Legal information
Privacy policy
Information on the processing of personal data in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
Informative translation. In the event of any discrepancy, the Spanish version prevails.
This Policy explains how personal data obtained through the Site https://sds.bomontec.net, its forms, the initial assessment and the associated technical security controls are processed.
1. Data controller
The data controller is BOMONTE TECNOLOGIAS, S.L.
| Item | Information |
|---|---|
| Owner / service provider | BOMONTE TECNOLOGIAS, S.L. |
| Tax ID (NIF) | B83820696 |
| Registered address | C.C. El Palacio, local 26, Ctra. de Majadahonda 50, 28660 Boadilla del Monte (Madrid), España |
| Telephone | 912 161 400 |
| Privacy and data-subject rights channel | gdpr@bomontec.net |
| Contact email | emm@bomontec.net |
| Company registry details | Registro Mercantil de Madrid, Tomo 19.466, Folio 14, Sección 8, Hoja M-341632 |
| Commercial name of the service | Bomontec EMM |
| Domain | https://sds.bomontec.net |
The email gdpr@bomontec.net is a privacy and data-subject rights channel. It is not presented as a Data Protection Officer unless BOMONTE TECNOLOGIAS, S.L. formally appoints and publishes one.
2. Data we may process
- Identification and contact data: name, surname, email address, telephone where provided and organisation.
- Professional and project data: job title, entity, industry, interest, current solution, approximate number of devices, current architecture and requirements voluntarily communicated.
- Content of enquiries: message, documentation or information the user decides to send, including the result of the fit evaluator if the user chooses to send it.
- Technical and security data: IP address, date and time, URL, HTTP method, user-agent, technical identifiers, anti-abuse signals of the form (submission limits, honeypot), errors and security logs.
- Communication preference data where the data subject requests to receive commercial information.
3. Purposes and legal bases
Data is processed for the purposes and on the legal bases set out below:
| Purpose | Description | Legal basis |
|---|---|---|
| Handling enquiries and requests | Managing the enquiry, replying, preparing meetings and coordinating contact. | Art. 6(1)(b) GDPR where these are pre-contractual measures requested; Art. 6(1)(f) GDPR to manage legitimate professional relationships where applicable. |
| Initial assessment | Preparing and delivering the requested technical session and drawing up preliminary conclusions. | Art. 6(1)(b) GDPR, pre-contractual measures at the request of the data subject or the entity they represent. |
| Preparing proposals and B2B relationship | Drawing up offers, coordinating presales, support and the professional relationship. | Art. 6(1)(b) GDPR and, for professional contacts associated with a legal entity, legitimate interest within applicable legal limits. |
| Site security | Detecting abuse, fraud, malware, intrusion attempts, investigating incidents, generating evidence and protecting the infrastructure. | Art. 6(1)(f) GDPR: legitimate interest in guaranteeing confidentiality, integrity, availability and defence against attacks. |
| Legal compliance and defence of claims | Meeting obligations and valid requirements and retaining the necessary evidence. | Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR. |
| Optional commercial communications | Sending news, invitations or information about Bomontec EMM, secure mobility and related services where applicable. | Consent, Art. 6(1)(a) GDPR, where required; and LSSI rules on commercial communications. |
4. Mandatory nature of the data
Fields marked as mandatory are necessary to process the corresponding request. Failure to provide the minimum data may prevent us from handling it. Subscription to commercial communications is voluntary and does not condition the handling of an enquiry or assessment.
5. Retention
Data is kept for as long as necessary for the corresponding purpose and thereafter for the applicable statutory limitation or retention periods, duly blocked where appropriate. Enquiries that do not lead to a professional relationship are reviewed and deleted when no longer necessary. Technical and security logs are kept for a period proportionate to their purpose and may be kept longer when linked to an incident, investigation, legal obligation or defence of claims.
6. Recipients and processors
Data is not sold. It may be accessed by providers that render services to BOMONTE TECNOLOGIAS, S.L. as data processors, such as hosting, infrastructure, email, support, security or corporate tools, under the contractual obligations set out in the GDPR.
Data may also be disclosed to authorities, courts, tribunals, law enforcement or other bodies where a legal obligation or valid requirement exists or where necessary to establish, exercise or defend claims.
Where a request requires the involvement of Samsung SDS, Samsung or another manufacturer or integrator, only the necessary data will be disclosed under an appropriate legal basis and the applicable contractual framework. If this involves an international transfer, the safeguards required by Chapter V of the GDPR will be applied beforehand and information will be provided where appropriate.
7. International transfers
In the current configuration of the Site, no analytics, advertising or third-party resources are loaded while browsing (fonts and other resources are served from our own domain), so no international transfers arising from mere browsing are foreseen. This situation will be reviewed if new providers, cloud services, external fonts, embedded videos, maps, CAPTCHA, analytics or marketing tools are added.
8. Automated decisions and profiling
The Site does not take decisions with legal or similarly significant effects based solely on automated processing. Automatic security measures (for example, form submission limits or blocking of abusive traffic) have a technical protective purpose and may be reviewed where a legitimate incident exists. The fit evaluator runs entirely in the user's browser and does not create profiles.
9. Rights of data subjects
You may exercise the rights of access, rectification, erasure, objection, restriction and portability, where applicable, and withdraw consent without affecting prior lawfulness, by writing to gdpr@bomontec.net or to the controller's address. The request must allow reasonable verification of identity; additional documentation will only be requested when necessary and proportionate.
You may also lodge a complaint with the Spanish Data Protection Agency (AEPD) if you consider that the processing infringes applicable law.
10. Commercial communications
Where sending is based on consent, it will be specific, freely given and unambiguous and may be withdrawn at any time through the mechanism indicated in each communication or by writing to the privacy channel. Withdrawal will not affect the handling of services already requested.
11. Minors
Bomontec EMM is a professional and business guidance service and is not aimed at minors. We do not knowingly seek to collect data from minors through commercial forms.
12. Security
BOMONTE TECNOLOGIAS, S.L. applies reasonable technical and organisational measures for access control, logging, perimeter protection, updates, backups and incident management according to risk. No Internet-connected system can guarantee absolute security; users must protect their credentials and report unauthorised use.
13. External links
Links to manufacturers, certification bodies, videos, social networks or other third parties lead to external services with their own policies. A mere link does not mean that such third parties receive data from the Site before the user accesses their page, unless an external resource is expressly embedded, in which case it will be reflected in this policy and in the cookie policy.
14. Changes to this policy
The Policy may be updated when the Site, the processing, the providers or the regulations change. The date of the current version is shown at the end of the document.
Public forms and ordinary email must not be used for classified information, keys, passwords, third-party secrets, sensitive indicators of compromise, operational configurations or documentation subject to special restrictions. Where a project requires it, an authorised channel and the corresponding processing regime will be agreed beforehand.
Last updated: 28 Sep 2026