FMIT Technologies S.L., a company of FMIT Group ("FMIT", "we", "us"), respects your privacy and is committed to processing your personal data lawfully, fairly and transparently. This Privacy Policy explains what personal data we collect through the website fmit.io (the "Website"), why we process it, on what legal basis, for how long we keep it, who we share it with and what rights you have.
Privacy Policy
Last updated: August 2026
1. Data controller
- Controller: FMIT Technologies S.L. (FMIT Group)
- Tax ID (CIF): B93706968
- Registered office: Alameda Principal 32, 1, 29005 Málaga, Spain
- Additional office: Santa Rosalía 49, 1A, 38002 Santa Cruz de Tenerife, Spain
- Email: info@fmit-solutions.com
- Phone: +34 952 65 76 03
2. Data protection contact
FMIT has not appointed a Data Protection Officer, as it is not required to do so under Article 37 GDPR. For any matter relating to the processing of your personal data, including the exercise of your rights, please write to info@fmit-solutions.com using the reference "Data Protection", or to our registered office at the address above.
3. Applicable legislation
We process personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR), Spanish Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD), and Spanish Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE).
4. What personal data we process, why, and on what basis
We only process the data we need for each purpose. Providing your data is voluntary, but if you choose not to provide the data marked as necessary for a given purpose, we may be unable to respond to your request.
4.1 Enquiries and commercial contact
- Data: Name, email address, telephone number, company and position where you provide them, and the content of your message.
- Purpose: To respond to your enquiry, manage the relationship with you and, where applicable, prepare and send you a proposal for our services.
- Legal basis: Your consent when you contact us voluntarily (Art. 6.1.a GDPR) and, where your enquiry concerns our services, the performance of a contract or the steps taken at your request prior to entering into one (Art. 6.1.b GDPR).
- Retention: For the time needed to deal with your enquiry and, thereafter, for one year from our last communication. If a contractual relationship arises, for its duration and subsequently for the periods required by commercial, tax and accounting legislation.
4.2 Recruitment and job applications
- Data: Identification and contact details, academic and professional background, and any other information you include in your CV or application.
- Purpose: To assess your application for the position concerned and to manage our selection processes.
- Legal basis: The steps taken at your request prior to a possible employment relationship (Art. 6.1.b GDPR).
- Retention: For the duration of the selection process. Thereafter, your application is either deleted or, on the basis described in section 4.3, kept in our candidate pool.
4.3 Candidate pool for future vacancies
- Data: The same data contained in your application.
- Purpose: To keep your details on file so that we can consider you for future vacancies matching your profile.
- Legal basis: Your consent (Art. 6.1.a GDPR). You may withdraw it at any time, as easily as you gave it, by writing to us at the address in section 2. Withdrawing your consent does not affect the lawfulness of the processing carried out beforehand.
- Retention: For a maximum of two years from the date we receive your application. Within that period we review our candidate pool whenever a new vacancy arises, and we delete any application that is no longer relevant to the profiles we recruit for. At the end of the two years your data is deleted, unless you renew your application or we ask you to confirm that you wish to remain in the pool.
Please do not include special categories of data in your application (such as health, trade union membership, religious or political beliefs, or racial or ethnic origin). We do not require them and we do not use them in our selection processes.
4.4 Audience measurement and website analytics
- Data: Pages visited, date and time of visit, approximate origin of the visit, device and browser type, and IP address.
- Purpose: To obtain anonymous aggregated statistics on the use of the Website and, where you consent, to analyse browsing in more detail in order to improve our content and structure.
- Legal basis: For anonymous aggregated audience measurement, the exception in Art. 22.2 LSSI-CE, under the conditions set out by the AEPD for audience measurement tools. For analytics that identify your browser, exclusively your consent (Art. 6.1.a GDPR), which you may withdraw at any time.
- Retention: Aggregated audience statistics, a maximum of 25 months. Analytics data subject to consent, a maximum of 14 months.
Full details of the technologies used, their providers and their duration are set out in our Cookie Policy.
4.5 Commercial communications
- Data: Name, professional email address and company.
- Purpose: To send you information about our services, publications or events.
- Legal basis: Your consent (Art. 6.1.a GDPR) or, where you are already a client, our legitimate interest in informing you about services similar to those you have contracted, as permitted by Art. 21.2 LSSI-CE (Art. 6.1.f GDPR).
- Retention: Until you withdraw your consent or object to receiving further communications.
You can object at any time and free of charge, either through the unsubscribe link in each communication or by writing to info@fmit-solutions.com.
4.6 Website security and legal compliance
- Data: Connection data and technical logs.
- Purpose: To keep the Website secure and available, prevent abuse and fraud, and comply with our legal obligations, including responding to requests from competent authorities.
- Legal basis: Our legitimate interest in protecting our systems and those who use them (Art. 6.1.f GDPR) and compliance with legal obligations to which we are subject (Art. 6.1.c GDPR).
- Retention: Technical logs, for a maximum of 12 months, unless they must be kept longer to investigate an incident or to comply with a legal obligation.
5. Accuracy of the data you provide
You warrant that the data you provide is true, accurate and complete, and undertake to keep it updated. If you provide us with the personal data of a third party, you must have informed them beforehand and obtained their authorisation to do so.
6. Who we share your data with
We do not sell your personal data and we do not disclose it to third parties for their own purposes. We do share it with the following categories of recipients, only where necessary:
- Technology service providers acting as data processors on our behalf and on our instructions: hosting and infrastructure providers, email and collaboration providers, website analytics and audience measurement providers, and customer relationship management (CRM) and marketing automation providers. Each is bound by a data processing agreement that complies with Article 28 GDPR.
- Companies of FMIT Group, where necessary to respond to your enquiry or manage the relationship with you, on the basis of our legitimate interest in the internal administration of the group.
- Professional advisers, such as legal, tax or audit advisers, where necessary and subject to a duty of confidentiality.
- Public authorities, courts and tribunals, where disclosure is required by law.
7. International data transfers
Some of our providers, in particular those used for website analytics and for customer relationship management, may process data outside the European Economic Area, including in the United States. Where this occurs, we ensure that appropriate safeguards are in place under Chapter V GDPR: an adequacy decision of the European Commission, such as the EU-US Data Privacy Framework, or the Standard Contractual Clauses approved by the European Commission together with the supplementary measures identified in our transfer assessments. You may request further information on the safeguards applied by writing to us at the address in section 2.
8. Security of your data
We apply the technical and organisational measures appropriate to the risk in order to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include access control on a need-to-know basis, encryption of communications, monitoring, staff training and incident response procedures.
They follow the framework of our Information Security Management System, certified by AENOR under ISO/IEC 27001:2022 with recognition by IQNET (certificate SI-0017/2023, valid until 26 January 2029). The certified scope covers the information systems that support the design, development, implementation and operation of a software system, at our Málaga site.
No system can guarantee absolute security. If a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you and the competent supervisory authority in accordance with Articles 33 and 34 GDPR.
9. Automated decision-making
We do not take decisions based solely on automated processing, and we do not carry out profiling that produces legal effects for you or otherwise significantly affects you.
10. Minors
The Website is aimed at professionals and organisations, not at children. Under Article 7 LOPDGDD, minors under the age of 14 may not consent to the processing of their personal data without the authorisation of a parent or guardian. We do not knowingly collect personal data from minors under 14. If you believe that a minor has provided us with personal data, please contact us at info@fmit-solutions.com and we will delete it.
11. Your rights
You have the following rights in relation to your personal data:
- Access: to obtain confirmation of whether we process your data and to receive a copy of it.
- Rectification: to have inaccurate or incomplete data corrected.
- Erasure: to have your data deleted where it is no longer necessary for the purposes for which it was collected.
- Restriction of processing: to ask us to suspend processing in the cases provided for by law.
- Objection: to object to processing based on our legitimate interest, and at any time to processing for direct marketing purposes.
- Portability: to receive your data in a structured, commonly used and machine-readable format, or to have it transmitted to another controller.
- Withdrawal of consent: to withdraw your consent at any time, as easily as you gave it, without affecting the lawfulness of processing carried out beforehand.
To exercise any of these rights, write to info@fmit-solutions.com or to our registered office, with the reference "Data Protection", indicating the right you wish to exercise. We may ask you for information that allows us to confirm your identity. We will respond within one month, extendable by two further months where the request is complex, in which case we will inform you.
Exercising these rights is free of charge. If you consider that we have not dealt with your request correctly, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid, www.aepd.es), which is the competent supervisory authority. You may also contact us first at the address in section 2 so that we can try to resolve the matter.
12. Links to third-party websites
The Website contains links to third-party sites and social media platforms that we do not control. This Privacy Policy does not apply to them. We recommend that you read the privacy policy of any site you visit through those links.
13. Changes to this policy
We may update this Privacy Policy to reflect changes in our processing activities, in the services we offer or in applicable legislation. Where a change is significant, we will make it visible on the Website and, where the law requires it, we will ask for your consent again. The date at the top of this page always indicates the version in force.
Company Information
- FMIT Technologies S.L. (FMIT Group)
- Tax ID (CIF): B93706968
- Registered office: Alameda Principal 32, 1, 29005 Málaga, Spain
- Additional office: Santa Rosalía 49, 1A, 38002 Santa Cruz de Tenerife, Spain
- Contact email: info@fmit-solutions.com
- Phone: +34 952 65 76 03
- Website: https://fmit.io