PRIVACY POLICY
Last updated: 11 September 2026
This English version is a courtesy translation. In the event of any discrepancy between this text and the Spanish version, the Spanish version is the one that prevails. Read the Spanish version
1. General information
At NURIA LABS SL (hereinafter, "NURIA LABS" or "the Controller"), we take the protection of personal data very seriously. This Privacy Policy (hereinafter, the "Policy") describes how we collect, use, retain and protect the personal data of persons who visit our website, request information, engage our services or use the Gescon platform.
This Policy has been drawn up in accordance with Regulation (EU) 2016/679, of 27 April, General Data Protection Regulation (GDPR), Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD), and Ley 34/2002, de 11 de julio, de Servicios de la Sociedad de la Información y de Comercio Electrónico (LSSI-CE).
2. Data controller
| Field | Detail |
|---|---|
| Corporate name | NURIA LABS SL |
| Tax ID (CIF) | B22853493 |
| Registered address | Carrer Sant Miquel, 36, 1.º A, 07002 Palma, Illes Balears, España |
| Email address | gescon@nurialabs.com |
| Phone | +34 871 55 71 41 |
| Company registry details | Registro Mercantil de Palma; FOLIO ELECTRÓNICO; IRUS 1000456757788; HOJA PM-104456 |
NURIA LABS has not appointed a Data Protection Officer, as none of the circumstances set out in Article 37(1) GDPR or Article 34 LOPDGDD apply. For any question relating to data protection, you may contact us at gescon@nurialabs.com.
3. Relevant definitions
For the purposes of this Policy, the following terms shall mean:
- User: any natural person who visits the Website or interacts with NURIA LABS without having engaged the service.
- Customer: the natural or legal person (typically, a company) that engages the Gescon service.
- End User: the natural person who uses the Gescon platform within the Customer's organisation (employees, collaborators, etc.).
- Customer Data: the personal data that the Customer uploads, connects or processes through the Gescon platform. With respect to this data, NURIA LABS acts as Data Processor (see Section 11).
4. Personal data we process, purposes and legal bases
The categories of data we process are described below, depending on the type of relationship with NURIA LABS:
4.1 Website visitors and contact form / demo request
| Item | Detail |
|---|---|
| Data processed | First and last name, company, email address and phone number supplied in the form, together with the date, language and evidence of acceptance of the Privacy Policy. The form does not request a job title or message. |
| Purposes | Handling the contact request, arranging product demonstrations and keeping a record of communications related to that request. Submitting the form does not subscribe the user to any mailing list. |
| Legal basis | The data subject's consent to handle their request (Article 6(1)(a) GDPR) and, where applicable, pre-contractual steps taken at their request (Article 6(1)(b) GDPR). |
| Retention period | For as long as the relationship or mutual interest is maintained and, in any event, until the data subject withdraws their consent. Communications will be kept for a maximum of 3 years from the last contact, unless a longer retention period is legally required. |
4.2 Customers and the contracting process
| Item | Detail |
|---|---|
| Data processed | Identifying and contact details of the Customer and of its legal representative or contact person (name, tax ID (NIF/CIF), address, email address, phone number, job title). Banking and billing data managed through Stripe. |
| Purposes | Managing account sign-up, activation and maintenance, providing the Gescon service, issuing and managing invoices, providing technical support and complying with legal obligations. |
| Legal basis | Performance of the contract entered into with the Customer (Article 6(1)(b) GDPR) and compliance with applicable legal obligations, in particular tax and commercial obligations (Article 6(1)(c) GDPR). |
| Retention period | For the term of the contract. After termination: 30 days for data recovery, after which the data will be deleted or anonymised. Billing data will be kept for 6 years in accordance with the Commercial Code and tax regulations. |
4.3 End Users of the Gescon platform
| Item | Detail |
|---|---|
| Data processed | Name, corporate email address, assigned role/permissions, activity records (logs) and queries made to the platform. |
| Purposes | Enabling authenticated access, assigning permissions according to role, providing the service, ensuring security, generating usage statistics for the Customer and providing technical support. |
| Legal basis | Where the data is provided by the Customer, NURIA LABS acts as Data Processor under Article 28 GDPR. The legal basis vis-à-vis the End User rests with the Customer (data controller). NURIA LABS processes this data on the Customer's behalf and in accordance with its documented instructions in the data processing agreement (DPA). |
| Retention period | For the term of the End User's account within the Customer. Technical logs are kept for 12 months for security and traceability purposes. |
4.4 Newsletter and commercial communications
| Item | Detail |
|---|---|
| Data processed | Name and email address, opening and interaction data for the communications sent. |
| Purposes | Sending Gescon news, educational content and events where a specific subscription to those communications exists. This processing is separate from the contact form, which does not subscribe the data subject to mailing lists. |
| Legal basis | Express consent of the data subject (Article 6(1)(a) GDPR and Article 21 LSSI-CE) or legitimate interest in B2B relationships with existing customers and leads (Article 21.2 LSSI-CE). |
| Retention period | Until the data subject requests to unsubscribe. Every communication includes a link to unsubscribe easily and free of charge. |
4.5 Candidates in recruitment processes
| Item | Detail |
|---|---|
| Data processed | Identifying details, curriculum vitae, professional experience, education and any other information the candidate chooses to provide. |
| Purposes | Managing recruitment processes and, where applicable, assessment for future vacancies. |
| Legal basis | Consent of the data subject upon submitting their application (Article 6(1)(a) GDPR) and, at the data subject's request, the taking of pre-contractual steps (Article 6(1)(b) GDPR). |
| Retention period | Up to 1 year from the candidate's last update, after which the data will be deleted unless the candidate expresses renewed interest. |
5. Processing through Artificial Intelligence
Gescon uses the OpenAI API for internal chat, in both normal and expert modes. In Open chat, the End User can choose OpenAI, Anthropic, Perplexity, xAI or Google AI Studio. The following 30-day retention periods apply exclusively to OpenAI:
- Data retention for audit and misuse-monitoring purposes: NURIA LABS uses the OpenAI API under the no-data-sharing arrangement with OpenAI. This means that the data submitted is processed and retained for 30 days to allow audit work and to ensure responsible use of the platform, in accordance with the contractual terms signed with that provider.
- No model training: Customer Data and End User data are never used to train, retrain or improve OpenAI's models or those of any other provider.
- Retention: data sent to OpenAI is processed to answer the query and is not kept on its systems after the stated 30 days. NURIA LABS retains queries and answers in the Customer's account to provide the service and ensure security and traceability, for the periods in Sections 4.2 and 4.3.
- Inherent limitations: AI systems can produce inaccurate, incomplete or outdated responses. Gescon's responses must be reviewed by the End User before making significant decisions based on them. NURIA LABS does not guarantee the absolute accuracy or truthfulness of the responses generated.
In Open chat, each query is sent to the selected provider without automatically including the business context of internal chat. Other providers' retention periods, processing locations and safeguards depend on the contracted service and configuration; OpenAI's 30-day period does not apply to them. A detailed list is available on request at gescon@nurialabs.com. The Acceptable AI Use Policy also applies.
6. Recipients and data disclosures
Your personal data may be disclosed to the following categories of recipients, exclusively for the purposes described:
- Public authorities and competent bodies: where there is a legal obligation to do so.
- Data Processors: service providers that assist NURIA LABS in providing the service (hosting, payment gateway, support and communication tools, AI model, etc.). These third parties have signed the corresponding data processing agreements under Article 28 GDPR.
- Banking and financial institutions: for the management of collections and payments.
The main data processors used by NURIA LABS are:
| Provider | Purpose | Location |
|---|---|---|
| Microsoft Ireland Operations Ltd. (Azure) | Hosting of the platform and storage of Customer Data | Azure Spain region (Madrid) |
| OpenAI Ireland Ltd. (API) | Processing of queries using AI models (with retention of interactions for 30 days) | European Union / United States |
| Stripe Payments Europe Ltd. | Payment processing and billing | Ireland / United States |
| Pipedrive and communication providers | Managing contact requests in Pipedrive and sending service-related communications | European Union / United States |
Anthropic, Perplexity, xAI and Google AI Studio also take part in Open chat when selected by the End User. A detailed, current list of providers, purposes, retention periods, locations and applicable safeguards is available on request at gescon@nurialabs.com.
7. International data transfers
Some of the providers referred to in the previous section may be located, or may carry out data processing, outside the European Economic Area, in particular in the United States. In these cases, NURIA LABS ensures that international transfers are carried out with the appropriate safeguards provided for under the GDPR, through one of the following mechanisms:
- An adequacy decision of the European Commission (for example, the EU-U.S. Data Privacy Framework for certified providers).
- Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914).
- Additional technical and organisational measures where necessary, following the corresponding impact assessment.
The Customer may request further information about the safeguards applied to international transfers at gescon@nurialabs.com.
8. Retention periods
Personal data is retained for as long as necessary to fulfil the purposes for which it was collected, as well as to address any liabilities that may arise from its processing. The specific periods are set out in Section 4 of this Policy.
Once the indicated periods have elapsed, the data will be deleted or, where applicable, duly blocked in accordance with data protection regulations for the limitation periods of any applicable legal actions. Once those periods have elapsed, the data will be permanently erased.
9. Rights of data subjects
Any person has the right to obtain confirmation as to whether or not NURIA LABS is processing personal data concerning them. In particular, they may exercise the following rights:
- Access: to know what data is being processed and to obtain a copy of it.
- Rectification: to request the correction of inaccurate or incomplete data.
- Erasure ("the right to be forgotten"): to request the deletion of data when it is no longer necessary for the purposes for which it was collected.
- Objection: to object to the processing of data on grounds relating to their particular situation.
- Restriction of processing: to request the suspension of processing in certain circumstances.
- Portability: to receive the data in a structured, commonly used, machine-readable format and to transmit it to another controller.
- Not to be subject to automated decisions: including profiling, except in the cases legally provided for.
- Withdrawal of consent: at any time, without affecting the lawfulness of processing carried out prior to its withdrawal.
End Users who use the Gescon platform within the Customer's organisation must direct the exercise of their rights to the Customer, in its capacity as Data Controller. NURIA LABS, as Data Processor, will assist the Customer in handling these requests in accordance with Article 28(3)(e) GDPR.
9.1 How to exercise your rights
Data subjects may exercise their rights free of charge by contacting NURIA LABS through any of the following means:
- Email: gescon@nurialabs.com
- Postal mail: NURIA LABS SL, Carrer Sant Miquel, 36, 1.º A, 07002 Palma, Illes Balears, España
To ensure the right is properly exercised, it may be necessary to verify the requester's identity by means of a copy of their ID card or equivalent document. NURIA LABS will respond to the request within a maximum period of one month, extendable by a further two months in cases of particular complexity.
9.2 Complaints to the Supervisory Authority
If a data subject considers that the processing of their personal data does not comply with the applicable regulations, or if the exercise of their rights has not been satisfactorily addressed, they have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), located at C/ Jorge Juan, 6, 28001 Madrid, or through its electronic office: https://www.aepd.es.
10. Security measures
NURIA LABS applies appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. Among other measures, NURIA LABS:
- Stores data on Microsoft Azure infrastructure in the Spain region, with encryption in transit (TLS 1.2 or higher) and at rest (AES-256).
- Applies role-based access controls (RBAC) and strong authentication for access to internal systems.
- Maintains activity records (logs) that allow traceability of access and operations performed on the data.
- Performs regular backups and has incident recovery procedures in place.
- Applies incident management and security breach notification policies in accordance with the timeframes set out in the GDPR.
- Trains its staff in data protection and information security.
- Enters into confidentiality agreements with all staff and providers who have access to the data.
11. Customer Data and role as Data Processor
With regard to the personal data that the Customer uploads, connects or processes through the Gescon platform ("Customer Data"), NURIA LABS acts as Data Processor, with the Customer being the Data Controller. The terms of this arrangement are governed by the corresponding Data Processing Agreement (DPA), which forms part of the Terms and Conditions of the service and is deemed to be signed upon acceptance of those Terms or upon activation of the account.
In its capacity as Data Processor, NURIA LABS:
- Will process Customer Data solely in accordance with the Customer's documented instructions and for the provision of the service.
- Will not use Customer Data for its own purposes or transfer it to third parties, other than authorised sub-processors.
- Will ensure the confidentiality of the persons authorised to process the data.
- Will apply appropriate technical and organisational measures.
- Will assist the Customer in addressing data subjects' rights and enquiries from the supervisory authority.
- Will notify any security breach affecting Customer Data without undue delay.
- Will return or delete Customer Data upon completion of the service, in accordance with the agreed timeframes.
12. Minors
NURIA LABS's services and communications are aimed exclusively at persons over 18 years of age. NURIA LABS does not knowingly collect data from minors. If you become aware that data has been collected from a minor without appropriate consent, you may report it to gescon@nurialabs.com so that it can be deleted.
13. Amendments to the Privacy Policy
NURIA LABS reserves the right to amend this Policy to adapt it to legislative or case-law developments, or to the practices and services provided. Amendments will be published on the Website and, where they materially affect the processing, will be expressly communicated to the data subject.
You are advised to periodically review this Policy. The date of the last update appears at the beginning of the document.
14. Contact
For any query about this Privacy Policy or about the processing of your personal data by NURIA LABS, you may contact us at:
| Field | Detail |
|---|---|
| Email address | gescon@nurialabs.com |
| Postal address | NURIA LABS SL, Carrer Sant Miquel, 36, 1.º A, 07002 Palma, Illes Balears, España |
| Phone | +34 871 55 71 41 |