Privacy Policy

Last update: January 30, 2026

1. Data controller
  • Responsible: Nass Senses SL
  • Tax ID Number: B25990078
  • Address: Calle Golfo de Salónica, 27, 3rd floor. 28033 Madrid
  • Email: info@nassscent.es
2. Data we process. Purposes and legal bases

We process personal data in a general manner, including but not limited to, to the extent necessary to manage the website and, where applicable, the relationship with users, customers, and individuals who contact the entity. At each point of collection (forms, contracts, email, etc.), additional specific information may be provided when applicable.

2.1 Handling inquiries and contact
  • Data: identification and contact details (e.g., name, email, telephone number), and message content.
  • Purpose: to respond to inquiries, requests, communications, and provide basic support.

Legal basis:

  • Legitimate interest (Art. 6.1.f GDPR) in managing communications received; and/or
  • Pre-contractual measures (Art. 6.1.b GDPR) when the consultation is linked to a possible contract.
2.2 Customer management and service provision (if applicable)
  • Data: identification and contact details; data necessary for the provision of services; billing and payment details (if applicable); operational communications.
  • Purpose: to manage the contractual relationship, provide the service, invoice, manage incidents, returns/cancellations if applicable, and customer service.

Legal basis:

  • Contract performance (Art. 6.1.b GDPR).
  • Legal obligation (Art. 6.1.c GDPR) for accounting, tax, commercial, or other applicable obligations.
2.3 Commercial communications (if applicable)
  • Data: identification and contact details.
  • Purpose: sending information and commercial communications about products/services.

Legal basis:

  • Consent (Art. 6.1.a GDPR) when requested; and/or
  • Legitimate interest (Art. 6.1.f GDPR) in permitted cases (e.g., prior relationship), guaranteeing the right to object and easy unsubscription.
2.4 Web browsing and cookies
  • Data: online identifiers and browsing data derived from the use of cookies/similar technologies.
  • Purpose: to enable the website to function and, where applicable, for analytics/measurement or personalization/advertising.

Legal basis:

  • Technical/strictly necessary cookies: service requirement.
  • Other cookies: consent, where applicable.
    More information: see Cookies Policy.
2.5 Applications (CVs) and selection processes (if received)
  • Data: CV (academic and professional data), identification and contact details, and any information provided by the candidate.
  • Purpose: to manage current or future selection processes.

Legal basis: pre-contractual measures (Art. 6.1.b GDPR) and, where applicable, consent (Art. 6.1.a GDPR) for storage beyond the process. Note: this information can be expanded upon in the CV reception channel.

Important notice: Processing relating to employees and suppliers is normally reported through specific clauses (in the contract, onboarding, purchase orders, etc.). This web policy focuses on processing linked to the website and the relationship with users/customers.

3. Recipients. Transfers and data processors
3.1 Data transfers (disclosures to third parties as controllers)

In general, we do not transfer personal data to third parties. Transfers will only be made when:

  • There is consent from the interested party; or
  • The transfer is required by law; or
  • It is necessary for legitimate interests that have been duly weighed; or
  • is necessary for the performance of a contract or the implementation of pre-contractual measures requested by the data subject.

In addition, data may be communicated to public authorities, courts, and law enforcement agencies when there is a legal obligation or valid request to do so.

3.2 Data processors (suppliers who process data on behalf of the Data Controller)

To provide services, we may rely on providers who process data on our behalf (e.g., hosting, technical maintenance, corporate email, management tools, analytics, payment gateway if applicable, support).

These providers act as data processors and are subject to a contract in accordance with Article 28 of the GDPR.

4. International data transfers

In the context of providing our services and operating the website, some suppliers or entities within the group may be located or provide support from countries outside the European Economic Area (EEA), which means that certain data may be subject to international access or transfer.


When this occurs, the transfer will be carried out with the guarantees required by law, mainly through the signing of Standard Contractual Clauses (SCC) approved by the European Commission or, where applicable, through Binding Corporate Rules (BCR) or other valid mechanisms. You can request additional information about these guarantees at info@nassscent.es.


As there is no adequacy decision for some of these countries, the level of data protection may not be equivalent to that of the EEA, and there may be risks arising from, among other things, applicable local regulations or the possible intervention of public authorities. To reduce these risks, we apply technical and organizational measures aimed at protecting information.

5. Retention periods

We will retain the data:

  • For as long as necessary to fulfill the purpose for which they were collected;
  • Subsequently, during the applicable legal deadlines and limitation periods for liability;
  • Where applicable, the data will remain blocked until the end of these periods.
  • When the legal basis is consent, as long as it remains valid and is not revoked.
6. Rights of individuals

You may exercise your rights of access, rectification, erasure, objection, restriction, and portability, where applicable, by sending a request to: info@nassscent.es

You may also withdraw your consent at any time when that is the basis for processing, without affecting the lawfulness of prior processing.

If you believe that your rights have not been respected, you may file a complaint with the Spanish Data Protection Agency (AEPD): https://www.aepd.es  

7. Security measures

We implement reasonable technical and organizational measures to protect personal data and prevent unauthorized access, loss, alteration, or improper disclosure, including access controls and security measures at our suppliers.

8. Policy changes

We may update this policy when necessary due to regulatory or operational changes. We will publish the date of the last update.