Last updated: 2026-05-24
Privacy Policy
Pursuant to Regulation (EU) 2016/679 of 27 April 2016 (GDPR) and Spanish Organic Law 3/2018 on Personal Data Protection (LOPDGDD), users are informed about the processing of their personal data.
1. Data controller
- Identity: [LEGAL NAME]
- VAT / Tax ID: [VAT ID]
- Postal address: [ADDRESS]
- Email: hola@approsearch.com
- Data Protection Officer: [DPO EMAIL] (if applicable)
2. Purposes of processing
- Commercial inquiries: respond to questions, demo requests and contact form submissions.
- APPROSEARCH service delivery: provide the contracted search service and manage the customer relationship.
- Marketing communications: only with explicit consent, send information about products, news, events and promotions.
- Legal obligations: invoicing, taxation, anti-money laundering (where applicable).
- Web analytics: measure website use to improve experience, always with consent.
3. Retention period
- Commercial inquiry data: 12 months from last contact unless contract begins.
- Customer data: throughout the contractual relationship plus legally required periods (6 years for tax/accounting under Spanish Commercial Code and Tax Law).
- Marketing data: until consent is withdrawn.
- Web analytics data: as specified in the Cookie Policy.
4. Legal basis for processing
- Consent (art. 6.1.a GDPR): for inquiries, marketing and web analytics.
- Contract performance (art. 6.1.b GDPR): for service delivery.
- Legal obligations (art. 6.1.c GDPR): for invoicing and tax compliance.
- Legitimate interest (art. 6.1.f GDPR): for website security, fraud prevention and technical maintenance.
5. Recipients and disclosures
Personal data may be disclosed to:
- Processors providing services to the controller (hosting, email, customer management, analytics), all bound by the corresponding agreement under art. 28 GDPR.
- Public Administrations when legally required (Tax Agency, Social Security, data protection authorities, courts).
- No commercial disclosures to third parties without explicit consent.
5.1 Public list of sub-processors
| Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| Resend, Inc. | Transactional email | USA | Data Privacy Framework + SCC 2021 |
| OpenAI, LLC | AI processing (semantic search, Whisper, CLIP) | USA | Data Privacy Framework + SCC 2021 |
| Easypanel | Application hosting | Brazil (migrating to EU) | SCC 2021 + additional technical measures |
| Google LLC (GA4) | Web analytics | USA / EU | Data Privacy Framework + IP anonymization |
| Cloudflare, Inc. | CDN, WAF, DDoS protection | Global network | SCC 2021 |
6. International transfers
Some sub-processors may process data outside the European Economic Area (EEA). In such cases, APPROSEARCH ensures that the transfer is made under one of the guarantees provided in Chapter V of the GDPR (adequacy decision, SCC 2021, BCR, or EU-US Data Privacy Framework adherence). Each transfer is preceded by a Transfer Impact Assessment following EDPB Recommendation 01/2020.
7. User rights
- Access
- Rectification
- Erasure ("right to be forgotten")
- Restriction of processing
- Objection
- Data portability
- Withdraw consent at any time
- Not to be subject to automated decision-making
To exercise these rights, write to hola@approsearch.com with subject "GDPR rights exercise", attaching a copy of an ID document. Complaints may be filed with the Spanish Data Protection Agency (AEPD): www.aepd.es.
8. Security measures
[LEGAL NAME] has adopted the technical and organizational measures necessary to ensure the security of personal data. More information at /en/security/.
9. Automated decision-making and profiling
APPROSEARCH does not make automated decisions that produce legal effects or significantly affect the user.
10. Policy changes
[LEGAL NAME] reserves the right to modify this Privacy Policy to adapt to legislative or jurisprudential changes. Material changes will be announced on the website with reasonable advance notice.