Optional product history
If you enable product history, this browser stores references to the last eight products viewed and the date of each visit for up to 30 days. Permission also expires after 30 days. We use local storage (eic.recent-products.v1 and eic.recent-products.consent.v1), without creating an account or following browsing on other sites. When displaying the list, references are sent to the catalogue to obtain current information; we do not create a history profile on the server. You can clear history or disable and erase it under “History” at the bottom of public pages. History is not shared across devices.
Data controller
- Controller
- GRUPO EIC IBERIA, S.L. (EIC Controls)
- Tax number
- B88259924
- Address
- Avenida de Madrid, 48, 28802 Alcalá de Henares, Madrid, Spain
- sales@eiccontrols.com
- Telephone
- +34 910 762 309
No data protection officer has been appointed. Any question about this policy or about your rights should be sent to the email address above.
Purposes, legal basis and retention
This site processes personal data in four situations, and only those four. The first three happen whenever somebody writes to EIC Controls, subscribes to the instrumentation notes or simply opens a page; the fourth — advertising — is off by default and only comes into existence once the visitor has expressly accepted it. Each has its own legal basis and its own period.
| Purpose | Legal basis | Retention |
|---|---|---|
| Answering a quote request or a contact message | Steps taken at the request of the data subject prior to a contract, and the legitimate interest of the controller in replying to whoever writes (Article 6(1)(b) and 6(1)(f) GDPR) | For as long as the enquiry is being handled and the reply may have to be accounted for; the public link to the request stops working 90 days after it was sent |
| Sending the instrumentation notes (newsletter), with double opt-in | Express consent of the data subject (Article 6(1)(a) GDPR) | Until the subscriber leaves the list or asks for erasure; the unsubscribe link is in every message and on the newsletter page |
| Measuring the audience of the site to learn which pages are useful | Legitimate interest of the controller in understanding the use of its own site, measured in aggregate and without identifying people (Article 6(1)(f) GDPR) | Detailed record 90 days; aggregated daily totals 25 months |
| Advertising and campaign measurement through the Meta Pixel — optional, and off by default | Express consent of the visitor (Article 6(1)(a) GDPR) and, for the storage of and access to information on the device, article 22.2 of Spanish Law 34/2002 (LSSI) | Exists only after acceptance: the choice is kept in this browser for 180 days and the cookies Meta sets last up to 90 days. EIC Controls keeps no data of its own from this processing |
Quote requests and contact messages
When you send a quote request or a contact message, what is stored is what you typed into the form:
- Name; company, telephone and country, which are optional fields; email address; the message you wrote.
- The channel you prefer to be answered on (email or WhatsApp) and the language the page was in.
- For quote requests, the list of references and quantities you had gathered, with the product title and variant as they stood when you sent it.
- The consent text you accepted and the moment you accepted it — the record of what you agreed to, stored verbatim.
- A reference code for the request, the date it was sent and the page of the site the form was opened from.
- The source, medium and campaign of the link that brought you, accepted only from a known list of names, and the domain — never the full address — of the site you came from.
To that the sales team adds its own work on the request: the status of the enquiry — new, in progress, answered, won, lost, closed or unwanted — and internal notes, in free text, about the request and about the conversation that followed. They are written by the team, never by the person who sent the form, and they exist only inside the administration area: they never appear on the public link to the request and are never passed to a third party. Like any other data in this processing, they can be accessed and corrected under the rights described below.
The IP address is not stored anywhere in this processing. It is read by the network when the form is sent, turned into a cryptographic digest in memory so that repeated submissions can be limited, and discarded: no table of this site has a column to hold it. It is also passed to Cloudflare in the anti-robot validation request, which is what lets that check tell a person from an automated program; there it is handled by Cloudflare, as a processor, for that purpose alone.
Filling in the form is voluntary, but without a name, an email address and a message no reply is possible. On submission the request is recorded and an internal message carrying it is sent to the sales team; no copy goes to any third party. That internal message stays in the site’s sending queue, carrying the content of the request, so that it can be sent again if delivery fails; the queue is not purged automatically, so the copy is kept for the same period as the request — for as long as the enquiry is being handled — and can be deleted on request, at the contact address given in this policy.
Every request gets a link of its own, carrying a long random code, where the sender can see its status and its lines. That link stops working 90 days after the request was sent and never shows contact details.
Newsletter
Subscription to the instrumentation notes uses double opt-in: after giving the address you receive a message with a link, and only following it makes the subscription active. An address that never confirms receives nothing.
- The email address and the language chosen.
- The status of the subscription and the dates of subscription, confirmation and unsubscription.
- The consent text accepted and the moment it was accepted.
- The form it was subscribed from and the same sanitised attribution described above.
You may leave the list at any time through the link in every message, with no reason given. It takes effect immediately and the record is kept only so that nothing is sent again.
If you would rather have full erasure than a simple unsubscription, ask for it at the contact address: the subscriber record is deleted and, with it, any messages still queued for that address. All that remains is an internal audit line recording that the operation happened and who performed it, without the address.
Audience measurement
We count visits to learn which pages are useful. The measurement is the site’s own, it is aggregated, it uses no cookies, it stores no IP address, it follows nobody between sites and it is shared with nobody. There is no way to link a visit to a quote request, a contact message or a subscription.
What carries that measurement on the device is a random identifier held in the session storage of the browser tab, which disappears when the tab is closed. The full list of what is measured, what is discarded and how long it is kept is in the cookies and similar technologies policy and in this section.
- Measured: the page, reduced to a normalised address from a closed list; the language; the country reported by the network; whether the device is mobile or desktop; relevant clicks; the search term, truncated and cleaned; and the origin of the visit reduced to a domain.
- Not measured: the IP address, the full browser identification, any name, address or free text, the full address you came from, and any parameter of the address.
- Pages whose link carries a code — the page of a request and the newsletter confirmation and unsubscribe pages — do not even load the measurement script.
- The detailed record is deleted after 90 days, once it has become daily totals that are kept for 25 months and no longer contain the tab identifier.
Because it identifies nobody, this measurement cannot find or delete one particular person’s visit: nothing links it to them. Anyone who would rather not be counted at all can turn on the browser’s do-not-track preference or block the measurement script, losing no feature of the site.
Advertising and campaign measurement
Besides the site’s own measurement described above, the site can load the Meta Pixel to measure how Facebook and Instagram advertising performs. It is a separate processing, optional and off by default: it only comes into existence when, at the same time, an administrator enables it in the administration area with a valid identifier and the visitor expressly accepts it on the page itself. Today it is switched off.
Acceptance is asked for in a notice shown on the page, with two equivalent buttons — accept advertising or reject advertising. Before acceptance nothing is requested from Meta: no script, no tracking image, no early connection to its domain. The choice is kept in the local storage of this browser for 180 days, under the entry “eic.marketing-consent.v1”, and can be reviewed at any time through the advertising preferences button.
Withdrawing acceptance takes effect immediately: the revocation instruction is sent to Meta, anything still queued is discarded, the script is removed from the page, the _fbp and _fbc cookies are deleted from this site’s domain and the page is reloaded so that none of Meta’s code stays in memory. A rejection also applies to the other tabs open at the same time. An acceptance is tied to the identifier that was active when it was given: if that identifier is changed or disabled, the acceptance no longer holds and the question is asked again — a rejection, by contrast, still holds.
- Where it may run: the home page, the root of the product type axis, the category pages of the three axes, product pages, the brand index and the brand pages, the blog with its categories and articles, and the “About EIC Controls” page.
- Where it never runs: the administration area, the quote and contact pages, the search, the newsletter page, the roots of the applications and measurements axes, the error pages, these four legal pages, and any address carrying a code — the page of a request and the newsletter confirmation and unsubscribe pages. The exclusions for addresses carrying a code are exactly those of the site’s own measurement.
- The integration also refuses to start if the address of the page, or the address the visitor came from, carries a fragment or a parameter outside the known list (utm_source, utm_medium, utm_campaign, utm_content, utm_term and fbclid): that is what stops Meta’s script from reading anything unforeseen out of the address.
- What is reported: the page view and, on a product page, the view of that product identified by its public reference. No form values, no advanced matching of personal data and no conversion events are sent — a quote request, a contact message or a subscription is never reported to Meta.
The legal basis for this processing is the consent of the visitor (Article 6(1)(a) GDPR) and, for the storage of and access to information on the device, article 22.2 of Spanish Law 34/2002 (LSSI). It is not the legitimate interest that supports audience measurement: without acceptance nothing runs, and withdrawing acceptance is as easy as giving it.
Meta is the controller of the processing it carries out on the data it receives this way — in particular to link it to an account and to measure and target its advertising — and that processing is governed by Meta’s privacy policy, at www.facebook.com/privacy/policy/. The _fbp and _fbc cookies that result are set by Meta and last up to 90 days; rejecting deletes them from this site’s domain. EIC Controls keeps no data of its own from this integration and has no way of linking what Meta receives to a request, a contact message or a subscription.
Recipients and processors
Data is not sold or rented. Apart from the advertising case described above — where, and only if the visitor accepts it, Meta receives browsing data and also handles it for its own purposes, as a controller — nothing is handed to third parties for their own purposes. Everything else is handled by those who provide the technical services that make the site work, in that capacity and on instructions:
| Who | What for | Where |
|---|---|---|
| Cloudflare | Hosting of the site, database of requests and subscriptions, storage of images and documents, delivery of the site’s email messages, and anti-robot verification of the forms (Turnstile) | Distributed network, with processing in the European Union and standard contractual clauses for any processing outside it |
| EIC Controls email service | Receipt and handling of the messages sent by the forms, in the sales team mailbox | European Union |
| Meta | Advertising pixel, on the content pages listed in the previous section and only if the visitor accepts it: it receives the browsing data of that visit and handles it for its own purposes, as a controller and not as a processor | Determined by Meta in its own privacy policy (www.facebook.com/privacy/policy/), including processing outside the European Economic Area |
Data may also be disclosed to public authorities where a legal rule requires it.
The anti-robot verification of the forms is run by Cloudflare at the moment of submission and exists only to tell a person from an automated program. It builds no profiles and is not used for advertising.
International transfers
The site and its database are configured to process data within the European Union. The providers above run global networks and, in occasional technical situations, processing may take place outside the European Economic Area.
In those cases the transfer is covered by the instruments of Chapter V GDPR — in particular the standard contractual clauses approved by the European Commission and, where applicable, an adequacy decision — together with the provider’s additional technical measures. A copy of the applicable instruments can be requested at the contact address.
Security
The site is served only over an encrypted connection. Access to the administration area is restricted to authorised people and protected by its own authentication; exports and queries in that area are written to an audit trail that stores no contact details.
Public forms are protected by anti-robot verification and by submission limits. Even so, no transmission over the Internet is entirely free of risk; in the event of a personal data breach likely to result in a high risk, data subjects will be informed as the GDPR requires.
Your rights
As a data subject you may exercise the following rights at any time:
- Access
- Find out what data about you is processed and obtain a copy of it.
- Rectification
- Correct inaccurate data or complete incomplete data.
- Erasure
- Ask for the data to be deleted where it is no longer needed, where you withdraw consent, or where you object on valid grounds.
- Objection
- Object to processing carried out on the basis of legitimate interest, setting out your particular situation.
- Portability
- Receive the data you provided in a structured, commonly used format, or ask for it to be transmitted to another controller where that is technically feasible.
- Restriction
- Ask for processing to be suspended while the accuracy of the data is checked or an objection is decided.
- Withdrawal of consent
- Withdraw at any time the consent given for the newsletter, without affecting the lawfulness of what was sent before.
To exercise any of these rights, write to sales@eiccontrols.com or to Avenida de Madrid, 48, 28802 Alcalá de Henares, Madrid, Spain, saying which right you wish to exercise. A reply is given within one month, extendable as the GDPR allows, and proof of the identity of the person asking may be requested where there is reasonable doubt.
If you believe the processing does not comply with the law, you may lodge a complaint with a supervisory authority. The authority of the country where the controller is established is the Agencia Española de Protección de Datos (AEPD, www.aepd.es); anyone in Portugal may address the Comissão Nacional de Proteção de Dados (CNPD, www.cnpd.pt), and any data subject may turn to the supervisory authority of the Member State where they live or work.
Automated decisions and minors
No decision is taken solely on the basis of automated processing, including profiling, that produces legal effects or significantly affects the data subject.
The site is aimed at professionals and is not intended for minors. No data about minors is knowingly collected; where any is found, the record is deleted.
Changes to this policy
This policy may be updated whenever the processing described here or the applicable law changes. The version in force is the one published on this page, carrying the review date shown at the top.
