Privacy policy
Version
28 April 2026
Introduction
GLAM SOFTWARE 2012, S.L. is committed to protecting the privacy of users who access this website and/or any of its services. Use of the website and/or of any of the services offered by GLAM SOFTWARE 2012, S.L. implies the user's acceptance of the provisions contained in this Privacy Policy and that their personal data will be processed as set out in it.
Please note that although there may be links from our website to other websites, this Privacy Policy does not apply to the websites of other companies or organisations to which the website redirects. GLAM SOFTWARE 2012, S.L. does not control the content of third-party websites and accepts no responsibility for the content or the privacy policies of those websites.
Information on data processing (Regulation (EU) 2016/679 and Organic Law 3/2018)
- Data controller: GLAM SOFTWARE 2012, S.L. Tax ID (NIF): B55144273. C. Pic de Peguera, 11 (Ed. Giroempren Ala B, 2.12), 17003 Girona, Spain. Email: admin@glamsw.com.
- Purpose of processing: to offer and manage our management software development services.
- Legal basis: consent obtained from the data subject when they request information from us. Performance of the services contract when they contract with us.
- Recipients: data will not be disclosed to third parties, unless required by law or necessary to fulfil the purpose of the processing.
- Rights of individuals: data subjects have the right to exercise their rights of access, rectification, restriction of processing, erasure, portability and objection, by sending their request to our address.
- Data retention period: for as long as the commercial relationship is maintained or for the years necessary to comply with legal obligations.
- Complaints: data subjects may contact the Spanish Data Protection Agency (AEPD) to lodge any complaint they consider appropriate.
- Additional information: you can consult the additional and detailed information below under «Privacy questions».
Privacy questions
In compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and Organic Law 3/2018 of 5 December on the Protection of Personal Data and guarantee of digital rights (LOPDGDD), we provide you with the following information on the processing of your personal data:
Who is the controller of your data?
- Identity: GLAM SOFTWARE 2012, S.L.
- Tax ID (NIF): B55144273
- Address: C. Pic de Peguera, 11 (Ed. Giroempren Ala B, 2.12), 17003 Girona, Spain
- Tel.: 972183310
- Email: admin@glamsw.com
For what purpose do we process your personal data?
We process the information provided to us in order to manage our management software development services.
If you contact us through the contact form on our website, we will process your data in order to handle your enquiry.
We may also use your data to inform you about our activities, products or services when you are already a client of ours or, if you are not, when you have given us your consent to do so.
If you send us a CV, we will process the data for the purpose of managing our CV database for recruitment.
How long will we keep your data?
The personal data provided will be kept for as long as you are a user of our services or wish to receive information, given that you may object to the processing of your data for promotional purposes, either when you provide it to us or at any time thereafter, by notifying us at admin@glamsw.com, and thereafter for the periods established to comply with our legal obligations, which in the case of accounting and tax documentation for commercial purposes will be 6 years, in accordance with Art. 30 of the Spanish Commercial Code, and for tax purposes will be 4 years, in accordance with Articles 66 to 70 of the Spanish General Tax Act.
In the case of CVs, the data will be kept for one year.
What is the legal basis for processing your data?
For the management of the contractual relationship with the data subject, we base the processing of the data on the performance of the contract or on the pre-contractual relationship.
For sending commercial information we base the processing on your consent, although if you are already a client of ours we may send you information about our products and services, always providing a simple and free means of unsubscribing, in accordance with Article 21.2 of Law 34/2002 of 11 July on information society services and electronic commerce.
To which recipients will your data be disclosed?
Data will not be disclosed to third parties, unless required by law or necessary to fulfil the purpose of the processing.
What are your rights when you provide us with your data?
Any person has the right to obtain confirmation as to whether or not we are processing their personal data.
Data subjects have the right to access their personal data, as well as to request the rectification of inaccurate data or, where applicable, to request its erasure when, among other reasons, the data is no longer necessary for the purposes for which it was collected.
In certain circumstances data subjects may request the restriction of the processing of their data, in which case we will keep it only for the exercise or defence of claims.
Also, in certain circumstances and for reasons relating to their particular situation, data subjects may object to the processing of their data. In this case we will stop processing it, except on compelling legitimate grounds or for the exercise or defence of possible claims.
Data subjects also have the right to the portability of their data.
Any data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
Finally, data subjects have the right to lodge a complaint with the competent Supervisory Authority.
How can you exercise your rights?
By sending us a written request, attaching a copy of a document that identifies you, to our postal or email address.
How did we obtain your data?
The personal data we process comes from the data subject themselves, who guarantees that the personal data provided is accurate and is responsible for notifying us of any change to it. Data marked with an asterisk is mandatory in order for us to provide the requested service.
What data do we process?
The categories of data we may process are:
- Identifying data
- Postal or email addresses
In the case of CVs, also:
- Personal characteristics
- Academic and professional data
The data is limited, since we only process the data necessary for the provision of our services and the management of our activity.
Do we carry out international data transfers?
In providing our services we make use of the auxiliary data hosting services of Microsoft or Google, which could hold data located in the United States. The international transfer of data is based on the Standard Contractual Clauses for processors approved by the European Commission, and on the Commission Implementing Decision of 10.7.2023 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, on the adequate level of protection of personal data under the EU-US Data Privacy Framework.
Do we use cookies?
We use cookies while you browse our website, with the user's consent.
Users can configure their browser to notify them of the use of cookies and to prevent their use. Please see our cookie policy.
What security measures do we apply?
We apply the security measures established in Article 32 of the GDPR, and have therefore adopted the security measures necessary to ensure a level of security appropriate to the risk of the data processing we carry out, with mechanisms that allow us to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
Some of these measures are:
- Informing staff of data processing policies.
- Making periodic backups.
- Access control to data.
- Regular verification, evaluation and assessment processes.
How do we process data on behalf of third parties?
When, in providing our services, we process personal data for which our clients are the controllers, we do so as a processor, in accordance with Article 28 of the GDPR and therefore, in these processing operations:
- We will process the personal data solely on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless we are required to do so by Union or Member State law to which we are subject. In this case, we will inform the controller of that legal requirement before processing, unless that law prohibits it on important grounds of public interest.
- We guarantee that the persons authorised to process personal data have committed to respecting its confidentiality.
We have adopted all the necessary security measures, in accordance with Article 32 of the GDPR, implementing mechanisms to:
- Ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
- Restore the availability of and access to personal data promptly in the event of a physical or technical incident.
- Regularly verify, evaluate and assess the effectiveness of the technical and organisational measures implemented to ensure the security of the processing.
- Pseudonymise and encrypt personal data, where applicable.
In addition, in these processing operations:
- We will respect the conditions set out in paragraphs 2 and 4 of Article 28 of the GDPR for engaging another processor.
- We will assist the controller, wherever possible, in accordance with the nature of the processing and by means of appropriate technical and organisational measures, so that it can comply with its obligation to respond to requests for the exercise of the rights of data subjects established in Chapter III of the GDPR.
- We will help the controller ensure compliance with the data security obligations established in Articles 32 to 36 of the GDPR, taking into account the nature of the processing and the information available to us.
- At the controller's choice, we will delete or return all personal data once the provision of processing services has ended, and we will delete existing copies unless the retention of the personal data is required by Union or Member State law.
- We will make available to the controller all the information necessary to demonstrate compliance with the obligations established in Art. 28 of the GDPR, as well as to allow for and contribute to audits, including inspections, by the controller or another auditor mandated by that controller.
As a processor, the types of data, the categories of data subjects and the processing operations we may carry out on behalf of our clients will be the following.
Types of personal data we may process:
- Identifying data
- Personal characteristics data
- Academic and professional data
- Employment details
- Economic, financial and insurance data
- Commercial information
- Transactions of goods and services
Categories of data subjects affected:
- Clients
- Prospective clients
- Suppliers
- Staff
- Candidates
- Users
Processing operations we may carry out:
- Organisation
- Structuring
- Storage
- Retrieval
- Consultation
- Display