Madrid · Domestic and International Service info@imts.es
ES / EN / PT

Privacy Policy

MANDATORY PRIVACY AND DATA PROTECTION POLICY

At IMTS, we specialize in Information Security, Regulatory Compliance (GRC), and Privacy. Therefore, protecting the personal data of our clients, contacts, and users is not only a legal obligation for us, but also the foundation of the trust upon which our services are based.

The purpose of this Privacy Policy is to provide detailed, clear, and transparent information about how we collect, use, protect, and store your personal data when you use the website www.imts.es or when you contract our services, in strict compliance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD).

1. DATA CONTROLLER

The data controller for the personal data collected is:

  • Company Name: Infraestructuras de Medios Técnicos y Servicios, S.L.] (hereinafter, “IMTS”)
  • Tax ID Number (NIF): B84255736
  • Registered Office: Avenida Alberto Alcocer, 46, 3°B, Postal Code 28046, Madrid
  • Email Address for Privacy Matters: RGPD@imts.es

For any matter related to data protection, the management of your privacy, or the exercise of your rights, please contact us directly at the email address provided. A specialized analyst will handle your request.

2. PURPOSE OF DATA PROCESSING: HOW DO WE USE YOUR DATA?

At IMTS, we process the information provided to us by data subjects exclusively for the following purposes:

  1. Management of website users, business contacts, and inquiries (Consulting)
  • To address, manage, and resolve inquiries, messages, evaluation requests, requirements gathering, and quote requests submitted through the contact channels on our website or via email.
  • Maintaining the necessary communication during the pre-contractual phase of GRC, Audit, ICT Implementation, or Support services.
  1. Provision and management of professional services to Clients
  • Formalizing, developing, or executing the contractual relationship, as well as the technical, operational, and maintenance management of the contracted services (Virtual CSO, supplier management, OSINT, IT equipment, etc.).
  • Administrative management, billing, accounting, and compliance with tax and commercial obligations.

3. LEGAL BASIS OR LEGITIMACY OF THE PROCESSING

The processing of your personal data is based on the following legal grounds (Art. 6 GDPR):

  • Consent of the data subject: For the management of inquiries submitted through the website. Every form includes a mandatory checkbox that ensures your express consent.
  • Performance of a contract or implementation of pre-contractual measures: For the management of quotes, gathering of requirements, and the provision of the contracted professional audit, security, and consulting services.
  • Compliance with legal obligations: To meet the requirements set forth in tax, accounting, and commercial laws, as well as other government regulations applicable to IMTS.
  • Legitimate interest: To maintain our professional and business relationship, prevent fraud, and ensure network and information security in our systems.

4. RETENTION PERIODS: HOW LONG DO WE RETAIN YOUR INFORMATION?

We retain your personal data only for as long as is strictly necessary to fulfill the purposes for which it was collected:

  • Inquiry and pre-contract data: This data will be retained for as long as necessary to respond to and process the request (up to 12 months from the end of the contact), unless the request results in a service contract.
  • Customer data (contract management, billing, and support): For the duration of the signed commercial contract and the business relationship.
  • Legal retention or blocking: Once the relationship has ended, the data will be securely blocked and made available exclusively to judges, courts, the Public Prosecutor’s Office, and public authorities to address any potential liabilities arising from the processing, in accordance with current regulations (e.g., 5 years for tax-related requirements; 10 years for anti-money laundering purposes, if applicable). Once these technical and legal retention periods have expired, the data will be securely deleted or irreversibly anonymized.

5. DISCLOSURE OF DATA TO THIRD PARTIES AND DATA PROCESSORS

Legal Obligation: IMTS does not sell, rent, disclose, or transfer your personal data to third parties under any circumstances, except where required by law (e.g., the Tax Agency, law enforcement agencies).

Data Processors (IMTS IT Service Providers): To support our company’s technical operations, we share information under strictly controlled conditions with certain infrastructure and technology providers (web hosting services, cloud platforms, corporate email, management software). All of these providers act as Data Processors, and are subject to our own IT Vendor Management Policy. We have signed data processing agreements with all of them that guarantee they apply security measures equivalent to those required internally by IMTS.

6. INTERNATIONAL DATA TRANSFERS

In general, the servers and infrastructure we use to host our corporate data are located within the European Economic Area (EEA).

In the event that the technological infrastructure of any of our vendors involves data being hosted on or transiting through servers located in the United States or other third countries, IMTS will ensure that such transfers are made only after verifying that the vendor:

  • Has adhered to the Data Privacy Framework (EU-U.S. Privacy Shield) applicable to such transfers, or
  • Has adopted the Standard Contractual Clauses (SCCs) approved by the European Commission, along with the completion of Data Transfer Impact Assessments (DTIA).

7. DATA SECURITY

Technical security is not merely a goal for IMTS; it is the technical foundation upon which we operate. We have implemented rigorous technological policies and technical, logical, organizational, and physical measures to protect against the destruction, alteration, accidental or unauthorized loss, disclosure, or unlawful access to personal data. We operate in accordance with the security requirements set forth by the national regulatory framework (ENS) and international standards (ISO/IEC 27001), continuously adapting our safeguards and controls regarding access control, data encryption, and immutable backups.

8. USER RIGHTS (ARCO+ RIGHTS)

The GDPR grants you a series of rights that you may freely exercise regarding the data we process. You may request to exercise the following rights at any time:

  • Right of Access: Confirm whether IMTS is processing your data and, if so, request a copy of it.
  • Right to Rectification: Correct any data that is inaccurate or incomplete.
  • Right to Erasure (Right to be Forgotten): Request the deletion of your data when it is no longer necessary for the purposes for which it was collected.
  • Right to Object: Request that we stop processing your data, based on legitimate grounds related to your particular situation.
  • Right to Restriction of Processing: Request that the technical processing of your data be restricted so that it is retained solely for the purpose of defending against claims.
  • Right to Data Portability: To receive the personal data you have provided to us in a structured, commonly used, and machine-readable format.

How to exercise these rights? You must send us an email clearly stating your request to: RGPD@imts.es.

Finally, we remind you that if you believe the processing of your personal data violates regulations or we have not properly addressed your request to exercise your rights, you have the right to file a formal complaint with the Spanish Data Protection Agency (www.aepd.es).

Last documented update: May 2026