Privacy Policy
Last updated: July 2026
This Privacy Policy explains how ZENTIC IT & CYBERSECURITY SOLUTIONS, S.L. ("Trustalia", "we") processes the personal data collected through the website www.trustalia.io, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).
1. Data controller
The controller of your personal data is:
- Legal name: ZENTIC IT & CYBERSECURITY SOLUTIONS, S.L.
- Tax ID (CIF): B21820477
- Address: C/ Andrade 156-A 1º-2º, 08020 Barcelona, Spain
- Email: hello@trustalia.io
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer, whom you can contact regarding any matter relating to the processing of your personal data at dpo@trustalia.io.
3. What data we collect
When you submit the contact or demo-request form, we collect the following personal data that you provide:
- Full name
- Work email address
- Company (optional)
- The message you write
The form may also request non-identifying information (for example, team size). Where such information does not allow you to be identified, it is not personal data and falls outside the scope of this policy.
Providing this data is voluntary. However, the fields marked as required are necessary in order to handle your request; if you do not provide them, we will not be able to process your enquiry.
We also process certain technical data (such as the IP address) strictly to protect the form against abuse and spam.
The processing of data through cookies and similar technologies is described in our Cookie Policy.
4. Purposes and legal basis
We process your personal data for the following purposes:
a) To handle your request, schedule a demo and contact you about Trustalia.
Legal basis: the taking of steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR).
b) Abuse prevention and form security.
Legal basis: our legitimate interest in keeping the service secure and free from fraud and spam (Art. 6(1)(f) GDPR).
We do not use your data to send marketing communications.
5. Retention
We keep your data only for as long as necessary to handle your request and any related follow-up. If no business relationship arises, we delete or anonymize your contact data within a maximum of 12 months from the last contact.
6. Recipients and processors
The form submission is delivered by email through Microsoft Azure Communication Services (Microsoft Corporation and its affiliates), which acts as a processor under Art. 28 GDPR. The email is processed within the European Union (Azure West Europe region).
No other processors are involved. We do not sell your personal data, nor do we share it with third parties for their own marketing.
7. International transfers
As a general rule, your data is processed within the European Economic Area (EEA).
Our provider Microsoft belongs to a group whose parent company is in the United States. To the extent that any processing might involve an international data transfer, such transfer is covered by appropriate safeguards under Chapter V of the GDPR, in particular the European Commission's Standard Contractual Clauses incorporated in Microsoft's Data Protection Addendum (DPA). Microsoft is also certified under the EU-U.S. Data Privacy Framework. You may request a copy of these safeguards by writing to hello@trustalia.io.
8. Your rights
You can exercise the following rights at any time by writing to hello@trustalia.io, stating the right you wish to exercise. We may ask you to verify your identity:
- Access to your personal data
- Rectification of inaccurate data
- Erasure (right to be forgotten)
- Restriction of processing
- Objection to processing
- Portability of the data
- Withdrawal of consent at any time, without affecting the lawfulness of processing carried out before withdrawal
If you believe your rights have been infringed, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es.
9. Automated decisions and profiling
We do not make decisions based solely on the automated processing of your data, including profiling, that produce legal effects concerning you or similarly significantly affect you.
10. Security
We apply appropriate technical and organizational measures to protect your data against destruction, loss, alteration or unauthorized access, including encryption in transit and at rest and strict access controls.
11. Minors
Our website and services are aimed at professionals and businesses, not at minors. We do not knowingly collect data from minors.
12. Changes to this policy
We may update this policy to reflect legal or operational changes. The most recent version will always be available on this page, indicating the date of the last update.