We, E-xisto Diseño Web S.L. (hereinafter "we/our"), take the protection of your personal data very seriously and strictly adhere to all applicable laws and regulations on data protection, in particular the General Data Protection Regulation (GDPR). The following explanations will give you an overview of how we ensure this protection and which data we process for which purpose.
The purpose of this Privacy Policy is to inform the owners of the personal data, regarding which information is being collected, of the specific aspects related to the processing of their data, the purposes of the processing, the contact details for exercising their rights, the periods for the conservation of the information and the security measures, among other things.
The Controller within the meaning of Art. 4 No. 7 of the GDPR is:
E-xisto Diseño Web S.L.
c/ Pepe Corzo 2, 1ª Planta.
41500, Alcalá de Guadaira, Sevilla (Spain).
Owner contact email: support@apirocket.io
If our processing of your personal data is subject to the European Union General Data Protection Regulation (“GDPR”), you have the following rights with respect to your personal data:
Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. These requests can be exercised free of charge and will be addressed by the Owner as early as possible and always within one month.
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data.
The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this Application (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner.
The updated list of these parties may be requested from the Owner at any time.
The Owner may process Personal Data relating to Users if one of the following applies:
In any case, the Owner will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following: Hosting and backend infrastructure, Registration and authentication, Analytics, Traffic optimization and distribution, Handling payments, Managing contacts and sending messages, Contacting the User and Advertising.
To register for our services, we collect your identifiers such as your email address, name or alias, and IP address. We will also collect the date and time of registration and log-ins and log the actions taken in the services. For paid use of our services, we will also request additional personal data from you or your organization, including identifiers such as address and payment details. Due to mandatory commercial and tax regulations, we are obliged to keep your address, payment and subscription data for a period of ten years. We share your identifiers and payment information with our service providers for service provision and payment processing purposes.
We collect Website Data from logged-in users and combine it with identifiers (such as your signup data) and information about how you use our services as well as firmographic data about the business you work in and your role in that business. In such cases we process the data as a controller based on GDPR article 6.1(f), our legitimate interests to provide our product development and engineering teams with accurate usage data and to make our customer success operations, marketing and sales messages more helpful and relevant. We will retain the data for as long as we consider the data being valuable for purposes of product development, customer success and support as well as marketing.
En la medida en que utilizamos cualquier tecnología de rastreo, como las cookies, la base jurídica para el procesamiento de dichos datos es el artículo 6.1(a) de la Ley de Protección de Datos con respecto a los datos procedentes de la Unión Europea, es decir, el consentimiento que solicitamos a través de un gestor de consentimiento de cookies implementado en la aplicación web.
We employs third-party processors under contract as part of providing our services to you, who may process your personal data in cases where we are the data controller. In these cases, we only share the necessary information to enable them to carry out their tasks. Such external service providers are carefully selected in order to ensure your privacy and to fulfil our obligations under the GDPR. Service providers may only use the data for the purposes under the agreement entered into between us and the service provider.
If it serves investigations of illegal use of our services or is required to pursue legal claims, personal data may be shared with law enforcement agencies, public bodies and third-party victims’ claims based upon court orders or other binding orders from public bodies. Such transfer of data will be made in accordance with applicable laws and regulations.
Personal Data is collected for the following purposes and using the following services:
This type of service allows this Application to access Data from your account on a third-party service and perform actions with it. These services are not activated automatically, but require explicit authorization by the User.
This service allows this Application to connect with the User’s account on the Google Accounts Services, provided by Google Inc.
Permissions asked: Company name, Email address, First name, Last name, User ID, Avatar Image.The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behavior.
Google Analytics is a web analysis service provided by Google Inc. (“Google”). Google utilizes the Data collected to track and examine the use of this Application, to prepare reports on its activities and share them with other Google services. Google may use the Data collected to contextualize and personalize the ads of its own advertising network. This integration of Google Analytics anonymizes your IP address. It works by shortening Users' IP addresses within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the complete IP address be sent to a Google server and shortened within the US.
Permissions asked: Cookies, Usage Data.Facebook Ads conversion tracking (Facebook pixel) is an analytics service provided by Facebook, Inc. that connects data from the Facebook advertising network with actions performed on this Application. The Facebook pixel tracks conversions that can be attributed to ads on Facebook, Instagram and Audience Network.
Permissions asked: Cookies, Usage Data.Google Ads conversion tracking is an analytics service provided by Google LLC that connects data from the Google Ads advertising network with actions performed on this Application.
Permissions asked: Cookies; Usage Data.Linkedin Ads conversion tracking is an analytics service provided by Linkedin Corporation that connects data from the Linkedin Ads advertising network with actions performed on this Application.
Permissions asked: Cookies, Usage Data.Hotjar is a behavior analytics and user feedback service that helps us understand the behavior of your website users and get their feedback through tools such as heatmaps, session recordings, and surveys.
Permissions asked: Cookies, Usage Data and various types of Data as specified in the privacy policy of the service.This type of service allows User Data to be utilized for advertising communication purposes displayed in the form of banners and other advertisements on this Application, possibly based on User interests.
This does not mean that all Personal Data are used for this purpose. Information and conditions of use are shown below.
Some of the services listed below may use Cookies to identify Users or they may use the behavioral retargeting technique, i.e. displaying ads tailored to the User’s interests and behavior, including those detected outside this Application. For more information, please check the privacy policies of the relevant services.
In addition to any opt-out offered by any of the services below, the User may opt out of a third-party service's use of cookies by visiting the Network Advertising Initiative opt-out page.
Google Ad Manager is an advertising service provided by Google LLC that allows the Owner to run advertising campaigns in conjunction with external advertising networks that the Owner, unless otherwise specified in this document, has no direct relationship with. In order to opt out from being tracked by various advertising networks, Users may make use of Youronlinechoices. In order to understand Google's use of data, consult Google's partner policy. This service uses the “DoubleClick” Cookie, which tracks use of this Application and User behavior concerning ads, products and services offered. Users may decide to disable all the DoubleClick Cookies by clicking on: www.google.com/settings/ads/onweb/optout?hl=en.
Permissions asked: Cookies, Usage Data.LinkedIn Ads is a paid marketing tool that offers access to LinkedIn social networks through various sponsored posts and other methods. Linkedin Ads is a powerful marketing tool for B2B companies to build leads, online recognition, share content, and more.
Permissions asked: xxx.By filling in the contact form with their Data, the User authorizes this Application to use these details to reply to requests for information, quotes or any other kind of request as indicated by the form’s header.
Permissions asked: Name, Email address.By registering on the mailing list or for the newsletter, the User’s email address will be added to the contact list of those who may receive email messages containing information of commercial or promotional nature concerning this Application. Your email address might also be added to this list as a result of signing up to this Application or after making a purchase.
Permissions asked: Name, Email address.This type of service makes it possible to manage a database of email contacts, phone contacts or any other contact information to communicate with the User. These services may also collect data concerning the date and time when the message was viewed by the User, as well as when the User interacted with it, such as by clicking on links included in the message.
Mailchimp is an email address management and message sending service provided by The Rocket Science Group, LLC.
Permissions asked: Name, Email address.This type of service has the purpose of hosting Data and files that enable this Application to run and be distributed as well as to provide a ready-made infrastructure to run specific features or parts of this Application. Some of these services work through geographically distributed servers, making it difficult to determine the actual location where the Personal Data are stored.
Heroku is a hosting service provided by Heroku, Inc.
Permissions asked: Various types of Data as specified in the privacy policy of the service..Amazon Web Services (AWS) is a hosting and backend service provided by Amazon Web Services, Inc.
Permissions asked: Various types of Data as specified in the privacy policy of the service.Google Cloud is a hosting service provided by Google, Inc.
Permissions asked: Various types of Data as specified in the privacy policy of the service.Netlify is a hosting service provided by Netlify, Inc.
Permissions asked: Various types of Data as specified in the privacy policy of the service.MongoDB is a general purpose, document-based, distributed database built for modern application developers and for the cloud era.
Permissions asked: Various types of Data as specified in the privacy policy of the service.Imgix is an API-first platform that enables you to optimize your images on the fly. Available optimizations and features include compression, resize & cropping, and face detection, hosted on a global CDN to make sure images are delivered fast.
Permissions asked: Cookies, Usage Data.This type of service allows this Application to distribute their content using servers located across different countries and to optimize their performance. Which Personal Data are processed depends on the characteristics and the way these services are implemented. Their function is to filter communications between this Application and the User's browser. Considering the widespread distribution of this system, it is difficult to determine the locations to which the contents that may contain Personal Information of the User are transferred.
Cloudflare is a traffic optimization and distribution service provided by Cloudflare Inc. The way Cloudflare is integrated means that it filters all the traffic through this Application, i.e., communication between this Application and the User's browser, while also allowing analytical data from this Application to be collected.
Permissions asked: Cookies and various types of Data as specified in the privacy policy of the service.By registering or authenticating, Users allow this Application to identify them and give them access to dedicated services. Depending on what is described below, third parties may provide registration and authentication services. In this case, this Application will be able to access some Data, stored by these third-party services, for registration or identification purposes.
The User registers by filling out the registration form and providing the Personal Data directly to this Application.
Permissions asked: Company name, Email address, First name, Last name; User ID, Avatar image.Google OAuth is a registration and authentication service provided by Google Inc. and is connected to the Google network.
Permissions asked: Company name, Email address, First name, Last name; User ID, Avatar image.Payment processing services enable this Application to process payments by credit card, bank transfer or other means. To ensure greater security, this Application shares only the information necessary to execute the transaction with the financial intermediaries handling the transaction.Some of these services may also enable the sending of timed messages to the User, such as emails containing invoices or notifications concerning the payment.
Stripe is a payment service provided by Stripe Inc.
Permissions asked: various types of Data as specified in the privacy policy of the service.This type of service allows interaction with social networks or other external platforms directly from the pages of this Application. The interaction and information obtained through this Application are always subject to the User’s privacy settings for each social network. This type of service might still collect traffic data for the pages where the service is installed, even when Users do not use it.
The Facebook Like button and social widgets are services allowing interaction with the Facebook social network provided by Facebook, Inc.
Permissions asked: Cookies, Usage Data.The Twitter Tweet button and social widgets are services allowing interaction with the Twitter social network provided by Twitter, Inc.
Permissions asked: Cookies, Usage Data.The LinkedIn button and social widgets are services allowing interaction with the LinkedIn social network provided by LinkedIn Corporation.
Permissions asked: Cookies, Usage Data.This type of service allows you to view content hosted on external platforms directly from the pages of this Application and interact with them. This type of service might still collect web traffic data for the pages where the service is installed, even when Users do not use it.
YouTube is a video content visualization service provided by Google Inc. that allows this Application to incorporate content of this kind on its pages.
Permissions asked: Cookies, Usage Data.This type of service analyzes the traffic of this Application, potentially containing Users' Personal Data, with the purpose of filtering it from parts of traffic, messages and content that are recognized as SPAM.
Google reCAPTCHA is a SPAM protection service provided by Google LLC. The use of reCAPTCHA is subject to the Google privacy policy and terms of use.
Permissions asked: Cookies, Usage Data.We are based in Spain and will primarily access your data from our regular place of business in Spain. Your personal data will be stored on servers within the EU hosted by our subprocessor Amazon Web Services. Your data may be stored transiently or cached in any country in which Amazon or its agents maintain facilities.
We also employ certain third-party processors outside of the EU (primarily in the US) to deliver our services, which may process personal data for which we are a controller. Under such circumstances, adequate safeguards for such transfer to third countries are in place, including data processing agreements compatible with EU standard clauses accepted by the European Commission.
Customer-controlled data is always permanently stored within the EU.
We take appropriate technical and organizational measures, de conformidad con lo establecido en el artículo 32 del RGPD, to protect your personal data from unauthorized access, abuse, loss and other disruption.
In any case, we have implemented the required mechanisms to:
The personal data collected from the User will be kept as long as it is necessary to fulfill the purpose for which the personal data was collected, so that, once the purpose is fulfilled the data will be cancelled. Such cancellation will result in the blocking of the data, which will be kept only at the disposal of the Public Administrations, Judges and Courts, in order to meet any possible liabilities arising from the treatment. Once the aforementioned period has expired, the information will be destroyed.
Therefore:
Once the retention period expires, Personal Data shall be deleted. Therefore, the right to access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.
This Application uses Cookies and other Identifiers. To learn more, the User may consult the Cookie Policy (link).
The User's Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of this Application or the related Services.
The User declares to be aware that the Owner may be required to reveal personal data upon request of public authorities.
For operation and maintenance purposes, this Application and any third-party services may collect files that record interaction with this Application (System logs) use other Personal Data (such as the IP Address) for this purpose.
More details concerning the collection or processing of Personal Data may be requested from the Owner at any time. Please see the contact information at the beginning of this document.
The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within this Application and/or - as far as technically and legally feasible - sending a notice to Users via any contact information available to the Owner. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.
Should the changes affect processing activities performed on the basis of the User’s consent, the Owner shall collect new consent from the User, where required.