Data protection
Privacy policy
How we collect, use, protect and retain personal data related to this website.
Updated on 27/07/20261. Who is the data controller?
This policy applies to personal data processed through aife.cat, the contact form and direct communications relating to enquiries, proposals or services.
2. What data may we process?
Depending on the relationship and the information you choose to provide, we may process:
- Identification and contact data: name, surname, email address, telephone number, role and company.
- Enquiry information: needs, processes, current systems, indicative project scope and message content.
- Professional or contractual data: contacts, quotations, assignments, billing and service follow-up.
- Technical and security data: IP address, date, time, requested resource and basic device information recorded by servers to operate, protect and diagnose the site.
- Analytics data, only with consent: pages viewed, interaction events, approximate source, country or city, device type, browser and approximate session duration through Google Analytics 4.
Data is obtained mainly from the data subject. We do not request special categories of personal data. Please do not include sensitive information or unnecessary third-party data.
3. Why do we use data and on what legal basis?
| Purpose | Typical data | Legal basis |
|---|---|---|
| Answer enquiries, assess needs and prepare a proposal. | Identity, contact details, company and message. | Pre-contractual steps requested by the data subject and, for general professional contacts, legitimate interest in responding to business-related communications. |
| Manage relationships with customers, suppliers or partners. | Professional contacts, contracts, project and billing data. | Performance of a contract and compliance with legal, tax, accounting or commercial obligations. |
| Measure website use in aggregate and improve content, navigation and performance with Google Analytics 4. | Browsing, device, source and approximate location data. | Consent, withdrawable at any time through “Cookie settings”. |
| Maintain security, prevent abuse and resolve technical incidents. | Minimum technical data, server logs and incident evidence. | AIFE®’s legitimate interest in protecting its systems, forms and services. |
| Establish, exercise or defend legal claims. | Information needed about the relationship or incident. | Legitimate interest and compliance with legal obligations. |
Fields marked with an asterisk are required to answer your enquiry. We do not make automated decisions or create profiles producing legal or similarly significant effects.
4. How long do we retain data?
- Enquiries with no later relationship: for the time needed to answer and reasonably follow up, generally up to twelve months after the last relevant communication.
- Proposals and contractual relationships: while the relationship remains in force and afterwards, blocked for applicable statutory limitation periods.
- Technical security data: for limited periods proportionate to incident detection, abuse prevention and service continuity.
- Analytics: according to the retention settings in Google Analytics and until consent is withdrawn; analytics cookies may last up to two years.
When no longer required, data will be deleted or anonymised. Data retained to comply with legal duties or address liabilities will remain blocked and access-restricted.
5. Who may receive the data?
We do not sell or disclose personal data for advertising purposes. Access may be granted to hosting, email, maintenance, security, accounting or professional service providers acting under contract and only as necessary.
Google Analytics is provided by Google. Its use may involve processing by entities located outside the European Economic Area. Where applicable, transfers are based on an adequacy decision, standard contractual clauses or another valid GDPR mechanism.
Data may also be disclosed to public authorities, courts or regulators where required by law.
6. What are your rights?
You may request access, rectification, erasure, restriction, portability and objection, and withdraw consent at any time without affecting prior lawful processing.
Send your request to info@aife.cat, identifying the right exercised and providing enough information to verify your identity. You may also lodge a complaint with the Spanish Data Protection Agency or the competent supervisory authority.
7. Security and confidentiality
AIFE® applies technical and organisational measures proportionate to the risks, including access controls, updates, backups where applicable, transport encryption and incident management. No Internet service can guarantee absolute security.
People with access to personal data are subject to confidentiality and need-to-know restrictions.
8. Minors, third-party data and updates
This website and AIFE®’s professional services are not directed at children. Minors should not submit personal data without the involvement of a parent or legal guardian.
If you provide third-party data, you must have a lawful basis to do so and provide the relevant information to that person.
This policy may be updated following legal, technical or service changes. The current version and update date will always be published on this page.
9. Supervised digital contracting and evidence
When the project request and private file workflow is used, AIFE® processes the data required to review the request, seek further information, prepare and version quotations, record acceptance, generate the contract and annexes, obtain signatures and activate the project.
The record may include company and contact data, messages, attachments, document versions and status, the accepting or signing person’s name and role, verified email, express statement, UTC date and time, OTP evidence, SHA-256 fingerprints, encrypted IP address, browser information and the audit chain. One-time codes are stored as hashes, expire and have an attempt limit.
The legal bases are steps requested before entering into a contract, formation and performance of the contract, compliance with legal obligations and AIFE®’s legitimate interest in security, document integrity and the establishment, exercise or defence of legal claims. Decisions to accept a request, issue a quotation or approve a contract are supervised by AIFE® and are not made automatically with legal effects.
As a general criterion, requests that do not proceed are retained for up to twelve months after the last activity. Contract documents, acceptances and evidence are retained during the relationship and afterwards for applicable commercial, tax, accounting and limitation periods; the initial configuration provides for six years, without prejudice to a longer period where an obligation or open claim requires it.