1. Introduction and Scope
Jebrex Tech, S.L. ("JEBREX", "we", "us" or "our") is a technology company based in Barcelona, Spain, that designs and operates software-as-a-service products, including BizzOS, MedLocal, TMS, FMS, SPE, 3alTari2 and PUSH. We are committed to protecting personal data and to processing it lawfully, fairly and transparently.
This Privacy Policy explains what personal data we collect through our website and our products, why we collect it, the legal grounds on which we rely, who we share it with, how long we keep it, and the rights available to you. It applies to visitors to our website, individuals who contact us through our forms or by email, and users of our products, except where a separate product-specific or customer-specific notice applies.
Where JEBREX processes personal data on behalf of a business customer that uses one of our products (for example, data that customer uploads into its own workspace), that customer acts as the data controller and we act as a processor under its instructions. In those cases, the customer's own privacy notice governs the processing, and this Policy describes our role and safeguards.
2. Data Controller and Contact Details
For the processing described in this Policy, the data controller is Jebrex Tech, S.L., established in Barcelona, Spain.
You may contact us in relation to this Policy or to any matter concerning your personal data using the details below. We ask that you make clear in your message that your enquiry relates to data protection so that we can route it appropriately and respond within the applicable time limits.
- Email: hello@jebrex.com
- Postal address: Jebrex Tech, S.L., Barcelona, Spain
3. Personal Data We Collect
We collect only the personal data we need for the purposes described in this Policy. The categories of data we process depend on how you interact with us.
We do not intentionally collect special categories of personal data (such as data revealing health, political opinions or religious beliefs) through our website or contact channels, and we ask that you do not include such information in messages you send us unless it is strictly necessary and we have expressly requested it.
- Contact and enquiry data: the name, email address, telephone number, company name and message content you provide when you complete a contact or demo request form, subscribe to updates, or write to us directly.
- Account and product data: identifiers, credentials, role and configuration settings created when an account is provisioned for you in one of our products, together with records of your activity within that product.
- Usage and analytics data: pages viewed, referring pages, approximate location derived from IP address, device and browser type, operating system, language settings, and the dates and times of your visits.
- Technical and log data: IP address, session identifiers, diagnostic logs and error reports generated automatically when you use our website or services.
- Commercial and correspondence data: records of our communications with you, contractual and billing information where you are a customer or supplier contact, and notes relating to support requests.
4. How We Use Your Personal Data
We use personal data to respond to enquiries, to deliver and support our products, to keep our systems secure and reliable, and to improve what we build. We do not sell personal data, and we do not use it to make decisions producing legal or similarly significant effects about you by automated means alone.
Specifically, we use personal data to:
- Respond to contact form submissions, demo requests and other enquiries, and to follow up on them.
- Create, administer and support user accounts, and provide the functionality of BizzOS, MedLocal, TMS, FMS, SPE, 3alTari2 and PUSH.
- Manage our contractual relationships, including onboarding, invoicing and account management.
- Monitor, secure and troubleshoot our infrastructure, detect and prevent fraud, abuse and unauthorised access, and maintain business continuity.
- Analyse aggregated usage patterns in order to measure performance, diagnose problems and improve the design and reliability of our website and products.
- Send service communications, and, where you have asked to receive them or where otherwise permitted by law, product updates and commercial communications from which you may opt out at any time.
- Comply with legal, accounting, tax and regulatory obligations, and establish, exercise or defend legal claims.
5. Legal Bases for Processing
Under Article 6 of the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR"), we must have a valid legal basis for each processing activity. The basis we rely on depends on the purpose.
Where we rely on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal, and it does not affect processing based on another legal basis.
- Performance of a contract, or steps taken at your request before entering into a contract (Article 6(1)(b)): providing accounts and product functionality, delivering support, and managing billing and the commercial relationship.
- Legitimate interests (Article 6(1)(f)): responding to business enquiries, securing our systems and preventing abuse, maintaining service quality, understanding aggregate usage of our products, and communicating with existing customers about comparable services. We balance these interests against your rights and freedoms, and you may object as described below.
- Consent (Article 6(1)(a)): non-essential cookies and similar technologies, analytics that are not strictly necessary, and marketing communications to individuals who are not existing customers.
- Compliance with a legal obligation (Article 6(1)(c)): accounting, tax and commercial record-keeping duties, and responses to lawful requests from competent authorities.
6. Cookies and Similar Technologies
Our website uses cookies and comparable technologies such as local storage and pixels. Strictly necessary cookies support core functions including session management, load balancing, security and the recording of your cookie preferences; these are placed on the basis of our legitimate interest in operating the site and do not require consent.
Analytics, performance and any advertising cookies are placed only where you have given consent. You may change or withdraw your choices at any time, and most browsers also allow you to block or delete cookies, although doing so may affect how parts of the site work.
Where analytics providers set cookies on our behalf, they act as our processors and are contractually restricted to processing data on our documented instructions. Where a provider determines its own purposes for the data it collects, it acts as an independent controller, as explained in our Cookie Policy. Further detail on the categories of cookies used, their purposes and their typical duration is set out in our Cookie Policy.
7. Sharing and Disclosure
We do not sell or rent personal data. We share it only where it is necessary for the purposes set out in this Policy, and always subject to appropriate contractual and technical safeguards.
We may disclose personal data to the following categories of recipients:
- Hosting and infrastructure providers that operate the servers, databases, storage and content delivery networks supporting our website and products.
- Analytics providers that help us measure and improve website and product performance.
- Communication, customer relationship management and support tools used to receive, route and answer enquiries.
- Payment, accounting and professional service providers, including auditors and legal advisers, where required for the administration of our business.
- Competent public authorities, courts or regulators where disclosure is required by law or necessary to establish, exercise or defend legal claims.
- A successor entity in connection with a merger, acquisition or reorganisation, in which case we will take steps to ensure the continued protection of personal data and will inform you where required.
8. Processors and Contractual Safeguards
Service providers that process personal data on our behalf act as processors within the meaning of Article 28 of the GDPR. Before engaging a processor, we assess its technical and organisational measures, and we enter into a written data processing agreement.
These agreements require the processor to act only on our documented instructions, to impose confidentiality obligations on its personnel, to implement appropriate security measures, to assist us with data subject requests and security incidents, to obtain our authorisation before engaging sub-processors, and to delete or return personal data at the end of the engagement.
9. International Data Transfers
We seek to keep personal data within the European Economic Area (EEA) wherever practicable. Some of our service providers, however, may process data outside the EEA.
Where personal data is transferred outside the EEA, we ensure that an appropriate transfer mechanism under Chapter V of the GDPR is in place. This may be an adequacy decision of the European Commission covering the destination country, or the Standard Contractual Clauses adopted by the European Commission, supplemented where necessary by additional technical, contractual and organisational measures identified through a transfer impact assessment.
You may request further information about the transfers relevant to you, and a copy of the relevant safeguards, by contacting us at hello@jebrex.com.
10. Data Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, tax or reporting requirements, and to establish, exercise or defend legal claims. When data is no longer needed, we delete it or irreversibly anonymise it.
The following periods indicate our general approach. Specific retention periods may vary where a longer period is required by law or where data is subject to an ongoing dispute or investigation.
- Contact form submissions and general enquiries: normally up to 24 months from the last meaningful interaction, unless the enquiry leads to a contractual relationship.
- Customer account and product data: for the duration of the contract and, thereafter, for the period agreed with the customer, after which data is deleted or returned in accordance with the applicable agreement.
- Contractual, billing and accounting records: for the periods required by Spanish commercial and tax legislation, generally up to six years.
- Technical and security logs: typically between 30 days and 12 months, depending on the system and the security purpose.
- Analytics data: retained in aggregated or pseudonymised form, generally for no more than 26 months.
- Marketing preferences and opt-out records: for as long as necessary to honour your choices.
11. Security
We implement technical and organisational measures appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as required by Article 32 of the GDPR.
These measures include encryption of data in transit and, where appropriate, at rest; role-based access controls and the principle of least privilege; authentication controls for administrative access; network segmentation and monitoring; regular patching of systems; logging and alerting; backup and recovery procedures; secure development practices and code review; and confidentiality obligations and training for personnel with access to personal data.
No system can be guaranteed to be entirely secure. In the event of a personal data breach likely to result in a risk to individuals' rights and freedoms, we will notify the competent supervisory authority within 72 hours where required, and will inform affected individuals without undue delay where the breach is likely to result in a high risk to them.
12. Your Rights
Subject to the conditions and exceptions in the GDPR and in Spanish data protection law, you have the following rights in relation to your personal data:
- Access: to obtain confirmation of whether we process your personal data and, if so, a copy of that data together with information about the processing.
- Rectification: to have inaccurate personal data corrected and incomplete data completed.
- Erasure: to request deletion of your personal data where one of the grounds in Article 17 of the GDPR applies.
- Restriction: to request that we limit our processing in the circumstances described in Article 18 of the GDPR.
- Portability: to receive the personal data you provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible, when processing is based on consent or contract and carried out by automated means.
- Objection: to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests, and to object at any time and without justification to processing for direct marketing purposes.
- Withdrawal of consent: to withdraw consent at any time where processing is based on consent.
13. Exercising Your Rights and Lodging a Complaint
To exercise any of the rights above, write to us at hello@jebrex.com or use the contact details in section 2, indicating the right you wish to exercise. We may ask for information reasonably necessary to verify your identity before acting on a request. We will respond within one month of receipt, extendable by up to two further months where the request is complex or where we have received a number of requests, in which case we will inform you of the extension and the reasons for it.
Exercising these rights is free of charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act, explaining our reasons.
If you consider that our processing of your personal data infringes data protection law, you have the right to lodge a complaint with the Spanish supervisory authority, the Agencia Espanola de Proteccion de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, Spain (www.aepd.es), or with the supervisory authority of your habitual residence or place of work. We would appreciate the opportunity to address your concerns directly before you approach the authority.
14. Children's Data and Changes to This Policy
Our website and products are intended for businesses and professional users. They are not directed at children, and we do not knowingly collect personal data from anyone under the age of 14, which is the age of consent for information society services under Spanish law. If we become aware that we have collected personal data from a child without the appropriate consent, we will delete it without undue delay. If you believe a child has provided us with personal data, please contact us at hello@jebrex.com.
We may update this Policy from time to time to reflect changes in our services, our processing activities, or applicable law. The current version is always published on our website, and the date at the top indicates when it was last revised.
Where a change materially affects how we process your personal data, we will provide notice by appropriate means, such as a notice on our website or a message to registered users, before the change takes effect. Where a change requires your consent, we will obtain it.