PRIVACY POLICY
At SISTEMAS INTEGRALES DE REDES Y TELECOMUNICACIONES, S.L., hereinafter referred to as SIRT, we are committed to privacy and transparency. Below, we provide detailed information about how we process personal data, as well as all related information.
- INFORMATION ABOUT THE DATA CONTROLLER:
- SISTEMAS INTEGRALES DE REDES Y TELECOMUNICACIONES, S.L.
- B-61588737
- 78 Pere IV Street, 8-1, 08005, Barcelona
- info@sirt.com
- Contact information for the Data Protection Officer (DPO):
PERSONAL DATA PROCESSING CONDUCTED BY SIRT
| PROCESSING OF JOB APPLICANTS' DATA | |
| For what purpose do we process your personal data? | At SISTEMAS INTEGRALES DE REDES Y TELECOMUNICACIONES, S.L., we process the information provided to us by interested individuals in order to manage the resumes we receive, conduct the recruitment process, hold interviews, and carry out other necessary procedures to identify the best possible candidate for a specific job position for which there is a current or future vacancy. Interested individuals may apply for active job openings posted on the website at any time, without needing to register. They simply need to fill out the information requested on the forms for the job openings to which they wish to apply. However, there is also the option to register on the website to manage their applications. In this case, the data of users registered on the SIRT portal will be processed to manage their registration and applications for the company’s recruitment processes. Through this platform, users can access the company’s talent community, which will allow them to track the status of their applications, apply for new job openings without having to re-enter their information, and receive notifications about opportunities that match their interests. If you do not provide your personal information, we will not be able to fulfill the purposes described. No automated decisions will be made based on the information provided. |
| How long will we retain your data? | For individuals who are not registered on the website and apply for the available positions, their data will be deleted once the relevant selection process has concluded or, where applicable, one year after the last interaction with the individual, provided the user has given consent, or, where applicable, when consent is withdrawn. For individuals who register on the website to manage their applications, the registration data provided will be retained as long as the individual does not request to be removed from the platform or request the deletion of such data. With regard to notifications about new job openings, the data will be used for that purpose as long as the individual does not unsubscribe from the platform or withdraw their consent. |
| What is the legal basis for processing your data? | We hereby inform you of the legal basis for the processing of your data: Performance of a contract or pre-contractual measures: Management of the resumes submitted by the data subject to conduct the recruitment process and identify the best possible candidate for a specific job opening for which there is a vacancy and an open recruitment process in which the data subject has applied (Art. 6.1.b) GDPR). Managing registrations on the SIRT portal to apply for positions and track the status of those applications. Through this platform, users can access the company’s talent community, which allows them to track the status of their applications and apply for new job openings without having to re-enter their information once their resume data has been submitted (Art. 6.1.b) GDPR). Consent of the data subject: To receive notifications about job openings that match the interests of candidates registered on the company’s website to manage their applications (Art. 6.1.a) GDPR). Consent of the data subject: Management of resumes submitted by users not registered on the website to be considered for future job openings that may arise at the company (Art. 6.1(a) GDPR). |
| To whom will your data be disclosed? | Data processors: web design and management providers, management software providers, storage providers, and business communication providers. These providers will have access to identifying information, contact information, professional information, academic information, and any other data provided by the data subject. |
| Data Transfers to Third Countries | The following international transfers of personal data are planned: Microsoft Ireland Operations Limited, located at One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, with a contact form at https://account.microsoft.com/privacy/privacy-request-signedout, as a provider of hosting, communication, and business management services. This provider will have access to data including identifying information, contact information, professional information, academic information, and any other data provided by the data subjects. Microsoft may engage third parties to provide these services, and such third parties may be located outside the EEA; consequently, international data transfers may occur. Such international transfers to a third country or an international organization will be based on an Adequacy Decision or Standard Contractual Clauses. In any case, any international transfer of personal data will be subject to the relevant safeguards as described in Article 46 of the GDPR, and such transfers and safeguards will be documented in accordance with Article 30(2) of the GDPR. For more information, see: Data Processor Agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA?lang=31&year=2025. Standard Contractual Clauses: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en and list of sub-processors: https://servicetrust.microsoft.com/DocumentPage/7a132d00-29c2-4d26-b0f5-486923c41223 LinkedIn Ireland Unlimited Company, located at Wilton Place, Dublin 2, Ireland, with contact information at: dpo@linkedin.com, as a provider of a professional social network. LinkedIn will have access to identifying, professional, academic, and contact information. This provider may subcontract third parties, who may be located outside the EEA, to provide its services. Consequently, international data transfers may occur. These transfers are based on an Adequacy Decision approved by the European Commission or Standard Contractual Clauses. You can find additional information at: Data Processor Agreement: https://es.linkedin.com/legal/l/dpa? List of Subprocessors: https://es.linkedin.com/legal/l/customer-subprocessors? |
| How did we obtain your information? | The personal data we process is provided by the data subject. |
| PROCESSING OF DATA FROM POTENTIAL CUSTOMERS AND WEBSITE CONTACTS | |
| For what purpose do we process your personal data? | At SISTEMAS INTEGRALES DE REDES Y TELECOMUNICACIONES, S.L., we process the information provided to us by data subjects in order to manage inquiries, claims, complaints, requests, or suggestions regarding our products or services through our corporate website and, where applicable, to send electronic marketing communications about SIRT’s products or services. If you do not provide your personal data, we will not be able to fulfill the purposes described. No automated decisions will be made based on the data provided. |
| How long will we retain your data? | The data will be deleted once the inquiries, claims, complaints, requests, or suggestions have been addressed or, if applicable, when the data subject requests their deletion. In the event that a service proposal is requested from SIRT, the data will be deleted once the proposal expires. |
| What is the legal basis for processing your data? | Performance of a contract or pre-contractual measures: Management of potential customers who have expressed interest in our products and/or services (GDPR, Art. 6.1.b). Legitimate interest of the Data Controller and the data subject: management and handling of claims, complaints, requests, or suggestions regarding our products or services through our corporate website (GDPR, Art. 6.1.f). The company has a legitimate interest in processing the data to safeguard its corporate image, provide proper service, improve its products, and identify shortcomings; this interest is also a legitimate interest of the third party (data subject) who submits the request and expects to receive a satisfactory response.Legitimate interest of the Data Controller: management of professional contact information (LOPDGDD Art. 19, GDPR Art. 6.1.f). Consent of the data subject: Sending commercial communications electronically (GDPR Art. 6.1.a) and LSSICE Art. 21.1). |
| To whom will your data be disclosed? | Data processors: providers of business management, storage, and communication software; website maintenance providers; and, where applicable, the company’s legal advisors. These providers will have access to identifying, professional, and contact information. |
| Data Transfers to Third Countries | The following international transfers of personal data are planned: Microsoft Ireland Operations Limited, located at One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, with a contact form available at https://account.microsoft.com/privacy/privacy-request-signedout, as a provider of hosting, communication, and business management services. This provider will have access to data including identifying information, contact information, professional information, and any other data that data subjects provide when making inquiries. Microsoft may engage third parties to provide these services, and such third parties may be located outside the EEA; consequently, international data transfers may occur. Such international transfers to a third country or an international organization will be based on an Adequacy Decision or Standard Contractual Clauses. In any case, any international transfer of personal data will be subject to the relevant safeguards as described in Article 46 of the GDPR, and such transfers and safeguards will be documented in accordance with Article 30(2) of the GDPR. Further information: Data Processor Agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA?lang=31&year=2025. Standard Contractual Clauses: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en Subprocessors: https://servicetrust.microsoft.com/DocumentPage/7a132d00-29c2-4d26-b0f5-486923c41223. |
| How did we obtain your information? | The personal data we process is provided by the data subject. |
| PROCESSING OF SUBSCRIBER DATA FOR COMMERCIAL COMMUNICATIONS | |
| For what purpose do we process your personal data? | At SISTEMAS INTEGRALES DE REDES Y TELECOMUNICACIONES, S.L., we process the information provided to us by data subjects in order to send electronic marketing communications regarding products and/or services offered by SIRT. No automated decisions will be made based on the data provided. |
| How long will we retain your data? | The data will be deleted once the data subject withdraws their consent or requests the deletion of their personal data. |
| What is the legal basis for processing your data? | Consent of the data subject: To send commercial communications electronically regarding the company’s products and/or services to its subscribers (GDPR, Art. 6.1.a, and LSSICE, Art. 21). |
| To whom will your data be disclosed? | The Rocket Science Group LLC, located at 675 Ponce De Leon Ave NE, Atlanta, Georgia 30308, United States, with a DPO contact form available at: https://www.intuit.com/privacy/submit-a-question/, will have access to identifying and contact information as an email marketing service provider. |
| Data Transfers to Third Countries | The following international transfers of personal data are planned: The Rocket Science Group LLC, located at 675 Ponce De Leon Ave NE, Atlanta, Georgia 30308, United States, with the DPO’s contact form available at: https://www.intuit.com/privacy/submit-a-question/, as a provider of email marketing services (Mailchimp). This provider may, in turn, subcontract third-party providers to deliver the service. These providers may be located outside the EEA. Consequently, international transfers of personal data will be made to the United States. These transfers will be based on an Adequacy Decision, specifically the Data Privacy Framework and Standard Contractual Clauses. Data processing agreement: https://mailchimp.com/es/legal/data-processing-addendum/. List of subprocessors: https://mailchimp.com/legal/subprocessors/?locale=es:unavailable. |
| How did we obtain your information? | The personal data we process is provided by the data subject. |
| PROCESSING OF DATA PERTAINING TO PARTIES INVOLVED IN THE INTERNAL WHISTLEBLOWER CHANNEL | |
| For what purpose do we process your personal data? | At SISTEMAS INTEGRALES DE REDES Y TELECOMUNICACIONES, S.L., we process the information provided to us by interested parties for the purpose of managing the internal whistleblower channel and protecting individuals who report regulatory violations and acts of corruption, with the aim of notifying the responsible party of acts or conduct that have occurred within the organization or been caused by third parties contracting with it, and that may be contrary to the general or sector-specific regulations applicable to it. If you do not provide your personal data, the report will be processed anonymously in accordance with applicable regulations. No automated decisions will be made based on the data provided. |
| How long will we retain your data? | The data subject to processing may be retained in the information system only for the time strictly necessary to determine whether to initiate an investigation into the reported facts (a maximum of three months). If it is established that the information provided, or part thereof, is untrue, it must be immediately deleted as soon as such a circumstance is confirmed, unless such falsehood constitutes a criminal offense, in which case the information will be retained for as long as necessary while the legal proceedings are ongoing. If three months have elapsed since receipt of the report without any investigative proceedings having been initiated, the information must be deleted, unless the purpose of retaining it is to provide evidence of the system’s operation. Reports that have not been acted upon may only be retained in anonymized form, and the blocking obligation provided for in Article 32 of Organic Law 3/2018 of December 5 shall not apply. The data shall be retained in the information registry for as long as necessary and proportionate and, in any case, for a maximum of ten years. |
| What is the legal basis for processing your data? | Compliance with a legal obligation: Directive (EU) 2019/1937 of the European Parliament and of the Council of October 23, 2019, on the protection of persons who report breaches of Union law (Art. 8; obligation to establish internal reporting channels – Law 2/2023 of February 20, regulating the protection of persons who report regulatory violations and the fight against corruption, and Law 2/2023 of February 20, regulating the protection of persons who report regulatory violations and the fight against corruption). Consent of the data subject: For the retention, recording, and/or storage of reports made via telephone lines and voice messaging systems with recording capabilities, as well as for the recording/transcription of the in-person meeting requested with the entity for the purpose of filing a report (Directive (EU) 2019/1937; Art. 18.2 and 4). |
| To whom will your data be disclosed? | State security forces and agencies; judicial bodies; the Public Prosecutor’s Office, for the purpose of reporting the commission of a possible crime (legal requirement). Data processors: companies that provide the whistleblowing channel software and data hosting services, and the company’s external legal advisors. These data processors will have access to data corresponding to the complainant’s identifying information and contact details if the complainant identifies themselves and, where applicable, any other information the data subject provides in their report. |
| Data Transfers to Third Countries | No international transfers of personal data are planned. |
| How did we obtain your data? | The personal data we process comes from the complaint filed by the data subjects who have an employment, business, or service relationship with the entity. The categories of data processed are: Identifying data. Business information. Professional or job-related data. Financial data. Potential irregularities/illegal acts. It is possible that special categories of data, such as health data, may be processed. |
| PROCESSING OF CUSTOMER DATA | |
| For what purpose do we process your personal data? | At SISTEMAS INTEGRALES DE REDES Y TELECOMUNICACIONES, S.L., we process the information provided to us by data subjects in order to provide the requested services, as well as to send promotional communications about our products and services. If you do not provide your personal data, we will not be able to provide the requested service. No automated decisions will be made based on the data provided. |
| How long will we retain your data? | The data will be retained as long as the data subject does not request its deletion and, where applicable, for as many years as necessary to comply with legal obligations. With regard to marketing communications, the data will be retained as long as the data subject does not object to the processing or request its deletion. |
| What is the legal basis for processing your data? | Performance of a contract or pre-contractual measures: Providing the requested services and handling clients’ tax, accounting, and administrative matters. (GDPR Art. 6.1.b). Legitimate interest of the Data Controller: Sending promotional communications electronically regarding the products or services offered by SIRT (GDPR Recital 47, LSSICE Art. 21.2). |
| To whom will your data be disclosed? | Financial institutions, for the purpose of issuing the corresponding invoices (contractual requirement). Data processors: providers of business management, customer communication, and data storage software. These providers will have access to identifying, contact, and professional information. |
| Data transfers to third countries | The following international transfers of personal data are planned: Microsoft Ireland Operations Limited, located at One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, with a contact form at https://account.microsoft.com/privacy/privacy-request-signedout, as a provider of hosting, communication, and business management services. Microsoft may engage third parties to provide these services, and such third parties may be located outside the EEA; consequently, international data transfers may occur. International transfers to a third country or to an international organization will be based on an Adequacy Decision or on Standard Contractual Clauses. In any case, any international transfer of personal data will be subject to the relevant safeguards as described in Article 46 of the GDPR, and such transfers and safeguards will be documented in accordance with Article 30(2) of the GDPR. For more information, see: Data Processor Agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA?lang=31&year=2025. Standard Contractual Clauses: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en. List of Subprocessors: https://servicetrust.microsoft.com/DocumentPage/7a132d00-29c2-4d26-b0f5-486923c41223. |
| How did we obtain your information? | The personal data we process is provided by the data subject. |
| PROCESSING OF SUPPLIER DATA | |
| For what purpose do we process your personal data? | At SISTEMAS INTEGRALES DE REDES Y TELECOMUNICACIONES, S.L., we process the information provided to us by data subjects in order to manage the provision of the contracted services, as well as to manage professional contact information. If you do not provide your personal data, we will not be able to fulfill the purposes described; that is, we will not be able to formalize or execute the contract. No automated decisions will be made based on the data provided. |
| How long will we retain your data? | The data will be retained for the duration of the service, as well as for the number of years necessary to comply with legal obligations (6 years in accordance with the provisions of the Commercial Code regarding accounting records, and 4 years with respect to tax obligations), always in accordance with the time limits established by law regarding the statute of limitations for liabilities. Professional contact information will be retained for as long as business relationships may continue and for a maximum period of 10 years from the date of collection or the last interaction, unless the data subject objects. |
| What is the legal basis for processing your data? | Performance of a contract or pre-contractual measures: Manage the provision of contracted services; handle administrative and contractual matters (GDPR, Art. 6.1.b). Legitimate interest of the Data Controller: Management of professional contact information (LOPDGDD, Art. 19; GDPR, Art. 6.1.f). |
| To whom will your data be disclosed? | Financial institutions, for the purpose of making the corresponding payments (contractual requirement). Data processors: providers of management, storage, and business communication software, as well as external legal advisors. These providers will have access to identifying, contact, and professional data. |
| Data transfers to third countries | The following international transfers of personal data are planned: Microsoft Ireland Operations Limited, located at One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, with a contact form at https://account.microsoft.com/privacy/privacy-request-signedout, as a provider of hosting, communication, and business management services. Microsoft may engage third parties to provide these services, and such third parties may be located outside the EEA; consequently, international data transfers may occur. International transfers to a third country or to an international organization will be based on an Adequacy Decision or on Standard Contractual Clauses. In any case, any international transfer of personal data will be subject to the relevant safeguards as described in Article 46 of the GDPR, and such transfers and safeguards will be documented in accordance with Article 30(2) of the GDPR. For more information, see: Data Processor Agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA?lang=31&year=2025. Standard Contractual Clauses: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en. List of Subprocessors: https://servicetrust.microsoft.com/DocumentPage/7a132d00-29c2-4d26-b0f5-486923c41223. |
| How did we obtain your information? | The personal data we process is provided by the data subject. |
| DATA PROCESSING FOR THE EXERCISE OF DATA SUBJECTS' RIGHTS | |
| For what purpose do we process your personal data? | At SISTEMAS INTEGRALES DE REDES Y TELECOMUNICACIONES, S.L., we process the information provided to us by data subjects in order to manage and respond to their requests regarding the exercise of the rights established in data protection regulations. If you do not provide your personal data, we will not be able to comply with the legal obligations described above, namely, to process the exercise of your rights. No automated decisions will be made based on the data provided. |
| How long will we retain your data? | They will be retained for as long as necessary to process requests and for a maximum of three years to address any potential complaints. |
| What is the legal basis for processing your data? | Compliance with a legal obligation: to manage and respond to requests from data subjects regarding the exercise of their rights under data protection regulations (GDPR, Art. 6.1.c). |
| To whom will your data be disclosed? | Competent regulatory authorities in this area, for the purpose of managing and addressing requests and potential complaints (legal requirement). Data processors: data hosting providers, business management and communication software providers. These providers will have access to the personal data necessary to address the request. |
| Data transfers to third countries | The following international transfers of personal data are planned: Microsoft Ireland Operations Limited, located at One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, with a contact form at https://account.microsoft.com/privacy/privacy-request-signedout, as a provider of hosting, communication, and business management services. This provider will have access to data including identifying information, contact information, professional information, and any other data provided by the data subjects. Microsoft may engage third parties to provide these services, and such third parties may be located outside the EEA; consequently, international data transfers may occur. International transfers to a third country or to an international organization will be based on an Adequacy Decision or on Standard Contractual Clauses. In any case, any international transfer of personal data will be subject to the relevant safeguards as described in Article 46 of the GDPR, and such transfers and safeguards will be documented in accordance with Article 30(2) of the GDPR. For more information, see: Data Processor Agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA?lang=31&year=2025. Standard Contractual Clauses: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en List of subprocessors: https://servicetrust.microsoft.com/DocumentPage/7a132d00-29c2-4d26-b0f5-486923c41223. |
| How did we obtain your information? | The personal data we process is provided by the data subject. |
| PROCESSING OF SOCIAL MEDIA USER DATA | |
| For what purpose do we process your personal data? | At SISTEMAS INTEGRALES DE REDES Y TELECOMUNICACIONES, S.L., we process the information provided to us by data subjects in order to send marketing communications to users who interact with the controller’s social media accounts, manage communications with users who contact the controller through its social media channels, and post content on SIRT’s social media profile in which data subjects have tagged themselves or have consented to its publication on those platforms. If you do not provide your personal data, we will not be able to fulfill the purposes described. No automated decisions will be made based on the data provided. |
| How long will we retain your data? | The data will be retained until the data subject withdraws their consent or stops following the controller's account. For processing based on legitimate interest, the data will be deleted once the request has been addressed. |
| What is the legal basis for processing your data? | Legitimate Interest of the Data Controller and Third Parties: to manage requests from users who contact the data controller through its social media accounts (GDPR, Art. 6.1.f). Consent of the data subject: to send marketing communications to users who interact with the data controller’s social media accounts. Following the Data Controller’s social media accounts constitutes consent to receive such communications (GDPR, Art. 6.1.a). Consent of the data subject: to post content on SIRT’s social media profile in which the data subjects have tagged SIRT. By tagging SIRT in a post, the data subject grants consent for SIRT to share that content on its own social media profiles (GDPR, Art. 6.1.a). |
| To whom will your data be disclosed? | Data processors: social media platforms, video-sharing platforms, and service providers responsible for managing the company’s social media accounts. These service providers will have access to identifying information, contact information, professional information, academic information, and any other data provided by the data subject. |
| Data Transfers to Third Countries | The following international transfers of personal data are planned: LinkedIn Ireland Unlimited Company, located at Wilton Place, Dublin 2, Ireland, with contact information at dpo@linkedin.com, as the provider of the professional social network LinkedIn, will have access to identifying, professional, academic, and contact data. This provider may subcontract third parties, who may be located outside the EEA, to provide its services. Consequently, international data transfers may occur. These transfers are based on an Adequacy Decision approved by the European Commission or Standard Contractual Clauses. You can find additional information at: Data Processor Agreement: https://es.linkedin.com/legal/l/dpa? List of sub-processors: https://es.linkedin.com/legal/l/customer-subprocessors? Google Ireland Limited, located at Gordon House, Barrow Street, Dublin 4, Ireland, with a contact form at https://support.google.com/policies/answer/9581826?p=privpol_privts&hl=es&visit_id=638984702589867518-4219727139&rd=1, as the provider of the YouTube platform, will have access to identifying data regarding subscribers and employees. This provider may subcontract third parties, who may be located outside the EEA, to provide its services. Consequently, international data transfers may occur. These transfers are based on an Adequacy Decision approved by the European Commission or Standard Contractual Clauses. You can find additional information at: Data Processing Addendum: https://www.youtube.com/t/terms_dataprocessing. Standard Contractual Clauses: https://www.youtube.com/t/terms_dataprocessing. Subprocessors: https://business.safety.google/adssubprocessors/ |
| How did we obtain your information? | The personal data we process is provided by the data subject. |
- RIGHTS OF DATA SUBJECTS:
Any person has the right to obtain confirmation as to whether SISTEMAS INTEGRALES DE REDES Y TELECOMUNICACIONES, S.L. is processing personal data concerning them.
Data subjects have the right to access their personal data, as well as to request the correction of inaccurate data or, where appropriate, to request its erasure when, among other reasons, the data is no longer necessary for the purposes for which it was collected. They also have the right to data portability.
Under certain circumstances, data subjects may request that the processing of their data be restricted; in such cases, we will retain their data solely for the purpose of asserting or defending legal claims.
Under certain circumstances and for reasons related to their specific situation, data subjects may object to the processing of their data. In this case, SISTEMAS INTEGRALES DE REDES Y TELECOMUNICACIONES, S.L., will cease processing the data, except where there are compelling legitimate grounds or for the exercise or defense of potential claims.
You may exercise your rights by sending an email to dpd@sirt.com or by writing to the following address: Calle Pere IV, 78, 8-1, 08005, Barcelona.
If you have given your consent for a specific purpose, you have the right to withdraw that consent at any time, without this affecting the lawfulness of the processing based on the consent given prior to its withdrawal.
If you feel that your rights regarding the protection of your personal data have been violated—especially if you have not received a satisfactory resolution regarding the exercise of your rights—you may file a complaint with the competent Data Protection Supervisory Authority through its website: www.aepd.es.