Privacy Policy – Electronic Invoicing Service

Updated: [02/06/2025]

1.Identification of the Data Controller

  • Owner: nexmart S.L.
  • Address: Miramon Technology Park, Paseo Mikeletegi 56, ES-20009 Donostia, Spain
  • Contact email:administracion@nexmart.com
  • Data Protection Officer (DPO): seguridad@nexmart.com (if applicable)

nexmart S.L. is responsible for processing personal data collected and managed within the framework of the electronic invoicing service provided to its clients, in accordance with Regulation (EU) 2016/679 (GDPR) and the Spanish LOPDGDD.

2.Purposes of Processing

The personal data provided by the client will be used exclusively for:

  • Manage the contractual relationship related to the electronic invoicing service.
  • Issue, receive, validate, digitally sign, and store electronic invoices in accordance with current legislation.
  • Comply with legal requirements established in tax, accounting, and commercial matters.
  • Provide technical and functional support during the use of the platform.
  • Send notifications regarding service status, technical issues, or regulatory updates.

Your data will not be used for purposes other than those mentioned above without your explicit consent.

3.Legal Basis for Processing

Data processing is based on the following legal grounds:

  • The execution of a contract.
  • Compliance with legal obligations.
  • The legitimate interest of the controller.

Under no circumstances will unnecessary data or data unrelated to the described purposes be collected.

4.Data Retention

Data will be retained for the duration of the contractual relationship and subsequently for the legally required periods (generally 5 years or 10 years if applicable under the country's tax regulations). Afterwards, it will be securely deleted or irreversibly anonymized if agreed by the client.

5.Data Recipients

Data may be communicated to:

  • Public bodies and tax administrations.
  • Technology providers necessary for system operation, under contract in accordance with Article 28 GDPR.
  • Auditors or legal advisors, when necessary.

Data will not be shared with third parties for commercial purposes.

6.International Transfers

nexmart does not transfer personal data outside the European Economic Area (EEA). If any provider offers services from outside the EEA, an adequate level of protection will be ensured through standard contractual clauses.

7.Data Subject Rights

You may exercise your rights of access, rectification, deletion, restriction, objection, and portability. To do so, you can send an email to seguridad@nexmart.com, providing proof of identity. You may also file a complaint with the Spanish Data Protection Agency (www.aepd.es).

8.Security and Confidentiality

nexmart applies appropriate technical and organizational measures to protect personal data. This includes access control, encryption, audits, backups, and incident recovery protocols.

9.Policy Updates

nexmart may modify this policy to adapt it to new regulatory or technical requirements. In case of significant changes, users will be notified with reasonable advance notice.