Legal

Legal Documentation

Comprehensive policies governing the services provided by ZenithoraLabs. Last updated: 01 August 2026.

1. Privacy Policy

1.1 Data Controller

ZenithoraLabs (“we”, “our”, “us”) is the data controller responsible for the processing of personal data collected through our website and services. Our registered office is located at Avenida de Maisonnave, 25, 03003 Alicante, España. For privacy-related inquiries, contact us at [email protected].

1.2 Data We Collect

We collect the following categories of personal data when you interact with our website or engage our services:

  • Identity data: full name, company name, job title.
  • Contact data: email address, telephone number, postal address.
  • Technical data: IP address, browser type and version, operating system, device identifiers, pages visited, and timestamps.
  • Communication data: content of messages submitted through our contact form or email correspondence.
  • Service data: project specifications, data schemas, and infrastructure details shared during engagement.

1.3 Legal Basis for Processing

We process personal data under the following legal bases as defined by Regulation (EU) 2016/679 (GDPR):

  • Contractual necessity (Article 6(1)(b)): Processing required to perform a contract or take pre-contractual steps at your request.
  • Legitimate interest (Article 6(1)(f)): Processing for our legitimate business interests, including service improvement, fraud prevention, and direct marketing, balanced against your rights.
  • Consent (Article 6(1)(a)): Where you have provided explicit consent, such as subscribing to communications or accepting non-essential cookies.
  • Legal obligation (Article 6(1)(c)): Processing required to comply with applicable Spanish and EU law.

1.4 Data Retention

Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected. Contact form submissions are retained for 24 months. Service engagement records are retained for 5 years in compliance with Spanish tax and accounting obligations. Technical data logs are retained for 12 months. Upon expiration of the retention period, data is securely deleted or anonymized.

1.5 Data Sharing

We do not sell personal data. Data may be shared with the following categories of recipients:

  • Cloud infrastructure providers (AWS, GCP, Azure) where data processing is required for service delivery.
  • Payment processors for transaction handling.
  • Analytics providers for website performance monitoring.
  • Legal and regulatory authorities where disclosure is required by law.

1.6 International Transfers

Where personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission or adequacy decisions under Article 45 of the GDPR.

1.7 Your Rights

Under the GDPR, you have the following rights:

  • Right of access (Article 15): Request a copy of the personal data we hold about you.
  • Right to rectification (Article 16): Request correction of inaccurate or incomplete data.
  • Right to erasure (Article 17): Request deletion of your personal data, subject to legal retention obligations.
  • Right to restriction (Article 18): Request restriction of processing in certain circumstances.
  • Right to data portability (Article 20): Receive your data in a structured, commonly used, machine-readable format.
  • Right to object (Article 21): Object to processing based on legitimate interests or direct marketing.
  • Right to withdraw consent: Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Spanish Data Protection Authority (AEPD) at www.aepd.es.

1.8 Data Security

We implement appropriate technical and organizational measures to protect personal data, including TLS encryption in transit, AES-256 encryption at rest, role-based access controls, regular security audits, and incident response procedures. In the event of a personal data breach, we will notify the supervisory authority within 72 hours and affected individuals without undue delay where the breach poses a high risk to their rights and freedoms.

1.9 Automated Decision-Making

We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects you.

2. Terms of Service

2.1 Acceptance of Terms

By accessing or using the services provided by ZenithoraLabs, located at Avenida de Maisonnave, 25, 03003 Alicante, España, you agree to be bound by these Terms of Service. If you do not agree, you must not access or use our services. These terms constitute a legally binding agreement between you (“Client”) and ZenithoraLabs (“Provider”).

2.2 Scope of Services

ZenithoraLabs provides data analytics consulting services including, but not limited to, ETL pipeline development, data warehouse design, dashboard development, predictive analytics integration, data governance, cloud migration, KPI monitoring, data quality assurance, business intelligence consulting, and API data integration. The specific scope, deliverables, timeline, and pricing for each engagement are defined in a separate Statement of Work (SOW) or service agreement.

2.3 Client Obligations

The Client shall: (a) provide timely access to necessary systems, data sources, and personnel; (b) ensure that data shared for service delivery does not violate applicable laws or third-party rights; (c) designate a primary point of contact for project coordination; (d) review and approve deliverables within the agreed review periods; and (e) maintain appropriate security credentials for shared infrastructure.

2.4 Intellectual Property

Upon full payment, all custom deliverables, code, configurations, and documentation produced specifically for the Client under a SOW shall transfer to the Client. ZenithoraLabs retains ownership of pre-existing tools, frameworks, libraries, and methodologies used in service delivery. Each party retains ownership of its pre-existing intellectual property.

2.5 Confidentiality

Both parties agree to maintain the confidentiality of proprietary information shared during the engagement. Confidential information shall not be disclosed to third parties without prior written consent, except as required by law. This obligation survives termination of the agreement for a period of 3 years.

2.6 Limitation of Liability

To the maximum extent permitted by applicable law, ZenithoraLabs shall not be liable for indirect, incidental, special, consequential, or punitive damages, including loss of profits, data, or business opportunities. Our total aggregate liability for any claim arising out of or relating to these terms or our services shall not exceed the total fees paid by the Client for the specific service giving rise to the claim during the 12 months preceding the event.

2.7 Indemnification

Each party agrees to indemnify and hold harmless the other party from and against any claims, damages, losses, and expenses arising from: (a) a breach of these terms; (b) a breach of applicable law; or (c) a claim that the indemnifying party’s data or materials infringed third-party intellectual property rights.

2.8 Term and Termination

These terms remain in effect for the duration of the service engagement. Either party may terminate with 30 days’ written notice. ZenithoraLabs may terminate immediately if the Client breaches material obligations, including failure to make payment within 15 days of the due date. Upon termination, the Client shall pay for all services rendered up to the termination date.

2.9 Governing Law and Dispute Resolution

These terms are governed by the laws of the Kingdom of Spain and the applicable regulations of the European Union. Any disputes shall first be submitted to mediation. If mediation fails within 60 days, disputes shall be resolved before the competent courts of Alicante, España, to the exclusion of any other jurisdiction.

2.10 Force Majeure

Neither party shall be liable for delays or failures in performance resulting from causes beyond its reasonable control, including natural disasters, war, terrorism, pandemic, government actions, or infrastructure failures. The affected party shall notify the other party promptly and use reasonable efforts to mitigate the impact.

3. Cookie Policy

3.1 What Are Cookies

Cookies are small text files placed on your device when you visit a website. They are widely used to make websites function correctly, improve user experience, and provide analytics data. This Cookie Policy explains how ZenithoraLabs, located at Avenida de Maisonnave, 25, 03003 Alicante, España, uses cookies on our website.

3.2 How We Use Cookies

We use cookies for the following purposes:

  • Strictly necessary cookies: Essential for website functionality, including session management and security. These do not require consent under the ePrivacy Directive (2002/58/EC).
  • Preference cookies: Remember your settings and choices to provide a personalized experience.
  • Analytics cookies: Collect anonymized data about website usage to help us improve performance and content.
  • Marketing cookies: Track browsing activity to deliver relevant advertisements and measure campaign effectiveness.

3.3 Consent

Upon your first visit, you will be presented with a cookie consent banner. Strictly necessary cookies are set automatically as they are essential for the website to function. All other categories of cookies require your explicit consent before activation. You may accept or decline non-essential cookies. Your consent choice is stored in your browser’s localStorage and will persist until you clear it or revoke consent.

3.4 Managing Cookies

You can manage cookies through your browser settings. Most browsers allow you to block or delete cookies. Note that disabling strictly necessary cookies may impair website functionality. To manage cookies in common browsers:

  • Chrome: Settings > Privacy and Security > Cookies
  • Firefox: Options > Privacy & Security > Cookies
  • Safari: Preferences > Privacy > Cookies
  • Edge: Settings > Privacy, Search, and Services > Cookies

3.5 Third-Party Cookies

Some cookies are set by third-party services that appear on our pages. We do not control these cookies. Please refer to the respective third-party privacy policies for further information. Third-party services we may use include Google Analytics for website analytics and embedded map providers.

3.6 Changes to This Policy

We may update this Cookie Policy from time to time. Material changes will be communicated via a prominent notice on our website or through the cookie consent mechanism. Continued use of the website after changes constitutes acceptance of the updated policy.

3.7 Contact

For questions about our use of cookies, contact us at [email protected] or write to ZenithoraLabs, Avenida de Maisonnave, 25, 03003 Alicante, España.

4. Refund Policy

4.1 General Policy

ZenithoraLabs, located at Avenida de Maisonnave, 25, 03003 Alicante, España, is committed to delivering high-quality data analytics services. Due to the bespoke and professional nature of our work, refunds are evaluated on a case-by-case basis under the conditions outlined below.

4.2 Pre-Engagement Cancellation

If you cancel a project before work has commenced, you are entitled to a full refund of any advance payments. Cancellation must be communicated in writing to [email protected].

4.3 Partial Refunds

Where work has commenced but the engagement is terminated by the Client, a partial refund may be issued based on the proportion of work completed versus the total scope. The calculation will be documented in a written statement provided to the Client within 14 days of termination. Milestone-based payments already earned for completed phases are non-refundable.

4.4 Non-Refundable Items

The following are non-refundable:

  • Completed and approved deliverables that have been delivered and accepted in writing.
  • Third-party licensing fees or infrastructure costs incurred on behalf of the Client.
  • Consulting hours already consumed and documented.
  • Work rejected due to scope changes not covered by the original SOW.

4.5 Quality Disputes

If you believe delivered work does not meet the specifications defined in the SOW, you must notify us in writing within 14 days of delivery. We will review the claim and, if justified, will either (a) remedy the deficiency at no additional cost, or (b) issue a proportional refund. Disputes that cannot be resolved amicably shall be submitted to mediation as outlined in Section 2.9 of our Terms of Service.

4.6 Refund Process

Refund requests should be submitted via email to [email protected] with the subject line “Refund Request” and include the project reference, reason for the request, and relevant documentation. We will acknowledge receipt within 2 business days and process approved refunds within 30 days to the original payment method.

4.7 Consumer Rights

Nothing in this policy affects your statutory rights under Spanish consumer protection law (Real Decreto Legislativo 1/2007) and the EU Consumer Rights Directive (2011/83/EU). Where mandatory consumer protection provisions conflict with this policy, the statutory provisions shall prevail.

Questions About These Policies?

Contact our legal and compliance team at ZenithoraLabs, Avenida de Maisonnave, 25, 03003 Alicante, España.

Request Architecture Review