TS ORBIX
Privacy Policy
1. Introduction and scope of this Policy
This Privacy Policy informs, in a detailed and transparent way, about the collection and processing of personal data carried out through the website tsorbix.com, its forms, the client private area, registration and login features and, where applicable, the analytics tools and other technological services used to provide TS Orbix (the "Website").This Policy has been drafted in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation ("GDPR"), Ley Orgánica 3/2018, on the Protection of Personal Data and the guarantee of digital rights ("LOPDGDD"), Ley 34/2002, on Information Society Services and Electronic Commerce ("LSSI-CE") and other applicable regulations.
This information must be read together with the Legal Notice and the Cookie Policy. When a form or service includes additional information or a specific clause, that information will prevail for the specific processing to the extent that it is more specific.
2. Identity of the data controllers and joint controllership
The processing activities carried out through TS Orbix will be the responsibility of the following entities:
- GLOBAL JOURNEY CONSULTING SL, NIF/CIF B87880191, with registered office at Calle O'Donnell 19, 1, Oficina 1, 28009 Madrid, Spain. Published contact email: [email protected].
- COREGRAM CONSULTORES SL, NIF/CIF B10733814, with registered office at C/ Félix Boix, 3, 2.º, centro-derecha 3, 28036 Madrid, Spain.
Both entities act as joint controllers of the processing pursuant to Article 26 GDPR. Joint controllership does not mean that both entities necessarily participate in every operation, but that they will share responsibility for those processing activities for which they jointly determine the essential elements.
To facilitate the exercise of rights, a common contact point will be provided: [email protected]. Requests may also be addressed to either of the joint controllers.
3. Principles governing the processing
The data controllers will process data in accordance with the principles of lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
Data protection by design and by default will be applied, ensuring that, by default, only the data necessary for each purpose is collected, kept for the time necessary and accessible at an appropriate level. The Spanish Data Protection Agency (AEPD) notes that protection by default requires a minimally intrusive configuration and that minimisation must be built into the design of processing activities.
4. Who may be affected
- People who request information or get in touch with TS Orbix.
- Prospective clients and representatives or contact persons of companies.
- Clients and authorised users of the private area.
- People acting on behalf of clients, companies or other organisations.
- Users who browse the Website when the technologies used allow personal data to be processed.
- People whose data is legitimately provided by a client or user within the context of a contractual relationship or request.
A user who provides data of another person must do so only when they have a legitimate basis for it and, where appropriate, must inform that person about the processing.
5. Categories of personal data
5.1. Identification and contact data
Full name, email address, phone number and other contact data reasonably requested.
5.2. Professional and business data
Company, role or position, department, sector, relationship with the organisation and other professional data needed to handle a request or provide the service.
5.3. Data relating to needs or projects
Information the user provides about their needs, goals, projects, services required, characteristics of a request and any other content voluntarily included in text fields.
5.4. Contractual, commercial and billing data
Data needed to prepare, formalise, manage or execute a contractual relationship, including client identification data, billing information, address, service conditions and, where strictly necessary, payment or banking data.
Bank card data must not be stored directly in TS Orbix unless there is a specific need and architecture designed for that purpose. When a payment provider is used, payment data may be processed directly by that provider under its own terms and as a processor or independent controller depending on its role.
5.5. Account and access data
For clients with private access, user identifiers, email address, credentials, authentication data, access logs, password recovery information, session information and data needed to keep the account secure may be processed.
Passwords must be stored using adequate cryptographic mechanisms that prevent recovery in clear text. The data controllers should not know or keep passwords in a readable format.
5.6. Technical and security data
IP address, date and time of access, browser, operating system, technical identifiers, activity logs, session information and security events may be processed to the extent necessary to provide the service, maintain security, detect abuse and resolve incidents.
5.7. Browsing and analytics data
When Google Analytics or other analytics tools are used, online identifiers, browsing information, pages visited, events, device, traffic source and statistical data may be processed. The use of technologies subject to consent will be carried out in accordance with the Cookie Policy.
5.8. Special categories of data
TS Orbix does not intend to request special categories of data under Article 9 GDPR. The user must avoid including health, biometric, genetic data, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life or sexual orientation in free-text fields, unless a specific purpose and an enabling legal basis make it necessary.
If, exceptionally, a special category is to be processed, the exception under Article 9 GDPR, the necessity, proportionality, reinforced measures and, where applicable, the obligation to carry out an impact assessment will be analysed in advance.
6. Sources of the data
Data may be obtained directly from the data subject through forms, registration, contracting, communications or use of the private area. They may also legitimately come from the company or organisation represented by the user, from providers involved in the service delivery or from public sources when a legal basis permits it.
When data is not obtained directly from the data subject, the information required under Article 14 GDPR will be provided, unless a legal exception applies.
7. Processing activities and purposes
7.1. Contact form / information request
Purpose: to receive and manage requests, contact the person concerned, answer questions, assess needs and carry out the prior actions requested.
Legal basis: pre-contractual measures at the data subject's request when the request aims to contract or prepare a contractual relationship; in other cases, legitimate interest in handling communications and managing the relationship, provided that such interest prevails over the rights of the data subject.
7.2. Lead management
Purpose: to manage commercial opportunities, learn about the needs communicated, prepare proposals, maintain communications related to the request and document the commercial relationship.
Legal basis: pre-contractual measures or legitimate interest, depending on the nature of the relationship and communication.
7.3. Onboarding and client management
Purpose: to create and administer the client relationship, manage contracted services, operational communications, support, incidents and compliance with contractual obligations.
Legal basis: performance of the contract or application of pre-contractual measures.
7.4. Client private area
Purpose: to allow authenticated access to features, documentation, information, services or reserved content; manage authorised users; maintain sessions; control permissions and protect the account.
Legal basis: performance of the contract and, to the extent necessary for security, legitimate interest.
7.5. Billing and accounting/tax obligations
Purpose: to issue and manage invoices, collect payments, keep accounting records, comply with tax obligations and respond to authority requests.
Legal basis: compliance with legal obligations and, where applicable, performance of the contract.
7.6. Customer service and support
Purpose: to answer enquiries, resolve incidents, keep a history of communications when necessary and improve the service provided.
Legal basis: performance of the contract, pre-contractual measures or legitimate interest, as the case may be.
7.7. Security and fraud prevention
Purpose: to detect anomalous access, prevent attacks, abuse, fraud, spam and misuse of accounts, investigate incidents and preserve the integrity of the Website.
Legal basis: legitimate interest in ensuring the security of systems, services, users and organisations, together with compliance with applicable legal obligations.
7.8. Analytics and service improvement
Purpose: to understand Website usage, measure performance, detect issues, produce statistics and improve content and features.
Legal basis: consent when the cookies or technologies used are not exempt from consent. Non-essential analytics will not be activated before consent when this is required.
7.9. Commercial communications
If commercial communications are sent, they will only be sent when there is consent or another legal basis permitted by the regulations. The recipient may object to or unsubscribe from commercial communications at any time and in a simple way.
The inclusion of a person in a commercial database will not be considered automatically legitimised by the mere fact of having contacted TS Orbix; the specific purpose and the applicable legal basis will be analysed.
8. Legal bases: summary table
| Processing | Main purpose | Legal basis | Consent? |
|---|---|---|---|
| Forms | Handle enquiries | Pre-contractual / Legitimate interest | No, unless the purpose is optional |
| Clients | Manage services | Contract | No |
| Private area | Access and service provision | Contract / Legitimate interest | No |
| Billing | Obligations | Legal obligation | No |
| Security | Prevent abuse | Legitimate interest | No |
| Non-essential analytics | Measurement and improvement | Consent | Yes, when required |
| Marketing | Communications | Consent or other legal basis | Depending on the case |
9. Consent
When processing is based on consent, the consent must be freely given, specific, informed and unambiguous. Silence, inactivity or pre-ticked boxes do not constitute valid consent.
Consent may be withdrawn at any time. Withdrawal will not affect the lawfulness of processing carried out before withdrawal.
When a purpose is optional, not consenting will not prevent access to services that do not depend on that purpose.
In forms, the basic information must be shown at the same time and medium as collection, and additional information may be provided in layers. The AEPD recommends this approach to comply with the duty of information.
10. Retention periods
Personal data will not be kept for longer than necessary for the purposes for which it was collected, taking into account legal obligations and possible liability periods.
- Enquiries and requests: for the time needed to handle them and, where there is a pre-contractual relationship, for the time needed to manage it; subsequently, for the periods necessary to evidence actions or address liabilities.
- Clients: during the term of the contractual relationship and subsequently for the legally applicable limitation and retention periods.
- Billing and accounting/tax records: for the periods required by tax, commercial and accounting regulations.
- Client accounts: as long as the account and contractual relationship remain active and for the subsequent period needed to address liabilities.
- Security data and logs: for a limited period proportionate to the security purpose, incident investigation and compliance.
- Data processed solely on the basis of consent: until consent is withdrawn or until they are no longer necessary, without prejudice to legal retention obligations.
The exact retention periods must be defined in the Record of Processing Activities and in the internal retention and erasure policy.
11. Recipients
Data may be accessed by the joint controllers and by the authorised persons who need to access it for their duties.
- Hosting, infrastructure and maintenance providers.
- Email and communications providers.
- Form, CRM and sales management providers.
- Authentication and account management providers.
- Support and security providers.
- Analytics and measurement providers, including Google Analytics when configured.
- Professional, accounting, tax or legal advisors when necessary.
- Financial institutions or payment providers when needed for a transaction.
- Public administrations, authorities, courts and regulatory bodies when there is a legal obligation or enabling rule.
Providers processing data on behalf of the data controllers must be bound by a contract or legal act that complies with the requirements of Article 28 GDPR when they act as processors.
12. Data processors
Before engaging a provider that will process personal data on behalf of the data controllers, its suitability must be assessed and the required contractual guarantees formalised. The contract must cover, among other aspects, documented instructions, confidentiality, security, sub-processors, assistance with data subject rights, breaches, erasure or return of data and audits.
The relationship with sub-processors must be documented and their engagement must respect GDPR requirements.
13. International transfers
When data is transferred or may be accessed from outside the European Economic Area, the existence of a valid international transfer mechanism under Chapter V GDPR will be verified in advance.
Where appropriate, adequacy decisions, standard contractual clauses or other safeguards under the GDPR may be used. The AEPD reminds that international transfers must be covered by one of the legally provided mechanisms.
In the case of Google Analytics or other global providers, the provider's current configuration and contractual documentation must be reviewed, as well as the access country and the applicable mechanism. It should not be asserted that a tool does or does not perform an international transfer without verifying its current configuration and documentation.
14. Rights of data subjects
Data subjects may exercise, where applicable, the following rights:
- Access: to know whether their data is being processed and to obtain a copy and the corresponding legal information.
- Rectification: to correct inaccurate data or complete incomplete data.
- Erasure: to request erasure when any of the legal grounds apply.
- Objection: to object to certain processing activities, especially when based on legitimate interest or for direct marketing purposes.
- Restriction: to request that processing be temporarily restricted in the cases provided by law.
- Portability: to receive certain data in a structured, commonly used and machine-readable format and, where technically possible and appropriate, to transmit them to another controller.
- Withdrawal of consent: when processing is based on consent.
- Not to be subject to a decision based solely on automated processing that produces legal effects or significantly affects them, except for the exceptions and safeguards in the GDPR.
Rights may be exercised free of charge by writing to [email protected] or to either of the joint controllers.
The request must contain sufficient information to verify identity when necessary. The data controllers may request additional information only when there are reasonable doubts about identity.
As a general rule, the request must be addressed within one month of receipt. This period may be extended by a further two months when necessary, taking into account the complexity and number of requests, informing the data subject of the extension within the first month.
15. Complaint to the supervisory authority
If the data subject considers that the processing breaches the regulations, they may lodge a complaint with the Spanish Data Protection Agency (AEPD), without prejudice to any other administrative or judicial remedy.
The complaint may be brought especially when the data subject considers that their rights have not been addressed or that the processing does not comply with the GDPR or Spanish regulations.
16. Information security
The data controllers will apply appropriate technical and organisational measures to the risk, taking into account the nature, scope, context and purposes of the processing and the risks to the rights and freedoms of individuals.
- Access control based on need-to-know and authorisation.
- Secure management of credentials and passwords.
- Encryption of communications through secure protocols where appropriate.
- Backups and recovery mechanisms.
- Vulnerability management and patching.
- Logging and monitoring of security events when proportionate.
- User provisioning, deprovisioning and permission management.
- Confidentiality of authorised personnel.
- Incident response and management procedures.
- Minimisation, retention and secure erasure measures.
Public information about security will be kept at a level that demonstrates sufficient safeguards without revealing technical details that could facilitate attacks.
17. Personal data breaches
If a security breach affecting personal data occurs, the data controllers will assess the incident and apply the corresponding procedure. Where there is a risk to the rights and freedoms of individuals, notification to the supervisory authority will be considered within the period provided by Article 33 GDPR and, where there is a high risk, communication to the affected persons in accordance with Article 34 GDPR.
Incidents must be documented, including the facts, effects and corrective measures, even when notification to the authority is ultimately not required.
18. Record of Processing Activities and accountability
The data controllers will maintain, when required, a Record of Processing Activities (ROPA) with the purposes, categories of data subjects and data, recipients, international transfers, retention periods and a general description of the security measures, among other elements.
The AEPD notes that the ROPA is an essential tool to demonstrate compliance and must be kept up to date.
Internal documentation must include, as appropriate, risk analyses, processor inventory, joint controllership agreements, contracts, provider assessments, rights management, incidents and security measures.
19. Data protection by design and by default
Before activating new features that involve personal data — for example, new forms, profiles, recommendation systems, automations, integrations or analytics — the data controllers must analyse the necessity, proportionality, legal basis, risks, default configuration and security measures.
The AEPD considers that data protection by design must be incorporated from the conception phase and maintained throughout the processing lifecycle.
20. Impact assessment and prior consultations
When a processing activity is likely to result in a high risk to the rights and freedoms of individuals, a Data Protection Impact Assessment (DPIA) will be carried out before starting the processing, pursuant to Article 35 GDPR.
If, despite the planned measures, the processing would still result in a high risk that cannot be sufficiently mitigated, the need for prior consultation with the supervisory authority will be considered pursuant to Article 36 GDPR.
The introduction of new profiling technologies, systematic monitoring, mass processing, especially sensitive data or other high-risk operations must be assessed before being put into production.
21. Automated decisions and profiling
TS Orbix does not intend to make decisions based solely on automated processing that produce legal effects or significantly affect individuals. If such processing were introduced in the future, information about its existence, general logic, importance and consequences will be provided in advance and the safeguards in Articles 13 to 22 GDPR will apply.
Profiling for commercial or personalisation purposes will likewise be subject to an assessment of legal basis, transparency, right to object and proportionality.
22. Minors
TS Orbix is not specifically aimed at minors for the contracting or use of professional services. It is not intended to deliberately collect data from minors under 14 years of age through processing based on their own consent.
When processing is based on consent and Spanish law sets an age below the age at which a person may give consent themselves, the specific rules on minors' consent will apply and, where appropriate, authorisation from those exercising parental authority or guardianship will be sought.
Data of minors will not be deliberately requested for purposes incompatible with the services offered.
23. Third-party data provided by the user
When a client or user enters data of employees, representatives, collaborators or other persons in TS Orbix, they must ensure that they have a sufficient legal basis for that communication and that they have provided the information required to the affected persons when applicable.
TS Orbix may process such data for purposes strictly related to the contractual relationship or service requested.
24. Electronic communications
Operational communications needed to provide the service — for example, confirmations, security notices, password recovery, incidents or contractual information — may be sent when necessary to perform the relationship.
Commercial communications will be distinguished from operational ones and must comply with the LSSI-CE. Each commercial communication must allow an easy and free opt-out.
25. Forms: layered information
Each form must include, next to the submit button or in a clearly visible area, a first layer of information that identifies the joint controllers, indicates the essential purposes, the legal basis, the existence of recipients or international transfers where applicable and refers to this Policy for further information.
Pre-ticked boxes must not be used for consent. Optional purposes must be able to be accepted or refused separately when necessary.
The AEPD specifically recommends providing basic information at the same time and medium as collection and a second, more complete and archivable layer.
26. Cookies, analytics and similar technologies
TS Orbix may use Google Analytics or other analytics tools. The installation or activation of cookies and similar technologies will be governed by the Cookie Policy and by the applicable regulations.
When an analytics technology is not exempt from consent, it will only be activated after obtaining a valid affirmative action. The configuration must respect the principles of minimisation and privacy by design.
27. Third-party links and services
TS Orbix may contain links or integrations with third-party services. When leaving TS Orbix or directly using an external service, the processing carried out by that third party may be subject to its own privacy policy and terms.
The existence of a link does not imply that the data controllers control the processing carried out by the third party.
28. Accuracy and updating of data
The user is responsible for ensuring that the data provided is accurate, truthful, complete and up to date. The data controllers may request the update of certain data when necessary to maintain the contractual relationship or to comply with legal obligations.
Data that is no longer necessary must be erased, anonymised or blocked in accordance with the internal retention policy.
29. Confidentiality
Persons accessing personal data in the course of their duties must be bound by a duty of confidentiality, whether by contractual or legal obligation or by a specific undertaking.
Access will be limited to the data needed for each role.
30. Changes to this Policy
This Policy may be updated to reflect legal, regulatory, technological or organisational changes, or changes in processing activities, providers, transfers or TS Orbix features.
When a change is substantial and required by law, additional information will be provided or consent will be sought again where appropriate. The current version will be identified by its update date.
31. Reference regulations
- Regulation (EU) 2016/679 (GDPR).
- Ley Orgánica 3/2018, of 5 December (LOPDGDD).
- Ley 34/2002, of 11 July (LSSI-CE).
- Spanish and European regulations applicable to contracting, e-commerce, consumers, intellectual property and information security, where relevant.
