If the change affects processing that relies on your consent, it cannot be applied to your data simply by publishing it: your consent has to be asked for again. A privacy policy is not amended against someone who already said yes to something else.

The usual line —"we recommend you consult this page periodically, and if you continue using the site you accept the changes"— does not appear here. It isn't reasonable to ask anyone to keep an eye on a legal document just in case, and consent is not obtained by wearing people down. If something important changes, the site will say so where it can be seen.

If you need to know exactly what this document said on an earlier date, ask at [email protected] and you will be given the version published at the time. This matters when it has to be shown what information was given at the moment someone gave consent.

27 · What is still missing from this document.

An incomplete legal notice that hides the fact is worse than one that flags its gaps. These are the ones it has, and they have been asked for.

The CIF and registration details of West Point Solution, S.L. and Upon Solution, S.L. are missing. They appear as PENDING in section 1 and they are visible on purpose.

The hosting provider for this site and the country where its servers are have yet to be identified publicly. Two sections depend on that: the one on processors and the one on international transfers, which today says what is known and no more.

The named list of processors has yet to be published. Today it is given to anyone who asks, which is what the law requires as a minimum; publishing it is better and that is the intention.

The direct contact details of the data protection officers are missing. They exist —the group says so— and they are given to anyone who asks, but a published mailbox is easier to use than a prior request.

The specific retention periods of each company are missing. Section 13 gives the criterion for each case, which is what lets you judge whether a period is reasonable; the numbers will be written down when they are confirmed, and not before.

And a lawyer's review is missing. This document has been written with the rules in front of us and covers the sections they require, but whoever is answerable for a legal text is whoever signs it. Saying so here isn't a flourish: it is the most useful information a document like this can give about itself.

Get started

Any questions about this?

Write to [email protected] and we will answer. To exercise any of your rights over your data, it is the same address.