HelixCore Back to HelixCore
HelixCore

Privacy policy

Last updated: 29 August 2026

This policy explains the processing of personal data on helixcore.biotecno.org, under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

The essentials first: this site collects personal data only when you voluntarily fill in one of the two contact forms. There is no analytics, no profiling, no third-party cookies and no trackers. Browsing the site leaves no personal data in any record of ours beyond those of the web server itself.

Controller

Controller
Javier Gamboa (BIOTECNO Research Group, a trading name without separate legal personality)
Tax ID (NIF)
11922423M
Address
Portal de Zurbano, 3 — 01013 Vitoria-Gasteiz (Álava), Spain
Email
info@biotecno.org

What we collect and why

The two forms on the site — "Request access" and "Talk to the team" — collect only:

Name
To address you and sign the reply.
Organisation
To understand the context of the request and the kind of environment you need.
Work email
The only channel through which we reply. Without it no reply is possible.
Modules of interest / capabilities sought
Only in "Request access". To prepare the right environment.
Message
The content of your enquiry.
Language and originating page
To reply in your language and know which sheet you wrote from.
IP address and submission timestamp
To prevent automated abuse of the form and to be able to evidence consent.

The purpose is one and one only: to handle and answer your request. This data is not used to send you unsolicited commercial messages, is not added to any mailing list, and is not used for profiling or automated decision-making.

We neither ask for nor want special category data (health, genetics of identifiable individuals, beliefs). Do not include clinical or patient-identifying data in the form. If it reaches us, it is deleted.

Legal basis

  • Consent (Art. 6(1)(a) GDPR): you tick the box before sending. You may withdraw it at any time by writing to info@biotecno.org; withdrawal does not affect the lawfulness of prior processing.
  • Legitimate interest (Art. 6(1)(f) GDPR) for the form’s anti-abuse measures (IP and timestamp), strictly to the extent needed to keep the service available.

How long we keep it

The service that receives the form keeps no database at all: it turns your submission into an email and forgets it. Retention is therefore that of the destination mailbox:

  • While your request is being handled and for a reasonable follow-up period afterwards.
  • At most two years from the last contact, unless a contractual relationship imposes longer tax or commercial periods.
  • Technical anti-abuse records are kept for at most twelve months.

Recipients and processors

We do not sell or share your data. Only the providers needed for the email to arrive and the site to run are involved, as processors under an Art. 28 GDPR agreement:

Zoho Corporation B.V.
Corporate email, servers in the European Union (smtp.zoho.eu).
Hosting provider
Virtual private server in the European Union, running the site and the contact service.

No international transfers outside the European Economic Area take place. Should any become necessary, it will be stated here and framed with the safeguards of Chapter V GDPR.

How we protect the data

  • All traffic is TLS-encrypted. The form does not work without a secure connection.
  • The destination address does not appear in the site code: it is resolved on the server, so email harvesters cannot scrape it.
  • The service persists nothing to disk or to your browser: no database, no local queue, no copy on your machine.
  • All fields are validated and sanitised on the server, with specific protection against email header injection.
  • Per-IP submission limits and bot detection, so the mailbox stays usable.
  • Platform accesses — where granted — are logged and audited by the Aegis module.

Your rights

You may at any time exercise the rights of access, rectification, erasure, restriction of processing, objection and portability, and withdraw your consent. An email to info@biotecno.org stating the right you exercise is enough; quoting the HX-… reference the form gave you helps us find your request faster.

We will reply within one month at the latest. If you believe the processing does not comply with the law, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es), C/ Jorge Juan 6, 28001 Madrid.

Your analysis data on the platform

This policy covers the public website. Processing of data a client uploads to the HelixCore platform is governed by the data processing agreement signed when access is granted. As a design principle: client data is not indexed for the HelixIA copilot — which reasons over the capability ontology and public documentation — it is queried with the client’s own token, and every access is audited.

Changes to this policy

If the processing changes, this page is updated and its date changed. Substantial changes will be communicated to anyone with an open request.

Legal noticePrivacyCookies
EspañolEnglishFrançaisDeutsch