Last updated: May 2026
This Privacy Policy describes how Sociedad de Servicios Tecnológicos y de Gestión IBER, S.L. (hereinafter, "styg" or the "Controller"), Tax ID B87084380, with registered address at C/ Conde de Peñalver, 60, 28006 Madrid, processes the personal data of users who access and use the website www.styg.es.
The Controller acts in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016 (GDPR), and Spanish Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
For any query relating to data protection, please contact: privacidad@styg.es
Simply browsing the Website does not require users to provide personal data. However, styg may collect data in the following situations:
a) Contact form and quote requests
- Full name
- Corporate email address
- Company name and job title
- Contact phone number (optional)
- Description of the enquiry or project
b) Cookies and browsing data
- IP address (anonymized)
- Browser and operating system type
- Pages visited and time spent
- Traffic source and keywords
c) Email communications
- Identifying and contact data voluntarily included in emails sent to styg
styg applies the principle of data minimization: it only requests the information strictly necessary for each purpose. Fields marked as mandatory in the forms are the minimum required to handle your request.
styg processes your personal data for the following purposes, backed by the corresponding legal basis under Article 6 of the GDPR:
| Purpose |
Legal basis |
| Handling enquiries and contact requests received through the web form or by email. |
Legitimate interest of the Controller (Art. 6.1.f GDPR) and consent of the data subject (Art. 6.1.a GDPR). |
| Preparing and sending quotes and commercial proposals related to Microsoft Dynamics 365 Business Central implementation and support services. |
Performance of pre-contractual measures at the data subject's request (Art. 6.1.b GDPR). |
| Managing the contractual relationship with customers: invoicing, service delivery, technical support and operational communications. |
Performance of a contract to which the data subject is a party (Art. 6.1.b GDPR). |
| Sending marketing communications about news, updates and events related to Business Central and styg's services. |
Express consent of the data subject (Art. 6.1.a GDPR). May be withdrawn at any time. |
| Statistical analysis of browsing behavior to improve the Website's performance and user experience. |
Legitimate interest (Art. 6.1.f GDPR) and consent for analytics cookies. |
| Compliance with legal obligations (tax, accounting, commercial). |
Compliance with a legal obligation (Art. 6.1.c GDPR). |
Personal data will be retained for as long as necessary to fulfil the purpose for which it was collected and, in any case, for the legally established periods:
- Contact data and enquiries: until the request is resolved and, at most, 1 year from the last contact.
- Customer data (contractual relationship): for the duration of the contract plus 5 additional years to fulfil civil, commercial and tax obligations.
- Marketing communications data: until the data subject withdraws consent or requests erasure.
- Browsing data (analytics cookies): up to 26 months from collection, in accordance with AEPD guidelines.
- Data subject to legal obligations (invoices, contracts): 6 years under the Commercial Code; 4 years under the General Tax Law.
Once the indicated periods have elapsed, the data will be securely erased or anonymized.
styg does not sell or transfer users' personal data to third parties, except in the following cases:
- Data processors: service providers acting on behalf of styg (hosting, CRM, email platform, analytics tools) that have signed the corresponding data processing agreement under Article 28 of the GDPR.
- Google LLC (Google Analytics): web analytics service provider. Data is anonymized before transmission and processed in accordance with Google's data processing agreement.
- Microsoft Corporation: in connection with the productivity tools (Microsoft 365) used internally by styg.
- Legal obligation: when required by applicable law or a judicial or administrative order.
Under no circumstances will your data be used by data processors for purposes other than those contracted with styg.
Some of the service providers mentioned above (Google LLC, Microsoft Corporation) are based in the United States. These transfers take place under the appropriate safeguards provided for in the GDPR:
- Google LLC: adheres to the EU-U.S. Data Privacy Framework (DPF), recognized by the European Commission as providing an adequate level of protection under its Decision of 10 July 2023.
- Microsoft Corporation: adheres to the DPF and uses standard contractual clauses approved by the European Commission.
You can obtain more information about the applicable safeguards by contacting privacidad@styg.es.
Under the GDPR and LOPDGDD, you have the right to exercise the following rights at any time in relation to your personal data:
Access
Get confirmation as to whether we process your data and access it.
Rectification
Correct inaccurate or incomplete data.
Erasure
Request deletion of your data when no longer necessary.
Objection
Object to processing based on legitimate interest.
Restriction
Request the temporary suspension of processing.
Portability
Receive your data in a structured, commonly used format.
To exercise any of these rights, email privacidad@styg.es or write to us at C/ Conde de Peñalver, 60, 28006 Madrid, Spain, enclosing a copy of your ID document. We will respond within a maximum of one month, extendable to three months in complex cases.
If you believe that the processing of your data does not comply with applicable regulations, you have the right to file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es or at C/ Jorge Juan, 6, 28001 Madrid.
styg does not carry out automated decision-making that produces legal effects on data subjects or significantly affects them, nor does it build individualized behavioral profiles for commercial purposes.
Browsing data obtained through analytics cookies is processed on an aggregated and anonymized basis, with no possibility of individually identifying users.
styg's services are aimed at businesses and professionals. The Website is not directed at minors under 14 and does not knowingly collect personal data from minors.
If styg becomes aware or is notified that it has collected data from a minor without verifiable parental or guardian consent, it will proceed to erase it immediately. If you are a parent or guardian and believe your child has provided personal data, please contact us at privacidad@styg.es.
styg has implemented technical and organizational measures appropriate to the level of risk to ensure a suitable level of security, including:
- Encryption of communications via TLS/HTTPS.
- Role-based access control to systems that store personal data.
- Periodic review and testing procedures for security measures.
- Staff training and awareness on data protection.
- An incident and personal data breach response plan.
In the event of a data breach that poses a high risk to your rights and freedoms, styg will notify you without undue delay in accordance with Article 34 of the GDPR.
styg reserves the right to amend this Privacy Policy to adapt it to legislative, case-law or business changes. The date of the last update will always appear at the top of the document.
We recommend reviewing this policy periodically. In the event of substantial changes affecting processing based on your consent, we will inform you directly and request, where applicable, renewed consent.