Information on personal data processing
In compliance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018, of December 5, on Personal Data Protection and guarantee of digital rights (LOPD-GDD), we inform you of the following:
1. Data Controller
The data controller for your personal data is the company that holds the Certward license contracted by your organization. Certward acts as data processor in accordance with Article 28 of the GDPR.
2. Purpose of Processing
Your data will be processed for the following purposes: (a) Managing authentication and secure access to the platform. (b) Managing and using digital certificates under custody. (c) Audit logging of operations performed with digital certificates (PDF document signing, access to government portals, DEHú notification scanning, automated downloads). (d) Sending service-related notifications.
3. Data Collected
Identification data (name, surname, email address), connection data (IP address, device identifier, user agent), usage data (certificate operation logs, timestamps, URLs of accessed government portals) and electronic notification data (DEHú).
4. Legal Basis
Processing is based on: (a) Performance of a contract or employment/professional relationship (Art. 6.1.b GDPR). (b) Compliance with legal obligations, including electronic signature and e-government regulations (Art. 6.1.c GDPR). (c) Your explicit consent for data processing on the platform (Art. 6.1.a GDPR).
5. Data Retention
Data will be retained for the duration of the contractual relationship and, once terminated, for the legally established periods. Audit logs are retained for a minimum period of 5 years in accordance with applicable regulations.
6. Data Subject Rights
You may exercise your rights of access, rectification, erasure, restriction of processing, portability and objection by contacting the data controller. You also have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
7. Security Measures
Certward implements appropriate technical and organizational measures to ensure the security of your data: encryption of certificates at rest and in transit, two-factor authentication, immutable audit logging, session isolation via local proxy, and automatic deletion of certificates from memory after use.
Version: v1.0