Contact us +34 910 05 34 11

Skip to content

Privacy Policy of Cofre

The Privacy Policy of Cofre describes the practices and principles related to the processing of personal data.

This policy helps you understand what personal data we collect and why, as well as how we process, protect, store and delete your data.

It applies to the Cofre website, the services offered to customers, the related software and information systems, as well as our hiring and recruitment processes.

Last updated: 16/10/2025

This is a courtesy translation. In case of any discrepancy, the Spanish version prevails.

Identity of the Data Controller

Controller: Quantum Core SL (Cofre)

Tax ID (NIF/CIF): B21959408

Address: Calle Doctor Luis Calandre, 34, 30205 Cartagena, Murcia (Spain)

Contact phone: 910 05 34 11

Contact email: protecciondedatos@cofre.io

Why do we process personal data?

Cofre stores and processes personal data to provide services within the framework of a contractual relationship with its customers (Art. 6(1)(b) GDPR).

Cofre may be required to disclose personal data where applicable laws or regulations so require, or to respond to a request from a judicial or administrative authority (Art. 6(1)(c) GDPR).

Cofre has a legitimate interest in processing personal data for the purpose of directing the marketing and sales of its services, as well as to improve the quality of its products and services (Art. 6(1)(f) GDPR).

Processing may also be based on the data subject's separate consent (Art. 6(1)(a) GDPR) for operations such as:

The data subject has the right to withdraw consent at any time through the links included in marketing messages.

What personal data do we process?

Cofre processes, among others, the following personal data:

In some services, Cofre processes personal data on behalf of its customers. In these cases, the customer is the Data Controller and Cofre acts as the Data Processor under the GDPR. These activities are governed by the Description of Activities included in this document.

The requested data are essential for providing the services; refusing to provide them may prevent their performance.

Regular sources of information

We receive your data mainly from you in situations such as:

In addition, we may receive information from:

How do we protect personal data?

Technical protection

Firewalls, password policy, two-factor authentication, TLS for communications, regular backups stored in a separate location, and internal/external audits of security and GDPR compliance.

Administrative protection

Internal information security and data protection policies, mandatory periodic training, role-based access rights, review and revocation of permissions, and contractual confidentiality.

Physical protection

Processing in data centers within the EU/EEA (for example, Spain or Finland), with certified redundancy, access control and monitoring.

Data disclosure and subcontracting

Transfer of data outside the EU/EEA

In general, the personal data processed by Cofre are not transferred outside the EU/EEA. Contact information used for marketing and statistical analytics data, as well as data from recruitment platforms, may be hosted in the United States. These transfers are protected in accordance with EU rules, applying Standard Contractual Clauses and additional safeguards.

Processors that could transfer data outside the EU/EEA (if used): Google Analytics.

How long do we keep the data?

How do we use cookies and web analytics?

Cofre collects information through cookies to improve the user experience, evaluate usage patterns and support marketing.

Information such as IP address, time, pages visited, browser, device, origin and destination is stored.

By using our site, you accept the use of cookies. You can prevent their use by configuring your browser, understanding that certain services may be affected. To manage consent we use, where applicable, tools such as Cookiebot, where you can configure and withdraw your consent at any time. See the Cookie Policy.

Rights of data subjects

In accordance with Arts. 15–22 of the GDPR, data subjects have the right to: access, restriction, objection, erasure, portability, objection to automated decision-making, rectification, and to lodge a complaint with the supervisory authority.

You may object to direct marketing at any time.

To exercise your rights, send a request to protecciondedatos@cofre.io. You may also lodge a complaint with the AEPD: www.aepd.es.

Data breach notification policy

We will notify the data subject if the breach entails a high risk to their rights and freedoms, describing the nature of the breach and the measures taken in accordance with the GDPR.

We are required to notify the data protection authority within 72 hours of becoming aware of the breach, where applicable.

Limitations

This policy does not apply to third-party sites, apps or services accessible from our services. When you navigate to a third party, it may collect and process your information under its own privacy policy. We recommend reviewing those policies before allowing the collection and use of your data.

Complaints to the supervisory authority

If you believe there is a problem with the processing of your data, you may take legal action and file a complaint with the supervisory authority of your country of residence, place of work or place of the alleged infringement. In Spain, the authority is the Spanish Data Protection Agency (www.aepd.es).

Acceptance of and changes to this Policy

You must have read and agree to the terms of this Privacy Policy. Use of the website implies your acceptance.

Cofre reserves the right to amend it due to legislative or case-law changes or criteria issued by the AEPD. We will publish the date of the latest update.

Use of the OpenAI API as a data sub-processor

Provider: OpenAI (OpenAI OpCo, LLC) and OpenAI Ireland Ltd.

Purpose of processing: the data sent to the API are processed exclusively to generate responses and, for a limited time, for abuse detection and technical debugging. OpenAI does not use these data to train its models.

Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and legitimate interest in the security of the service (Art. 6(1)(f) GDPR).

Retention: data processed via the OpenAI API are kept for up to 30 days for security and diagnostic purposes, after which they are automatically deleted, unless retention is legally required.

Location and transfers: data may be processed in the United States and other jurisdictions. OpenAI applies Standard Contractual Clauses (SCCs) approved by the European Commission to legitimize the international transfer.

Security measures: access controls, encryption, logging and incident response, as well as technical and organizational measures aligned with industry best practices.

Rights: data subjects may exercise their GDPR rights before Cofre; requests affecting data processed through OpenAI will be handled in accordance with the applicable framework.

Description of the Processing Activities

Data Controller: Customer

Processor: Quantum Core SL (Cofre)

Why do we process personal data?

Cofre processes personal data to provide services within the framework of a contractual relationship between Processor and Controller (Art. 6(1)(b) GDPR), to comply with legal obligations (Art. 6(1)(c) GDPR) and, where applicable, on the basis of legitimate interest (Art. 6(1)(f) GDPR).

What data do we process?

Among others, and depending on the contracted service:

Processing activity Legal basis Purpose
Employment management (where applicable: payroll, contracts, obligations) GDPR 6.1.b (contract) Compliance with employment and administrative obligations
Accounting and tax advisory GDPR 6.1.b / 6.1.c Accounting, taxes, tax planning
Corporate and legal advisory GDPR 6.1.b Regulatory compliance and legal management
Invoicing software and operations GDPR 6.1.b / 6.1.f Service delivery, support and improvement

Category of data subjects

Individual customers, representatives of corporate customers, their employees, suppliers and their customers; agents involved in administrative/financial/corporate operations; data of customers' family members where applicable.

Category of processing

Collection, recording, structuring, alteration, storage, retrieval, consultation, access, interconnection, cross-checking, communication, erasure and destruction.

Security measures

International transfers

In general, none are carried out. If they become necessary, appropriate legal safeguards will be applied (e.g., Standard Contractual Clauses).

Regular sources of information

Personal data disclosure policies

Cofre may share data with its auditor. For other collaborators of the Customer (e.g., lawyers/consultants), the Customer's authorization will be required. Evidence of the disclosure will be kept (date, recipient, scope).

Data will be communicated to tax authorities, financial institutions, electronic money institutions, insurers, trade unions, the INSS or pension funds where required by law. Digital processing is supervised through logs and automatic/manual controls.

Cofre may disclose data to group entities. It does not sell or rent data to third parties.

Categories of recipients

Tax and social security authorities, insurers, trade unions, pension funds, financial institutions, and others as per the contract and applicable law. In general, data are not transferred outside the EU/EEA; if transfers occur, Standard Contractual Clauses will be applied.

Rights and channel

Rights requests by email to: protecciondedatos@cofre.io.

Data breach notification

Processor → Controller: notification without undue delay describing the nature of the breach and the measures taken. Controller → Data subject/AEPD: where the risk is high, notification to the data subject and to the AEPD within 72 hours. The Processor will assist the Controller with the notification.

Processor's contact details

Data Processor: Quantum Core SL (Cofre)

Calle Doctor Luis Calandre, 34, 30205 Cartagena, Murcia

NIF: B21959408

DPO/Privacy email: protecciondedatos@cofre.io

Last updated: 16/10/2025

Book a demo WhatsApp Call us Email us