At GRUPO BIA INGENIERÍA Y PREVENCIÓN, S.L. (hereinafter, "Bia360") the privacy of personal data is a priority. This Policy describes how we process the personal data we collect through the website bia360cae.com and the associated contact channels, in compliance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on Personal Data Protection and the guarantee of digital rights (LOPDGDD).
1. Data controller
- Controller:
- GRUPO BIA INGENIERÍA Y PREVENCIÓN, S.L.
- Tax ID (CIF):
- B12642849
- Address:
- C/ Doctor Vicente Altava, 8 — 12004 Castellón (Spain)
- Email:
- info@grupobia.com
2. Data we process
Depending on the interaction, we may process the following categories of data:
- Identification and contact data: first name, surname, email address, telephone number, company and position.
- Content of the communication: the message or request you send us, together with the technical information needed to handle your enquiry.
- Billing data: in the event of contracting, tax ID (NIF/CIF), company name, fiscal address and bank or payment details managed through certified providers.
- Technical browsing data: IP address, device identifiers, browser, operating system, usage events and, where applicable, anti-fraud verification signals (e.g. reCAPTCHA).
We do not knowingly request or process special categories of data (Art. 9 GDPR).
3. Purposes and legal bases
a) Handling enquiries and commercial contact
Processing the requests for information you send us via forms, email or telephone, and contacting you with a reply.
Legal basis: the data subject's consent (Art. 6.1.a GDPR) and/or pre-contractual measures taken at the data subject's request (Art. 6.1.b GDPR).
b) Provision of services and contractual relationship
Managing the relationship with clients, providing the contracted CAE services, invoicing and support.
Legal basis: performance of the contract (Art. 6.1.b GDPR) and applicable legal obligations (Art. 6.1.c GDPR).
c) Website security
Protecting the Website's forms, records and resources against automated abuse, fraud, spam or attacks.
Legal basis: Bia360's legitimate interest in maintaining a secure environment (Art. 6.1.f GDPR).
d) Commercial communications
Sending news, content and offers about our services, provided you have given us your prior express consent or there is a prior contractual relationship relating to similar products or services (Art. 21.2 of the Spanish LSSI-CE law).
Legal basis: consent (Art. 6.1.a GDPR) or legitimate interest in the cases permitted by the LSSI-CE.
4. Retention period
Data will be kept for as long as strictly necessary to fulfil the purpose for which it was collected and, where applicable, for the legally required periods to address potential liabilities. In particular:
- Commercial enquiries: until the enquiry is resolved and, at most, 12 months if it does not lead to a contractual relationship.
- Clients: for the duration of the contractual relationship and afterwards, for the applicable statutory limitation periods (tax, commercial, employment).
- Technical security data and logs: the time needed to guarantee the security of the service, up to a maximum of 12 months unless legally required otherwise.
5. Recipients
Your data will not be disclosed to third parties except where legally required. It may, however, be accessed by duly contracted data processors — the providers strictly necessary for delivering the service:
- Infrastructure and hosting providers with servers in the European Union.
- Email, support and CRM providers used to handle communications.
- Payment gateways (e.g. Stripe) to process client transactions.
- Analytics and anti-fraud services (e.g. Google Analytics, Google reCAPTCHA) in accordance with the Cookie Policy.
We do not sell personal data to third parties.
6. International transfers
Wherever possible we contract providers with servers in the European Union. Where a provider requires processing outside the EEA, an adequate level of protection is guaranteed through European Commission adequacy decisions, Standard Contractual Clauses or other safeguards provided for in Chapter V of the GDPR.
7. Your rights
As a data subject, you may at any time exercise the rights recognised by the GDPR:
- Access to your personal data.
- Rectification of inaccurate or incomplete data.
- Erasure ("right to be forgotten") where applicable.
- Objection to processing on grounds relating to your particular situation.
- Restriction of processing.
- Portability of your data in a structured, commonly used and machine-readable format.
- Withdrawal, at any time, of previously given consent, without affecting the lawfulness of processing carried out before the withdrawal.
You may exercise these rights by sending a request to info@grupobia.com, indicating the right you wish to exercise and attaching a copy of your ID card or equivalent document.
If you consider that we have not handled your request correctly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
8. Security
Bia360 applies appropriate technical and organisational measures to guarantee a level of security appropriate to the risk, in accordance with Article 32 GDPR, including encryption in transit (TLS), access control, backups and continuous auditing of providers.
9. Amendments
This Policy may be updated to adapt to regulatory or case-law developments or to changes in our services. The date of the latest update appears in the header of this document.
