Informative translation. In the event of any discrepancy, the Spanish version prevails.
This Policy explains how personal data obtained through the Site bomontec.net, its forms, assessment requests and the associated technical security controls are processed.
Data controller
The data controller is BOMONTE TECNOLOGIAS, S.L..
| Item | Information |
|---|---|
| Owner / service provider | BOMONTE TECNOLOGIAS, S.L. |
| Tax ID (NIF) | B83820696 |
| Registered address | C.C. El Palacio, local 26, Ctra. de Majadahonda 50, 28660 Boadilla del Monte (Madrid), España |
| Company registration details | Registro Mercantil de Madrid, Tomo 19.466, Folio 14, Sección 8, Hoja M-341632 |
| Telephone | +34 912 161 400 |
| Contact email address | contacto@bomontec.net |
| Privacy and data subject rights channel | gdpr@bomontec.net |
| Domain | bomontec.net |
The email address gdpr@bomontec.net is a channel for privacy matters and the exercise of data subject rights. It is not presented as a Data Protection Officer unless BOMONTE TECNOLOGIAS, S.L. formally designates and publishes one.
Data we may process
- Identification and contact data: first name, surname, email address, telephone number where provided, country and organisation.
- Professional and project data: position, entity, sector, area of interest, commercial proposal of interest and requirements communicated voluntarily.
- Content of enquiries: the message, documentation or information you choose to send.
- Technical and security data: IP address, date and time, URL, HTTP method, user agent, technical identifiers, anti-abuse signals from the form (submission limit, honeypot, verification code (captcha)), errors and security logs.
- Communication preference data where the data subject asks to receive commercial information.
Purposes and legal bases
Data are processed for the purposes and on the legal bases set out below:
| Purpose | Description | Legal basis |
|---|---|---|
| Handling enquiries and requests | Managing the enquiry, replying, arranging meetings and coordinating contact. | Art. 6(1)(b) GDPR where these are pre-contractual steps taken at your request; Art. 6(1)(f) GDPR for managing legitimate professional relationships where applicable. |
| Initial assessment | Preparing and conducting the requested assessment session and drawing up preliminary conclusions. | Art. 6(1)(b) GDPR, pre-contractual steps at the request of the data subject or of the entity they represent. |
| Preparing proposals and B2B relationship | Preparing offers, coordinating pre-sales, support and the professional relationship. | Art. 6(1)(b) GDPR and, for professional contacts associated with a legal entity, legitimate interest within the applicable legal limits. |
| Protection of high-profile individuals | Handling requests for a private, confidential review. | Art. 6(1)(b) GDPR, pre-contractual steps at the request of the data subject. |
| Site security | Detecting abuse, fraud, malware and intrusion attempts, investigating incidents, generating evidence and protecting the infrastructure. | Art. 6(1)(f) GDPR: legitimate interest in ensuring confidentiality, integrity, availability and defence against attacks. |
| Legal compliance and defence of claims | Meeting obligations and valid requests and retaining the necessary evidence. | Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR. |
| Optional commercial communications | Sending news, invitations or information about the group's services and products where appropriate. | Consent, Art. 6(1)(a) GDPR, where required; and the LSSI rules on commercial communications. |
| Audience measurement (optional) | Anonymised analytics to understand which content is of most interest. | Consent, Art. 6(1)(a) GDPR and Art. 22.2 LSSI. Only if you accept the “Analytics” category. |
Mandatory nature of the data
Fields marked as mandatory are necessary to process the corresponding request. Failure to provide the minimum data may make it impossible to deal with it. Subscribing to commercial communications is voluntary and is not a condition for handling an enquiry or assessment.
Retention
Data will be kept for as long as necessary for the corresponding purpose and, thereafter, for the applicable limitation or statutory retention periods, duly blocked where appropriate. Commercial requests that do not lead to a professional relationship are reviewed and deleted in accordance with the configured retention policy (24 months as a reference). Technical and security logs will be kept for a period proportionate to their purpose and may be retained for longer where they are linked to an incident, investigation, legal obligation or the defence of claims.
Recipients and processors
Data are not sold. They may be accessed by providers that render services to BOMONTE TECNOLOGIAS, S.L. as data processors, such as hosting, infrastructure, email, support, security or corporate tools, under the contractual obligations laid down in the GDPR.
Data may also be disclosed to authorities, courts, tribunals, law enforcement agencies or other bodies where there is a legal obligation or a valid request, or where necessary to establish, exercise or defend legal claims.
Where a request requires the involvement of a manufacturer, partner or integrator (for example, Samsung SDS in mobility projects), only the necessary data will be disclosed, on an appropriate legal basis and under the applicable contractual framework. Should this involve an international transfer, the safeguards required by Chapter V of the GDPR will be applied beforehand and you will be informed where appropriate.
International transfers
In the Site's default configuration, no analytics, advertising or third-party resources are loaded while browsing (fonts and other resources are served from the Site's own domain), so no international transfers arising from mere browsing are envisaged. If audience analytics is enabled (only with consent), the Cookies Policy will provide information on the provider and the applicable safeguards.
Automated decision-making and profiling
The Site does not make decisions producing legal or similarly significant effects based solely on automated processing. Automated security measures (for example, form submission limits or the blocking of abusive traffic) serve a technical protective purpose and may be reviewed where there is a legitimate incident.
Rights of data subjects
You may exercise your rights of access, rectification, erasure, objection, restriction and portability, where applicable, and withdraw your consent without affecting the lawfulness of prior processing, by writing to gdpr@bomontec.net or to the controller's registered address. The request must make it reasonably possible to verify your identity; additional documentation will only be requested where necessary and proportionate.
You may also lodge a complaint with the Agencia Española de Protección de Datos (AEPD, the Spanish Data Protection Authority) if you consider that the processing infringes the applicable legislation.
Commercial communications
Where communications are sent on the basis of consent, such consent will be specific, freely given and unambiguous and may be withdrawn at any time through the mechanism indicated in each communication or by writing to the privacy channel. Withdrawal will not affect the provision of services already requested.
Minors
The Site's services are aimed at organisations and professionals and not at minors. We do not knowingly seek to collect data from minors through the commercial forms.
Security
BOMONTE TECNOLOGIAS, S.L. applies reasonable technical and organisational measures for access control, logging, perimeter protection, updates, backups and incident management, in proportion to the risk. No system connected to the Internet can guarantee absolute security; you should protect your credentials and report any unauthorised use.
External links
Links to the websites of the group's products, manufacturers, bodies, social networks or other third parties lead to services with their own policies. The mere presence of a link does not mean that those third parties receive data from the Site before you access their page.
Changes to this policy
This Policy may be updated when the Site, the processing operations, the providers or the legislation change. The date of the version in force is shown at the end of the document.
Public forms and ordinary email must not be used for classified information, keys, passwords, third-party secrets, sensitive indicators of compromise, operational configurations or documentation subject to special restrictions. Where a project so requires, an authorised channel and the corresponding processing arrangements will be agreed in advance.
Version 2.0 · Last updated: 05/10/2026
