1. Data controller
The controller responsible for personal data processed through this corporate website is listed below.
No separate data-protection-officer contact is published for this website; privacy enquiries and rights requests are handled through the address above.
2. Legal framework
Personal data is processed in accordance with applicable data-protection law, including Regulation (EU) 2016/679 (General Data Protection Regulation, or GDPR) and Spanish Organic Law 3/2018 on Personal Data Protection and the guarantee of digital rights.
3. Personal data and sources
We receive contact and professional details directly from you when you email us, together with the content of your enquiry and subsequent correspondence. The website and hosting infrastructure necessarily receive technical connection data such as IP address, date and time, requested resource, browser or user agent and security events.
Only after analytics consent, Google Analytics 4 receives a pseudonymous client identifier, page and interaction events, referral source, approximate geography, and browser/device details. Limited JavaScript or resource-error descriptions may also be sent; email-like strings and URL query fragments are removed first.
4. Purposes and legal bases
- Delivering and securing the site: technical connection and security data are processed to provide the service, prevent abuse and diagnose availability issues, based on our legitimate interest in operating a secure corporate website and applicable legal obligations.
- Business enquiries: details in emails are processed to respond and follow up, based on steps requested before a possible contract or our legitimate interest in handling relevant professional communications.
- Optional analytics: GA4 measures use and diagnoses errors only on the basis of your consent. You may withdraw it through Cookie settings at any time.
- Legal compliance: information may be retained or disclosed where required to establish, exercise or defend legal claims or comply with law.
Google Signals, advertising storage, ad-user-data, advertising personalisation, functionality storage and personalisation storage are disabled in the website implementation.
5. Retention
- Email enquiries are kept only while needed to answer and manage the professional relationship, and afterwards for limitation periods applicable to possible claims or legal duties.
- Technical and security records are kept for the shortest period needed for delivery, troubleshooting, fraud prevention and legal compliance under the hosting provider’s configured controls.
- Your cookie choice is stored for no more than 24 months. GA4 first-party identifier cookies have a default expiry of two years and may be removed sooner through Cookie settings or browser controls. Analytics event data follows the retention setting selected in the linked GA4 property.
6. Recipients and service providers
Google Ireland Limited and its affiliates provide Firebase Hosting and, after consent, Google Tag Manager and Google Analytics 4. Email providers process correspondence when you choose to contact us. Data is not sold through this corporate website. It may be disclosed to public authorities or professional advisers only where legally required or necessary for legal claims.
Provider information is available in Google’s Privacy Policy and Firebase privacy documentation.
7. International transfers
Google or email-service providers may process data outside the European Economic Area. Depending on the destination and service, safeguards may include an adequacy decision, participation in the EU–US Data Privacy Framework, or European Commission Standard Contractual Clauses. You may request information about safeguards by emailing us.
8. Your rights and consent withdrawal
Subject to applicable law, you may request access, rectification, erasure, restriction or portability, or object to processing. You may withdraw analytics consent at any time without affecting the lawfulness of earlier processing. To exercise a right, email info@teknexchange.com, identify the request and provide only the information reasonably needed to verify it.
You may lodge a complaint with the Spanish Data Protection Agency (AEPD) or another competent supervisory authority.
9. Voluntary information and automated decisions
This site has no contact form or user account. Sending an email is voluntary, but we may be unable to answer if you do not provide a return address or enough context. Do not include sensitive personal data unless it is strictly necessary.
The corporate website does not make decisions based solely on automated processing that produce legal or similarly significant effects, and it does not profile visitors for advertising.
10. Security
Tekne & Creemy Group S.L. applies proportionate technical and organisational measures designed to protect personal data against unauthorised access, alteration, loss or disclosure. No internet service can guarantee absolute security.
11. Scope of this notice
This notice covers the public corporate website and enquiries sent through its published email address. It does not describe operational bidstream or advertising-identifier processing. If Tekne Exchange activates an ad-tech platform that performs that processing, a separate platform privacy notice and contractual documentation must be published before activation.
12. Changes to this policy
We may update this Privacy Policy to reflect legal, technical or operational changes. Material changes affecting consent will cause the site to ask for a new choice. The current version and update date are always available on this page.
Back to home ↗