Privacy policy
Last updated: June 2026. This Privacy Policy describes in detail how Wixet Intelligence Systems SL processes personal data in connection with this website, its forms, communications, embedded content, security mechanisms, aggregated analytics and related services.
This text has been drafted with reference to Regulation (EU) 2016/679, Spanish Organic Law 3/2018 on Data Protection and Digital Rights Guarantee, Spanish Law 34/2002 on information society services and electronic commerce, and general principles of transparency, data minimization and accountability. It does not replace individualized legal advice.
1. Data controller
The data controller is Wixet Intelligence Systems SL, Tax ID B88657507, registered office at Calle Fragua, 4 - B, Santovenia de Pisuerga, 47155, Valladolid, Spain. Contact email: [email protected]. Phone: +34 644 281 363.
For any matter relating to privacy, data protection, rights requests, information security or interpretation of this policy, the data subject may contact the email address above. In order to process a request properly, Wixet may request reasonable additional information to identify the requester, verify the legitimacy of the request and clarify its scope.
2. Scope
This policy applies to personal data processed through the domain https://wixet.com, its pages, contact forms, communications initiated from the website, technical logs, anti-abuse mechanisms, aggregated analytics, embedded content and links or integrations forming part of the website experience.
It does not govern processing carried out by third-party websites, social networks, repositories, video platforms, infrastructure providers or services when they act under their own terms. If you access an external link, interact with a third-party platform or load embedded content, that third party may apply its own policies, notices, legal bases and control mechanisms.
3. Principles applied
Wixet seeks to process personal data according to the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality and accountability.
In practical terms, the website is designed to collect only the information necessary to respond to contacts, protect the service, measure website use in aggregated form and comply with legal obligations. Wixet does not sell personal data, does not use advertising cookies, does not create commercial profiles of visitors and does not enable invasive tracking tools by default.
4. Categories of data processed
Depending on how you interact with the website, Wixet may process the following categories of data:
- Identification and contact data: name, email address, phone number, company, organization, role or equivalent data voluntarily provided.
- Professional or project information: project type, technical description, needs, timelines, operational context, security requirements, contact preferences and free-text message content.
- Technical navigation and security data: IP address, user agent, request headers, date and time, requested route, network information, anti-abuse signals and logs generated by hosting, DNS, security or content delivery providers.
- Form metadata: language, consent confirmation, anti-spam validation result, technical identifiers required to process the submission and minimal request audit data.
- Aggregated analytics data: page views, visited routes, approximate country, traffic volume, device or browser data in aggregated form where Cloudflare Web Analytics is enabled.
- Third-party interaction data: data that may be processed by YouTube/Google, GitHub, X/Twitter, Telegram or other third parties when you access external links or load embedded content.
- Data arising from subsequent communications: email history, proposals, meetings, agreements, technical documentation or information required for a potential professional relationship.
5. Purposes of processing
Personal data may be processed for the following purposes:
- Responding to enquiries, information requests, project proposals, professional communications or requests sent by the data subject.
- Managing pre-contractual, commercial or professional relationships initiated by the user.
- Operating, maintaining, protecting, auditing and improving the website and its forms.
- Preventing spam, abuse, fraud, automated submissions, malicious activity, attacks, abusive scraping or unauthorized access.
- Obtaining aggregated statistics to understand general website use without identifying individual visitors.
- Complying with legal, regulatory, accounting, tax, security or retention obligations where applicable.
- Defending rights, responding to claims, documenting technical decisions or protecting legitimate interests of Wixet, its clients or third parties.
6. Legal bases
The legal bases that may legitimize processing include, depending on the case:
- Consent: when you submit the form, accept the policy, decide to load an embedded video or perform a voluntary action requiring your intervention.
- Pre-contractual measures: when you contact Wixet to request information, quotes, proposals, services or professional discussions before contracting.
- Contract performance: if a communication results in a service relationship or professional collaboration.
- Legitimate interest: website security, abuse prevention, basic management of professional contacts, reasonable retention of communications, service improvement and defense against claims.
- Legal obligation: where Wixet must retain, disclose or process data due to legal requirements, valid authority requests or compliance obligations.
7. Contact form
The contact form allows messages to be sent directly to Wixet. The data entered is used to receive, classify, reply to and follow up on the request. It is not used to subscribe users to unsolicited newsletters, trigger automated marketing sequences, score leads, create commercial profiles or sell information to third parties.
The form may include Cloudflare Turnstile or equivalent anti-abuse mechanisms. These controls help distinguish legitimate interactions from automated traffic, spam or malicious use. Their purpose is strictly the security and availability of the contact channel.
8. Providers, processors and third parties
Wixet may rely on technology providers to operate the website. Depending on the service, these providers may act as processors, independent controllers or infrastructure providers. The following may be involved:
- Cloudflare: DNS, hosting, CDN, edge security, Pages Functions, Turnstile, technical logs and aggregated web analytics.
- Resend: delivery of transactional email generated by the contact form.
- YouTube/Google: playback of embedded videos only when the user decides to load them.
- GitHub, X/Twitter and Telegram: external platforms linked from the website, subject to their own policies when visited.
- Professional providers: legal, accounting, technical or administrative advisors where necessary to comply with obligations or manage professional relationships.
Wixet seeks to select appropriate providers, limit their involvement to what is necessary and apply reasonable measures so that processing remains proportionate to the service provided.
9. International transfers
Some providers may be located outside the European Economic Area or use internationally distributed infrastructure. Where applicable, international transfers should be covered by mechanisms recognized by applicable law, such as adequacy decisions, Standard Contractual Clauses, data processing agreements, binding corporate rules or other valid instruments.
The use of global services may involve certain technical metadata being processed in different jurisdictions to ensure availability, security, content delivery or protection against abuse.
10. Data retention
Data will be retained for the time necessary to fulfill the purpose for which it was collected and, afterwards, for the periods required or permitted by applicable law or reasonable defense needs against claims.
- Contact enquiries may be retained while the request is handled and for a reasonable follow-up period.
- Communications resulting in a professional relationship may be retained during the relationship and applicable legal limitation periods.
- Technical and security logs will be retained according to operational needs, abuse prevention and provider retention policies.
- Aggregated analytics data is not intended to identify individual visitors and may be retained while useful for general metrics.
11. Security
Wixet applies reasonable technical and organizational measures to protect data against unauthorized access, loss, alteration, improper disclosure or destruction. These measures may include HTTPS, access controls, reputable infrastructure providers, data minimization, anti-abuse mechanisms, configuration reviews and limitation of third-party dependencies.
No internet-connected system can guarantee absolute security. In the event of an incident affecting personal data that must legally be notified, Wixet will act according to applicable law and, where appropriate, notify the competent authority or affected persons.
12. Cookies, analytics and similar technologies
The website is designed to avoid advertising cookies, behavioral tracking and marketing pixels. The Cookie Policy describes in greater detail the technologies used or contemplated, why a consent banner is not currently shown and the circumstances under which that approach would need to be reviewed.
13. Videos and embedded content
Embedded videos are not loaded automatically when opening the page. A loading block is shown first and external content is requested only when the user decides to play it. From that moment, the relevant third party may process data according to its own terms and policies.
14. Recipients and disclosures
Wixet does not sell personal data. Data may be accessed by authorized Wixet personnel, collaborators or providers who need to process the information to respond to requests, operate the website, provide services, comply with legal obligations or defend rights. Data may also be disclosed to authorities, courts, law enforcement bodies, advisors or legitimately entitled third parties where there is a legal obligation, valid request or sufficient legitimate interest.
15. Data subject rights
Data subjects may exercise, under the terms provided by applicable law, rights of access, rectification, erasure, objection, restriction of processing, portability, withdrawal of consent and the right not to be subject to decisions based solely on automated processing where applicable.
To exercise rights, send a request to [email protected]. The request should clearly state the right exercised, the scope of the request and the information necessary to verify identity. Withdrawal of consent will not affect the lawfulness of prior processing or processing based on another legal basis.
16. Minors and third-party data
The website is not specifically directed at minors. Users must not submit data relating to minors or personal data of third parties unless they have sufficient legitimacy to do so. Anyone providing third-party data declares that they have informed those persons and have an appropriate legal basis.
17. Accuracy of information
The user is responsible for ensuring that data provided is accurate, complete, lawful and up to date. Wixet may discard, block or request clarification regarding communications that appear false, abusive, incomplete, malicious or unrelated to a legitimate purpose.
18. Complaints
If you believe that the processing of your data does not comply with applicable law, you may contact Wixet first so the matter can be reviewed. You also have the right to lodge a complaint with the Spanish Data Protection Agency or the competent supervisory authority.
19. Changes to this policy
Wixet may amend this Privacy Policy to reflect legal, technical, operational, organizational or service changes. The applicable version will be the one published on this page. If changes are substantial and the law requires it, reasonable measures will be taken to inform affected persons or obtain consent where appropriate.