Skip to content

Privacy policy

This page explains what personal data Lapsor Cybersecurity S.L. processes when someone visits lapsor.com or requests a proposal, what it is used for, how long it is kept and how to exercise the rights granted by Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018.

Who processes your data

The controller is Lapsor Cybersecurity S.L., tax ID B23984115, registered in Madrid, Spain. For anything related to this policy: contacto@lapsor.com.

What data is collected and where it comes from

All data is provided by the person concerned or generated while browsing. We do not buy databases or obtain profiles from third parties.

  • Request form: name, work email address and, if you choose to give them, company, service of interest and the content of your message.

  • Email verification: a one-time code sent to the address given, along with the IP address and user agent the request was sent from.

  • Later correspondence: whatever you write to us by email while an engagement is being agreed or carried out.

  • Browsing: the technical data tied to the cookies you have accepted, set out in the cookies policy.

What it is used for, and on what legal basis

Each purpose rests on a different basis under Article 6 GDPR:

  • Handling your request and preparing the proposal: pre-contractual steps taken at your request.

  • Checking the email address is real and stopping automated use of the form: legitimate interest in protecting the contact channel.

  • Carrying out the engagement and keeping the correspondence: performance of the contract.

  • Meeting accounting, tax and record-keeping duties: compliance with a legal obligation.

  • Sending you information about the services, only if you asked for it: your consent, which you can withdraw at any time.

  • Setting non-essential cookies: your consent, managed from the cookie notice.

No automated decisions with legal effects are made about individuals, and no behavioural profiles are built.

How long it is kept

  • A request that is never verified is deleted automatically after fifteen minutes.

  • The record of a verified request is kept for thirty days.

  • Correspondence and engagement documentation are kept while the relationship lasts and then for the limitation periods applicable to any claims arising from it.

  • Records with accounting or tax relevance are kept for the periods set by the applicable rules.

Once those periods end, the data is deleted or anonymised.

Who else can access it

Data is not sold or transferred to third parties for commercial purposes. Running the site involves providers acting as processors, under a signed agreement and only on our instructions:

  • The hosting and content delivery provider.

  • The service that protects the form against automated submissions.

  • The transactional email provider that delivers the verification code and the internal notice of the request.

Data may also be disclosed to courts and public authorities where a rule requires it.

Transfers outside the European Economic Area

Some of those providers are established outside the European Economic Area. Those transfers rely on the standard contractual clauses approved by the European Commission or on the adequacy decision applicable to the destination country.

How it is protected

The site is served only over an encrypted connection, the form requires the email address to be verified before a request is recorded, attempts are limited per address and per IP, and access to requests is restricted to the team members who handle them. Data that is no longer needed is deleted automatically.

Your rights and how to exercise them

You can request access to your data, its correction or erasure, the restriction of or objection to its processing, and the portability of what you provided. Where processing rests on your consent, you can withdraw it at any time without affecting what was processed before.

To exercise them, write to contacto@lapsor.com stating which right you are exercising and enclosing proof of identity. We reply within one month.

The Spanish Data Protection Agency publishes a request form for each right:

If you believe the processing does not comply with the rules, you can lodge a complaint with the Spanish Data Protection Agency.

Changes to this policy

This policy is updated when the processing or the rules governing it change. The version in force is always the one published on this page, and material changes are communicated to anyone with an ongoing relationship with Lapsor.

Request an auditCall