Privacy

Privacy Policy & Cookies

ISMShed — Version v1.2 · Last updated: 2026-07-14

This Privacy Policy governs the processing of personal data carried out by Axelia Digital SL ("Axelia Digital", "we", "us") as controller of the corporate website axeliacybersecurity.com and of the ISMShed multi-tenant GRC SaaS platform, accessible at grc.ismshed.ai. It is drafted in accordance with Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD), and the Spanish National Security Framework (Royal Decree 311/2022, "ENS").

1. Data controller

The controller of your personal data is:

If you have contracted ISMShed as a customer to manage compliance for your own organisation, please note that with respect to the personal data you enter into the platform about your employees, suppliers or third parties, you act as the data controller and Axelia Digital acts as the data processor, under the terms of the data processing agreement (Art. 28 GDPR) governing your subscription. This policy describes the processing for which Axelia Digital is the controller (the relationship with the service user, contact, and platform operation).

2. Requirements for providing us with your personal data

To use ISMShed or provide us with your data you must be of legal age and have sufficient legal capacity. The platform is intended for organisations and their professional users; it is not directed at minors (see section 11). You undertake that the data you provide is truthful, accurate and up to date, and that you will inform us of any changes. You are responsible for the accuracy of the data you enter.

3. Data we process, purposes and legal basis

We process different categories of data depending on how you interact with us:

3.1 When you contact us or request a demo

  • Data: identification and contact data (name, company, job title, email, phone) and the content of your enquiry.

  • Purpose: to handle your request and manage the pre-contractual commercial relationship.

  • Legal basis: your consent and/or the taking of pre-contractual measures at your request (Art. 6(1)(a) and 6(1)(b) GDPR).

  • Retention: until your request is resolved and, thereafter, blocked for the legally required periods.

3.2 When you are a platform user (service account)

  • Data: identification and contact data, authentication credentials, role and permissions (RBAC), organisation/tenant identifier, and usage and activity data (access and audit logs, IP address, timestamp).

  • Purpose: to provide and administer the service, authenticate access, isolate your organisation from others (multi-tenant), ensure security and traceability, and bill the service.

  • Legal basis: performance of the subscription contract (Art. 6(1)(b) GDPR); legitimate interest in platform security and fraud prevention (Art. 6(1)(f) GDPR); and compliance with legal obligations (Art. 6(1)(c) GDPR).

  • Retention: for the duration of the contract and, after termination, blocked for the legal periods. Audit and security logs are retained in immutable storage for the applicable retention period (see section 8).

3.3 When you have a contractual relationship with us

  • Data: identification, contact, billing and administrative data.

  • Purpose: performance, administration and billing of the contract; and, where applicable, commercial communications about similar services.

  • Legal basis: performance of the contract (Art. 6(1)(b) GDPR); legitimate interest for commercial communications to customers (Art. 6(1)(f) GDPR), with a right to object.

  • Retention: for the duration of the contractual relationship and subsequent legal periods (commercial, tax).

3.4 Browsing data (cookies)

Browsing grc.ismshed.ai may involve the use of cookies. Details are set out in our Cookie Policy — see section 10.

3.5 When you apply for a job with us

  • Data: identification and contact data, and academic and professional information contained in your CV and application.

  • Purpose: to assess your application and manage the selection process.

  • Legal basis: application of pre-contractual measures at your request (Art. 6(1)(b) GDPR) and your consent to keep your CV for future processes (Art. 6(1)(a) GDPR).

  • Retention: for the duration of the selection process; with your consent, up to one additional year for future vacancies, after which it is deleted.

3.6 Social media

We maintain profiles on professional networks such as LinkedIn. When you interact with them, the processing is governed by the terms and privacy policies of each platform. We process your interaction data (comments, messages) solely to manage our presence, respond to you and announce our services; we do not extract this data into our own systems.

4. Recipients and processors

We do not disclose your data to third parties except in the following cases:

  • Providers acting as processors, under a data processing agreement (Art. 28 GDPR) and with confidentiality and security guarantees. In particular, the platform is hosted on Google Cloud Platform (GKE), which acts as a sub-processor, with data located in the European Union region europe-southwest1 (Madrid, Spain).

  • Communication and delivery providers: emails generated by the website contact forms are delivered through Twilio SendGrid, and our public websites are served and protected through Cloudflare; both act as processors under Art. 28 GDPR agreements.

  • Public authorities and bodies, where there is a legal obligation.

  • Corporate operations (mergers, acquisitions), ensuring the continuity of this policy.

  • Aggregated or anonymised data, which does not allow you to be identified.

  • Third parties with your consent or another legitimate basis.

5. International transfers

Platform data resides in the European Union (GCP region europe-southwest1, Spain), and as a general rule we do not transfer personal data outside the European Economic Area (EEA). Certain providers used by our websites — Twilio SendGrid, Inc. (delivery of contact-form emails) and Cloudflare, Inc. (CDN and perimeter security) — are United States companies, and Google LLC may provide support functions from outside the EEA. Where such processing involves an international transfer, it is covered by the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework or by Standard Contractual Clauses approved by the Commission, together with any supplementary measures necessary to ensure a level of protection equivalent to the GDPR.

6. Your rights as a data subject

You may exercise the following rights over your personal data:

  • Right to withdraw consent at any time, without retroactive effect.

  • Right of access: to know what data we process and obtain a copy.

  • Right to rectification: to correct inaccurate or incomplete data.

  • Right to erasure (“right to be forgotten”): to request deletion when no longer necessary.

  • Right to data portability: to receive your data in a structured, commonly used and machine-readable format.

  • Right to restriction of processing in the cases provided for by law.

  • Right to object: to object to processing based on legitimate interest or to profiling, including commercial communications.

7. How to exercise your rights and lodge a complaint

You may exercise your rights by writing to compliance@axeliacybersecurity.com, stating the right you wish to exercise. We may ask you to prove your identity. We will respond within the legally established time limits.

If you believe that the processing of your data does not comply with the applicable regulations, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), https://www.aepd.es, without prejudice to any other administrative or judicial remedy.

8. Security measures

Axelia Digital applies appropriate technical and organisational measures to guarantee the confidentiality, integrity, availability, authenticity and traceability of data, in line with the ISO/IEC 27001 standard and the Spanish National Security Framework (ENS), MEDIUM category (RD 311/2022). These include:

  • Encryption of data at rest and in transit using keys managed by the cloud provider (Google Cloud KMS).

  • Role-based access control (RBAC) and multi-tenant isolation, so that each organisation only accesses its own data.

  • Logging and auditing of security and access events, with immutable (WORM) storage of the evidence for its retention period, and security event correlation (SIEM) with alerting.

  • Web Application Firewall (WAF) with protection against common attacks and rate limiting (Cloud Armor).

  • Data residency in the European Union (europe-southwest1 region).

No system is completely infallible; the internet carries inherent risks. In the event of a breach of the security of your data that entails a risk to your rights, we will act diligently and notify the authorities and affected individuals as required by the GDPR.

9. Information security policy

Axelia Digital maintains an Information Security Management System based on the UNE-EN ISO/IEC 27001 standard and aligned with the ENS. Management is committed to compliance with security requirements, continuous improvement, staff awareness and applicable legal compliance.

10. Cookies

Our websites and the ISMShed platform (grc.ismshed.ai) use only strictly necessary cookies to keep your session secure and the service working (authentication, security and load balancing). We do not use advertising or third-party tracking cookies. These technical cookies are exempt from prior consent under Article 22.2 of Law 34/2002 (LSSI). Should we ever add analytics or non-essential cookies, we will request your consent beforehand via a cookie banner. Cookie handling follows the security controls of the National Security Framework (ENS, Royal Decree 311/2022). You can block or delete cookies at any time in your browser settings, though this may affect access to the platform.

11. Minors

ISMShed is a professional service directed at organisations and is not intended for minors. We do not knowingly collect data from minors. If we detect that we have processed a minor's data without an appropriate legal basis, we will delete it.

12. Changes to this policy and versioning

We may amend this Privacy Policy to adapt it to legislative, case-law or regulatory-interpretation changes, or to changes in the service. The version in force will be the one published at grc.ismshed.ai with its version number and last-updated date. We recommend that you review it periodically.

Current version: v1.2 — Last updated 2026-07-14. The Spanish version is the legal master; in case of discrepancy the Spanish version prevails.