Legal
Privacy policy
What we do with the data you give us through this website, and what you can demand from us about it.
Última actualización: September 24, 2026
1. Who is the controller
The controller for the data we collect through this website is GMAO CLOUD, S.L. (Sociedad Unipersonal), with tax ID (NIF) B02894947 and registered address at C/ Real de Gandia 1, bajo, 46020 Valencia.
For any question related to your personal data, including exercising your rights, you can write to hola@gmao.cloud.
2. What data we collect and where from
This website only collects data you voluntarily provide through a form. We don't buy databases, we don't obtain data from third parties, and we don't track your browsing: there's no analytics or advertising pixels, as detailed in the cookie policy.
- Demo request form: first and last name, company, work email, phone number if provided, the type of facility you maintain, and anything else you choose to tell us.
- Contact form: name, email, company if provided, and the content of your message.
- Server logs: IP address, date and time, and technical request data, generated automatically when any page is served.
Only your name and email are required so we can respond to you; the rest of the fields are optional and marked as such. When you submit a form, your IP address is logged for a limited time to prevent automated mass submissions, and is included in the email we receive.
3. What we use it for, and under what legal basis
Each purpose has its own legal basis, which is what entitles us to process your data:
- To handle your inquiry or prepare the demo you requested. Legal basis: taking pre-contractual measures at your request, and your consent when you check the box on the form, which is freely given and revocable.
- To keep up the business contact arising from that request, for as long as there is a mutual legitimate interest in the conversation. You can object at any time and we will stop writing to you.
- To ensure the security and proper functioning of the service, through technical logs and automated-submission controls. Legal basis: our legitimate interest in protecting the site against abuse.
- To comply with any legal obligations that apply to us, when relevant.
We don't use your data to build profiles, we don't make automated decisions that affect you, and we don't send you marketing communications unrelated to the request you made.
4. How long we keep it
Data from an inquiry or demo request that doesn't lead to a business relationship is kept for durante un año desde el último contacto, after which it is deleted.
Technical server logs are kept for durante doce meses.
If the request leads to a contractual relationship, the data is kept for as long as that relationship lasts and, afterward, for the statutory limitation periods required by applicable legal and accounting obligations. Once those periods elapse, the data is deleted.
The temporary record of your IP address for submission control is automatically deleted after one hour.
5. Who else can see your data
Your data isn't shared with or sold to third parties. It is accessed, out of technical necessity, by the providers who host the site and handle our email, who act as data processors and are contractually bound to process it only according to our instructions.
There are no international data transfers: the providers involved process the information within the European Union. If we were to adopt a tool in the future that involved a transfer outside the European Economic Area, it would be disclosed here, along with the applicable safeguard.
We may disclose data to public authorities when there is a legal obligation to do so.
6. Your rights
You can exercise the following rights over your personal data at any time:
- Access: know what data of yours we process and obtain a copy.
- Rectification: correct data that is inaccurate or incomplete.
- Erasure: request that we delete it when it is no longer needed.
- Objection: object to processing based on our legitimate interest.
- Restriction: request that processing be restricted in the cases provided for by law.
- Portability: receive your data in a structured, commonly used format.
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
To exercise them, simply write to hola@gmao.cloud stating which right you want to exercise. We will respond within a maximum of one month. We may ask you to verify your identity, and will only do so when there is reasonable doubt about it.
If you believe we have not properly handled your request, you can file a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es), the competent supervisory authority.
7. How we protect your information
We apply technical and organizational measures to protect data against loss, unauthorized access, and misuse. The website is served entirely over encrypted HTTPS, access to information is limited to people who need to process it, and the infrastructure is described in detail on the security and infrastructure page.
No system is invulnerable, which is why we prefer not to make absolute claims. If a security breach occurred that posed a risk to your rights, we would notify you and report it to the supervisory authority within the required timeframes.
8. Data inside the product is a different matter
This policy covers only what happens on this website. Personal data that a client enters inside GMAO Cloud — belonging to their employees, technicians, or their own clients — follows a different regime: there, the client is the data controller and we act as a processor, handling it strictly according to their instructions and what is agreed in the corresponding data processing agreement.
This is an important distinction, not a merely formal one: it determines who decides about that data, who is accountable to the affected individuals, and who to contact to exercise rights. If you are an employee or client of a company that uses GMAO Cloud and want to exercise your rights, you need to contact that company, since they are the ones who decide about your data.
9. Changes to this policy
This policy may be updated whenever the way we process data changes, when we adopt new tools, or when required by regulation. The date of the last update appears at the top of the document, and material changes will be announced visibly.