Fundamentia
How We WorkUse cases
AboutFAQs
ContactPrivacÿShield Access|

Privacy and Security Policy

At Fundamentia, we process personal data responsibly, securely and transparently.

This Policy explains what data we process, what we use it for, how long we retain it, which providers are involved and how we protect the information. It applies to the Fundamentia website, our contact forms, our communications, our services and the PrivacÿShield SaaS application.

Privacy Policy

Who is the controller?

The data controller is: Fundamentia Business Consulting, S.L. — Tax ID: B86644598 — Registered address: Calle de Santiago Ramón y Cajal 41, 1st floor, 03203 - Elche, Alicante, Spain. Company registration: Commercial Registry of Alicante, sheet A-194618.

To contact Fundamentia, the user must use the contact form available on the corporate website.

What data do we process?

We may process the following data:

  • Contact data: first name, surname, company, position, email, telephone number, country and any information the user includes in forms or communications.
  • Account and access data: user, organization, role, permissions, registration date, accesses, activity within the application, technical logs and user settings.
  • PrivacÿShield usage data: patterns configured by the user, anonymization jobs launched, job status, job history, consumption metrics, page batches acquired, page balance and, where displayed by the application, the scheduled deletion date for anonymized documents.
  • Billing data: company name, tax ID, tax address, country, purchases made, page packages acquired and invoices issued.
  • Payment data: the data required to process online purchases. Payment is processed through Stripe.
  • Usage and analytics data: technical information about browsing, device, language, pages visited, usage events and aggregated metrics. For this purpose, we may use Google Analytics.
  • Documents uploaded to PrivacÿShield: the documents that the user uploads for anonymization may contain personal data, financial data, professional data, health data, specially protected data or other confidential information. These documents are processed solely to provide the requested anonymization service.
What do we use the data for?

We process data to:

  • Respond to requests received through the website.
  • Manage the commercial or contractual relationship with clients and users.
  • Create and manage user accounts.
  • Enable access to and use of PrivacÿShield.
  • Manage patterns, anonymization jobs, activity history and consumption metrics.
  • Process documents for anonymization.
  • Manage payments, billing and invoice downloads.
  • Provide technical support and operational communications.
  • Improve the website, the application and our services.
  • Measure use of the website and the application.
  • Protect the security of the service and prevent misuse.
  • Comply with legal, tax, accounting and regulatory obligations.
  • Defend Fundamentia’s rights and legitimate interests.
What is the legal basis?

We process data on the following bases:

  • Performance of a contract, when processing is necessary to provide the service, create the account, process documents, manage patterns and jobs, manage payments or issue invoices.
  • Consent, when the user gives it, for example, in certain forms, commercial communications or non-technical cookies.
  • Legitimate interest, for security, fraud prevention, service improvement, support for existing clients and defense of rights.
  • Legal obligation, when we must retain or disclose data for tax, accounting, corporate or regulatory reasons, or at the request of a competent authority.
When does Fundamentia act as controller and when as processor?

Fundamentia may act in two different roles.

Fundamentia as controller. Fundamentia acts as data controller when it decides why and how to process the data. This occurs, for example, in the management of the website, forms, commercial contacts, user accounts, payments, billing, support, security, analytics and communications.

Fundamentia as processor. Fundamentia acts as data processor when it processes, on behalf of the client, the data contained in the documents that the user uploads to PrivacÿShield. In this case, the client is the data controller and Fundamentia processes the documents only to provide the anonymization service. Fundamentia does not use those documents for its own purposes and does not train its own or third-party models with the client’s documents, unless expressly, specifically and documentedly authorized.

How are documents processed in PrivacÿShield?

PrivacÿShield allows documents to be uploaded in order to anonymize personal, financial, confidential or specially protected data. The Service will allow PDF documents to be processed and, where enabled, other files (DOC, PPT, TXT, JPG, PNG, TIF, etc.). It will also allow the upload of ZIP files containing documents of the above types. The service will process documents in accordance with the formats, limits and technical conditions in force at any given time.

The user may select or configure processing patterns. A pattern defines the categories of data to be anonymized, the masking method and the applicable processing mode. Each processing request is called a job and may include one or more documents.

The basic mode is aimed at the direct anonymization of standard personally identifiable information. The advanced mode may also include specially protected data, images, personal photographs, handwritten signatures, customized data and contextual anonymization through semantic analysis and co-reference resolution.

Document processing follows these rules:

  • Original documents are deleted immediately after they have been processed.
  • Anonymized documents are retained for a maximum of 5 days to allow their download.
  • After that period, anonymized documents are automatically deleted.
  • Except as stated above, Fundamentia does not retain any other results of document processing.
  • The user must review the anonymized document before sharing, publishing, sending or using it.
  • Where the functionality is available, the user may consult the status of their jobs and the scheduled deletion date for anonymized documents, as well as request or carry out their early deletion within the retention period.

PrivacÿShield is a technological tool that supports anonymization. It does not replace human review or the legal, regulatory or risk analysis that corresponds to the client.

Which providers do we use?

To provide our services, we may use specialized technology providers.

Microsoft Azure. PrivacÿShield is provided on Microsoft Azure infrastructure and services. We may use Azure services for hosting, storage, processing, OCR, artificial intelligence, language models, security, monitoring and transactional communications.

Stripe. Online payments are processed through Stripe. Stripe processes the data necessary to verify cards, process payments, prevent fraud and comply with its legal obligations as a payment service provider.

Google Analytics. We use Google Analytics to analyze use of the website and, where applicable, the application, measure performance and improve our services.

We may also use other technical, legal, tax, accounting, support or security providers when necessary to provide the service, comply with legal obligations or protect our rights.

Are there international transfers?

Fundamentia will endeavor to ensure that the main processing of documents uploaded to PrivacÿShield takes place in the European Union.

However, the use of global providers such as Microsoft, Stripe or Google may involve international data transfers. Where such transfers occur, the safeguards provided for by applicable law will apply, such as adequacy decisions, standard contractual clauses or other legally valid mechanisms.

How long do we retain data?

We retain data only for the time necessary for each purpose:

  • Form data is retained for the time necessary to respond to the request and manage possible follow-ups.
  • Client and user data is retained while there is a contractual relationship or active account.
  • Data relating to patterns, jobs, activity history, consumption metrics and page batches is retained while necessary to provide the service, manage the account, evidence consumption, ensure security or address liabilities.
  • Billing data is retained for the periods required by tax, accounting and commercial regulations.
  • Payment data is retained for the time necessary to manage the transaction and possible claims.
  • Technical and security logs are retained for the time necessary to ensure security, traceability, fraud prevention and defense against incidents.
  • Original documents uploaded to PrivacÿShield are deleted immediately after processing.
  • Anonymized documents are retained for a maximum of 5 days and then automatically deleted.
  • Data processed on the basis of consent is retained until the user withdraws that consent or until it is no longer necessary.

Where there is a legal obligation or possible liability, data may be blocked for the legally applicable periods.

What rights does the user have?

The user may exercise the rights of access, rectification, erasure, objection, restriction of processing, portability, withdrawal of consent and not to be subject to automated decisions where applicable.

To exercise these rights, the user must use the contact form available on the Fundamentia website and clearly indicate which right they wish to exercise.

Where the request relates to data contained in documents processed on behalf of a PrivacÿShield client, Fundamentia may forward the request to the client acting as data controller, unless it is legally required to act otherwise.

The user may also lodge a complaint with the Spanish Data Protection Agency or another competent supervisory authority.

Do we send commercial communications?

We may send commercial communications about our services when the user has given consent or when there is another valid legal basis, such as legitimate interest in relation to existing clients.

The user may unsubscribe from or object to these communications using the mechanisms included in each communication or through the website contact form.

Do we use cookies?

The website and, where applicable, the application may use cookies and similar technologies for technical, personalization, analytics or measurement purposes.

Non-technical cookies will be used in accordance with applicable law and, where necessary, after obtaining the user’s consent.

Detailed information about cookies is set out in the Cookie Policy.

Can minors use our services?

Fundamentia’s services, including PrivacÿShield, are not intended for minors.

The user declares that they have sufficient legal capacity to use the website, contract services or act on behalf of the organization they represent.

Can this Policy change?

Yes. Fundamentia may update this Policy to adapt it to legal, technical, organizational, commercial or functional changes.

The current version will be the one published on Fundamentia’s corporate website and, where applicable, accessible from the PrivacÿShield application.

Relationship with other documents

This Policy is complemented by the Legal Notice, the PrivacÿShield Terms and Conditions, the Cookie Policy and any specific contract entered into between Fundamentia and the client.

In the event of any contradiction between this Policy and a specific contract signed with a client, the specific contract shall prevail to the extent that it is legally valid and applicable.

Security Policy

Commitment to Security
  • Information security is a strategic pillar for Fundamentia.
  • We apply technical and organizational measures aimed at protecting the confidentiality, integrity, availability and resilience of data and services.
  • Fundamentia holds ISO 27001 Information Security certification.
Protection Measures
  • Encryption of communications.
  • Access control and identity management.
  • Roles and permissions per user.
  • Access limited to authorized personnel.
  • Separation of environments and clients where applicable.
  • Automatic deletion of documents in PrivacÿShield.
  • Technical monitoring and security logs.
  • Continuity and recovery measures.
  • Incident management.
  • Internal confidentiality obligations.
  • Continuous improvement of the security system.
User Responsibilities
  • Protect their access credentials.
  • Properly manage their organization’s permissions.
  • Correctly configure anonymization patterns.
  • Review anonymization results before sharing, publishing, sending or using them.
  • Download documents securely.
Liability for Incorrect Use
  • Failure to comply with the above responsibilities may compromise the security of the processed data.
  • Fundamentia shall not be liable for damages arising from incorrect use of credentials or improper configuration of patterns by the user.
EU Excellence
EU Seal
of Excellence
European Union Recognition
ISO Certification
ISO 27001
Certified
Information Security
Funded by Next Generation EU
Plan de Recuperación, Transformación y Resiliencia

Sectors

Banking & FinanceInsuranceLegalReal EstateHealthcareEducation

Solutions

SimplÿDataPrivacÿShield

Company

AboutFAQsContactCareers
Fundamentia 2026. © All rights reserved.
Legal NoticePrivacy and Security Policy
in