GDPR Compliance
Last Updated: December 21, 2025
At APOGA SL we take data protection seriously. This statement outlines our internal commitment and the measures we have implemented to ensuring full compliance with the General Data Protection Regulation (EU) 2016/679.
1. Our Commitment
We are dedicated to safeguarding the personal data of our clients, employees, and partners. We have integrated data protection principles into our business operations and software development lifecycles (Privacy by Design and Default).
2. Data Processing Agreements (DPA)
We ensure that all third-party vendors and service providers we engage with act in accordance with GDPR requirements. We have signed Data Processing Agreements (DPAs) with all processors to guarantee the security and confidentiality of data.
3. Security Measures
We have implemented robust technical and organizational measures to protect data, including:
- Encryption of data in transit (TLS/SSL) and at rest.
- Regular security audits and vulnerability assessments.
- Strict access controls and authentication mechanisms.
- Employee training on data privacy and security best practices.
4. Data Breach Procedures
In the event of a data breach, we have a documented Incident Response Plan. We are committed to notifying the relevant supervisory authority (AEPD) within 72 hours and communicating with affected data subjects without undue delay if there is a high risk to their rights and freedoms.
5. International Transfers
For any data transfers outside the European Economic Area (EEA), we rely on adequacy decisions by the European Commission or Standard Contractual Clauses (SCCs) to ensure an adequate level of data protection.