Privacy Policy - BRANDLEX GROUP, S.L.
Version: 2.1 | Publication date: July 08, 2026
Clause 1: Identification of the Data Controller
Pursuant to Regulation (EU) 2016/679 (“GDPR”) and Spanish Organic Law 3/2018 (“LOPDGDD”), the data subject is informed that the controller of the personal data collected through this website is BRANDLEX GROUP, S.L., Tax ID B75931832, registered office at Plaza de San Cristobal, 14, 03002, Alicante, Spain, contact email info@brand-lex.com, contact phone +34 744 74 34 62. BRANDLEX GROUP S.L. acts as data controller in relation to personal data processed within its business, technological and consulting activity, in strict compliance with EU data protection law.
Clause 2: Definitions and applicable regulatory framework
For the purposes of this Privacy Policy: “Personal data” means any information about an identified or identifiable natural person (art. 4.1 GDPR); “Data subject” means the natural person whose data are processed; “Processing” means any operation performed on personal data; “Controller” means the legal person determining the purposes and means of processing; “Processor” means the person processing data on behalf of the controller; and “International data transfer” means sending personal data outside the European Economic Area. Processing by BRANDLEX GROUP, S.L. is governed by the GDPR, the LOPDGDD, Spanish Law 34/2002 (LSSI-CE), EDPB guidelines, and, for transfers, instruments recognised by the European Commission such as Standard Contractual Clauses (SCCs).
Clause 3: Principles applicable to the processing of personal data
Processing by BRANDLEX GROUP, S.L. complies with the principles of Article 5 GDPR: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability, which BRANDLEX GROUP, S.L. can demonstrate through appropriate technical, organisational and documentary measures.
Clause 4: Categories of personal data processed
BRANDLEX GROUP, S.L. processes only general-nature personal data, avoiding special categories under Article 9 GDPR unless expressly authorised or legally required. Categories include: identification data; contact details; professional data; browsing and technical data (where the relevant cookies have been accepted); electronic communications data; and economic, contractual and transactional data, only within contractual or pre-contractual relationships. Specially protected data (ethnic origin, political opinions, religious beliefs, genetic data, health data, sexual orientation or trade union membership) are never systematically processed.
Clause 5: Purposes of processing and legal basis
Data are processed for specific, explicit and legitimate purposes (art. 5.1.b GDPR), on the legal basis under Article 6 GDPR applicable to each case: (a) contact-form and meeting management, on legitimate interest (art. 6.1.f); (b) provision of contracted services, on performance of contract (art. 6.1.b); (c) newsletters and promotional communications, on express consent (art. 6.1.a); (d) statistical analysis via cookies, on informed consent given through the cookie panel (art. 5.3 ePrivacy Directive and art. 6.1.a GDPR); (e) compliance with legal obligations (art. 6.1.c); (f) management of supplier and collaborator relationships (art. 6.1.b and 6.1.f); and (g) prevention of and response to security incidents (art. 6.1.f). Any future different or incompatible processing will require the data subject’s prior, specific consent.
Clause 6: Data retention periods
Contact form or meeting request data are kept for a maximum of 12 months from the last interaction; client data, for the duration of the contract plus 6 additional years for tax and commercial obligations; newsletter data, until consent is withdrawn or after 2 years of inactivity; cookie-based data, per the Cookies Policy; supplier/collaborator data, during the relationship plus 5 additional years; and security-incident data, a maximum of 3 years unless judicial or administrative proceedings are ongoing. After these periods, data are securely deleted or blocked in accordance with Article 32 LOPDGDD.
Clause 7: Data recipients and processors
BRANDLEX GROUP, S.L. does not disclose or transfer personal data to third parties except where necessary to provide a contracted service, where required by law, or with the data subject’s express consent. For auxiliary, administrative, technological or support functions, BRANDLEX GROUP, S.L. may grant access to external providers acting as processors (art. 28 GDPR), under written data processing agreements meeting the guarantees required by that article. Recipients or processors may include cloud infrastructure providers, email marketing platforms, external advisors, and entities of the BRANDLEX group, in particular Gualet SpA (trading as BRANDLEX Chile), within the framework of internal operating relations, with the guarantees set out in Clause 8 (international transfers). Under no circumstances is there any sale, rental, or free or paid transfer of personal data to third parties unrelated to the activity of BRANDLEX GROUP, S.L.
Clause 8: International data transfers
BRANDLEX GROUP, S.L. may carry out international transfers of personal data outside the European Economic Area (EEA) exclusively where there is a European Commission adequacy decision (art. 45 GDPR), Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914), Binding Corporate Rules (art. 47 GDPR), or the data subject’s explicit consent as a last resort (art. 49.1.a GDPR).
In particular, BRANDLEX GROUP, S.L. maintains operational relations with its associated entity Gualet SpA, (trading as BRANDLEX Chile), incorporated in the Republic of Chile, a country that currently has no adequacy decision from the European Commission. Accordingly, any data flow to that entity takes place under a bilateral agreement based on the Standard Contractual Clauses (Implementing Decision (EU) 2021/914, modular version), with a prior transfer risk assessment (including an analysis of local legislation), reinforced technical and organisational measures (encryption, pseudonymisation, access control in line with EDPB Guidelines 01/2020), and access limited to what is strictly necessary for the specific engagement or contractual relationship.
In addition, certain technology providers based in the USA or other third countries may access personal data only under updated SCCs, after verifying that their conditions respect European standards. BRANDLEX GROUP, S.L. keeps a register of international transfers in accordance with the accountability principle, available to the competent supervisory authority.
Clause 9: Rights of data subjects
Data subjects may exercise, free of charge, the rights of access (art. 15 GDPR), rectification (art. 16), erasure (art. 17), restriction (art. 18), portability (art. 20), objection (art. 21), the right not to be subject to automated decisions (art. 22), and the right to withdraw consent, by writing to info@brand-lex.com with their name, the right being exercised, the data concerned, and a copy of an identity document. BRANDLEX GROUP, S.L. will respond within a maximum of one (1) calendar month, extendable to two (2) months for particularly complex requests (art. 12.3 GDPR).
Data subjects may lodge a complaint with the Spanish Data Protection Agency (AEPD), through its electronic office: www.aepd.es.
Without prejudice to the foregoing, and in accordance with Article 77.1 GDPR, the data subject may also lodge a complaint with the supervisory authority of the EU Member State of their habitual residence, place of work, or the place of the alleged infringement.
Clause 10: Security and confidentiality measures
BRANDLEX GROUP, S.L. has implemented technical and organisational measures appropriate to the risk (art. 32 GDPR), including access controls, encryption in transit and at rest, intrusion detection systems, regular backups, strong password management, activity logging and auditing, breach-notification protocols within a maximum of 72 hours (art. 33 GDPR), ongoing staff training, and periodic review of security measures. All personnel, including authorised external collaborators, are subject to ongoing confidentiality duties.
Clause 11: Automated decisions and profiling
BRANDLEX GROUP, S.L. does not make decisions based solely on automated processing that produce significant legal effects on the data subject (art. 22 GDPR). Should such processing be implemented in the future, meaningful human intervention, prior information on the logic applied, and the right to challenge the decision will be guaranteed, with a DPIA where applicable. BRANDLEX GROUP, S.L. may build basic, non-automated profiles for content personalisation, always on a valid legal basis and without discriminatory effects; the data subject may object at any time.
Clause 12: Changes to the Privacy Policy
This Policy may be updated due to legislative changes, EDPB or AEPD guidance, new processing activities, or changes to BRANDLEX GROUP, S.L.’s structure or technology. The updated version will be published on the website indicating the last-update date, with clear and advance notice of any substantial change, and renewed consent will be sought where a change is substantive for processing based on that legal basis.
Clause 13: Final provisions
This Privacy Policy constitutes BRANDLEX GROUP, S.L.’s internal data protection framework, complements any specific notice given at data collection points, and is governed by Spanish and European law. For any dispute concerning its interpretation, application or validity, the parties submit to the Courts of Alicante (Spain), without prejudice to the rights of data subjects as consumers or residents of another EU Member State.
BRANDLEX GROUP, S.L.
Corporate name: BRANDLEX GROUP, S.L.
Tax ID: B75931832
Registered office: Plaza de San Cristóbal, 14, 03002, Alicante, Spain
Website: https://www.brand-lex.com
Contact Email: info@brand-lex.com
Effective Date: July 08, 2026
Version: 2.1