GR Soft Industrial & business software
Legal

Privacy policy

What personal data we collect, why we collect it, who we share it with and what you can ask us to do about it.

1. Data controller

Gestión Global de Recursos de Software España S.L.
VAT number / NIF: B-84060995
C. José M. Mulet Ortiz, 16, 12006 Castellón de la Plana, Spain

Privacy contact: a.carceller@gr-soft.net

This policy applies to https://gr-soft.net and to the services we provide to our customers. It is written in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on data protection and digital rights (LOPDGDD).

2. What we collect and why

SituationDataPurposeLegal basisKept for
You use the contact form or email us Name, email, company, subject, message content To answer your enquiry and keep a record of the exchange Your consent, and our legitimate interest in responding to enquiries Up to 2 years from the last contact
You become a customer Contact and billing details, company data, VAT number, order and support history To provide the service, give support and manage the account Performance of the contract For the duration of the contract
You pay us Billing details, transaction amount, payment reference. We never see or store your full card number. To take payment and issue invoices Performance of the contract, and our legal accounting obligations 6 years, as required by Spanish commercial and tax law
You visit the website IP address, date and time, page requested, browser type (web server logs) To keep the site running, diagnose faults and protect against abuse Our legitimate interest in the security and stability of the service Up to 12 months

We do not carry out profiling or automated decision-making that produces legal effects for you. We do not sell personal data, and we do not use your data to send you marketing unless you have asked us to.

3. Who we share data with

We share personal data only with providers who need it in order for us to run the service. Each of them acts as a data processor under a contract that meets Article 28 of the GDPR.

  • Payment processing. Card payments are handled by Stripe Payments Europe, Ltd. and, for some transactions, by our acquiring bank through the Redsys platform. They receive the data needed to process the payment and to prevent fraud. Card details are entered directly into the payment provider's systems.
  • Hosting and email. Our website and mail are operated on hosting infrastructure on our behalf.
  • Software publishers. Where a support case has to be escalated to the publisher of iLEAN or carmen, we share only what is needed to resolve it.
  • Professional advisers and authorities. Our accountants, and public authorities where we are legally required to disclose.

4. Transfers outside the European Economic Area

Our data is processed within the European Economic Area wherever possible. If a provider processes data outside the EEA, we rely on an adequacy decision by the European Commission or on the European Commission's Standard Contractual Clauses, together with any additional safeguards required. You can ask us for details of the safeguards in place using the contact address above.

5. How long we keep data

We keep personal data for as long as it is needed for the purpose it was collected for, as set out in the table above. After that it is deleted, or anonymised so that it can no longer be linked to you. Data that we are required by law to retain — chiefly invoicing and accounting records — is kept for the statutory period and is not used for any other purpose.

6. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you.
  • Rectify data that is inaccurate or incomplete.
  • Erase your data where we no longer have a lawful reason to keep it.
  • Restrict or object to processing based on legitimate interests.
  • Portability — receive the data you gave us in a structured, commonly used, machine-readable format.
  • Withdraw consent at any time, where processing is based on consent. This does not affect processing carried out before you withdrew it.

To exercise any of these rights, write to a.carceller@gr-soft.net or to the postal address above, stating which right you wish to exercise. We may ask you to confirm your identity. We will respond within one month; if the request is complex we may extend this by two further months and will tell you if so.

If you believe we have not handled your data correctly, you may complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es, or to the supervisory authority in your country of residence.

7. Security

We apply technical and organisational measures appropriate to the risk, including encrypted connections (HTTPS) across the website, access control on the systems that hold customer data, and restricting access to staff who need it for their work. No system is perfectly secure, but if a personal data breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority and, where required, you.

8. Children

Our services are sold to businesses and professionals. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

9. Cookies

This website uses only the cookies strictly necessary for it to work. There is no advertising, analytics or third-party tracking. See the cookie policy for the full list.

10. Changes to this policy

We may update this policy when our processing or the law changes. The date of the last review is shown at the top of this page. If a change materially affects how we use your data, we will tell customers directly.