Privacy policy

Last updated: August 2026

1. Controller of the site and role in the processing

The owner of Zetein is Hefiris SW, S.L., Tax ID B93857498, with registered office at Calle Hernández Lázaro 34, 6.º B — 46015 Valencia, and contact e-mail contacto@zetein.es.

Dual capacity depending on the type of data:

This Policy mainly governs the first capacity. The relationship as Processor is governed by the Data Processing Agreement entered into with each contracting company (see Annex).

2. Data we process as controller

In relation to the customer’s account, we may process:

3. Purposes and legal bases

4. End-to-end encryption

Zetein incorporates end-to-end encryption over site data. Sensitive data are encrypted on users’ devices with a company encryption key that resides only on those devices and that the Owner neither stores nor can know. As a result:

5. Recipients and processors

In order to provide the Service, the Owner may use providers acting as data processors, such as the server hosting provider, the payment gateway provider and the e-mail delivery provider. Those providers process the data in accordance with the Owner’s instructions and with the safeguards required by law. Data are not transferred to third parties except where legally required.

6. Retention

Data shall be retained for as long as the contractual relationship is maintained and, thereafter, for the periods legally required to address potential liabilities (in particular, tax and commercial periods). Once those periods have elapsed, the data shall be deleted or anonymised.

7. Rights of data subjects

Data subjects may exercise their rights of access, rectification, erasure, objection, restriction of processing and portability by writing to contacto@zetein.es, proving their identity. They may also lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) if they consider that their rights have not been properly addressed.

Where the data have been entered into the platform by a contracting company (Controller), the Owner, in its capacity as Processor, shall forward to that company any requests to exercise rights it receives, so that the company may handle them.

8. Security

The Owner applies appropriate technical and organisational measures to protect the data, including encryption, access control, activity logging and backups, aimed at ensuring the confidentiality, integrity and availability of the information.

9. Changes to the Policy

The Owner may update this Policy to adapt it to regulatory or Service changes, informing of this through the usual means of communication with customers.

Annex — Data Processing Agreement

This Annex forms an inseparable part of the Privacy Policy and of the Terms and Conditions of Zetein, and is accepted at the time of contracting the Service.

1. Parties

Of the one part, the CONTRACTING COMPANY identified in its registration with Zetein, hereinafter the «Controller».

Of the other part, Hefiris SW, S.L., hereinafter the «Processor».

Both parties acknowledge that they have sufficient capacity and agree to enter into this Data Processing Agreement (hereinafter, «the Agreement»), which forms an inseparable part of the Terms and Conditions of Zetein.

2. Purpose

This Agreement governs the processing of personal data carried out by the Processor on behalf of the Controller as a result of the provision of the Zetein service, in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

3. Description of the processing

4. Obligations of the Processor

The Processor undertakes to:

5. Obligations of the Controller

6. Sub-processors

The Controller generally authorises the Processor to use the providers necessary for the provision of the Service (hosting, payment gateway and e-mail delivery, among others), which shall act as sub-processors with the safeguards required by the GDPR. The Processor shall report any change affecting such sub-processors, allowing the Controller to object on justified grounds.

7. Security measures

The Processor shall apply the appropriate measures in accordance with Article 32 GDPR, taking into account the state of the art and the risks of the processing, including: encryption of site data, role-based access control, activity logging, backups and restoration procedures.

8. Liability

Each party shall be liable for the damages it causes through breach of its respective obligations under the GDPR and applicable law. The Processor’s liability shall be without prejudice to the limits agreed in the Terms and Conditions of the Service, to the extent that they are compatible with data protection legislation.

9. Duration and applicable law

This Agreement shall remain in force for as long as the Service is provided. It is governed by Spanish and European Union data protection law. For any dispute, the parties submit to the Courts and Tribunals of Valencia.

In witness whereof, the parties accept this Agreement at the time of contracting the Service.

Language. This is an English translation provided for convenience. The Spanish version published at zetein.es/politica-de-privacidad is the binding text; in the event of any discrepancy, the Spanish version prevails.