Privacy policy
What data we process, on what legal basis, for how long and who else sees it. No copy-pasted clauses: only what actually happens at IndustriaKit.
Last updated: 2 August 2026
Two different roles, and they should not be confused
When you visit this website, write to us, download a template or buy a kit, IndustriaKit is the data controller: we decide what data we ask for and why.
When your company subscribes to the panel and enters data about its workers, contractors or incidents, your company is the controller and we are the processor (Article 28 GDPR). We only touch that data on your instructions, and the relationship is documented in a data processing agreement you can generate and sign from our website.
This policy covers the first role. The second is governed by that agreement.
Who processes your data
Owner: Oscar Escanez Abad · NIF 23302334T
Trade name: IndustriaKit (Potencia Digital)
Address: Calle Trece de Septiembre n.º 10, Primero, 30310 Cartagena (Murcia), España
Contact: info@industriakit.com
We are not required to appoint a data protection officer and have not appointed one. Privacy enquiries are handled at the address above.
What exactly we process
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Contact or download form: name, email, company and whatever you write in the message. | Reply to you and send the requested material. | Your consent and pre-contractual steps (Art. 6(1)(a) and 6(1)(b)). | Three years from the last contact, unless you ask for erasure earlier. |
| Kit purchase: email, billing details and country. | Deliver the product, issue the invoice and account for VAT. | Performance of the contract and legal accounting and tax obligations (Art. 6(1)(b) and 6(1)(c)). | The applicable tax and commercial periods, generally six years. |
| Panel account: name, work email, company, role and access logs. | Give access to the service, bill it and be able to investigate a security incident. | Performance of the contract and legitimate interest in the security of the service (Art. 6(1)(b) and 6(1)(f)). | For as long as the subscription lasts. Access logs, twelve months. |
| Server technical logs: IP address, date, requested resource and user agent. | Keep the service running and detect attacks or abuse. | Legitimate interest in network security (Art. 6(1)(f)). | Thirty days, unless they need to be kept to investigate an incident. |
| Regulatory newsletter, only if you expressly request it. | Notify you of regulatory changes affecting your sector. | Your consent, withdrawable in every message (Art. 6(1)(a)). | Until you unsubscribe. |
What we do not do
- We use no analytics, no advertising pixels and no third-party cookies. There is no Google Analytics or equivalent tool on this website.
- We do not sell or transfer your data to anyone for commercial purposes.
- We take no automated decisions with legal effects on you, and we do not profile.
- Fonts are hosted on our own server: loading this page triggers no request to any third-party domain.
Who we share data with, and why
Only with the providers needed for the service to work. All act as our processors and all process data within the European Economic Area. We make no international transfers outside the EEA.
- Raiola Networks S.L. (Spain) — hosting of this website.
- Hostinger International Ltd. — panel server, located in Paris (France).
- Stripe Payments Europe Ltd. (Ireland) — payment collection. Your card details are entered on Stripe's domain and we never see them.
- Brevo (Sendinblue SAS, France) — transactional email and newsletter delivery.
In addition, where the law requires it, we hand data over to the tax authorities or to a court.
Health data: what the panel does not store
The staff module lets you record that a worker is on sick leave and since when, because your company needs that to plan shifts. It does not store the medical reason or the diagnosis: that would be special category data under Article 9 GDPR and the field simply does not exist.
If your company needs to keep medical information, it must do so at the occupational health service or the insurer, not here.
Security: what we do and what we do not yet
All traffic is encrypted with TLS, panel access requires a password, and the servers are in the European Union with periodic backups.
It is also worth saying what we do not have, because reading it elsewhere later would be worse: we have no ISO 27001 certification, no SOC 2 report, no external security audit and no database encryption at rest. If your procurement policy requires any of these, today we cannot meet it.
If a security breach occurs in our infrastructure, we will notify you in writing within a maximum of 24 hours of becoming aware, with whatever we know at that point, so that your company can meet its own 72-hour deadline before the supervisory authority.
Your rights
You may ask us for access to your data, its rectification or erasure, restriction of or objection to processing, and portability. An email to info@industriakit.com stating what you want is enough. We reply within one month at most.
If you are a panel customer, you can also export all your company information in an open format and request its complete deletion when you cancel: we do it within a maximum of thirty days, except for what we must keep for tax reasons.
If you believe we have not handled your request properly, you may complain to the Spanish Data Protection Agency (www.aepd.es) or to the supervisory authority in your country.
Minors and changes
This service is aimed at companies and professionals. It is not intended for minors and we do not knowingly collect data from minors.
If we change this policy, we will publish the new version with its date. If the change is substantial and affects panel customers, we will notify them by email before it takes effect.
