Table of contents
1. WEBSITE OWNER
2. PURPOSE
3. PERSONAL DATA PROCESSED BY MERELY ACCESSING THE WEBSITE
3.1. What data is processed
3.2. What this data is used for
3.3. Data recipients
3.4. Lawful processing
3.5. Data retention period
4. OTHER PROCESSING OF PERSONAL DATA
4.1. Cookies and similar technologies
4.2. Contact form
4.3. Product demo request
4.4. Newsletter subscription
4.5. Chatbot
4.6. “Ebooks” and “White papers” forms
4.7. “Watch webinar” form
4.8. “Let’s work together” form
5. USER RIGHTS AND HOW TO EXERCISE THEM
6. FURTHER INFORMATION
7. SECURITY POLICY
8. CUSTOMER SERVICE VIA WHATSAPP BUSINESS
1. WEBSITE OWNER
This website is the responsibility of TRUEITSYSTEMS S.L., with Tax ID (NIF) B87306841, a company with registered office at Calle Miguel Yuste 17, 28037 Madrid (hereinafter, “ICR” or “the Company”).
The Company has formally appointed a Data Protection Officer (hereinafter, the DPO), who may be contacted at dpo@icr-evolution.com.
2. PURPOSE
ICR respects the privacy rights of its Users and recognises the importance of protecting the personal data that the Company collects about its Users.
The purpose of this document is to inform website Users about the processing of personal data carried out on this website.
3. PERSONAL DATA PROCESSED BY MERELY ACCESSING THE WEBSITE
3.1. What data is processed
By merely accessing the website, the Company collects the IP address and other data relating to the connection and its origin. An IP address is a code that identifies the User’s internet connection at a specific time.
Only the User’s internet service provider can identify the subscriber to whom an IP address was assigned at a specific time.
Due to the nature of the server supporting the website, the User’s IP address is automatically recorded together with the date and time of access.
3.2. What this data is used for
This data is used solely to manage the normal operation of the website and to carry out statistical analyses of website usage.
3.3. Data recipients
The Company does not disclose this information to any third party unless required to do so by applicable law (for example, pursuant to an official request in the context of a police investigation).
3.4. Lawful processing
The legal basis for processing the IP address is the technological necessity of enabling the provision of the website.
3.5. Data retention period
IP addresses will be retained for a period of one month.
4. OTHER PROCESSING OF PERSONAL DATA
4.1. Cookies and similar technologies
The Company uses cookies and other similar mechanisms for storing and retrieving data on terminal equipment (hereinafter, cookies).
Cookies are files downloaded to the User’s browser that may subsequently be read by the Company. Cookies enable various functions, such as recognising a User who has previously accessed the website and analysing use of the web service in order to improve it. However, it is not possible to determine the User’s identity from the cookies used by ICR unless the User provides additional information through other means and that information can be linked to the cookies downloaded to their device. For further information, please refer to the Cookie Policy.
4.2. Contact form
ICR will process the data provided through the contact form for the purpose of responding to the contact request.
- Legal basis: The legal basis for the processing is the User’s consent, given when submitting the contact request.
- Retention period: The data will be processed for as long as necessary to resolve the User’s contact request. It will subsequently be blocked and retained for three years to address any potential liabilities arising from the processing.
You may withdraw your consent and exercise your rights at any time, as indicated in the section on data subjects’ rights in this Privacy Policy.
4.3. Product demo request
ICR will process the data provided through the form for the purpose of responding to the request.
- Legal basis: The legal basis for the processing is the User’s consent, given when submitting the request.
- Retention period: The data will be processed for as long as necessary to resolve the User’s request. It will subsequently be blocked and retained for three years to address any potential liabilities arising from the processing.
You may withdraw your consent and exercise your rights at any time, as indicated in the section on data subjects’ rights in this Privacy Policy.
4.4. Newsletter subscription
ICR will process the data provided through the subscription form in order to send you the newsletter and keep you informed about ICR products, services, events or news that may be of interest to you.
- Legal basis: The legal basis for this processing is your consent, given when submitting your newsletter subscription request.
- Retention period: The data will be processed indefinitely until you withdraw your consent or request the erasure of your data.
In each communication, the User may opt out of receiving this type of information using the specific unsubscribe mechanisms provided, and may also exercise, where applicable, the right to withdraw consent, object to processing or request erasure, as indicated in the section on data subjects’ rights in this Privacy Policy.
4.5. Chatbot
ICR will process the data provided through the chatbot in order to respond to a contact or demo request made by a customer contacting ICR through the chatbot. ICR does not require the inclusion of any specific personal data; therefore, any data processed will be voluntarily provided by the User.
- Legal basis: The legal basis for the processing is the User’s consent, given when submitting the request.
- Retention period: The data will be processed for as long as necessary to resolve the User’s contact request. It will subsequently be blocked and retained for three years to address any potential liabilities arising from the processing.
You may withdraw your consent and exercise your rights at any time, as indicated in the section on data subjects’ rights in this Privacy Policy.
4.6. “Ebooks” and “White papers” forms
ICR will process the data provided through the contact form for the purpose of handling the User’s download request.
- Legal basis: The legal basis for the processing is the User’s consent, given when submitting the request.
- Retention period: The data will be processed for as long as necessary to resolve the User’s request. It will subsequently be blocked and retained for three years to address any potential liabilities arising from the processing.
You may withdraw your consent and exercise your rights at any time, as indicated in the section on data subjects’ rights in this Privacy Policy.
4.7. “Watch webinar” form
ICR will process the data provided through the contact form for the purpose of responding to the request.
- Legal basis: The legal basis for the processing is the User’s consent, given when submitting the request.
- Retention period: The data will be processed for as long as necessary to resolve the User’s request. It will subsequently be blocked and retained for three years to address any potential liabilities arising from the processing.
You may withdraw your consent and exercise your rights at any time, as indicated in the section on data subjects’ rights in this Privacy Policy.
4.8. “Let’s work together” form
ICR will process the data provided through the form in order to respond to the contact and initiate a potential collaborative relationship between the parties.
- Legal basis: The legal basis for the processing is ICR’s legitimate interest in contacting the data subject who provides their email address through the form.
- Retention period: The data will be processed for as long as necessary to address the potential commercial partnership between the parties. Thereafter, retention periods will be linked to any commercial relationship established between the parties. Once that relationship has ended, the data will be blocked and retained for the period legally required to address any potential liabilities arising from the processing.
You may exercise your rights at any time, as indicated in the section on data subjects’ rights in this Privacy Policy.
5. USER RIGHTS AND HOW TO EXERCISE THEM
Data protection legislation guarantees Users the following rights:
- Access: Allows the User to know what information is held, where it was obtained from, to whom it has been disclosed and for what purposes it has been processed.
- Rectification: Allows the User to correct inaccurate or outdated data.
- Erasure: Allows the User to request that their data cease to be processed.
- Objection: Allows the User to request that their data cease to be used for a specific purpose.
- Restriction: Allows the User to restrict the processing of their data while allowing it to be retained for a subsequent purpose.
- Data portability: Allows the User to obtain a copy of their data in electronic format and, in certain circumstances, request that it be transmitted to another service provider. This right applies only to automated processing carried out with the User’s consent or for the performance of a contract.
- Withdrawal of consent: Allows the User to withdraw any consent previously given for the processing of their data. These rights require the possibility of identifying the User making the request and linking their identity to the data processed by the Company. However, the Company cannot establish this link with any of the data processed merely as a result of accessing the website, unless the User can provide documentation that enables their identification (for example, a certificate from their internet service provider indicating the IP address assigned to the User on a specific date and at a specific time).
Users are informed that they may exercise the aforementioned rights before the Company, as well as withdraw consent for processing for which consent has been given, by post at the address stated above or by email at dpo@icr-evolution.com.
If Users require further information or believe that their right to data protection has been infringed, they may contact the Spanish Data Protection Agency (www.aepd.es)
6. FURTHER INFORMATION
If the User has any questions regarding the information contained in this Privacy Policy, they may send an email to: dpo@icr-evolution.com.
7. SECURITY POLICY
ICR has chosen to manage its information systems in accordance with best practices and ISO 27001:2022. Recognising the significant importance of information systems, the Company establishes the following fundamental information security principles:
- Regulatory Compliance Principle: All information systems shall comply with applicable legal, regulatory and sector-specific requirements affecting information security. This includes, in particular, provisions relating to personal data protection and the security of systems, data, communications and electronic services.
- Risk Management Principle: Risks shall be minimised to acceptable levels while maintaining a balance between security controls and the nature of the information. Security objectives must be established, reviewed and aligned with information security considerations.
- Awareness and Training Principle: Training, awareness and educational programmes will be implemented for all users with access to information on matters related to data security.
- Confidentiality, Integrity and Availability Principles:
- Ensure that information is accessible only to authorised persons, entities or processes, preventing unauthorised access.
- Ensure the integrity of information, keeping it clear and accurate, with particular emphasis on the accuracy of the content and the processes involved.
- Ensure the availability of information and business continuity through contingency plans supported by information services.
- Accountability Principle: All ICR members must take responsibility for their conduct regarding information security and comply with the established rules and controls.
- Continuous Improvement Principle: The effectiveness of the security controls implemented by the Company will be reviewed periodically in order to improve its ability to adapt to the constant evolution of risk and the technological environment.
- Incident Management Principle: An incident response plan will be established to address security breaches effectively and minimise the impact of potential threats.
8. PROVISION OF CUSTOMER SERVICE VIA WHATSAPP BUSINESS
When a User contacts, via WhatsApp, an ICR business customer that uses our platform to manage its customer service communications, ICR may process, on behalf of that business, the personal data necessary to manage those communications. By way of example and without limitation, ICR may process the following personal data:
- Telephone number;
- WhatsApp profile name;
- Content of exchanged messages and attached files;
- Data associated with the communications, such as the date and time of the messages and their delivery status.
This data is processed solely for the purpose of providing the customer service and conversational automation service contracted by the business with which the User is communicating. ICR does not use this data for its own advertising purposes or disclose it to third parties for purposes other than providing that service, except where required by law.
- Parties involved in the processing of the data: In relation to this processing, the ICR customer with whom the end User maintains the conversation determines the purposes and means of the processing and acts as the data controller of the personal data of its users. ICR processes such data on behalf of and in accordance with the instructions of the business customer, acting as processor in accordance with Article 28 of the GDPR. The corresponding data processing agreement will always be entered into between ICR and each customer.
- Legal basis: It is the responsibility of each ICR customer to determine the legal basis legitimising the processing of end Users’ data, in its capacity as controller. ICR will process such data in accordance with the documented instructions of its customer.
- Recipients: For the provision of the service through WhatsApp Business, ICR and the customer, depending on the configuration of the service, use WhatsApp Ireland Limited and the entities and providers involved in the provision of the WhatsApp Business Platform. ICR may also use technology service, hosting and infrastructure providers necessary to provide its services. Such providers will process the data only to the extent necessary and will be subject to the corresponding contractual data protection obligations. The use of the WhatsApp Business Platform and certain technology providers may involve international transfers of personal data, including to the United States. Where applicable, such transfers will be carried out using one of the mechanisms recognised by applicable data protection legislation and subject to the safeguards required thereunder, such as applicable adequacy decisions or standard contractual clauses approved by the European Commission.
- Retention period: ICR will process the data for the duration of the contractual relationship with its customer. Once that relationship has ended, the data will be deleted from ICR’s systems or returned to the customer in accordance with the provisions of the data processing agreement entered into by the parties. Notwithstanding the foregoing, ICR may retain duly blocked personal data until the expiry of any liabilities applicable to ICR as a result of the service provided to its customer.
End Users may exercise the rights recognised under applicable data protection legislation by contacting the controller with whom they have a direct relationship. Notwithstanding the foregoing, Users may request the deletion of data associated with their conversations by emailing dpo@icr-evolution.com, providing the information necessary to identify the conversation in respect of which deletion is requested. ICR will process such request in coordination with the business acting as data controller and in accordance with its instructions.