Privacy

Privacy policy

Last updated: 29/08/2025

This Privacy Policy explains how MELFAVORES SLU (Aigenrix) processes your personal data in accordance with the GDPR and applicable Spanish data protection law.

1) Data Controller

This Privacy Policy applies to the use of the Website and associated services (the "Services"). It forms an integral part of our Terms of Use.

  • ·Melfavores SLU (hereinafter "Aigenrix", "we", "us", "our")
  • ·Tax ID: B13696315
  • ·Registered office: Calle Narcís Macià i Domènech, 21, Esc. A, 2º 1ª, 17310 Lloret de Mar, Girona, Spain
  • ·Website: https://www.aigenrix.com/
  • ·Email: team@aigenrix.com

2) Applicable regulatory framework

The processing of personal data by Aigenrix is governed by:

  • ·Regulation (EU) 2016/679 (GDPR)
  • ·Organic Law 3/2018 (LOPDGDD)
  • ·Law 34/2002 (LSSI)
  • ·Other applicable state and regional regulations

3) Data protection principles

We process data in accordance with GDPR principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.

4) Categories of data we process

Depending on the use of the Website and Services, we may process:

  • ·Contact data: name, surname, email, postal address, phone.
  • ·Identity and profile data: username/ID, language, preferences.
  • ·Billing and payment data: tax identifiers (e.g., VAT), billing address, tokenised payment methods, transaction metadata. We do not store complete card data; processing is performed by certified payment providers (PCI DSS).
  • ·Communications: messages you send us through forms or messaging.
  • ·Technical/usage data: IP, online identifiers, logs, device, browser, OS, pages viewed, events.
  • ·Marketing and cookie preferences: consent and choices about communications and advertising.
  • ·Special data: we do not request or wish to process special categories (health, biometric, ideology, etc.). We ask you not to provide such information unless strictly necessary, in which case explicit consent and enhanced measures apply.

5) Purposes and legal bases

You can withdraw your consent at any time without retroactive effect. When the basis is legitimate interest, you can request the balancing test.

  • ·Contact and inquiry management — Consent / Legitimate interest
  • ·Service contract execution — Contract execution
  • ·Billing and tax obligations — Legal obligation
  • ·Marketing and commercial communications — Consent
  • ·Web analytics and service improvement — Consent / Legitimate interest
  • ·Security and fraud prevention — Legitimate interest / Legal obligation

6) Data retention

We retain data only for the time necessary for the stated purposes and, where applicable, for the periods required by law. As guidance:

  • ·Contractual and billing data: up to 6 years (art. 30 CCom) and applicable tax prescription.
  • ·Support and communications: up to 3 years from last interaction.
  • ·Marketing: until you revoke consent or object; periodic purges.
  • ·Security logs: short and proportionate periods, except incidents.

7) Recipients and processors

We do not sell your data. We may share it with:

  • ·Providers/processors who provide us services under Art. 28 GDPR contract, with documented instructions and adequate technical and organisational measures.
  • ·Independent third parties when necessary to comply with the law or requests from competent authorities and jurisdictional bodies.

Hosting and platform

  • ·Vercel Inc. — website hosting, build pipeline and edge delivery network (Processor).

Analytics

  • ·Google Ireland Ltd. (Google Analytics 4) — audience measurement, loaded only if you accept the Analytics cookie category (Processor).

Scheduling

  • ·Cal.com, Inc. — the discovery-call booking widget embedded on this site, loaded only if you accept the Marketing cookie category (Processor).

Communications

  • ·If you choose to contact us via WhatsApp, Meta Platforms processes that conversation as an independent controller under its own terms — we do not embed WhatsApp on the site, it is only a link you may click.

8) International transfers

When transfers occur outside the EEA/EU/UK to countries without an adequacy decision, we use Standard Contractual Clauses (and, where applicable, IDTA/UK Addendum), together with complementary measures (encryption in transit and at rest, access controls, minimisation and pseudonymisation). You can request a copy of essential safeguards.

9) AI / LLM processing safeguards

When you use AI-based functions:

  • ·We limit inputs to what is necessary, mask direct identifiers when viable, and disable use for training by default when the provider allows it.
  • ·We do not process special categories through these providers without explicit consent and additional safeguards.
  • ·We log accesses for auditing.
  • ·We do not use AI providers for direct marketing without your consent.

10) Security

We apply technical and organisational measures appropriate to the risk: TLS encryption, access controls, logging and monitoring, backups, hardening and least-privilege policies. No system is 100% secure; in case of a security breach involving risk, we will notify the DPA and affected parties in accordance with Arts. 33 and 34 GDPR.

11) Minors

Our Services are not directed to persons under 18. If we detect unauthorised processing, we will delete the data reasonably soon. Parents or guardians can write to team@aigenrix.com to request deletion.

12) Data subject rights

You can exercise at any time your rights of access, rectification, deletion, opposition, limitation, portability, and not to be subject to automated decisions (including profiling with legal or similar effects).

  • ·How to exercise: send a request to team@aigenrix.com or by postal mail to the controller's address, indicating the right exercised and proving your identity. If acting via representation, attach sufficient power/mandate.
  • ·Deadlines: we will respond within one (1) month from receipt; this may be extended by two more months in complex cases (art. 12.3 GDPR).
  • ·Claims: if you are not satisfied, you may contact the Spanish DPA at www.aepd.es.

13) Commercial communications (LSSI)

We will only send commercial communications by electronic means with your prior consent, or if there is a prior contractual relationship and they refer to similar products/services, always offering a simple and free means to object in each shipment. You can revoke at any time through unsubscribe links or by writing to team@aigenrix.com.

14) Cookies and similar technologies

We use cookies and similar technologies for technical purposes and, with your prior consent, for analytics and optional marketing functionality. Detailed information about categories, providers, purposes, periods and how to configure or withdraw your consent is in our Cookies Policy, available on this website and manageable through the Preference Centre (CMP) accessible from the footer.

15) Automated decisions and profiling

We do not make exclusively automated decisions that produce legal effects or significantly affect you in a similar manner. If applied in the future, we will inform you transparently and offer you the right to human intervention and to challenge the decision.

16) Policy updates

We may modify this Policy to keep it aligned with regulations and our processing. We will publish the updated version with the last update date and notify you of material changes when appropriate.

Questions about this document?

Email team@aigenrix.com or write to MELFAVORES SLU, Calle Narcís Macià i Domènech, 21, Esc. A, 2º 1ª, 17310 Lloret de Mar, Girona, Spain.

← Back to home