Legal
Privacy & Cookie Policy
Last updated: 7 September 2026
1. Data controller
In accordance with Regulation (EU) 2016/679 of 27 April 2016 (GDPR) and Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), the data controller for personal data processed through the website is:
- Owner: PORTUUM MARITIME S.L.
- Registered address: Mas Florit 10, 1-1, Blanes (Girona), Spain
- Email: [email protected]
- Telephone: (+34) 696 825 875
- Tax identification number (NIF): [TO BE COMPLETED]
For identification and legal notice details, see also our Legal Notice.
2. Personal data we process
Depending on your relationship with PORTUUM MARITIME S.L., we may process the following categories of data:
- Identification data: name and surname.
- Contact details: email address, telephone number and company.
- Professional data: position, company, professional activity and information related to the business relationship.
- Billing information and information necessary to manage the contractual relationship, where applicable.
- Information voluntarily provided through contact forms, demonstrations or requests for information.
- Technical data necessary to ensure security and proper operation of the website and, where applicable, the services.
- Browsing data and information obtained through cookies, in accordance with section 11 below.
PORTUUM MARITIME S.L. applies the principle of data minimisation and processes only data that are adequate, relevant and necessary for the corresponding purposes.
3. Purposes of processing
Personal data may be processed for the following purposes:
- Handling enquiries and requests: managing enquiries, requests for information, demonstrations and communications submitted through the website.
- Managing the business relationship: managing quotations, contracts, subscriptions, invoicing, payments, incidents and other aspects related to the relationship with customers, where a commercial relationship exists.
- Providing contracted services: where you or your organisation have contracted PORTUUM, managing access to and operation of the PORTUUM platform and providing the contracted functionalities, in accordance with the applicable customer contract and, where PORTUUM acts as processor, section 7 below.
- Security and operation: detecting, preventing and managing security incidents, fraud, unauthorised access and other misuse of the website or platform.
- Marketing communications: sending commercial information about PORTUUM MARITIME S.L., its products, services, updates or news where there is a valid legal basis and, where required, the user’s consent.
- Compliance with legal obligations: complying with applicable legal obligations, including tax, accounting, corporate and administrative obligations under Spanish and EU law.
4. Legal bases
We rely on one or more of the following legal bases under Article 6 GDPR:
- Performance of a contract (Art. 6(1)(b) GDPR): where processing is necessary to provide contracted services or take steps at your request prior to entering into a contract.
- Consent (Art. 6(1)(a) GDPR): where consent is required, particularly for certain marketing communications or non-essential cookies and similar technologies.
- Compliance with a legal obligation (Art. 6(1)(c) GDPR): where processing is necessary to comply with applicable EU or Spanish law.
- Legitimate interests (Art. 6(1)(f) GDPR): for certain activities relating to management, security, fraud prevention and service improvement, provided that such interests are not overridden by the rights and freedoms of the data subjects.
5. How long we retain data
Personal data will be retained for as long as necessary to fulfil the purpose for which it was collected.
Where a contractual relationship exists, data will be retained for the duration of the relationship and thereafter for the periods required to comply with legal obligations and to establish, exercise or defend potential claims under Spanish law.
Data processed on the basis of consent will be retained until consent is withdrawn or for as long as necessary for the relevant purpose.
Once the applicable retention periods have expired, data will be deleted or, where appropriate, anonymised.
6. Recipients of personal data
Personal data may be disclosed to:
- Public authorities and competent bodies where legally required.
- Financial institutions and payment service providers where necessary to manage collections and payments.
- Technology providers and other processors providing services necessary for the operation of PORTUUM MARITIME S.L. (for example hosting, email delivery or error monitoring).
- Professional advisers where necessary to manage the business relationship or comply with legal obligations.
PORTUUM MARITIME S.L. does not sell personal data to third parties.
Where a provider processes personal data on behalf of PORTUUM MARITIME S.L., the relevant data processing agreement will be entered into where legally required (Article 28 GDPR).
7. PORTUUM as data processor
Within the SaaS service, PORTUUM MARITIME S.L. customers may enter personal data for which they are the controllers.
In such cases, PORTUUM MARITIME S.L. will act as a data processor, processing such data only in accordance with the customer’s documented instructions and the applicable data processing agreement.
The customer is responsible for determining the purposes and means of the processing of data entered into the platform and for ensuring that it has an appropriate legal basis.
PORTUUM MARITIME S.L. will implement appropriate technical and organisational measures to protect personal data processed on behalf of its customers.
8. International transfers
PORTUUM MARITIME S.L. will seek to ensure that personal data processing takes place within the European Economic Area.
Where providers located outside the European Economic Area are used, or where data may be accessed from third countries, PORTUUM MARITIME S.L. will implement the safeguards required by Chapter V of the GDPR, including, where applicable, European Commission adequacy decisions, Standard Contractual Clauses and other legally applicable safeguards.
9. Security
PORTUUM MARITIME S.L. will implement appropriate technical and organisational measures under Article 32 GDPR to protect personal data against destruction, loss, alteration, unauthorised disclosure or access.
These measures may include access controls, authentication, encryption where appropriate, backups, infrastructure security measures and incident management mechanisms.
Measures may be adapted according to the nature, scope, context and risks associated with each processing activity.
10. Data subject rights
Data subjects may exercise the rights recognised under the GDPR and LOPDGDD:
- Right of access.
- Right to rectification.
- Right to erasure.
- Right to object.
- Right to restriction of processing.
- Right to data portability.
- Right to withdraw consent where processing is based on consent.
- Right not to be subject to a decision based solely on automated processing where the applicable legal requirements are met.
Requests may be sent to: [email protected].
Data subjects also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD) at www.aepd.es if they consider that their personal data have been processed in breach of applicable law.
12. Children's data
PORTUUM MARITIME S.L. services are primarily intended for businesses and professionals and are not directed at children. PORTUUM MARITIME S.L. does not knowingly request personal data from children for purposes incompatible with applicable law.
13. Changes to this policy
PORTUUM MARITIME S.L. may amend this Privacy & Cookie Policy where necessary to reflect legislative, regulatory, judicial, technical or service-related changes.
The version published on the website will be the version in force at any given time. The “Last updated” date at the top of this page indicates the current version.
14. Applicable law and jurisdiction
This Privacy & Cookie Policy shall be governed and interpreted in accordance with applicable Spanish law and the GDPR.
In the event of any dispute arising from the interpretation, application or compliance with this policy, the parties shall submit to the courts and tribunals having jurisdiction in accordance with applicable law.
