Privacy Policy
Data controller
The controller responsible for processing your personal data is:
- Registered name
- BRANDING YOUR POS, S.L.
- Trading name
- BYP Global
- Tax ID (NIF)
- B90128240
- Registered office
- Avda. Eduardo Dato, 26, 5º B1, 41005 Sevilla, España
- Companies register
- Registro Mercantil de Sevilla, Tomo 5847, Folio 13, Sección 8, Hoja SE-100845
- info@byp-global.com
- Telephone
- +34 955 947 907
For any question relating to your personal data or to this policy, write to us at info@byp-global.com with "Data protection" in the subject line.
What data we process
We only process the data you give us voluntarily, together with the technical data your browsing generates. We do not buy databases and we do not obtain your data from third-party sources.
- Contact form data
- Name, email address, subject and the content of the message you send us.
- Direct communication data
- If you email or call us, whatever data you choose to share in that exchange.
- Technical browsing data
- IP address, browser type and version, operating system, language, pages visited and timestamp. This is generated automatically by the infrastructure serving the website and recorded in its activity logs.
- Preferences stored on your device
- Your chosen visual theme (light or dark) and a flag indicating whether you have visited before. These are stored in your own browser and do not reach our servers as identifying data.
This website has no private area, requires no user registration, does not sell products or services online, and never asks for bank or payment card details.
Why we use your data and on what legal basis
The General Data Protection Regulation requires a legal basis for every processing activity. Ours are as follows:
| Purpose | Legal basis |
|---|---|
| Handling and answering the enquiries you send us through the contact form, by email or by telephone. | Your consent, given when you send us the communication (Art. 6(1)(a) GDPR). |
| Managing the pre-contractual or contractual relationship if your enquiry leads to a service proposal. | Performance of a contract or of pre-contractual measures taken at your request (Art. 6(1)(b) GDPR). |
| Maintaining the security, availability and integrity of the website, and preventing abusive or fraudulent use. | Our legitimate interest in protecting our systems and their users (Art. 6(1)(f) GDPR). |
| Complying with the legal, accounting and tax obligations that apply to us. | Compliance with a legal obligation (Art. 6(1)(c) GDPR). |
We do not make automated decisions producing legal effects concerning you, and we do not build behavioural profiles from your data.
Who else has access to your data
We do not sell or transfer your personal data to third parties for commercial purposes. We do work with technology providers who, acting as data processors, access certain data solely in order to provide their service to us, under a contract binding them to confidentiality and to GDPR compliance:
| Provider | Service | Data | Location |
|---|---|---|---|
| EmailJS | Delivering contact form messages to our inbox. | Name, email, subject and message. | United States |
| Amazon Web Services | Website hosting (Amplify and CloudFront) and file storage (S3). | Technical browsing data and activity logs. | European Union (eu-west-3, Paris) and global delivery network. |
| Mux | Playback and delivery of the videos embedded in the website. | Technical playback and browsing data. | United States |
| Bunny.net | Content delivery network for images and video. | Technical browsing data. | European Union and global delivery network. |
| Google Maps | Embedded map showing our office location. | Technical browsing data, if you load the map. | United States |
We may also disclose your data to courts, tribunals, law enforcement bodies and public authorities where a legal obligation requires us to do so.
International transfers
Some of the providers listed above are established outside the European Economic Area, mainly in the United States. This involves an international transfer of data.
Those transfers rely on the safeguards set out in Chapter V of the GDPR: the European Commission's adequacy decision on the EU-US Data Privacy Framework where the provider is certified under it, or Standard Contractual Clauses approved by the European Commission together with any supplementary measures required.
You may ask us for further information about the safeguards applied to a specific transfer by writing to info@byp-global.com.
How long we keep your data
- Enquiry data that does not lead to a business relationship: kept for a maximum of twelve months from the last contact, then deleted.
- Client and contractual data: kept for the duration of the relationship and, once it ends, for the applicable statutory limitation periods under commercial, accounting and tax law.
- Server activity logs: kept for the retention period applied by our hosting provider, for security and diagnostic purposes.
- Preferences stored in your browser: until you clear them from your browser settings.
Once these periods expire, the data is deleted or anonymised so that it can no longer identify you.
Your rights
Data protection law grants you the following rights, which you may exercise free of charge:
- Access
- To know whether we process data about you and obtain a copy of it.
- Rectification
- To correct inaccurate data or complete incomplete data.
- Erasure
- To ask us to delete your data when it is no longer necessary for the purpose that gave rise to it.
- Objection
- To object to processing based on our legitimate interest, on grounds relating to your particular situation.
- Restriction
- To ask us to suspend processing while a challenge or complaint is verified.
- Portability
- To receive your data in a structured, commonly used format, or to ask us to transmit it to another controller.
- Withdrawal of consent
- To withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
To exercise them, send your request to info@byp-global.com or by post to Avda. San Francisco Javier, 9, 4ª planta, módulo 26, Edificio Sevilla 2, 41018 Sevilla, España, stating the right you wish to exercise and enclosing a copy of a document proving your identity. We will respond within one month of receiving the request.
If you believe we have not handled your request properly, or that the processing of your data breaches the applicable rules, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid — www.aepd.es), which is the competent supervisory authority.
Minors
This website is aimed at professionals and businesses, not at minors. We do not knowingly collect data from children under fourteen. If you become aware that a minor has provided us with data without the consent of their parents or guardians, please tell us and we will delete it.
Information security
We apply appropriate technical and organisational measures to protect your data against destruction, loss, alteration or unauthorised access, including HTTPS traffic encryption, system access controls and the selection of providers offering sufficient data protection guarantees.
No transmission of data over the internet can be guaranteed as absolutely secure. Should a security breach occur that presents a high risk to your rights, we will inform you and notify the supervisory authority in accordance with Articles 33 and 34 GDPR.
Changes to this policy
We may update this policy to reflect regulatory changes, new services, or changes in the way we process data. The version in force is always the one published on this page, and the date of the latest revision appears at the top of the document.
If a change materially affects processing based on your consent, we will inform you and, where appropriate, ask for fresh consent.