Last updated: June 13, 2026
Privacy policy
At G2-F Technologies, S.L. ('G2-F', 'we') we take the protection of your personal data very seriously. This Privacy Policy explains transparently what data we collect through the website g2-f.com and through our services, for what purpose, on what legal basis, with whom we share it and what rights you have. All of this in accordance with Regulation (EU) 2016/679 General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD).
1. Data controller
The controller of your personal data is:
• Company name: G2-F Technologies, S.L.
• NIF/CIF: B24903833
• Registered office: Calle Tirso de Molina 11, 1ºA, 28912 Leganés, Madrid, Spain
• Contact email: team@g2-f.com
You may write to this address for any matter relating to the processing of your data or the exercise of your rights.
2. Definitions
For the purposes of this policy, the following terms shall apply:
• 'Personal data': any information about an identified or identifiable natural person (for example, name, email address or IP address).
• 'Processing': any operation performed on personal data, such as collection, recording, storage, consultation or erasure.
• 'Data controller': the party that determines the purposes and means of the processing; in this case, G2-F.
• 'Data processor': the third party that processes data on behalf of the controller following its instructions (for example, our technology providers).
• 'Data subject': the natural person to whom the personal data belongs.
3. Data we process
We process only the data strictly necessary for the purposes described. Depending on your interaction with us, we may process the following categories of data:
• Contact and identification data: first name, surname, email address, company or position and the content of the messages you send us through the contact form or by email.
• Account and access data: credentials and authentication data when you access our platform.
• Browsing and usage data: IP address, device and browser identifiers, pages viewed and interaction events with the website, collected for analytical purposes.
• Data of the documents you entrust to us: when you contract our service, we may process the content of the documents you upload to the platform for their classification, extraction and reconciliation, acting in such cases as a processor on behalf of your organization.
We do not intentionally collect special categories of data (health, ideology, religion, etc.). We ask that you do not provide us with this type of information unless it is strictly necessary and there is a legal basis for doing so.
4. Purposes of the processing
We process your personal data for the following purposes:
• To attend and respond to the inquiries, demonstration requests and communications you send us.
• To manage the commercial and pre-contractual relationship, as well as the provision of our services.
• To enable secure access to the platform and to authenticate users.
• To measure, analyze and improve the performance, usability and security of the website.
• To comply with the legal, accounting and tax obligations applicable to us.
• To send, where applicable, informational or commercial communications about our services, where there is a legal basis that permits it.
5. Legal basis for the processing
Each processing operation is based on a legal basis pursuant to Article 6 of the GDPR:
• Performance of a contract or pre-contractual measures (art. 6.1.b): to manage your request for information, the commercial relationship and the provision of the service.
• Consent (art. 6.1.a): when you send us the contact form or agree to receive commercial communications. You may withdraw it at any time.
• Legitimate interest (art. 6.1.f): for website analytics, the security of our systems and the improvement of our services, following the corresponding balancing of interests.
• Compliance with legal obligations (art. 6.1.c): to meet accounting, tax and other obligations.
6. Recipients and data processors
We do not transfer your data to third parties, except where there is a legal obligation or where it is necessary for the provision of the service. To this end, we rely on providers that act as data processors and with whom we have entered into the corresponding contracts pursuant to Article 28 of the GDPR:
• Amazon Web Services (AWS): infrastructure and hosting, with servers in the European Union region (Frankfurt, eu-central-1).
• PostHog: web analytics, with data hosted in the European Union.
• Microsoft (Microsoft / Azure): access authentication and email.
• Google (Google Workspace / Gmail): management of corporate email.
• Resend: sending of transactional emails.
• Cloudflare: content delivery network and security (processes IP addresses).
• Contadores Tecnológicos: accounting and administrative management.
Likewise, we may disclose your data to Public Administrations, Courts and Tribunals where there is a legal obligation to do so.
7. International transfers
Our infrastructure (AWS) and our analytics (PostHog) process data within the European Economic Area.
Some providers (Microsoft, Google, Resend and Cloudflare) may process data on servers located in the United States. Such transfers are carried out with the safeguards required by Chapter V of the GDPR, in particular adherence to the EU-U.S. Data Privacy Framework and/or the execution of the Standard Contractual Clauses approved by the European Commission, supplemented where applicable with additional security measures.
You may request further information about these safeguards by writing to team@g2-f.com.
8. Retention periods
We retain your data only for as long as necessary to fulfill the purposes for which it was collected:
• Contact form data: for the time necessary to attend to your request and, thereafter, for up to 1 year from the last communication.
• Data arising from the commercial or contractual relationship: for the duration of the relationship and, once it has ended, for the legal limitation periods applicable to potential liabilities (generally, up to 6 years for accounting and commercial obligations).
• Analytical data: for a maximum of 14 months.
Once these periods have elapsed, the data is deleted or irreversibly anonymized.
9. Your rights
In relation to your personal data, you have the following rights:
• Access: to know what data of yours we process.
• Rectification: to correct inaccurate or incomplete data.
• Erasure ('right to be forgotten'): to request the deletion of your data when it is no longer necessary.
• Objection: to object to certain processing based on our legitimate interest.
• Restriction: to request that the processing be suspended in certain cases.
• Portability: to receive your data in a structured, commonly used format, or to request its transmission to another controller.
• Withdrawal of consent: at any time, without this affecting the lawfulness of the prior processing.
You may exercise these rights by writing to team@g2-f.com, indicating the right you wish to exercise and attaching, if necessary, a document proving your identity. We will respond within a maximum period of one month.
10. Complaint before the supervisory authority
If you consider that the processing of your data does not comply with the regulations, or that we have not properly handled the exercise of your rights, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid, or through its electronic headquarters at www.aepd.es.
11. Data security
We apply appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including the encryption of communications (TLS), access control, pseudonymization where appropriate and the traceability of operations. Our providers are selected on the basis of their guarantees regarding security and data protection.
12. Minors
Our services are aimed at professionals and companies, not at minors. We do not knowingly collect data from children under 14 years of age. If we detect that we have processed the data of a minor without the corresponding authorization, we will proceed to delete it.
13. Changes to this policy
We may update this Privacy Policy to adapt it to regulatory, technical or service-related changes. We will publish the current version on this page, indicating the date of the last update. We recommend that you review it periodically.
Contact us with any questions about this document.
