Personal data protection
Privacy Policy
Last updated: 17 August 2026
This policy explains how SURINFO CADIZ SL collects, uses, retains and protects data relating to visitors to surinfo.es, persons submitting an enquiry or RFQ, and business contacts. Processing follows Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 and other applicable rules. It replaces earlier website privacy policies.
1. Data controller
- Company name
- SURINFO CADIZ SL
- Spanish tax ID (NIF)
- B11469632
- Registered address
- Calle Cristaleria 24, 1, 1A, 11408 Jerez de la Frontera (Cádiz), España
- Commercial Registry
- Registered with the Commercial Registry of Cádiz.
- gerencia@surinfo.net
- Telephone
- +34 601 21 52 52
2. Data we may process
- Identity and contact: name, company, position, telephone and email.
- Professional and commercial: references, models, quantities, specifications, destination and RFQ, quotation, order and communication history.
- Billing and compliance: tax ID, address, payment and accounting, tax, customs or anti-fraud documents where applicable.
- Technical: IP, date, browser and logs essential for security and abuse prevention.
Do not include special-category data unless strictly necessary and lawfully supported.
3. Purposes and legal bases
- Enquiries and RFQs: analysis, sourcing, quotations and replies; pre-contractual steps and legitimate interest in professional contacts.
- Orders and supply: performance, logistics, warranty and after-sales; contract or pre-contractual steps.
- Legal compliance: tax, accounting, commercial, customs and authority requirements; legal obligation.
- Security and fraud prevention: legitimate interest.
- Marketing: only with consent, a lawfully permitted prior relationship or another applicable basis. You may object or withdraw consent.
4. Required and accurate data
Required fields are needed to process a request. Without them we may not be able to assess an RFQ or respond. Users warrant that data are accurate and that they may provide any third-party data included.
5. Sources
Data come from the data subject, represented company, legitimate professional communications or contractual documents. Anyone providing another person’s data must first inform them and have authority to disclose it.
6. Recipients and providers
Surinfo does not sell personal data. Necessary access may be given to hosting, maintenance, security and IT providers; Google Workspace/Gmail; banks, insurers, carriers, logistics operators, manufacturers or distributors; confidential professional advisers; and authorities where legally required. Processors act under contract and instructions unless law makes them independent controllers.
7. International transfers
Providers may operate outside the EEA. Surinfo will require GDPR safeguards such as an adequacy decision, European Commission standard contractual clauses or another recognised mechanism. Ask gerencia@surinfo.net for details.
8. Retention
- Enquiries and RFQs: handling and reasonable follow-up.
- Contracts: relationship and restricted retention for limitation periods.
- Business records and correspondence: generally six years from the last accounting entry, subject to special periods.
- Technical logs: minimum security period.
- Consent-based data: until withdrawal, subject to compliance evidence.
Data are then securely erased or anonymised.
9. Rights
You may request access, rectification, erasure, objection, restriction and portability, withdraw consent and, where relevant, avoid solely automated decisions. Contact gerencia@surinfo.net or the registered address. You may complain to the Spanish Data Protection Agency (AEPD).
10. Automated decisions
Surinfo does not make legally significant decisions solely by automated website processing and does not create advertising profiles of visitors.
11. Security and confidentiality
Reasonable safeguards protect against loss, alteration, unauthorised access, disclosure or destruction. Access is limited and confidential. Report incidents to gerencia@surinfo.net.
12. Children
Services target businesses and professionals, not children under 14. Improperly collected children’s data will be erased.
13. Cookies, links and changes
External sites apply their own policies. See our Cookies Policy. The current policy is the version published here with its date.