Skip to content
The Privacy Policy of Cofre describes the practices and principles related to the processing of personal data.
This policy helps you understand what personal data we collect and why, as well as how we process, protect, store and delete your data.
It applies to the Cofre website, the services offered to customers, the related software and information systems, as well as our hiring and recruitment processes.
Last updated: 16/10/2025
This is a courtesy translation. In case of any discrepancy, the Spanish version prevails.
Controller: Quantum Core SL (Cofre)
Tax ID (NIF/CIF): B21959408
Address: Calle Doctor Luis Calandre, 34, 30205 Cartagena, Murcia (Spain)
Contact phone: 910 05 34 11
Contact email: protecciondedatos@cofre.io
Cofre stores and processes personal data to provide services within the framework of a contractual relationship with its customers (Art. 6(1)(b) GDPR).
Cofre may be required to disclose personal data where applicable laws or regulations so require, or to respond to a request from a judicial or administrative authority (Art. 6(1)(c) GDPR).
Cofre has a legitimate interest in processing personal data for the purpose of directing the marketing and sales of its services, as well as to improve the quality of its products and services (Art. 6(1)(f) GDPR).
Processing may also be based on the data subject's separate consent (Art. 6(1)(a) GDPR) for operations such as:
The data subject has the right to withdraw consent at any time through the links included in marketing messages.
Cofre processes, among others, the following personal data:
In some services, Cofre processes personal data on behalf of its customers. In these cases, the customer is the Data Controller and Cofre acts as the Data Processor under the GDPR. These activities are governed by the Description of Activities included in this document.
The requested data are essential for providing the services; refusing to provide them may prevent their performance.
We receive your data mainly from you in situations such as:
In addition, we may receive information from:
Firewalls, password policy, two-factor authentication, TLS for communications, regular backups stored in a separate location, and internal/external audits of security and GDPR compliance.
Internal information security and data protection policies, mandatory periodic training, role-based access rights, review and revocation of permissions, and contractual confidentiality.
Processing in data centers within the EU/EEA (for example, Spain or Finland), with certified redundancy, access control and monitoring.
In general, the personal data processed by Cofre are not transferred outside the EU/EEA. Contact information used for marketing and statistical analytics data, as well as data from recruitment platforms, may be hosted in the United States. These transfers are protected in accordance with EU rules, applying Standard Contractual Clauses and additional safeguards.
Processors that could transfer data outside the EU/EEA (if used): Google Analytics.
Cofre collects information through cookies to improve the user experience, evaluate usage patterns and support marketing.
Information such as IP address, time, pages visited, browser, device, origin and destination is stored.
By using our site, you accept the use of cookies. You can prevent their use by configuring your browser, understanding that certain services may be affected. To manage consent we use, where applicable, tools such as Cookiebot, where you can configure and withdraw your consent at any time. See the Cookie Policy.
In accordance with Arts. 15–22 of the GDPR, data subjects have the right to: access, restriction, objection, erasure, portability, objection to automated decision-making, rectification, and to lodge a complaint with the supervisory authority.
You may object to direct marketing at any time.
To exercise your rights, send a request to protecciondedatos@cofre.io. You may also lodge a complaint with the AEPD: www.aepd.es.
We will notify the data subject if the breach entails a high risk to their rights and freedoms, describing the nature of the breach and the measures taken in accordance with the GDPR.
We are required to notify the data protection authority within 72 hours of becoming aware of the breach, where applicable.
This policy does not apply to third-party sites, apps or services accessible from our services. When you navigate to a third party, it may collect and process your information under its own privacy policy. We recommend reviewing those policies before allowing the collection and use of your data.
If you believe there is a problem with the processing of your data, you may take legal action and file a complaint with the supervisory authority of your country of residence, place of work or place of the alleged infringement. In Spain, the authority is the Spanish Data Protection Agency (www.aepd.es).
You must have read and agree to the terms of this Privacy Policy. Use of the website implies your acceptance.
Cofre reserves the right to amend it due to legislative or case-law changes or criteria issued by the AEPD. We will publish the date of the latest update.
Provider: OpenAI (OpenAI OpCo, LLC) and OpenAI Ireland Ltd.
Purpose of processing: the data sent to the API are processed exclusively to generate responses and, for a limited time, for abuse detection and technical debugging. OpenAI does not use these data to train its models.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and legitimate interest in the security of the service (Art. 6(1)(f) GDPR).
Retention: data processed via the OpenAI API are kept for up to 30 days for security and diagnostic purposes, after which they are automatically deleted, unless retention is legally required.
Location and transfers: data may be processed in the United States and other jurisdictions. OpenAI applies Standard Contractual Clauses (SCCs) approved by the European Commission to legitimize the international transfer.
Security measures: access controls, encryption, logging and incident response, as well as technical and organizational measures aligned with industry best practices.
Rights: data subjects may exercise their GDPR rights before Cofre; requests affecting data processed through OpenAI will be handled in accordance with the applicable framework.
Data Controller: Customer
Processor: Quantum Core SL (Cofre)
Cofre processes personal data to provide services within the framework of a contractual relationship between Processor and Controller (Art. 6(1)(b) GDPR), to comply with legal obligations (Art. 6(1)(c) GDPR) and, where applicable, on the basis of legitimate interest (Art. 6(1)(f) GDPR).
Among others, and depending on the contracted service:
| Processing activity | Legal basis | Purpose |
|---|---|---|
| Employment management (where applicable: payroll, contracts, obligations) | GDPR 6.1.b (contract) | Compliance with employment and administrative obligations |
| Accounting and tax advisory | GDPR 6.1.b / 6.1.c | Accounting, taxes, tax planning |
| Corporate and legal advisory | GDPR 6.1.b | Regulatory compliance and legal management |
| Invoicing software and operations | GDPR 6.1.b / 6.1.f | Service delivery, support and improvement |
Individual customers, representatives of corporate customers, their employees, suppliers and their customers; agents involved in administrative/financial/corporate operations; data of customers' family members where applicable.
Collection, recording, structuring, alteration, storage, retrieval, consultation, access, interconnection, cross-checking, communication, erasure and destruction.
In general, none are carried out. If they become necessary, appropriate legal safeguards will be applied (e.g., Standard Contractual Clauses).
Cofre may share data with its auditor. For other collaborators of the Customer (e.g., lawyers/consultants), the Customer's authorization will be required. Evidence of the disclosure will be kept (date, recipient, scope).
Data will be communicated to tax authorities, financial institutions, electronic money institutions, insurers, trade unions, the INSS or pension funds where required by law. Digital processing is supervised through logs and automatic/manual controls.
Cofre may disclose data to group entities. It does not sell or rent data to third parties.
Tax and social security authorities, insurers, trade unions, pension funds, financial institutions, and others as per the contract and applicable law. In general, data are not transferred outside the EU/EEA; if transfers occur, Standard Contractual Clauses will be applied.
Rights requests by email to: protecciondedatos@cofre.io.
Processor → Controller: notification without undue delay describing the nature of the breach and the measures taken. Controller → Data subject/AEPD: where the risk is high, notification to the data subject and to the AEPD within 72 hours. The Processor will assist the Controller with the notification.
Data Processor: Quantum Core SL (Cofre)
Calle Doctor Luis Calandre, 34, 30205 Cartagena, Murcia
NIF: B21959408
DPO/Privacy email: protecciondedatos@cofre.io
Last updated: 16/10/2025