Controller and scope
The controller is the owner identified on this page. This policy applies to data processed through rocotech.es under the RocoTech brand.
- Site owner
- Roberto González Linares
- Tax identifier
- 55075251A
- info@rocotech.es
- Other direct contact method
- Web form
- Privacy and rights email
- info@rocotech.es
- Hosting provider
- Hostinger International Ltd.
Categories of personal data
We may process name, email, organisation and information voluntarily included in an enquiry; service, objective, sector and project context; controlled attribution data such as page, language, CTA origin and UTM fields; and security data such as IP address, date, time, URL, browser, device and server logs.
Do not submit special-category data or confidential information that is unnecessary for the enquiry.
Enquiries and proposals
Purpose: receive, assess and answer enquiries, prepare a proposal when requested and follow it up. Legal basis: steps requested before entering a contract under Article 6(1)(b) GDPR; for general communications initiated by the individual, legitimate interests in responding under Article 6(1)(f).
Data is kept while the request is handled and, if no engagement begins, for the configured period after the last communication. Contract data is kept during the relationship and then restricted for applicable statutory periods.
- Enquiry retention without an engagement
- 6 months
- Site form limiter
- Active ten-minute window; expired files are removed during later cleanup operations.
- Hosting-provider logs
- For as long as needed to provide, protect and diagnose the service under the provider’s current terms and technical criteria; longer where required for an incident, legal obligation or claim.
- GA4 data retention
- 2 months
Security and abuse prevention
Data is processed to protect availability and security, limit abusive submissions, detect errors and manage incidents, based on legitimate interests. The site’s form limiter is separate from the provider’s logs: it stores a hash of the IP address and a counter for an active ten-minute window; expired files are removed during later cleanup operations. Separately, the hosting provider manages access, error and security logs and retains them for as long as needed to provide, protect and diagnose the service under its current terms and technical retention criteria. They may be kept longer where necessary to handle an incident, legal obligation or claim.
We also use Hostinger’s native server-access reports to understand aggregate use and diagnose the service, based on our legitimate interest in operating the website. We add no tracking tag, advertising cookies or cross-site profiles. These reports rely on technical logs that may include IP addresses and should not therefore be considered anonymous. Requests and distinct IP addresses do not equal an exact number of people and may include bots.
Analytics with consent
When analytics cookies are accepted, Google Analytics 4 measures site use to produce statistics and improve navigation and content. The basis is consent, which can be withdrawn through Analytics preferences.
First-party events cover CTA clicks, contact clicks and successful form delivery using controlled technical parameters. They exclude names, email addresses, phone numbers, organisations, messages, UTM values and submission IDs.
Basic Consent Mode
Before acceptance and if you reject, we do not load Google Analytics or send measurements to Google. If you accept, _ga and _ga_<id> cookies may be created for up to 180 days without refreshing their expiry on each visit. Your choice is stored for 180 days and can be withdrawn from the footer. We do not use advertising or send form data to Google.
Recipients and processors
Authorised people and necessary providers may access data: Hostinger for hosting, security and email; Google Ireland Limited for Analytics; and authorities where legally required. Personal data is not sold.
International transfers
Providers may use entities or subprocessors outside the EEA. Relevant safeguards will apply, such as adequacy decisions, the EU-US Data Privacy Framework where available or European Commission standard contractual clauses.
Provider information
Your rights
You may request access, rectification, erasure, objection, restriction and portability, and withdraw consent where it is the basis, by writing to the address below. Extra identification will be requested only where reasonable doubts exist.
You may also complain to the Spanish Data Protection Agency at aepd.es.
Required fields, children and decisions
Required form fields are needed to handle the request. Services are aimed at businesses and professionals, not specifically at children under fourteen. No solely automated decisions produce legal or similarly significant effects.
Security and updates
Reasonable technical and organisational safeguards are applied. This policy will be updated when processing, providers or legal requirements change.