HODEITEK SL (hereinafter, "Hodeitek") is committed to protecting the privacy of users who visit hodeitek.com. This Privacy Policy has been drafted in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (GDPR), Organic Law 3/2018, of December 5, on the Protection of Personal Data and guarantee of digital rights (LOPDGDD) and Law 34/2002, of July 11, on Services of the Information Society and Electronic Commerce (LSSI-CE).
1. Identity of the data controller
- Controller: HODEITEK SL
- Tax ID (CIF): B56478027
- Address: Markole, Aretxabaleta, 20550, Gipuzkoa, Spain
- Email: info@hodeitek.com
- Data protection contact: privacidad@hodeitek.com (mailbox managed by company management; use it to exercise your rights or for any question about this policy).
- Phone: +34 747 42 45 03
2. Processing purposes, legal bases and data collected
Retention periods applicable to each purpose are consolidated in section 6 (Data retention).
2.1. Handling inquiries via the contact form
- Purpose: Handle the inquiry and maintain the commercial relationship.
- Data collected: Name, email, company (optional), phone (optional) and message content.
- Legal basis: Controller's legitimate interest (Art. 6.1.f GDPR) in handling B2B commercial inquiries.
2.2. Service information or quote requests
- Purpose: Manage the request and prepare the commercial proposal.
- Data collected: Name, email, company, message (optional).
- Legal basis: Application of pre-contractual measures at the request of the data subject (Art. 6.1.b GDPR).
2.3. Sending the newsletter and commercial communications
- Purpose: Sending commercial communications about cybersecurity, AI and Hodeitek news.
- Data collected: Email and, optionally, name.
- Legal basis: Express and specific consent of the data subject (Art. 6.1.a GDPR and Art. 21 LSSI-CE), collected through a newsletter-specific consent checkbox, separate from the general contact checkbox: subscribing to the newsletter is never implicit in submitting another form on the Website.
- You may unsubscribe at any time; see section 9 (Newsletter unsubscribe).
2.4. Statistical analysis of website usage
- Purpose: Analyze website usage through analytical cookies (Google Analytics 4).
- Data collected: Pseudonymized identifiers, truncated IP, pages visited, device and browser.
- Legal basis: Consent of the data subject (Art. 6.1.a GDPR).
- More information, cookie list and opt-out procedure in section 10 (Cookies) of this policy and in the Cookie Policy.
3. Subprocessors
Personal data will not be shared with third parties except for legal obligation. However, the following subprocessors may access it to provide the indicated service, under a data processing agreement pursuant to Article 28 of the GDPR:
| Subprocessor | Country | Service | Transfer safeguard |
|---|---|---|---|
| OVHcloud | France (EU) | Website hosting and object storage (S3) | Within the EEA — not an international transfer |
| Cloudflare, Inc. | United States | Content delivery network (CDN), access control (Cloudflare Access) and anti-bot form verification (Cloudflare Turnstile) | Standard Contractual Clauses (SCC) |
| Google LLC | United States | Google Analytics 4 (web analytics, only with consent) | EU-US Data Privacy Framework, complemented with Standard Contractual Clauses (SCC) — see section 4 |
| Microsoft 365 (Microsoft Ireland Operations Ltd.) | Ireland (EU) | Corporate email | Microsoft's Standard Contractual Clauses (SCC) |
| n8n (self-hosted by Hodeitek) | European Union | Automated processing of form submissions | Not applicable — infrastructure stays within the EU |
| Resend | United States | Transactional email delivery (notifications and form responses) | Standard Contractual Clauses (SCC) |
- Subprocessor
- OVHcloud
- Country
- France (EU)
- Service
- Website hosting and object storage (S3)
- Transfer safeguard
- Within the EEA — not an international transfer
- Subprocessor
- Cloudflare, Inc.
- Country
- United States
- Service
- Content delivery network (CDN), access control (Cloudflare Access) and anti-bot form verification (Cloudflare Turnstile)
- Transfer safeguard
- Standard Contractual Clauses (SCC)
- Subprocessor
- Google LLC
- Country
- United States
- Service
- Google Analytics 4 (web analytics, only with consent)
- Transfer safeguard
- EU-US Data Privacy Framework, complemented with Standard Contractual Clauses (SCC) — see section 4
- Subprocessor
- Microsoft 365 (Microsoft Ireland Operations Ltd.)
- Country
- Ireland (EU)
- Service
- Corporate email
- Transfer safeguard
- Microsoft's Standard Contractual Clauses (SCC)
- Subprocessor
- n8n (self-hosted by Hodeitek)
- Country
- European Union
- Service
- Automated processing of form submissions
- Transfer safeguard
- Not applicable — infrastructure stays within the EU
- Subprocessor
- Resend
- Country
- United States
- Service
- Transactional email delivery (notifications and form responses)
- Transfer safeguard
- Standard Contractual Clauses (SCC)
If Hodeitek adds a new subprocessor or replaces an existing one, it commits to updating this table and informing the clients whose data may be affected, under the terms of their service contract or data processing agreement (DPA).
4. International data transfers
As shown in the table above, some subprocessors (Cloudflare, Google LLC, Microsoft 365 and Resend) may process data in the United States. Following the Court of Justice of the European Union's ruling of July 16, 2020 (Case C-311/18, "Schrems II"), which invalidated the previous Privacy Shield, the European Commission adopted the EU-US Data Privacy Framework through Implementing Decision (EU) 2023/1795, which recognizes an adequate level of protection for the purposes of Article 45 GDPR for US entities certified under that framework.
As an additional safeguard against a possible future challenge to the adequacy framework itself — as already happened with the Privacy Shield after Schrems II — Hodeitek complements the EU-US Data Privacy Framework with Standard Contractual Clauses (SCC) approved by the European Commission (Implementing Decision (EU) 2021/914) in its contracts with these providers. This way, the transfer is covered cumulatively by both mechanisms and does not depend exclusively on the DPF remaining in force.
5. Data Protection Agreement (DPA)
When Hodeitek processes third parties' personal data on behalf of a client while providing its cybersecurity and AI services (e.g., audits, penetration testing, SOC or GRC consulting), it acts as the client's data processor. For those cases, Hodeitek makes available to its clients a Data Protection Agreement (DPA) template pursuant to Article 28 GDPR, available upon request by emailing privacidad@hodeitek.com.
6. Data retention
When an exact period cannot be set in advance, the GDPR allows retention to be determined through objective criteria (Art. 13.2.a GDPR). Hodeitek applies the following periods and criteria depending on the type of data:
| Data type | Retention period or criterion |
|---|---|
| Browsing / analytics cookies (Google Analytics 4) | According to the retention period configured in Google Analytics 4 (see Cookie Policy) |
| Newsletter subscription | Until the data subject withdraws consent |
| Contractual and billing documentation (clients under a formalized contract) | Throughout the contractual relationship and up to 6 years after its end (Art. 30 Commercial Code) |
| Commercial inquiries and quote requests without a formalized contract | For as long as the legitimate interest justifying the response subsists, never exceeding what is strictly necessary, applying the data minimization principle |
| Data processed while delivering services to clients | As agreed in the service contract and, where applicable, in the Data Protection Agreement signed with each client (see section 5) |
7. Data subject rights
Pursuant to Articles 15 to 22 of the GDPR, you have the right to:
- Access: Know what personal data of yours we are processing.
- Rectification: Request the correction of inaccurate data.
- Erasure (right to be forgotten): Request the deletion of your data.
- Objection: Object to the processing of your data.
- Restriction: Request the restriction of processing in certain cases.
- Portability: Receive your data in a structured and readable format.
- Withdrawal of consent: Withdraw the consent given at any time, without affecting the lawfulness of prior processing.
Under Spanish law these are traditionally known as "derechos ARCO" (Access, Rectification, Cancellation — broadly equivalent to erasure — and Objection), which the GDPR extends with portability, restriction and withdrawal of consent.
How to exercise them: Send an email to privacidad@hodeitek.com indicating the right you wish to exercise and attaching a copy of your ID or equivalent document to verify your identity.
How your request is stored: Requests to exercise rights are logged internally (date received, right exercised and response given) solely to evidence compliance with this obligation, and are kept for one year after resolution.
Response time: Hodeitek will respond within one month of receiving the request, extendable by two further months for particularly complex requests, pursuant to Article 12.3 GDPR.
We also inform you of your right to file a claim with the Spanish Data Protection Agency (AEPD), at C/ Jorge Juan, 6, 28001 Madrid, or through its electronic headquarters www.aepd.es, if you consider that the processing of your data does not comply with regulations.
8. Minors
The Website and Hodeitek's services are aimed at businesses and professionals (a B2B relationship) and are not intended for minors. Hodeitek does not knowingly collect data from minors under 14, in line with Article 7 of the LOPDGDD. If a minor under 14 provided their data without the consent of their parents or legal guardians, or if Hodeitek became aware of this by any means, it will delete that data as soon as it becomes aware, without requiring a prior request. Any parent or guardian who believes a minor in their care has provided data through the Website may contact privacidad@hodeitek.com.
9. Newsletter unsubscribe
You can unsubscribe from the newsletter at any time using the unsubscribe link included in every communication, which is processed automatically and immediately. If you prefer to request unsubscription another way, you can email privacidad@hodeitek.com and the request will be processed without delay.
10. Cookies
hodeitek.com uses first-party and third-party cookies. Technical cookies do not require consent; analytical cookies (Google Analytics 4) are only activated if you expressly authorize them in the consent banner. The full list, by name, is as follows:
| Cookie | Type | Consent |
|---|---|---|
hodeitek-cookie-consent-v2 | Technical (first-party) | Not required |
NEXT_LOCALE | Technical (first-party) | Not required |
_ga, _ga_<container-id>, _gid, _gat | Analytics — Google Analytics 4 (third-party) | Requires consent |
- Cookie
hodeitek-cookie-consent-v2- Type
- Technical (first-party)
- Consent
- Not required
- Cookie
NEXT_LOCALE- Type
- Technical (first-party)
- Consent
- Not required
- Cookie
_ga,_ga_<container-id>,_gid,_gat- Type
- Analytics — Google Analytics 4 (third-party)
- Consent
- Requires consent
How to opt out of Google Analytics: you can (a) reject analytics cookies in the consent banner or via the "Cookie settings" link in the footer; (b) install Google Analytics' opt-out browser add-on, available at tools.google.com/dlpage/gaoptout; or (c) block third-party cookies from your browser settings.
Provider and duration details for each cookie, plus what exactly happens when you withdraw consent, are available in the Cookie Policy.
11. Security measures
Hodeitek has adopted the technical and organizational measures necessary to guarantee the security of personal data and prevent its alteration, loss, processing or unauthorized access, in accordance with Article 32 of the GDPR. Implemented measures include: encryption in transit (HTTPS/TLS), role-based access control, encrypted backups, record of processing activities, and periodic security assessments.
12. Policy modifications and version history
Hodeitek reserves the right to modify this Privacy Policy to adapt it to legislative or case-law developments. In such cases, it will announce on this page the changes introduced with reasonable advance notice before they come into effect.
| Version | Date | Main changes |
|---|---|---|
| v1.0 | April 26, 2026 | Initial publication of the Privacy Policy. |
| v2.0 | September 27, 2026 | Comprehensive update: table of contents, Google Analytics opt-out procedure, exercise and storage of ARCO/GDPR rights, minors clause, international transfers after Schrems II, subprocessor table with country and safeguards, Data Protection Agreement (DPA), dedicated data retention section, cookie list by name, privacidad@hodeitek.com contact and newsletter unsubscribe mechanism. |