Last updated: 23 July 2026
Introduction
This Privacy Policy describes how BIOTFY SOLUTIONS, S.L. (hereinafter, “BIOTFY”), with Tax Identification Number (CIF) B21779905 and registered office at Calle Loma de los Riscos 59, 29620 Torremolinos (Málaga), Spain, collects, uses, processes, and protects the personal data of its users and clients (hereinafter, the “User” or “Client”) in the context of providing its services through the “BIOTFY” website and platform (hereinafter, the “Platform”).
At BIOTFY, we are committed to protecting your privacy and processing your personal data with the utmost diligence and in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation, GDPR) and Organic Law 3/2018 of December 5, on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD).
By using our Platform and services, you accept the practices described in this Privacy Policy. We recommend that you read it carefully.
1. Definition of Personal Data
“Personal Data” shall be understood as any information concerning an identified or identifiable natural person. This includes, among other things, name, surname, postal address, email address, and phone number.
2. Principles Governing Personal Data Processing
At BIOTFY, the processing of personal data is governed by the following principles set forth in the GDPR:
- Lawfulness, fairness, and transparency: Data are processed lawfully, fairly, and in a transparent manner in relation to the data subject.
- Purpose limitation: Data are collected for specified, explicit, and legitimate purposes and will not be further processed in a manner that is incompatible with those purposes.
- Data minimisation: Data are adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.
- Accuracy: Data are accurate and, where necessary, kept up to date; all reasonable steps will be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay.
- Storage limitation: Data are kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
- Integrity and confidentiality: Data are processed in a manner that ensures appropriate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organisational measures.
3. Purposes of Processing, Legal Basis, Retention Periods, and Third-Party Disclosures
Below is a breakdown of the main purposes for which BIOTFY processes your personal data, the legal basis legitimising such processing, the applicable retention periods, and potential disclosures to third parties:
| Purpose of Processing | Legal Basis | Retention Period | Third-Party Disclosures |
| A. Management of inquiries and requests for information (Contact Forms and Emails) Responding to inquiries, questions, or requests for information submitted by the User through contact forms on the Platform or via email. | BIOTFY’s legitimate interest in attending to requests from potential clients and users. Consent of the data subject upon submitting the form or email. | For as long as necessary to manage and resolve the inquiry, and subsequently blocked during the legal statute of limitations for potential claims. | No disclosures to third parties are foreseen, except under legal obligation. |
| B. Provision of BIOTFY Platform Services (SaaS) Managing the registration and User account on the Platform. | Performance of a contract or pre-contractual measures at the request of the data subject (Platform Subscription). | Duration of the contractual relationship and, once terminated, during the applicable legal limitation periods (e.g., 6 years for commercial documentation, 10 years for anti-money laundering regulations). | Cloud infrastructure service providers (e.g., Amazon Web Services, Google Cloud Platform) for hosting the Platform and data. Payment service providers, where applicable, for subscription management. |
| Enabling access to and use of Platform functionalities (real-time environmental information via customizable dashboards, automated collection, processing, and report generation, etc.). | Performance of a contract. | Duration of the contractual relationship and, once terminated, during the applicable legal limitation periods. | Cloud infrastructure service providers. |
| Providing technical support and customer care to resolve incidents and queries related to Platform usage. | Performance of a contract (Platform Subscription) and BIOTFY’s legitimate interest in maintaining service operations. | Duration of the contractual relationship and, once terminated, during the applicable legal limitation periods. | Incident management and support tool providers. |
| C. Commercial Communications and Marketing Sending commercial communications, news, offers, and promotions related to BIOTFY services via electronic or non-electronic means. | Data subject’s consent (when explicitly requested). BIOTFY’s legitimate interest for existing customers, pursuant to Article 21.2 of the LSSI. | Until the data subject withdraws consent or objects to the processing. | Communication delivery platforms (e.g., email marketing services). |
| D. Platform Improvement and Maintenance Conducting statistical and usage analysis of the Platform to improve its performance and design, and to offer new functionalities. | BIOTFY’s legitimate interest in improving its products and services. | Anonymised or aggregated data indefinitely. Non-anonymised data for the time necessary to conduct the analysis and implement improvements. | Web analytics service providers (e.g., Google Analytics), with guarantees of anonymisation or pseudonymisation. |
| E. Compliance with Legal Obligations Handling legal, tax, accounting, and administrative requirements. | Compliance with a legal obligation applicable to BIOTFY. | For the periods legally established for each type of obligation (e.g., 4 years for tax obligations, 10 years for anti-money laundering regulations). | Competent Public Administrations (Tax Agency, Social Security, Courts and Tribunals, etc.). |
4. Customer Data (BIOTFY as Data Processor)
When the Client enters personal data of their own users, employees, or third parties into the BIOTFY Platform to monitor and manage ecosystems efficiently, obtaining real-time data and analytics, the Client acts as the Data Controller for those data, and BIOTFY acts as the Data Processor, in accordance with Article 28 of the GDPR.
In this context, BIOTFY undertakes to:
- Process personal data only on documented instructions from the Client, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which BIOTFY is subject; in such a case, BIOTFY shall inform the Client of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
- Ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Take all appropriate technical and organisational security measures to ensure a level of security appropriate to the risk, including, among others, the measures described in Section 6 of this Policy.
- Assist the Client, taking into account the nature of the processing, by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Client’s obligation to respond to requests for exercising data subjects’ rights.
- Assist the Client in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR (security of processing, notification of a personal data breach, data protection impact assessment, and prior consultation).
- At the choice of the Client, delete or return all personal data after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage of the personal data.
- Make available to the Client all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and allow for and contribute to audits, including inspections, conducted by the Client or another auditor mandated by the Client.
4.1. Sub-processors
BIOTFY may engage other processors (sub-processors) to deliver the services, such as cloud infrastructure providers (e.g., Amazon Web Services). BIOTFY will ensure that these sub-processors enter into agreements imposing equivalent obligations to those set out in this Privacy Policy and the Data Processing Agreement, in compliance with Article 28.4 of the GDPR.
4.2. International Data Transfers
In the event that international transfers of personal data to countries outside the European Economic Area (EEA) become necessary, BIOTFY will ensure that such transfers comply with the GDPR by applying appropriate safeguards, such as Standard Contractual Clauses approved by the European Commission, and adopting supplementary measures where necessary to guarantee a level of protection equivalent to European standards.
5. Security of Your Personal Data
BIOTFY has implemented and maintains an Information Security Management System (ISMS) based on recognised standards, such as ISO/IEC 27001, to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Formalised information security policies.
- Logical access controls based on roles and the principle of least privilege.
- Secure authentication mechanisms.
- Encryption of communications and, where appropriate, stored data.
- Security incident management procedures.
- Regular backup copies and disaster recovery / business continuity plans.
- Continuous evaluation and enhancement of security levels.
BIOTFY regularly reviews and updates these measures to adapt to evolving risks, state-of-the-art technical developments, and applicable regulatory requirements.
6. Use of Cookies
The BIOTFY Platform uses cookies to improve User browsing experience, analyse Platform usage, and offer specific features. Cookies are small text files stored on the User’s device upon accessing the Platform.
For detailed information regarding the cookies we use, their purposes, legal basis, retention periods, and how to manage them, please refer to our dedicated Cookie Policy, available at Cookie Policie.
7. User Rights
You have the right to exercise the following rights regarding your personal data:
- Right of Access: Obtain confirmation as to whether BIOTFY is processing your personal data and, if so, access that data.
- Right to Rectification: Request the correction of inaccurate or incomplete data.
- Right to Erasure (Right to be Forgotten): Request the deletion of your personal data when, among other reasons, it is no longer necessary for the purposes for which it was collected.
- Right to Restriction of Processing: Request the limitation of the processing of your data, in which case we will only retain it for the exercise or defence of legal claims.
- Right to Data Portability: Receive the personal data you provided to us in a structured, commonly used, and machine-readable format, and transmit it to another controller.
- Right to Object: Object to the processing of your personal data, in which case BIOTFY will cease processing it, unless compelling legitimate grounds or the exercise or defence of potential claims require otherwise.
- Right to Withdraw Consent: Withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, you can send a communication to our Data Protection Officer at the email address info@biotfy.com, attaching a copy of your National ID (DNI) or an equivalent identification document. You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) if you believe your rights have not been adequately addressed.
8. Changes to the Privacy Policy
BIOTFY reserves the right to modify this Privacy Policy at any time to adapt it to legislative or case-law developments, or changes in business practice. Any modifications will be published on the Platform and, in the case of substantial changes, you will be notified via electronic means (e.g., email) so you can review the changes before they take effect. Continued use of the Platform after changes are published implies acceptance of the updated policy.
9. Contact
If you have any questions or concerns about this Privacy Policy or the processing of your personal data, you can contact us via our Data Protection Officer’s email: info@biotfy.com.
