GDPR Compliance

Last Updated: December 21, 2025

At APOGA SL we take data protection seriously. This statement outlines our internal commitment and the measures we have implemented to ensuring full compliance with the General Data Protection Regulation (EU) 2016/679.

1. Our Commitment

We are dedicated to safeguarding the personal data of our clients, employees, and partners. We have integrated data protection principles into our business operations and software development lifecycles (Privacy by Design and Default).

2. Data Processing Agreements (DPA)

We ensure that all third-party vendors and service providers we engage with act in accordance with GDPR requirements. We have signed Data Processing Agreements (DPAs) with all processors to guarantee the security and confidentiality of data.

3. Security Measures

We have implemented robust technical and organizational measures to protect data, including: - Encryption of data in transit (TLS/SSL) and at rest. - Regular security audits and vulnerability assessments. - Strict access controls and authentication mechanisms. - Employee training on data privacy and security best practices.

4. Data Breach Procedures

In the event of a data breach, we have a documented Incident Response Plan. We are committed to notifying the relevant supervisory authority (AEPD) within 72 hours and communicating with affected data subjects without undue delay if there is a high risk to their rights and freedoms.

5. International Transfers

For any data transfers outside the European Economic Area (EEA), we rely on adequacy decisions by the European Commission or Standard Contractual Clauses (SCCs) to ensure an adequate level of data protection.