Privacy policy
How Cétery, S.L. processes the personal data of people who contact the company through this website: what data, on what legal basis, for how long, who it is shared with and what rights you can exercise.
This is a courtesy translation. In the event of any discrepancy, the Spanish version prevails. Read the Spanish version
Data controller
Data controller: Cétery, S.L. Tax ID (NIF): B10949451 Address: Avenida de la Universidad s/n, Elche (Alicante) Email: manton@cetery.com Telephone: 626 149 729 Website: cetery.com
Cetery, S.L. has not appointed a data protection officer because none of the circumstances set out in Article 37 of Regulation (EU) 2016/679 (GDPR) or in Article 34 of Spanish Organic Act 3/2018 on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD) applies. If one is appointed in the future, their contact details will be published in this section.
For any matter relating to your personal data you can write to us at manton@cetery.com.
What data we process and where it comes from
This website does not sell online, has no user registration or private area, and does not request data beyond what is necessary to deal with an enquiry. We process two groups of data.
Data that you provide when you write to us, by email at manton@cetery.com or through the contact form if it is enabled: first name and surname, email address and, optionally, company, job title, telephone number and the content of the message you choose to send us, including any data you voluntarily include when describing your situation or your project.
Technical data generated by browsing itself and recorded by the server and, where applicable, by the cookies described in the Cookie policy: IP address, date and time of access, pages requested, and type of browser and device. These logs are used to keep the service available and secure.
We do not process special categories of data (health, ideology, trade union membership, biometric data and the like) and we ask you not to include them in your messages. If we receive any, they will be deleted unless there is a legal obligation to retain them.
What we use your data for and on what legal basis
Dealing with your enquiry and maintaining the exchange of emails arising from it. Legal basis: taking steps at your request prior to entering into a contract (Article 6(1)(b) of the GDPR) where the enquiry is aimed at assessing a possible project; and, where no such pre-contractual relationship exists, our legitimate interest in replying to whoever writes to us (Article 6(1)(f) of the GDPR).
Preparing proposals and quotations and, if there is an agreement, managing the contractual relationship and the delivery of the project. Legal basis: performance of the contract or of pre-contractual steps (Article 6(1)(b) of the GDPR).
Sending you commercial information about our services by electronic means, if you expressly authorise us to do so. Legal basis: your consent, under Article 6(1)(a) of the GDPR and Article 21 of Spanish Act 34/2002 of 11 July on Information Society Services and Electronic Commerce (LSSI-CE). If you are already a client, we may inform you about services similar to those you have contracted, in accordance with Article 21(2) of the LSSI-CE. In both cases you can unsubscribe at any time, free of charge, by writing to manton@cetery.com.
Complying with legal obligations, in particular accounting, tax and commercial law obligations. Legal basis: compliance with a legal obligation (Article 6(1)(c) of the GDPR).
Maintaining the security, availability and integrity of the website and of our systems. Legal basis: legitimate interest (Article 6(1)(f) of the GDPR).
We do not use your data for purposes other than those described. If at any time we wished to do so, we would inform you beforehand and, where the law so requires, ask for your consent.
How long we keep your data
Enquiries that do not lead to a business relationship: we keep the message and the associated data for the time needed to deal with it and, after that, for a maximum of [PLAZO DE CONSERVACIÓN DE CONSULTAS, P. EJ. 12 MESES] so that we can evidence our reply and pick up the conversation if you write to us again. Once that retention period has elapsed, they are deleted.
Client data: for the whole of the contractual relationship and, once it has ended, for the limitation periods of any legal actions and obligations that apply, including those laid down in Article 1964 of the Spanish Civil Code, Article 30 of the Spanish Commercial Code and tax legislation.
Data processed with your consent for commercial communications: until you withdraw your consent or ask to unsubscribe.
Technical server logs and cookie data: for the periods indicated in the Cookie policy and in the hosting provider's terms.
For as long as we have to keep data because of a legal obligation or for the defence of possible claims, they will remain blocked: they are kept solely at the disposal of the competent authorities and are not used for any other purpose.
Who we share your data with
We do not sell or disclose your data to third parties for commercial purposes.
Your data are accessed only by the providers we need in order to operate, acting as processors and under a contract signed in accordance with Article 28 of the GDPR: the website hosting and maintenance provider [PROVEEDOR DE ALOJAMIENTO WEB]; the email and office software provider [PROVEEDOR DE CORREO ELECTRÓNICO]; OpenRouter, Inc., which processes the messages you type into the website's robot chat in order to reply to you (see the section "Automated decisions and artificial intelligence"); and the tax, accounting and employment advisers [ASESORÍA], for invoicing where a contractual relationship exists.
In addition, we may disclose data to public authorities, judges and courts, law enforcement agencies and financial institutions where there is a legal obligation or where it is necessary for the defence of rights.
The up-to-date list of providers can be requested at manton@cetery.com.
International transfers of data
We endeavour to work with providers that host data within the European Economic Area.
If any of the providers indicated in the previous section processes data outside the European Economic Area, the transfer is covered by one of the safeguards provided for in Chapter V of the GDPR: an adequacy decision of the European Commission or, failing that, standard contractual clauses approved by the Commission, supplemented where necessary by additional measures.
Providers that currently involve an international transfer: OpenRouter, Inc. (United States), which processes the messages from the website's robot chat. Safeguard applied: [GARANTÍA APLICADA SEGÚN EL CONTRATO DE ENCARGO DE TRATAMIENTO DE OPENROUTER — VERIFICAR CLÁUSULAS CONTRACTUALES TIPO U OTRA GARANTÍA VIGENTE].
You can request information about these safeguards, and a copy of them where appropriate, by writing to manton@cetery.com.
Automated decisions and artificial intelligence
Cétery works with artificial intelligence, and precisely for that reason it is worth being explicit about what we do with your data on this website.
We do not take automated decisions that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 of the GDPR, nor do we build profiles from your browsing or your messages.
We do not use the personal data you send us by email or your company's information to train, fine-tune or evaluate artificial intelligence models, whether our own or those of third parties.
This website includes a chat ("the Cétery robot") that answers questions about our services, our working method and how to get in touch, and that is programmed not to talk about any other subject. The messages you type into that chat are sent to OpenRouter, Inc., which forwards them to the relevant language model in order to generate the reply; they are not stored on any Cétery server or database, but only in the memory of your own browser while you keep the tab open, and they are lost when the page is reloaded. To prevent abusive use, the server applies a technical limit on requests per IP address, without this involving building a profile of you. [VERIFICAR CON OPENROUTER Y CON EL PROVEEDOR DEL MODELO CONCRETO SI RETIENEN O UTILIZAN PARA ENTRENAMIENTO LOS MENSAJES ENVIADOS A TRAVÉS DE SU API, Y REFLEJAR AQUÍ SU POLÍTICA REAL].
In projects with clients, the relevant data processing is governed by the service agreement and the corresponding data processing agreement, not by this policy, which relates solely to the website.
Your rights
As a data subject, you can exercise the following rights at any time.
Right of access: to know whether we process data about you and to obtain a copy of them. Right to rectification: to correct inaccurate data or complete incomplete data. Right to erasure: to ask us to delete your data when they are no longer necessary or where this is appropriate under the legislation. Right to object: to object to processing based on our legitimate interest, including the receipt of commercial communications. Right to restriction of processing: to request that we suspend processing while a complaint or a rectification is being verified. Right to data portability: to receive, in a structured and commonly used format, the data you have provided to us and that we process with your consent or in order to perform a contract. Withdrawal of consent: to withdraw it at any time, without this affecting the lawfulness of the earlier processing.
To exercise them, write to manton@cetery.com or to Avenida de la Universidad s/n, Elche (Alicante), indicating the right you are exercising. We may ask you to prove your identity if there are reasonable doubts as to who is making the request. We will reply within one month, which may be extended by a further two months where the request is complex, and we will inform you of the extension.
If you believe that we have not dealt with your request properly, or that we are processing your data improperly, you can lodge a complaint with the supervisory authority, the Spanish Data Protection Agency (AEPD), at C/ Jorge Juan, 6, 28001 Madrid, or at www.aepd.es. Before doing so, you can raise the matter with us: we will try to resolve it.
Information security
We apply technical and organisational measures appropriate to the risk of the processing, in accordance with Article 32 of the GDPR: encryption of the website's communications, access control so that only authorised persons can reach mailboxes and systems, strengthened authentication, backups, and the selection of providers that offer sufficient guarantees.
Remember that no system is infallible and that ordinary email is not a secure channel. Avoid sending us credentials, confidential documentation or third parties' personal data by that means.
Should a personal data breach occur that poses a risk to your rights and freedoms, we will notify the supervisory authority and, where the risk is high, the persons affected as well, within the time limits and on the terms laid down in Articles 33 and 34 of the GDPR.
Third-party data and accuracy of the information
If in your message you give us personal data of other people (colleagues at your company, contacts, employees or suppliers), you are responsible for having informed them beforehand of the content of this policy and for having a valid legal basis for disclosing those data to us.
The data you give us must be truthful and up to date. If they change, let us know so that we can keep them correct.
This website is not aimed at minors, and we do not knowingly request or process data of children under fourteen. If we find that we have received data from a minor without the corresponding authorisation, we will delete them.
Changes to this policy
We may amend this privacy policy when the applicable legislation changes, when our providers change or when the way we process data through the website changes.
The current version is always the one published on this site. If the change is substantial and affects processing based on your consent, we will inform you through the contact details we hold.
Last updated: 30 August 2026.
Warning: base text pending legal review
This document is a base text. It must not be published as it stands.
Before publishing it, it is necessary to: (1) replace all the placeholders in square brackets with the real details of Cétery, S.L.; (2) verify the actual list of providers that access data, their data processing agreements and their location, and confirm whether or not there is an international transfer; (3) check whether a data protection officer is ultimately appointed and whether the site includes a contact form, analytics or third-party tools; and (4) submit the full text for review by a legal adviser specialising in data protection.
Publishing this draft without completing it and without professional validation may constitute a breach of the GDPR, of the LOPDGDD and of the LSSI-CE, with the consequent risk of penalties for the company.