Skip to content
DATABILIDAD
Home
Solutions
Origen VisibleProduct information made visible: a QR that opens your product's page.ExtremoBatch product information, data imports and certifications in one dashboard.CercaníaAI agents that answer calls, email, and WhatsApp for you.Aula RaízPractical training on request for agri-food businesses.See our solutions
Explore
ProducersProducts
Company
About usNewsContact
Get access
EspañolEnglishCurrentFrançaisDeutschPortuguês
HomePrivacy policy

Privacy

Privacy policy

How Databilidad processes personal data.

This policy explains how Databilidad collects, uses, retains and protects personal data submitted through the website and contact channels.

Legal noticePrivacyDataCookiesAccessibilityContact
Need help?

We are here to help with any legal or privacy question.

Contact
Last updated: 15/05/2024
OwnerDatabilidad, S.L.AddressGarrovillas de Alconétar, CáceresEmail[email protected]ActivityProduct information and agri-food management

1. Controller

The data controller for personal data collected on this website is Databilidad, S.L., NIF B26894907, represented by Úrsula Sánchez Macías.

  • Address: Calle Doctor Pardo 13, 10940, Garrovillas de Alconétar (Cáceres), Spain.
  • Email: [email protected].
  • Website: www.databilidad.com.

2. Applicable rules

This policy follows current Spanish and European personal data protection rules.

  • Regulation (EU) 2016/679, General Data Protection Regulation (GDPR).
  • Spanish Organic Law 3/2018 on Data Protection and Digital Rights.
  • Spanish Law 34/2002 on Information Society Services and Electronic Commerce.

3. Personal data processed

Databilidad mainly processes identifying and contact data voluntarily provided through forms, information requests, commercial communications or queries.

Ordinary public forms do not request special categories of personal data under Article 9 GDPR.

Beyond data you provide voluntarily, some technical data is collected automatically: QR-code scans on batch pages (the batch's public identifier, timestamp, and browser/device, plus whether the scanned code was valid or had been revoked), and, in the producer app, screen-view events and technical error reports for strictly operational purposes.

For visits to the public website, the IP address is currently used only transiently in memory to curb abusive requests; new web telemetry rows do not retain the IP, its hash or network prefix, though they may retain approximate location (country, region and city). Some historical web records created before this change may retain a pseudonymized IP hash and network prefix (/24 for IPv4, /64 for IPv6), together with that location, for up to 12 months; this change does not rewrite those records and they remain subject to their retention period. Producer-app telemetry and its security records may retain a pseudonymized IP hash and network prefix tied to the session. The full IP address is never kept as a permanent record.

Producers can view, for their own products, aggregated statistics about the visits they receive, including a breakdown by country, region and, when visit volume is high enough, approximate city or town of origin. They never see the record of an individual visit. That city- or region-level breakdown is only shown once a product has received a minimum number of visits, and visitor groups too small to distinguish safely are merged into one combined category or, if still too small, withheld entirely -- specifically to reduce the risk that a single visitor could be singled out within that data.

The producer app requests certain device permissions solely for its own functionality, never for tracking or advertising purposes: camera access, to capture photos and videos of products and batches that are uploaded directly to the producer's own catalog; microphone access, used only to record audio during that video capture; and access to files/storage, to import CSV/XLSX catalog files and to select existing photos or videos already on the device. The app's session credential is stored in the device's secure system storage (Android Keystore) and never leaves it except to authenticate requests with Databilidad's servers.

4. Processing principles

Processing follows the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality and accountability.

5. Purposes

Data is processed to answer requests, manage demos or proposals, maintain the relationship initiated by the user and comply with commitments derived from forms or communications.

Data may also be used proportionally for operational, statistical, commercial or quality-improvement purposes.

6. Legal basis

The main legal basis is consent when the data subject provides data for specific purposes.

Where a request relates to pre-contractual measures, proposals or requested services, processing may rely on pre-contractual measures. Security and abuse prevention may rely on Databilidad's legitimate interest.

7. Retention

Retention periods vary by data type, unless the user requests earlier deletion, a longer legal retention duty applies, or liability evidence must be kept:

  • Contact, demo or query requests: for as long as the relationship is managed and, generally, up to 12 months.
  • Website analytics, QR-code scans and producer-app telemetry: up to 12 months.
  • Internal technical diagnostic logs (system logs): up to 6 months.
  • Compliance audit trail (audit events): up to 24 months.
  • Infrastructure backups: rotated every 90 days.

8. Recipients and transfers

Data may be processed by providers needed for hosting, security, analytics, communications or request management, under confidentiality and data protection conditions.

If international data transfers become necessary, prior information and GDPR safeguards will be applied when required.

9. Security and confidentiality

Databilidad applies technical and organizational measures appropriate to the risk to prevent destruction, loss, alteration, disclosure or unauthorized access to personal data.

Personal data is processed confidentially by Databilidad and by the people or providers that need access to provide the service.

10. Rights

Users may exercise rights of access, rectification, erasure, objection, restriction, portability and not being subject to solely automated decisions where applicable.

To exercise rights, write to databilidad.com/contacto with reference GDPR-www.databilidad.com and information needed to verify identity. A person on Databilidad's team always handles these requests: there is no self-service portal or automated process for exercising them.

11. Complaints

If a user considers that data protection rules have been infringed, they may lodge a complaint with the competent supervisory authority. In Spain, this is the Spanish Data Protection Agency.

If you have any question about this document, you can contact Databilidad through the channels shown on this page.
Sections1. Controller2. Applicable rules3. Personal data processed4. Processing principles5. Purposes6. Legal basis7. Retention8. Recipients and transfers9. Security and confidentiality10. Rights11. Complaints

Transparency also applies to our legal information.

We build trust from the origin, with clear information and real commitment.

Legal notice Privacy Data Cookies Accessibility
Follow us
DATABILIDAD

From the field to your screen: good work, in plain sight.

Solutions
Origen VisibleExtremoCercaníaAula Raíz
Company
ProducersProductsAbout usNewsContact
Legal
Legal noticePrivacyDataCookiesAccessibilityCredits
© 2026 Databilidad. All rights reserved.Extremadura, Spain

Your privacy matters

Databilidad may store or access device information to run the site and measure basic audience visits. This basic measurement stays active and records the visit, visible section, and broad device, source, and approximate location data. Optional analytics adds detailed usage, a persistent browser identifier, and Google Analytics only with consent. Configure each purpose.

You can change your preferences at any time from the cookie policy. Cookie policy