Privacy policy

This is a courtesy translation. The binding version is the Spanish text, which prevails in the event of any discrepancy.

1. Data controller

Owner: Antonio Cebreiro Bernárdez (ACBSEC)
Tax ID (NIF): 35589647E
Address: Lugar O Covelo 14, 36892 Ponteareas (Pontevedra), Spain
Contact email: [email protected]
Website: https://acbsec.com

2. What data I process and for what purpose

I process the data you voluntarily provide when you get in touch with me and, in addition, the technical data your visit necessarily generates so that the site works and stays protected. I do not use that data to compile usage statistics or measure downloads, clicks, browsing paths or interactions with the tools. Under no circumstances do I build profiles or make automated decisions about you.

ProcessingDataPurpose
Contact form Name, company, email and the content of the message Reply to your enquiry and, where appropriate, prepare a service proposal
Email communication The data you include in your email Maintain the commercial or professional relationship
Website security and delivery IP address, browser and device type, page requested, date and time of the request Protect the website against attacks (denial of service, malicious traffic), guarantee its availability and speed up its loading

How the form works: when you click "Send message", the data is transmitted in encrypted form to a Cloudflare Worker. The Worker validates Cloudflare Turnstile anti-abuse protection and, if the request is legitimate, delivers the message to my mailbox through Microsoft Graph and Microsoft 365. The Worker does not store the content in a database or include it in its technical logs.

Template requests and optional commercial contact

When you request the AI policy template, I process your email, the requested resource and language, the request date and your commercial contact choice. The primary purpose is to handle your request and provide the file in your browser, based on your consent when requesting it (GDPR Article 6(1)(a)).

If you tick the commercial contact box, you also authorise Antonio Cebreiro Bernárdez (ACBSEC) to contact you by email about AI governance and cybersecurity services. This purpose has separate, optional and withdrawable consent; it does not condition the download. Without that authorisation, the template request will not be used to send you commercial communications.

The form uses Cloudflare Workers and Turnstile to process the request and check for automated abuse. Microsoft Graph delivers a notification to my Microsoft 365 mailbox containing the request, your choice, the server timestamp and the version and wording of the consent displayed. The Worker does not create a requester database or include your email or form contents in application logs. The file becomes available after Microsoft 365 accepts the notification; whether you save or use the document is not measured.

The request is retained for up to one year if no professional relationship results. Commercial authorisation is used until you withdraw it or one year passes without interaction, at which point commercial use ceases. Withdraw consent and exercise your rights by emailing [email protected]; commercial communications will include that option. The minimum evidence necessary to demonstrate consent or its withdrawal is retained with restricted access for applicable limitation periods. The providers and international transfer safeguards described in this policy apply.

Form information version: ai-policy-2026-09-08-v1.

  • Your consent (art. 6.1.a GDPR), given when you voluntarily send me a message.
  • Pre-contractual measures (art. 6.1.b GDPR) where your enquiry relates to engaging my services.
  • Compliance with legal obligations (art. 6.1.c GDPR) in tax and accounting matters, should we formalise a commercial relationship.
  • Legitimate interest (art. 6.1.f GDPR) for processing technical connection data for network and information security purposes. Recital 49 GDPR expressly recognises network and system security as a legitimate interest of the controller.

4. How long I keep your data

I keep your enquiry for as long as needed to deal with it and, if it does not lead to a professional relationship, I delete it within a maximum of one year. If we do end up working together, the data arising from that relationship is kept for the duration of the contract and thereafter for the applicable statutory limitation periods (generally six years for commercial matters and four for tax matters).

Technical connection data processed for security purposes is kept for short periods, in line with the retention policies of my technology providers, and is not used for any purpose other than protecting the service.

5. Who I share your data with

I do not sell or transfer your data to third parties for commercial purposes. The only third parties who may access it are my technology providers, acting as processors under a contract signed in accordance with art. 28 GDPR:

  • Web hosting: OVH (OVH SAS, France). The servers are located in the European Union, so no international data transfer takes place.
  • Web delivery, form processing and abuse protection: Cloudflare, Inc. (United States). All acbsec.com traffic passes through its network. Cloudflare distributes content, filters malicious traffic and runs the Worker and Turnstile validation used by the form; to do so it processes the IP address, technical data and, during submission, the data entered in the form.
  • Email and office software: Microsoft 365 and Microsoft Graph (Microsoft Ireland Operations Limited), which receive the validated message for delivery to my mailbox.

International transfers: Cloudflare, Inc. is a US company and Microsoft Ireland Operations Limited, although established in Ireland, is part of a US corporate group. In both cases their involvement may entail processing of, or access to, data from outside the European Economic Area. Both transfers are covered by the standard contractual clauses approved by the European Commission, incorporated into the respective data processing agreements I have signed with those providers. In Cloudflare's case, European traffic is served preferentially from its data centres located in the European Union. Beyond these cases, I do not carry out international data transfers except where legally required.

6. Your rights

You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability at any time and free of charge, as well as withdraw the consent given without this affecting the lawfulness of prior processing.

To do so, write to me at [email protected] stating the right you wish to exercise. I will respond within a maximum of one month.

If you believe your request has not been handled properly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es), C/ Jorge Juan 6, 28001 Madrid.

7. Information security

As a cybersecurity professional, I apply technical and organisational measures appropriate to the risk in order to protect your data against unauthorised access, loss or alteration, in accordance with art. 32 GDPR.

8. Minors

The services on this website are aimed exclusively at professionals and companies. I do not knowingly collect data from children under 14.

9. Changes to this policy

I may update this policy to adapt it to legislative changes or to changes in the services provided. The version in force will always be the one published on this page, with its update date.

Legal notice →