Reconectando con el servidor

Mantén esta pestaña abierta: tu trabajo no se ha perdido.

No hemos podido reconectar

Recarga la página para continuar donde lo dejaste.

La sesión ha caducado

Vuelve a cargar la página para iniciar sesión de nuevo.

Spain's authority is now operating and tick-box channels are under review. Would yours hold up?Act now →
Legal information

Privacy policy

Courtesy translation. In case of discrepancy the Spanish version prevails; it is the only one with legal effect. See the Spanish version

Version v1.0 · last updated: 27 de julio de 2026

This policy explains how DSA Nexus S.L. handles the personal data collected through the site www.dsacompliance.net, in compliance with Regulation (EU) 2016/679 (GDPR) and Spain's Ley Orgánica 3/2018 on Personal Data Protection and the guarantee of digital rights (LOPDGDD).

It does not cover the data processing each customer carries out inside the DSA Compliance platform: in that case the customer is the controller and DSA Nexus S.L. acts as a processor, under the article 28 GDPR agreement that applies.

1. Data controller

OwnerDSA Nexus S.L. (Sociedad Unipersonal)
Tax ID (NIF)B06995476
AddressC/ Gerardo Cordón 11, Puerta C, Planta 4 · 28017 Madrid, España
Email addresshola@dsanexus.com
Phone+34 91 829 31 79
Data protection officerdpo@dsanexus.com

2. What data we process, and where it comes from

All data comes from the data subject themselves. None is obtained from third-party sources, and no profiles are built.

  • Contact form: name, work email, company, headcount band, country, reason for the enquiry and whatever message you choose to include.
  • Exposure test and calculator: email address and the answers or parameters entered, so we can send you the result.
  • Product sheet download: email address.
  • Regulatory Radar subscription: email address.
  • Technical connection data: what the server logs for security and operation (IP address, date and time, resource requested and user agent).

We do not ask for special category data under article 9 GDPR. Please don't include that kind of information in the free-text field of the form.

3. Purposes and lawful bases

PurposeLawful basis
Handling your request for information, a demo or an assessment, and the commercial contact arising from it The data subject's consent (art. 6(1)(a) GDPR) and pre-contractual steps at their request (art. 6(1)(b) GDPR)
Sending you the exposure test result, the calculator report or the product sheet you requested The data subject's consent (art. 6(1)(a) GDPR)
Sending the Regulatory Radar to subscribers The data subject's consent (art. 6(1)(a) GDPR), withdrawable at any time
Keeping the site secure and preventing abuse of the forms The controller's legitimate interest in the security of its systems (art. 6(1)(f) GDPR)
Keeping evidence of the consent given Meeting the accountability duty of art. 5(2) GDPR

Providing the fields marked as required is necessary to handle the request; without them we cannot answer it. All other fields are optional.

4. Retention periods

  • Contact requests: for as long as the relationship arising from the request lasts and, afterwards, for a maximum of two years from the last contact, unless you ask for erasure sooner.
  • Regulatory Radar subscription: until you withdraw consent or unsubscribe, which is available in every issue.
  • Evidence of consent: for as long as we may be required to evidence it and for the limitation periods of the relevant legal actions.
  • Server technical logs: strictly as long as needed to ensure security, up to a maximum of twelve months.

5. Recipients and processors

We do not disclose your data to third parties or use it for advertising purposes other than those described. Providers acting as processors, under an article 28 GDPR contract, are involved in delivering the service:

  • Hosting of the site, the database and corporate email: SmarterASP.NET (VPS semidedicado).

International transfers

Our hosting provider is established outside the European Economic Area, so access to the data from a third country for infrastructure administration and support cannot be ruled out. Article 44 GDPR treats that remote access as an international transfer too, even where the servers sit in Europe.

Those transfers rely on the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914, together with the applicable supplementary measures: encryption in transit and at rest, access control, and minimisation of the data the provider can reach. You can request information about these safeguards by writing to dpo@dsanexus.com.

6. Automated decisions and profiling

No decisions are taken based solely on automated processing that produce legal effects or similarly significantly affect you, within the meaning of article 22 GDPR. The exposure test and calculator results are indicative and a person reviews them before replying to you.

7. Your rights

You may exercise the following rights at any time:

  • Access (art. 15): to know what data of yours we process.
  • Rectification (art. 16): to correct inaccurate data.
  • Erasure (art. 17): to have data deleted once it is no longer needed.
  • Restriction (art. 18): to have data kept but not processed while a dispute is resolved.
  • Portability (art. 20): to receive your data in a structured, commonly used format.
  • Objection (art. 21): to object to processing based on legitimate interest.
  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.

To exercise them, write to dpo@dsanexus.com stating which right you wish to exercise. We will reply within one month of receiving the request, extendable by two further months where complexity requires, under article 12(3) GDPR.

If you believe the processing does not comply with the rules, you may lodge a complaint with the Spanish Data Protection Agency (AEPD) (C/ Jorge Juan 6, 28001 Madrid · www.aepd.es), without prejudice to contacting us first.

8. Security measures

Aplicamos las medidas técnicas y organizativas apropiadas exigidas por el artículo 32 del RGPD: cifrado de las comunicaciones, control de acceso por rol, registro de accesos, copias de seguridad periódicas y separación de entornos. El sitio no instala cookies de publicidad ni elabora perfiles; la única medición de audiencia requiere su consentimiento previo y no se activa si usted la rechaza. Puede consultar el detalle en la cookie policy.

9. Minors

This site is aimed at professionals and organisations. It is not intended for children under 14 and we do not knowingly collect their data.

10. Changes to this policy

We may update this policy when the purposes, the legal bases or the applicable rules change. Each version is identified by its number and date in the header of this page. The version in force is v1.0, from 27 de julio de 2026.

Cookie policy Legal notice