Privacy and personal
data protection policies

 

 

Last update: July 1st, 2026.

* This policy was originally drafted in the Spanish language. In the event of any discrepancy between the original and a translated version, the Spanish language original shall prevail.

 

 

IntroductionWelcome to FRACTTAL

Hello! Welcome to FRACTTAL, a cloud service software (SaaS) for maintenance management and business asset management, from now on we will be called "PLATFORM" or simply "FRACTTAL" and you and all the people who use FRACTTAL, will be called in this document as USER(S) or HOLDER.

Definitions

Definitions

User or HolderUser or Holder: It is the PHYSICAL person who makes use of the services of FRACTTAL or who enjoys the web page, even without having an account, with whom the personal data is related.

 

Personal informationPersonal information: All information about an identified or identifiable PHYSICAL person.

 

Data Processing (or “Processing”)Data Processing (or “Processing”): Any set of operations on personal data, such as collection, storage, use, circulation or deletion.

 

Responsible for TreatmentResponsible for Treatment: Natural or legal person, public or private, that by itself or in association with others, determines the purposes and means in which personal data will be processed.

 

Treatment ManagerTreatment Manager: It is the natural or legal person, public authority or other body that processes personal data on behalf of or on behalf of the data controller.

 

General Data Protection RegulationGeneral Data Protection Regulation: (Hereinafter, RGPD/GDPR) It is the new regulation that regulates the protection of the data of citizens who live in the European Union.

Principles Principles

In the processing of your personal data, the following principles are especially applied:

 

Principle of legalityPrinciple of legality: In FRACTTAL the data of our USERS are treated in accordance with the provisions of the laws that regulate the matter and in the other provisions that develop them.

 

Principle of purposePrinciple of purpose: The Treatment of our users' data obeys a defined, legitimate and informed purpose, in accordance with current laws and the General Regulations for the Protection of Personal Data. In this document the USER can know the purposes of the processing of their data.

 

Principle of freedomPrinciple of freedom: We process data only with the prior, express and informed consent of the HOLDER. Personal data may not be obtained or disclosed without the prior authorization of the HOLDER, or in the absence of a legal or judicial mandate.

 

Transparency principleTransparency principle: We guarantee the HOLDER's right to obtain, at any time and without restrictions, information about the existence of data that affects him.

 

Safety principleSafety principle: The information subject to Treatment is handled with the technical, human and administrative measures necessary to provide security to the records, avoiding their adulteration, loss, consultation, use or unauthorized or fraudulent access to personal data.

 

principio-de-confidencialidadConfidentiality principle: All the people of our company, who intervene in the Processing of personal data, are obliged to guarantee the confidentiality of the information, even after the end of their relationship with any of the tasks that the Processing comprises.

 

principio-de-limite-plazoThe principle of limitation of the term of conservation: The conservation of the data is limited to the purposes that we inform in this document. Once these purposes have been achieved, the data is deleted or, at least, devoid of any element that allows the interested parties to be identified.

responsable-tratamiento Who is responsible for the treatment?

 

The Data Controller for USERS' personal data is the FRACTTAL parent company or its subsidiaries located in Brazil, Chile, Colombia, Mexico and Peru. For operations in other markets, FRACTTAL TECH S.L. shall act as the sole Controller.


Within the framework of the provision of Fracttal One SaaS services, FRACTTAL acts as the Data Processor of the personal data that the Client enters on the platform, with the Client being the Controller of such data, in accordance with Article 28 of the GDPR (EU) 2016/679 and applicable data protection legislation in each jurisdiction.

 

Headquarters: FRACTTAL TECH S.L. - NIF: B-42756734

Address: San José Artesano 12-14 Street, 2nd Floor, PC 28108 Alcobendas, Madrid, Spain

Activity: Servicios Informáticos

Email: privacy@fracttal.com

https://www.fracttal.com/en/contacto

autorizacion

Authorization of the Owner for Data Processing

FRACTTAL, requires the free, prior, express and informed consent of the HEADLINE of personal data for the treatment of these. The authorization of the Holder will not be necessary in the cases that the RGPD expressly excludes and/or indicates the applicable law on personal data protection. This authorization will be granted by the HOLDER, who must prove their identity.

 

The personal information that we process is limited to identification data (name and surname, address, DNI, telephone, address and email), payment and billing data.

Ways to acquire authorization Ways to acquire authorization

We collect the personal information of the Holder through different means, such as our contracts, website, social networks, forms, newsletter, or mobile app, but the HOLDER will always be informed at the time about the person responsible for the treatment, the purposes, the recipients of the data and the retention period of your information, as well as the way in which you can exercise the rights you have in terms of data protection.

 

SOCIAL NETWORKSSOCIAL NETWORKS: As we explained FRACTTAL, it uses social networks and this is another way to communicate with the HOLDER. These social networks have their own privacy policies that explain how they use and share your information, so FRACTTAL recommends that you consult them before using them to confirm that you agree with the way your information is collected, treated and shared.

 

WEB PAGEWEB PAGE: Through our website we collect personal information related to your browsing through the use of cookies. To clearly and precisely know the cookies we use, what their purposes are and how you can configure or disable them, see our Cookies Policy HERE.

 

MOBILE APPMOBILE APP: When using our mobile app and to provide you with the services it offers, we use the geolocation data of your mobile device if you have activated said functionality. If you do not have geolocation activated, we will inform you and ask for your permission beforehand with a notification. Most mobile devices provide users with the ability to disable these services at will, usually through the device's settings menu. If you have questions about how to activate/deactivate this functionality, consult the website of the manufacturer of your device or contact your telephone operator.

finalidadesWhat are the Purposes and Uses of the Data?

FRACTTAL will carry out operations that include the collection of personal data, its storage, use, circulation and/or deletion. This Processing of personal data will be carried out exclusively for the purposes authorized and provided for in this Policy and in the specific authorizations granted by the owner. Personal data will be processed in accordance with the interest group and in proportion to the purposes of each processing, as described below:

 

CustomersCustomers: 

 

  1. Administrative, commercial, promotional, informative, marketing and sales purposes.
  2. Offer all kinds of commercial services; as well as carrying out promotion, marketing and advertising campaigns.
  3. Management of the Human Resources Module in the Fracttal One software, categorized as maintenance technicians or supervisors in the client's database whose treatment activities are registration, structuring, safeguarding, interconnection and transmission, d Perform all internal procedures and compliance with accounting, tax and legal obligations.
  4. Manage the accounting and billing process of the company.
  5. Maintain a digital file that allows having the information corresponding to each contract with the client so that they can participate in our Fracttal University courses.
  6. When the Client activates the Model Context Protocol (MCP) access feature, FRACTTAL acts as Data Processor of the MCP endpoint it manages, pursuant to Article 28 of the GDPR. Processing activities in this context include: querying, transmitting and audit-logging of Client data accessed via the MCP endpoint. Data accessed through the endpoint is transmitted exclusively to the external artificial intelligence assistant selected and configured by the Client itself; FRACTTAL does not receive or process such content for its own purposes. The processing carried out by the external AI provider (including, without limitation, Anthropic, OpenAI, Microsoft or Google) falls outside the scope of this Policy and is the exclusive responsibility of the Client as Data Controller, who must verify the guarantees of the chosen AI provider and enter into the corresponding data processing agreements.

    Context Protocol (MCP), FRACTTAL acts as the Data Processor of the MCP endpoint it manages, under the terms of Article 28 of the GDPR. The processing operations in this context are: consultation, transmission and audit logging of the Customer's data accessed via the MCP endpoint. The data accessed via the endpoint is transmitted exclusively to the external AI assistant or content for its own purposes. Processing by the third-party AI provider (including, but not limited to, Anthropic, OpenAI, Microsoft, or Google) is outside the scope of this Policy and is the sole responsibility of the Customer in its capacity as Data Controller, who must verify the warranties of the chosen AI provider and enter into the corresponding data protection agreements. Legal basis: performance of a contract (Art. 6.1(b) GDPR).

 

Potential customersPotential customers:

 

  1. Advertising or promotional purposes, information about our services, marketing and sales.
  2. Offer all kinds of commercial services; as well as carrying out promotion, marketing and advertising campaigns.

 

ProvidersProviders:

 

  1. For all purposes related to the object of the selection, contractual or related processes.
  2. Perform all internal procedures and compliance with accounting, tax and legal obligations.
  3. Manage the company's budget chain: company payments, issuance of certificates, income and withholdings (individuals and legal entities) and payment relationships.
  4. Manage the accounting process of the company.
  5. Carry out all the activities necessary to comply with the different contractual stages in relations with suppliers and contractors.
  6. Issue the contractual certifications requested by the company's contractors or requests from the control entities.
  7. Maintain a digital file that allows having the information corresponding to each contract.

 

Candidates interested in job vacancies or employeesCandidates interested in job vacancies or employees:

 

The purpose of the delivery of the data provided by the interested parties in the vacancies of FRACTTAL and the personal information obtained from the selection process is limited to participation in the same or future selection processes where there are vacancies that apply to the person's profile; therefore, its use for different purposes is prohibited.

 

These data are processed for the following purposes:

 

  1. Manage the employment relationship between FRACTTAL and the employee.
  2. Report the data to the social security system.
  3. Perform all internal procedures and compliance with accounting, tax and legal obligations.
  4. Issue the labor certifications requested by the company's employees or requests from the control entities.
  5. Manage the budget chain of the company: payments, issuance of income certificates and withholdings and payment relationships.

User ResponsibilityUser Responsibility

By providing us with your data through electronic channels, the user guarantees that they are over 18 years of age and that the data provided to FRACTTAL is true, accurate, complete and up-to-date. The user is responsible for the veracity of the data communicated and for keeping said information updated.

Third Party LinksThird Party Links

FRACTTAL may contain links to third party websites. FRACTTAL has no control over such THIRD PARTY SITES nor is it responsible for the availability of these nor for the services, contents, advertisements, products or any material available in them.

 

The THIRD PARTY SITES are governed by their corresponding Terms and Conditions of Use and Privacy Policy, so it is the responsibility of the USER to verify them before accepting them.

How long do we keep your information? How long do we keep your information?

At FRACTTAL we only keep your information for the period of time necessary to fulfill the purpose for which it was collected, to comply with the legal obligations that are imposed on us and to attend to the possible responsibilities that may derive from the fulfillment of the purpose for which the data is collected. data was collected.

 

In the event that you want to become part of our staff and opt for one of our jobs, the data provided will become part of our job bank and will be kept for the duration of the selection process and for a maximum of 2 years or until you exercise your right of deletion.

 

If at any time we have collected your data to address you as a potential user of our services or to respond to a request for information made by you, said data will be kept for a maximum of 5 years from its collection, and will be deleted after said period. period if a contractual relationship has not been formalized or at the time you request it.

 

In any case, and as a general rule, we will keep your personal information while there is a contractual relationship that binds us or you do not exercise your right to suppress and/or limit the treatment, in which case, the information will be blocked without giving it use beyond its conservation, as long as it may be necessary for the exercise or defense of claims or some type of responsibility that had to be addressed could arise.

What are your rights in relation to the processing of your data and how can you exercise them?What are your rights in relation to the processing of your data and how can you exercise them?

The regulations on data protection allow you to exercise your rights of access, rectification, deletion or revocation and data portability and opposition and limitation to their treatment.

 

If you are in a country of the European Union and in order to facilitate its exercise, we provide you with links to the application form for each of the rights:

 

Exercise of the right of access form

Form for exercising the right of rectification

Opposition right exercise form

Form for exercising the right of suppression (right “to be forgotten”)

Form for exercising the right to limitation of treatment

Right to portability exercise form

Exercise form not to be subject to automated individual decisions

 

Our USERS who are outside the EU can also use the above forms or make a request, which must contain at least the following:

 

  • Name of the Holder, and their representatives, if applicable.
  • Specific and precise request for information, access, update, rectification, cancellation, opposition or revocation or deletion of consent for the processing of personal data.
  • Physical and/or electronic address for notifications.
  • Documents that support the request.
  • Signature of the request by the Holder.


To exercise their rights, FRACTTAL makes the following means available to its USERS:

 

 

The Holder and / or interested in exercising their rights, will prove their status by means of a copy of the relevant document and their identity document. In the event that the Holder is represented by a third party, the respective power of attorney must be submitted, in this case, the proxy must also prove his identity in the terms indicated, all of the above in order to verify that we only respond to the interested party or their legal representative.

What is the response time to requests?What is the response time to requests?

Requests, after meeting the admission requirements under legitimacy, will be addressed within a maximum period of ten (10) business days from the date of receipt. In the event that the request cannot be addressed within this period, the requester will be informed before the expiration of the ten (10) business days, stating the reasons for the delay and indicating the date on which the request will be fulfilled, which in no case may exceed five (5) additional business days after the end of the initial period.

What does FRACTTAL do for the security of my personal data?What does FRACTTAL do for the security of my personal data?

FRACTTAL foresees, cares for and adopts the technical, human and administrative measures that are necessary to maintain the security of the information of the USERS and attempts are made to prevent its loss, adulteration, access or consultation by unauthorized third parties through industry standard technologies and internal procedures. Likewise, FRACTTAL has the following protection measures

 

  • With security protocols and access to information, storage and processing systems, including physical security risk control measures.
  • FRACTTAL has the duty to notify Users within 72 hours if there is a security breach in the information.
  • Access to the different databases is restricted even for employees and collaborators.
  • All employees and third parties have signed confidentiality clauses in their contracts and are committed to the proper handling of the databases in accordance with the guidelines on the treatment of information established in the Law.
  • Documents or electronic media, if any (CD, pen drives, hard drives, etc.) with personal data will not be discarded without guaranteeing their effective destruction.
  • The devices and computers used for the storage and processing of personal data are kept up to date as much as possible.
  • To avoid improper remote access to personal data, care will be taken to guarantee the existence of an activated and correctly configured firewall on those computers and devices in which personal data is stored and/or processed.
  • When it is necessary to carry out the extraction of personal data outside the premises where its treatment is carried out, either by physical means or by electronic means, the possibility of using an encryption method should be assessed to guarantee the confidentiality of the personal data in the event of improper access to information.
  • Backup Copies: Periodically, a backup copy will be made in the cloud in order to allow the recovery of personal data in case of loss of information.

 

All these security measures are reviewed periodically to ensure their suitability and effectiveness. However, absolute security cannot be guaranteed and there is no security system that is impenetrable, therefore, in the event that any information subject to treatment and under our control is compromised as a result of a security breach, we will take the adequate measures to investigate the incident, notify the Control Authority and, where appropriate, those users who may have been affected so that they take the appropriate measures.

To whom do we communicate your data?To whom do we communicate your data?

Generally, in FRACTTAL we do not share the personal information of USERS, except for those transfers that we must make based on imposed legal obligations. However, to develop and provide the requested service, we transfer your data to other companies, which will act as Treatment Managers.

 

When the Client activates the MCP Service (Model Context Protocol), personal data accessed via FRACTTAL's endpoint is directed by the Client itself to the external artificial intelligence provider of their choice. FRACTTAL does not determine that recipient or control the processing carried out by that provider. The Client, as Data Controller, is exclusively responsible for verifying the guarantees of their external AI provider, including entering into a valid data processing agreement (DPA) with that provider, as well as complying with international data transfer mechanisms when the provider operates outside the European Economic Area. The personal data accessed via the FRACTTAL endpoint is directed by the Customer to the external AI provider of their choice. FRACTTAL does not determine this recipient and does not control the processing of the data by the provider. The Client, in its capacity as Data Controller, is solely responsible for verifying the guarantees of its external AI provider, including the subscriber, as well as for complying with international data transfer mechanisms when the provider operates outside the European Economic Area.

 

You can communicate your opposition to the transfer of your data, although in this case, it would not be possible to provide the requested service. Likewise, your personal information will be available to the Public Administrations, Judges and Courts, for the fulfillment of legal duties.

MCP Integration (Model Context Protocol)

FRACTTAL offers, as an additional service to the Fracttal One subscription, the activation of an access endpoint using the open standard Model Context Protocol (MCP). This service allows the Client to connect, under their own responsibility and configuration, third-party artificial intelligence assistants (including, without limitation, Anthropic's Claude, OpenAI's ChatGPT, Microsoft's Copilot and Google's Gemini) to the Client's Fracttal One data environment.tivación de un endpoint de acceso mediante el protocolo estándar abierto Model Context Protocol (MCP). This service allows Customer to connect, at its own risk and configuration, third-party AI assistants (including, but not limited to, Anthropic's Claude, OpenAI's ChatGPT, Microsoft's Copilot, and Google's Gemini) to Customer's Fracttal One data environment.

 

In the context of the MCP Service, FRACTTAL acts exclusively as Data Processor of the endpoint it manages, pursuant to Article 28 of the GDPR. The Client acts as Data Controller of the personal data that flows through that endpoint to the external AI provider of their choice. The MCP endpoint operates within FRACTTAL's ISO 27001 certified security perimeter and under the same authentication and access control model as the rest of Fracttal One. Data accessed through the endpoint is transmitted exclusively to the external assistant configured by the Client; FRACTTAL does not receive or use it for its own purposes.

 

In accordance with Article 28 of the GDPR. The Client acts as the Data Controller of the personal data flowing through such endpoint to the external AI provider of its choice. The MCP endpoint operates within FRACTTAL's ISO 27001 certified security perimeter and under the same authentication and access control model as the rest of Fracttal One. The data accessed by the Client; FRACTTAL does not receive them or use them for its own purposes.

 

The processing of personal data carried out by the external artificial intelligence provider chosen by the Client falls outside the scope of this Privacy Policy and is the exclusive responsibility of the Client. In particular, the Client is responsible for: (i) entering into a valid data processing agreement (DPA) with their external AI provider; (ii) verifying the applicable international data transfer mechanisms when the provider operates outside the European Economic Area (including its adherence to the EU-U.S. Data Privacy Framework or the use of Standard Contractual Clauses); and (iii) informing data subjects whose data is accessed via MCP in accordance with Articles 13 and 14 of the GDPR and applicable local legislation. The specific terms of the MCP Service are governed by the MCP Annex to the principal contract and the Data Processing Agreement (DPA) available at fracttal.com/en/dpa.

 

The external AI agent chosen by the Client is outside the scope of this Privacy Policy and is the sole responsibility of the Client. In particular, the Customer is responsible for: (i) entering into a valid processor agreement (DPA) with its third-party AI provider; (ii) verify the mechanisms for international data transfer when the provider operates outside the European Economic Area (including— or the subscription of Standard Contractual Clauses); and (iii) inform data subjects whose data is accessed through MCP in accordance with Articles 13 and 14 of the GDPR and applicable local regulations. The specific terms of the MCP Service are regulated in the MCP Annex of the Main Contract and in the Processing Order Agreement (DPA) available in fracttal.com/es/dpa.

modificacionesChanges to the Privacy Policy

FRACTTAL reserves the right to modify these data processing policies at any time. Any changes in the Privacy Policy will take effect from the "last update" and the continued use of the service by the User on the date of last revision will constitute acceptance of these.

 

For any clarification regarding these regulations, you can send us an email or request to the following email: privacy@fracttal.com.

 

Copyright © 2026 FRACTTAL TECH SL All rights reserved. This Website and/or Mobile App and the accompanying products and documentation are the intellectual property of FRACTTAL TECH SL and/or its licensors and are protected by copyright laws and international intellectual property treaties. FRACTTAL and the related logo, and all related product and service names, design marks and slogans are registered trademarks and/or registered trademarks of FRACTTAL TECH SL All other product and service marks contained in this document are trademarks of their respective owners. Any use of the trademarks or logos of FRACTTAL or third parties without the prior written consent of FRACTTAL TECH SL or the owner of the applicable trademark is strictly prohibited.