Legal
Privacy policy
1. Data controller
- Controller: PETROSECUR CONSULTING, S.L. (Sociedad Unipersonal)
- NIF: B16740821
- Address: Centro Comercial Le Village, Carretera de Istán, km 1, oficina 11, 29602 Marbella (Málaga)
- Contact: administracion@petrosecur.es
2. What data we process and where it comes from
Only the data users voluntarily provide through the audit request form: name, company or organisation, email, phone, asset type, location and the free text describing what needs protecting. No data is obtained from third-party sources and no profiling is carried out.
Recommendation: do not include detailed information about vulnerabilities, floor plans or existing security measures in the form. That information is handled during the technical visit, under a confidentiality agreement.
The fields marked with an asterisk in the form are necessary in order to handle the request: without them we cannot reply. The rest are optional and only help us prepare the technical visit.
2 bis. Server access logs
Independently of the form, the server hosting this site logs technical data for each connection (IP address, date and time, requested resource and browser). Purpose: to maintain the service and its security. Legal basis: the legitimate interest of the controller in ensuring network and information security (art. 6.1.f GDPR). These logs are not used for profiling and are not cross-referenced with form data. In addition, to prevent mass submissions, the form temporarily keeps an encrypted digest (not the address itself) of the IP it is sent from, solely to limit the number of submissions per hour; it is deleted automatically. Same purpose and same legal basis.
3. Purpose and legal basis
- Purpose: to handle the request, assess whether a technical visit applies and, where appropriate, prepare a proposal.
- Legal basis: pre-contractual measures at the data subject's request (art. 6.1.b GDPR) and their express consent when ticking the form box (art. 6.1.a GDPR).
4. Retention period
While the request is being handled and thereafter for the limitation period of any actions arising from the relationship. If no contractual relationship arises, data is deleted within a maximum of one year from the last contact, unless a legal obligation requires otherwise.
5. Recipients
No data is transferred to third parties except by legal obligation. Form requests are sent by email, from the server hosting the website, to the controller's mailboxes. Providers supplying services to the controller (hosting and email) may access them as processors.
International transfers: the website and the petrosecur.es mailboxes are hosted on a server located in the European Union (the Netherlands). The hosting provider, BanaHosting, is based in the United States and states that it processes data in the United States and Europe, and email leaving that server may pass through sending services located outside the European Union. Access to the data from outside the European Economic Area in order to provide the service therefore cannot be ruled out. BanaHosting does not participate in the EU-US Data Privacy Framework, so such access is not covered by an adequacy decision of the European Commission.
6. Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw consent at any time without affecting the lawfulness of prior processing. To do so, write to the contact address stating the right exercised and enclosing proof of identity.
If you believe the processing does not comply with the regulations, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es, C/ Jorge Juan 6, 28001 Madrid).
7. Security
The controller applies technical and organisational measures appropriate to the risk, in accordance with article 32 GDPR, to protect data against destruction, loss, alteration or unauthorised access.
Last updated: 21 September 2026