Privacy policy
This is a convenience translation. In case of discrepancy, the Spanish version is the reference version.
Last updated: 26 September 2026
1. Data controller
Controller: Elohim Cabezas Sánchez
NIF: 48250174S
Address: C/ Ramón Muntaner 22, 25600 Balaguer (Lleida), España
Privacy email: info@elimflow.com
Phone: +34 614 767 383
2. Data we process
When you request a demo or information through the form, we may process the data you provide: name, company, email address, phone number if provided, approximate team size, deployment model of interest and the content of your inquiry.
Technical data required to operate and protect the website are also generated, such as the date and time of the request, internal request reference and data included in server technical logs. To limit automated submissions, a cryptographic fingerprint derived from the IP address is temporarily used; the IP address itself is not stored in plain text in the leads database.
3. What we use the data for
- Handling requests for information and ElimFlow demos.
- Contacting the interested person and preparing a conversation, demo or proposal tailored to their organization.
- Sending an automatic receipt confirmation with the request reference.
- Keeping an internal record of requests in order to properly manage the requested commercial follow-up.
- Preventing abuse, spam, fraud or automated use of the form and maintaining website security.
Data submitted through this form will not be used to automatically add you to a newsletter or send recurring marketing campaigns unrelated to your request.
4. Legal basis
The main legal basis for managing a demo or information request is taking pre-contractual steps at the request of the data subject and managing the request itself.
Measures strictly necessary for security, abuse prevention and technical maintenance are based on the controller’s legitimate interest in protecting the website and its systems. Where an applicable legal obligation exists, processing necessary to comply with it will be based on that obligation.
5. How long we retain data
Requests that do not lead to a contractual relationship may be retained for up to 12 months from the last interaction in order to manage reasonable follow-up. After that period they will be deleted, unless a legal obligation, dispute or legitimate reason requires blocking or retaining them for longer.
If the request leads to a contractual relationship, the necessary data will be retained for the legal and contractual periods applicable to that relationship. Technical security logs will be kept only for the time reasonably necessary to detect incidents, abuse or attacks.
6. Recipients and providers
We do not sell or disclose form data to third parties for advertising purposes.
Technical providers acting as processors may be involved in providing the website and managing communications, including hosting and infrastructure services and the email provider. IONOS email infrastructure is currently used to send and receive communications related to the form.
Data may be disclosed to public administrations, courts, tribunals or other authorities only where there is a legal obligation or valid request.
7. International transfers
No international data transfers are expected from the ordinary operation of the form. If a provider involving international transfers is added in the future, the safeguards required by law will be applied and this policy will be updated where appropriate.
8. Data subject rights
You may exercise your rights of access, rectification, erasure, objection, restriction of processing and, where applicable, data portability by writing to info@elimflow.com. To process the request, it may be reasonably necessary to verify your identity.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) if you believe that the processing of your data does not comply with applicable law.
9. Security
Technical and organizational measures are applied to reduce the risks of unauthorized access, alteration, loss or disclosure. Among other measures, the website uses HTTPS, form validation, basic anti-abuse controls, email credentials stored outside the public web directory and restricted access to the internal request log.
10. Third-party data
If you provide another person’s personal data, you must ensure that you are authorized to do so and that the person has been informed where necessary.
11. Changes to this policy
This policy may be updated when website features, providers or applicable legal obligations change. The date of the latest update will be shown at the beginning of the document.