Privacy Policy
Last updated: September 8th, 2026
1. Data Controller
In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 («GDPR») and Spanish Organic Law 3/2018 of 5 December on Personal Data Protection and Guarantee of Digital Rights («LOPDGDD»), we inform you that the personal data collected through this website will be processed by:
INNOVATE AI SECURITY, S.L.
NIF: B-01807338
Registered Office: C/ Cardenal Marcelo Spínola, 14, 5th Floor, 28016 Madrid, Spain
Email: dpo@innovate-security.ai
Website: www.innovate-security.ai
For any questions relating to this Privacy Policy or the processing of your personal data, you may contact us using the details above.
2. Purpose of Processing
INNOVATE may process personal data collected through this website for the following purposes:
a) Contact Requests
To manage and respond to inquiries, information requests, demonstrations, meeting requests, or communications submitted through website forms, email, or other contact channels.
b) Commercial Communications
To send information regarding our services, events, webinars, publications, cybersecurity insights, and business activities where permitted by law or where consent has been provided.
c) Business Relationship Management
To manage relationships with prospective customers, partners, suppliers, and professional contacts.
d) Recruitment Processes
Where applicable, to assess applications submitted through careers or recruitment forms and manage candidate selection processes.
e) Website Operation and Security
To ensure the proper functioning, security, maintenance, monitoring, and protection of our website, systems, and services.
f) Legal and Regulatory Compliance
To comply with applicable legal obligations, regulatory requirements, and requests from public authorities.
3. Categories of Personal Data
Depending on your interaction with our website, we may process:
- Identification data (name, surname).
- Professional information (job title, company, department).
- Contact information (email address, telephone number).
- Recruitment information (curriculum vitae, qualifications, employment history).
- Technical information (IP address, browser type, operating system, cookies, and device identifiers).
- Information voluntarily provided through forms, emails, or other communications.
We do not intentionally collect special categories of personal data unless required for a specific legitimate purpose and supported by an appropriate legal basis.
4. Legal Basis for Processing
The legal bases for processing personal data include:
Consent
Where you voluntarily complete forms, subscribe to communications, or otherwise expressly authorize specific processing activities.
Pre-contractual Measures
Where processing is necessary to respond to requests, proposals, quotations, service inquiries, or potential business opportunities.
Performance of a Contract
Where processing is required to provide services or fulfill contractual obligations.
Legitimate Interests
Where processing is necessary for legitimate business purposes, including:
- Customer and partner relationship management.
- Website security and fraud prevention.
- Improvement of services and user experience.
- Corporate communications with existing professional contacts.
Legal Obligation
Where processing is required to comply with applicable legal, tax, accounting, regulatory, or judicial obligations.
5. Data Retention
Personal data will be retained only for as long as necessary to fulfill the purposes for which it was collected. In general:
- Contact inquiries: until the request has been resolved and for any legally required retention period.
- Commercial communications: until consent is withdrawn or an objection is received.
- Business relationship data: for the duration of the relationship and subsequent legal retention periods.
- Recruitment records: for a maximum period permitted under applicable employment and data protection legislation.
- Security logs: for the period necessary to ensure cybersecurity, compliance, and incident investigation.
Upon expiry of applicable retention periods, personal data will be securely deleted or anonymized.
6. Recipients of Data
Personal data may be disclosed to:
- Companies within the AXAITRA Group, when necessary for internal administration and service delivery.
- Technology service providers acting as data processors.
- Cloud hosting and business application providers.
- Professional advisors, auditors, and legal representatives.
- Competent public authorities when legally required.
All service providers processing personal data on behalf of INNOVATE are contractually bound to implement appropriate technical and organizational security measures.
INNOVATE does not sell personal data to third parties.
7. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), INNOVATE will ensure that appropriate safeguards are implemented in accordance with GDPR requirements. Such safeguards may include:
- European Commission adequacy decisions.
- Standard Contractual Clauses (SCCs).
- Other legally approved transfer mechanisms.
You may request additional information regarding these safeguards using the contact details provided above.
8. Security Measures
INNOVATE implements appropriate technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, accidental loss, destruction, or misuse. These measures may include:
- Access control mechanisms.
- Encryption technologies.
- Network and endpoint protection.
- Monitoring and logging systems.
- Security awareness programs.
- Business continuity and incident response procedures.
As a cybersecurity-focused organization, we continuously review and improve our security controls to align with industry standards and best practices.
9. Data Subject Rights
You may exercise the following rights at any time:
- Right of access.
- Right to rectification.
- Right to erasure.
- Right to restriction of processing.
- Right to data portability.
- Right to object.
- Right not to be subject solely to automated decision-making where applicable.
To exercise these rights, please send a request to: dpo@innovate-security.ai
Your request should include sufficient information to verify your identity.
10. Right to Lodge a Complaint
If you believe that the processing of your personal data violates applicable data protection laws, you have the right to lodge a complaint with the competent supervisory authority. In Spain, this authority is:
Spanish Data Protection Agency (AEPD)
Website: https://www.aepd.es
The AEPD is the supervisory authority responsible for GDPR and LOPDGDD enforcement in Spain.
11. Third-Party Websites
This website may contain links to external websites operated by third parties.
INNOVATE is not responsible for the privacy practices, content, or policies of external websites. Users should review the privacy policies of any third-party website they visit.
12. Cookies
This website uses cookies and similar technologies.
Detailed information about the cookies used, their purposes, retention periods, and management options is available in our Cookie Policy.
13. Changes to this Privacy Policy
INNOVATE reserves the right to amend this Privacy Policy at any time to reflect legal, regulatory, operational, or technological changes.
The most current version will always be available on this website together with its effective date.