Legal

Privacy policy

This policy describes how Tarraco App Lab processes the personal data of the users of this website, in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and with Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).

2. What data we process

  • Contact data: the data you provide when filling in forms or writing to us (name, email address, phone number and the content of your message).
  • Account data (if the service allows registration, such as the "Work with us" area): email address and the files you provide (for example, your CV); access is granted through a one-time link sent to your email.
  • Technical data: IP address, session identifiers and logs necessary for security and operation.

3. Purposes and legal basis

  • Handling your request and providing the contracted service — performance of a contract or pre-contractual measures.
  • Security and abuse prevention — legitimate interest.
  • Analytics and commercial communicationsconsent (which you can withdraw at any time).
  • Applicable legal obligationslegal obligation.

4. Specific processing on this site

Contact form

Data submitted through the form is processed in serverless functions hosted on Netlify and routed to the owner’s support mailboxes. Users declare that the data they provide is their own or that they have sufficient legal grounds to provide it.

«Work with us» applications area

Access to the private applications area is granted through a single-use link sent to the candidate’s email address, without a password. The CV and any supporting documents are stored in Supabase under Row-Level Security policies, so each candidate can only access their own file. Candidates may request deletion of their application at any time.

Client projects

Where Tarraco App Lab develops or maintains a site, application or integration on behalf of a client and personal data of third parties is processed in that work, the client acts as data controller and Tarraco App Lab as processor, under the terms of the Data Processing Agreement (DPA).

Nature of the service

The information published on this site is indicative and does not constitute professional advice. Where artificial intelligence tools are used in the development of a project, their output is reviewed before delivery, but the client must verify it before making decisions based on it.

5. Recipients and data processors

To deliver the service we rely on the following providers (data processors), with whom the guarantees required by the GDPR are in place:

  • Netlify, Inc. (USA): website hosting and management of the contact form.
  • Supabase, Inc. (USA): database, file storage (CV) and authentication for the "Work with us" area.

6. International transfers

Some providers are located outside the European Economic Area (mainly the USA). These transfers are covered by the Standard Contractual Clauses (SCCs) approved by the European Commission and by supplementary measures. You can request information about these safeguards by writing to privacidad@tarracoapplab.com.

7. Retention

Data will be retained for as long as necessary to fulfil the stated purposes, to meet legal obligations or to resolve incidents and claims. Indicative retention periods by type of data:

  • Contact form data: retained for as long as necessary to handle the enquiry and, where applicable, to respond to any subsequent claims.
  • Applications to the «Work with us» area: the CV and supporting documents are retained while the selection process remains open and, unless the candidate objects, for up to one (1) year for future processes. Candidates may request deletion at any time.
  • Client project documentation: retained for the duration of the contractual relationship and thereafter for the limitation period of any actions arising from the contract.
  • Accounting and invoicing data: retained in accordance with applicable tax and commercial legislation (generally 6 years).
  • Server technical logs: limited retention, 30 days by default on Netlify.

8. Your rights

You can exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to privacidad@tarracoapplab.com. You may also withdraw your consent at any time and lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) if you consider that your request has not been addressed.

9. Security

We apply the following technical and organisational measures appropriate to the risk of the processing, in accordance with Art. 32 GDPR:

  • Encryption in transit: TLS 1.2 / 1.3 mandatory on all communications. HSTS enabled. Cookies with Secure and SameSite=Lax flags.
  • Encryption at rest: AES-256 on the Supabase database and file storage.
  • Access control: Row-Level Security in Supabase (each user can only access their own data). API keys rotated periodically. Administrative access with mandatory multi-factor authentication. Least-privilege principle.
  • Secrets management: credentials and keys kept out of the codebase, in the provider’s encrypted environment variables.
  • Backups: automatic backups with retention according to the provider’s policy.
  • Staff confidentiality: personnel with access to systems sign a perpetual confidentiality undertaking and receive periodic data protection training.
  • Activity logging: server technical logs with limited retention (30 days by default on Netlify).
  • Analysis and testing: continuous review of dependencies (lockfiles, vulnerability alerts) and penetration testing whenever a critical component is introduced.

Reporting of security breaches

In the event of a personal data breach that may pose a risk to the rights and freedoms of data subjects, we will act in accordance with Articles 33 and 34 GDPR:

  • Notification to the AEPD: within a maximum of 72 hours of becoming aware of the breach, through the AEPD electronic register, stating the nature of the breach, the categories and approximate number of data subjects, the measures taken and the likely consequences.
  • Communication to data subjects: where the breach is likely to result in a high risk, individual notification by email without undue delay, explaining in plain language the nature of the breach, the likely consequences, the measures taken and the contact points for further information.
  • Internal record: every breach, whether or not notifiable to the AEPD, is recorded internally together with its analysis and the corrective measures adopted, to facilitate subsequent auditing.

Users who detect or suspect a security incident can report it by writing to privacidad@tarracoapplab.com with the subject «Security breach».

Data Processing Agreement (DPA)

Where a client engages Tarraco App Lab to develop, host or maintain a digital product and personal data of third parties is processed in the course of that engagement, the client acts as data controller and Tarraco App Lab acts as data processor under the terms of the Data Processing Agreement (DPA), which forms an integral part of the service terms.

Data of a specially sensitive nature

Do not request or send specially sensitive data (racial origin, health, beliefs, trade union membership, etc.) unless strictly necessary and supported by an appropriate legal basis. If such data is sent by mistake, contact us immediately through the form so that it can be deleted.

10. Changes to this policy

We may update this policy to reflect legal or service changes. The current version will always be published on this page.