Acuerdo de Tratamiento de Datos
Un acuerdo de tratamiento de datos que puedes descargar, firmar y archivar.
Estas políticas se publican en inglés. El texto en inglés es la versión vinculante; las traducciones se ofrecen solo como referencia.
Última actualización: 2026-08-01
Los datos registrales de la sociedad que presta este servicio aún no se han publicado. Aparecerán aquí y en el pie de página en cuanto se confirmen.
This is the template we sign. Download it, fill in your organisation's details, and return it to legal@shelftap.com. We counter-sign and return a copy.
1. Roles
For the personal data a customer submits or generates through the Service, the customer is the controller and [LEGAL ENTITY NAME — TO BE SUPPLIED] is the processor. For the account, billing and public-source directory data described in the Política de Privacidad, [LEGAL ENTITY NAME — TO BE SUPPLIED] is an independent controller and this agreement does not apply.
2. Subject matter and duration
Processing lasts for the term of the subscription plus the retention windows published on the Conservación de Datos page. The subject matter is the operation of a B2B company-discovery service.
3. Nature and purpose
Storage, retrieval, structuring, analysis and export of company records and search results; delivery of transactional email; and processing of payment metadata.
4. Categories of data subject and data
Data subjects: the customer's own users, and individuals named in publicly published company contact information. Data: name, business email, business telephone, business address, job title where published, and the source URL of each fact. No special-category data is processed.
5. Processor obligations
- Process personal data only on the controller's documented instructions, including for transfers.
- Ensure that personnel with access are bound by confidentiality.
- Apply the technical and organisational measures published on the Resumen de Seguridad page.
- Engage only the sub-processors listed on the Subencargados del tratamiento page, and give notice before adding another.
- Assist the controller with data-subject requests, security, breach notification and impact assessments.
- Delete or return personal data at the end of the term, at the controller's choice.
- Make available the information needed to demonstrate compliance and allow audits, subject to reasonable notice and confidentiality.
6. Breach notification
We notify the controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting their data. Details are on the Respuesta a Incidentes page.
7. Transfers
Where a listed sub-processor is outside the EEA, the United Kingdom or Türkiye, transfers are made under that provider's standard contractual clauses or an equivalent mechanism.
8. Signature block
Processor: [LEGAL ENTITY NAME — TO BE SUPPLIED], [REGISTERED ADDRESS — TO BE SUPPLIED], registration number [REGISTRATION NUMBER — TO BE SUPPLIED]. Controller: to be completed by the customer.