Privacy Policy
Granxal Technologies S.L.
Last updated: August 4, 2025
Version: 3.0 - GDPR Compliant
🔒 This policy explains how we collect, use and protect your personal information in strict compliance with GDPR, LOPD and applicable data protection regulations.
📋 Table of Contents
1. General Information
Granxal Technologies S.L. ("we", "our", "the Company") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store and protect your personal information when you use our services.
This policy applies to all users of our services, regardless of how you access or use our platforms.
📖 Transparency: We believe in full transparency about how we handle your data. If you have any questions about this policy, please do not hesitate to contact us.
2. Data Controller
Controller Information
Company Name: Granxal Technologies S.L.
Tax ID: B-XXXXXXXX
Registered Address: Galicia, Spain
Email: info@granxal.com
Commercial Registry: A Coruña, Volume XXX, Folio XXX, Sheet XXXX
2.1 Data Protection Officer (DPO)
We have appointed a certified Data Protection Officer to oversee compliance with data protection regulations:
📧 DPO Contact: dpo@granxal.com
📍 Postal Address: For the attention of the DPO, Granxal Technologies S.L., Galicia, Spain
3. Data We Collect
3.1 Registration and Account Data
| Data Type | Specific Information | Required |
|---|---|---|
| Identification | Full name | Yes |
| Contact | Email address | Yes |
| Contact | Phone number | No |
| Professional | Company/farm name | Yes |
| Billing | Billing address, tax details | Yes* |
| Payment | Card information (tokenised) | Yes* |
| Geographic | Country and province/region of the farm | No |
| Consents | Record of consents given (marketing, cookies) with date and means | Yes* |
* Required for paid plans
** Country/region is used for geographic analysis of client origin and content personalisation.
3.2 Livestock Farm Data
- Animal Information: Identification, breed, weight, age, genealogy, location
- Veterinary Records: Treatments, vaccines, medications, withdrawal periods
- Reproductive Data: Inseminations, pregnancies, births, genealogy
- Machinery Information: Inventory, maintenance, operating costs
- Financial Data: Income, expenses, profitability analysis
- Land Information: Plots, surface areas, crops
3.3 Technical and Usage Data
| Category | Specific Data | Purpose |
|---|---|---|
| Connection | IP address, approximate location | Security and geolocation |
| Device | Browser, operating system, device | Compatibility and support |
| Activity | Access logs, pages visited, actions | Security and improvements |
| Performance | Load times, errors, usage metrics | Service optimisation |
🔒 Important: All data is encrypted with AES-256 both in transit and at rest. We never store passwords in plain text.
4. Legal Basis for Processing
We process your personal data under the following GDPR legal bases:
4.1 Contract Performance (Art. 6.1.b GDPR)
- Providing contracted services
- Managing your user account
- Processing payments and billing
- Providing technical support
4.2 Legitimate Interest (Art. 6.1.f GDPR)
- Improving our services and developing new features
- Ensuring security and preventing fraud
- Conducting internal usage and performance analysis
- Service-related communications
4.3 Consent (Art. 6.1.a GDPR)
- Marketing communications (newsletters, promotions)
- Analytical and personalisation cookies
- Sharing data with third parties for additional features
4.4 Legal Obligation (Art. 6.1.c GDPR)
- Compliance with tax and accounting obligations
- Cooperation with competent authorities
- Compliance with livestock sector regulations
⚖️ Your Rights: You may withdraw your consent at any time when processing is based on this legal basis, without affecting the lawfulness of prior processing.
5. Purposes of Processing
5.1 Primary Purposes
- Service Provision: Providing access to the platform and all its features
- Account Management: Creating, maintaining and administering your user account
- Billing and Payments: Processing payments, generating invoices and managing subscriptions
- Technical Support: Resolving incidents and providing technical assistance
- Legal Compliance: Complying with legal and regulatory obligations
5.2 Secondary Purposes
- Service Improvement: Analysing usage to improve features
- Security: Detecting, preventing and responding to fraudulent activities
- Communications: Sending important notifications about the service
- Research and Development: Developing new features and services
5.3 Marketing and Commercial Communications (Only with Explicit Consent)
Commercial communications are sent only when the user has given explicit and unambiguous consent (Art. 6.1.a GDPR), through an independent checkbox in the registration form. This consent is:
- Voluntary: Denial does not affect access to the service
- Specific: Granted for Granxal communications, not shared with third parties
- Informed: With express indication of the purpose and legal basis
- Revocable: At any time without consequences for the service
Communications sent under this consent include:
- Newsletters with livestock sector news
- Information about new features and services
- Invitations to webinars and training events
- Special offers and promotions
- Content segmented by country/region and farm type
Important distinction: Transactional communications (invoices, security alerts, notifications of changes to the terms) are sent under the legal basis of contract performance (Art. 6.1.b) and legitimate interest (Art. 6.1.f), regardless of marketing consent.
📋 Consent register: We maintain a detailed record of all consents given, including date, means, text shown to the user and version of the policy in force at the time of collection, in compliance with Art. 7.1 GDPR.
6. Data Sharing
Your data may be shared only in the following circumstances:
6.1 Service Providers (Data Processors)
| Category | Purpose | Location | Guarantees |
|---|---|---|---|
| Cloud Hosting | Storage and processing | EU (Germany) | DPA contract, ISO 27001 |
| Payment Processing | Transaction management | EU (Ireland) | PCI DSS, Stripe/PayPal |
| Email Marketing | Communications (with consent) | EU (Netherlands) | DPA contract, GDPR |
| Technical Support | Customer service | Spain | Internal DPA contract |
6.2 Competent Authorities
We may share data when required by law with:
- Tax Authority (tax obligations)
- Judicial authorities (court orders)
- Official livestock bodies (SITRAN, regional authorities)
- Data protection authorities (investigations)
6.3 Official Integrations
- SITRAN: Livestock traceability data exchange as required by regulation
- Regional Bodies: Reporting of aggregated statistical data
- Official Veterinarians: Health information when required
🤝 Guarantees: All our providers sign data processing agreements (DPA) and must comply with the same protection standards we apply internally.
7. Data Security
We implement appropriate technical and organisational measures to protect your data:
7.1 Technical Measures
- Encryption: AES-256 at rest, TLS 1.3 in transit
- Authentication: Strong passwords, optional 2FA
- Access Control: Principle of least privilege
- Monitoring: 24/7 intrusion detection
- Backups: Encrypted backups every 15 minutes
- Segregation: Data separated by client
7.2 Organisational Measures
- Training: Staff trained in data protection
- Policies: Internal security policies
- Audits: Quarterly security audits
- Incident Management: Response procedures
- Confidentiality: Confidentiality agreements
7.3 Certifications and Compliance
ISO 27001
Information Security Management
RGPD
General Data Protection Regulation
ENS
National Security Scheme
7.4 Breach Notification
In the event of a security breach affecting your data:
- We will notify the supervisory authority within 72 hours
- We will inform you directly if there is a high risk to your rights
- We will take immediate steps to mitigate the impact
- We will investigate the cause and implement improvements
8. Your Rights as Data Subject
Under GDPR, you have the following rights:
8.1 Right of Access (Art. 15 GDPR)
You may request information about what personal data we hold about you and how we process it.
How to exercise it: Request it from your user panel or by sending an email to dpo@granxal.com
Response period: 30 calendar days
8.2 Right of Rectification (Art. 16 GDPR)
You may correct inaccurate or incomplete data.
How to exercise it: Directly from your account or by contacting us
Response period: Immediate (simple changes) or 30 days
8.3 Right to Erasure (Art. 17 GDPR)
You may request the deletion of your personal data in certain circumstances.
Limitations: Not applicable if we need the data due to a legal obligation or for the fulfilment of the contract
Response period: 30 calendar days
8.4 Right to Restriction (Art. 18 GDPR)
You may request that we restrict the processing of your data in specific cases.
When applicable: When you contest the accuracy of the data, the processing is unlawful, or we no longer need the data
8.5 Right to Data Portability (Art. 20 GDPR)
You may receive your data in a structured format and transfer it to another provider.
Available format: JSON, CSV, XML
Includes: Account data, settings, farm data
8.6 Right to Object (Art. 21 GDPR)
You may object to the processing of your data based on legitimate interest or for direct marketing.
Marketing: Absolute objection – we will cease immediately
Legitimate interest: We will assess whether we have compelling legitimate grounds
8.7 Right to Withdraw Consent
You may withdraw consent at any time when processing is based on this legal basis.
Effect: Does not affect the lawfulness of processing prior to withdrawing consent
8.8 How to Exercise Your Rights
Available Methods:
- 📧 Email: dpo@granxal.com
- 🖥️ User Panel: Section "Privacy and Data"
- 📮 Postal Mail: For the attention of the DPO, Granxal Technologies S.L., Galicia, Spain
Information required to exercise rights:
- Full name and email associated with the account
- Copy of identity document (to verify identity)
- Specific description of the right you wish to exercise
- Additional documentation if acting on behalf of a third party
⚖️ Right to Lodge a Complaint: If you consider that we have not adequately addressed your rights, you may lodge a complaint with the Spanish Data Protection Agency (AEPD) - www.aepd.es
9. Data Retention
We retain your data for the following periods:
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Active account data | While account is active | Contract performance |
| Financial/tax data | 7 years after cancellation | Legal obligation (Commercial Code) |
| Farm data | 7 years after cancellation | Livestock regulations |
| Technical logs | 2 years | Legitimate interest (security) |
| Marketing data | Until consent is withdrawn | Consent |
| Backups | 7 years (encrypted) | Legitimate interest |
9.1 Secure Deletion
At the end of retention periods:
- Data is deleted securely and irreversibly
- Cryptographic erasure is used for encrypted data
- Backups are overwritten multiple times
- A destruction certificate is generated when required
10. International Transfers
🇪🇺 Data in the EU: All our data is processed and stored exclusively on servers located in the European Union. We do not carry out international transfers of data outside the European Economic Area (EEA).
10.1 Server Locations
- Main Server: Frankfurt, Germany (AWS EU-Central-1)
- Secondary Backup: Dublin, Ireland (AWS EU-West-1)
- CDN: Multiple EU locations (Cloudflare EU)
10.2 Future Exceptions
If we were to transfer data outside the EU in the future, we would implement the following safeguards:
- European Commission adequacy decisions
- EU-approved standard contractual clauses
- Binding corporate rules (BCR)
- Recognised certifications (Privacy Shield successors)
In any case, we would notify you at least 30 days in advance of any change in the location of data processing.
12. Minors
Our services are directed at livestock sector professionals and businesses. We do not knowingly collect personal data from individuals under 16 years of age.
12.1 Policy on Minors
- Parental consent required for users aged 13–15
- Registration prohibited for those under 13
- Immediate deletion if we detect minors' data without consent
- Additional verification for suspicious accounts
12.2 If We Detect Minors' Data
If we discover we have collected data from a minor without parental consent:
- We will immediately suspend the account
- We will contact the parents/guardians
- We will delete all the minor's data
- We will strengthen our verification processes
13. Changes to this Policy
13.1 Update Process
We may update this policy occasionally. For significant changes:
- Advance notice: Minimum 30 days
- Personal email: To all registered users
- Platform notice: Visible banner in the application
- Versioning: We maintain a version history
13.2 Types of Changes
| Type of Change | Notification | Action Required |
|---|---|---|
| Minor corrections | Website update | None |
| New data uses | Email + 30 days | Explicit consent |
| Changes to rights | Email + 30 days | Opportunity to cancel |
| New third parties | Email + 15 days | Possibility to object |
13.3 Your Response to Changes
In response to significant changes, you may:
- Continue using the service (tacit acceptance)
- Modify your privacy settings
- Exercise your right to object or restrict
- Cancel your account if you disagree
14. Contact Information
🏢 Granxal Technologies S.L.
14.1 Office Hours
- DPO Queries: Mon–Fri 9:00–18:00 CET
- General Support: 24/7 (email), Mon–Fri 8:00–20:00 (phone)
- Security Emergencies: 24/7
14.2 Available Languages
We can handle enquiries in:
- Spanish: Full (primary language)
- Galician: Full
- English: Technical and legal queries
- Other languages: Enquire about availability
14.3 Supervisory Authorities
📋 Lead Authority: Spanish Data Protection Agency (AEPD)
🌐 Web: www.aepd.es
📧 Email: ciudadano@aepd.es
📞 Phone: +34 901 100 099 / +34 912 663 517
This policy was updated on August 4, 2025
Granxal Technologies S.L. - Committed to your privacy