web-shop & certificates Privacy Policy
Last updated: 06/08/2026
In this Privacy Policy, you will find all the information relating to the processing of personal data that we carry out in order to properly provide the services offered on this website.
If you wish to use our web services or purchase any of our products, you must expressly consent to the processing of your personal data by VINTEGRIS, in accordance with the purpose applicable to the specific service requested, and accept the Terms of Use applicable to the service purchased, which we will provide to you prior to the completion of each transaction.
Who is the data controller?
Company name: VINTEGRIS, S.L. (VINTEGRIS)
Tax Identification Number (NIF): B62913926
Address: Calle Pallars, 99. 08018 Barcelona (Spain)
Contact: info@vintegris.com
Who are the data subjects?
The personal data processed relates to:
- Individuals who have registered on this website to purchase certificates.
- Individuals acting as certificate administrators.
- Individuals with rights over the certificates other than the holder – subscribers – (e.g. a company requesting certificates for its employees).
- Holders of the certificates issued.
For what purposes do we process your data?
- Your data may be processed for the following purposes:
If you are a registered user on our website:
- Management of registered users on this website.
- Management of certificate orders placed and processing of refund requests, using the STRIPE payment platform.
- To manage any issues you have reported to us.
- To manage the issuance and lifecycle of certificates.
- To send you information about our services or products.
If you are an invited administrator:
In this case, your email address has been provided to us by a registered user who has invited you to manage the certificates they have purchased, and we understand that you have consented to this transfer of data. Your email address will only be used to send you the invitation to become an administrator, which you may accept or decline. If you accept it, you will need to register as a user of the website so that you can manage the certificates assigned to you on the VINTEGRIS platform.
If you are the certificate holder:
The certificate holder may be the same user registered with the shop who purchased the certificate, a certificate manager invited by the user, or a third party to whom the certificate owner or manager assigns a certificate so that they may act as the holder.
Your data will be processed in order to grant you a digital identity through the issue of an electronic certificate in your name. It is essential to verify your identity via an accredited video identification process. Furthermore, it will be necessary to check the authenticity, validity and integrity of the identification documents used, and to verify that the holder of the document is the same person as the applicant carrying out the procedure.
Identity verification via the video identification process is carried out using certified technology integrated into the nebulaSUITE platform, owned by VINTEGRIS, which is the data controller for this processing of personal data; it will process your biometric facial recognition data to verify that you are a living person and that your identity is not being impersonated. Biometric data is not stored in all cases; should it be retained, please note that this will not exceed 15 days. By accepting this privacy policy and clicking the ‘ACCEPT’ button, you are expressly consenting to the processing of your data. However, you will be informed of the terms and conditions of the Nebula platform’s service and the data protection policy relating to this processing when you access the platform.
Where your certificate is that of a legal representative of a legal entity or the holder of a company seal, an additional purpose of data processing is to validate the documentation provided to verify the attributes that such certificates necessarily include.
Once these checks have been carried out by our registration operators, and provided everything is in order, the certificate will be approved and you will be able to issue it yourself.
Once the certificate has been issued, the data may be processed for the purposes of internal auditing and monitoring of our certificate issuance processes, in accordance with the legislation applicable to trust services and the legitimate interests of the data controller, and will be retained for as long as necessary to fulfil these obligations of the trust service provider. The data may be disclosed to the competent authorities or auditors in compliance with the applicable regulations.
If you provide data relating to third parties, you must inform them in advance of the content of this clause and ensure that they have given their consent.
What personal data do we process?
We apply the principle of data minimisation when collecting personal data, gathering only the data necessary for the purpose of the processing.
Data provided during user registration on the website:
- Identification details: First name, surname and National Identity Card number
- Tax Identification Number (required for invoicing)
- Contact details: Email
- Password (always encrypted)
Administrator details:
- Contact details: Email. (This information is always provided by a registered user, who must have previously informed you of the data being shared with us)
Certificate holder details:
- Identification details: First name and surname, National Identity Card (DNI), passport or Foreign Resident Identity Card (TIE)
- Contact details: Email and mobile phone number
- Details of attributes contained in the certificate: details proving your status as the legal representative of an organisation or your affiliation with an organisation.
What is the legal basis for processing?
Data from user registration on the website:
Consent, which is deemed to have been given when you register on the website, and in any case upon acceptance of this policy.
For the purchase process, management of your certificates, incident management and returns management: the existing contractual relationship.
We consider that VINTEGRIS has a legitimate interest in carrying out the necessary checks to detect and prevent potential fraud when a purchase is made. We therefore understand that the processing of this data is beneficial to all parties involved when a purchase is paid for, and in particular to the user, as it enables VINTEGRIS to take the necessary measures to prevent and protect against attempts at fraud by third parties.
For the sending of information about our products or services related to your purchase: Article 21 of the LSSICE.
Data relating to account managers:
The person who provides us with your email address must have informed you in advance and ensured that they have obtained your consent. However, when you receive the invitation email as an account manager, you may decline it; in which case, we will remove your email account from our databases.
Data relating to certificate holders:
The contractual relationship between the holder and VINTEGRIS is governed by the Terms and Conditions of Use for the certificates, which you expressly accept during the process prior to their issue; we will retain a copy of the document signed by you, known as the ‘acceptance form’. This contractual relationship is based on compliance with the legislation applicable to the provision of trust services: the European eIDAS Regulation (EU) No 910/2014 of 23 July on electronic identification and trust services for electronic transactions in the internal market, and Spanish Law 6/2020 of 11 November, regulating certain aspects of electronic trust services, as well as VINTEGRIS’s internal regulations, set out in its Statement of Certification Practices (SCP).
With regard to data processing relating to internal audits and the monitoring of our certificate issuance processes, the legal basis is compliance with the requirements laid down in current legislation for trust service providers, as well as the data controller’s interest in verifying that the actions carried out are correct.
Although acceptance of this policy already constitutes your express consent to the processing of your biometric data as a necessary step in obtaining the certificate, you will be reminded again of the data protection clause relating to this processing when you undergo video identification.
What is the data retention period?
Data in the user’s online account:
Once the relationship has ended, we will retain your data for as long as necessary to deal with any potential claims arising from the relationship, or to comply with requirements set out in applicable legislation.
We may send you information after the contractual relationship has ended, provided you do not object to this.
Data of administrators:
If you, as an invited administrator, decline the invitation, we will delete your data.
If you accept the invitation, you must register as a website user (see the relevant section).
Data of certificate holders:
The retention period for data relating to issued certificates shall be 15 years from the date of their expiry or revocation, in accordance with the provisions of the applicable regulations.
· If the certificate issuance process is not completed, the data will not be retained.
Biometric data obtained during the video identification process, if retained at all, will not be kept for more than 15 days.
The retention period for processing related to internal auditing and the monitoring of processes for the validation, approval and issue of certificates will remain in force for as long as our legal audit obligation remains in force.
To whom will the data be disclosed?
Payments made on this website are processed via Stripe Payments Europe, Ltd. (“Stripe”), which acts as a payment processing service provider. To execute the transaction, Stripe receives only the information necessary to process the payment and verify that it has been completed correctly.
Transaction data:
· Internal product identifiers and prices.
· Quantities purchased.
· Applicable tax identifiers.
User identification data:
· Internal user ID on the VINTEGRIS platform.
Metadata required for administrative management and payment reconciliation:
- · Billing details (name or company name, identification document, full address).
- Internal identifiers for vouchers or discounts and promotional codes applied.
- User analytics identifier (ga_client_id) for the purposes of conversion measurement and sales attribution.
International data transfers
Stripe may process personal data on servers located both within and outside the European Economic Area, including the United States. In such cases, Stripe applies the safeguards set out in Regulation (EU) 2016/679 (GDPR), including the EU–US Data Privacy Framework, the Standard Contractual Clauses approved by the European Commission, and additional technical and organisational measures designed to protect the USER’s information.
You can view Stripe’s privacy policy at: https://stripe.com/privacy
Under no circumstances does VINTEGRIS transmit payment card details, expiry dates or security codes (CVV) to Stripe. This information is entered directly by the USER within Stripe’s secure environment, in accordance with PCI-DSS standards.
Please be advised that you are responsible for the use of your certificate. The inclusion of personal data in the CN (Common Name) field and in any other field relating to the signatory (Subject) means that, when you sign a document electronically, this personal data may be accessible to anyone who receives the document.
Furthermore, we would like to remind you that the personal data required for the issuance of the certificate, as well as your certificate’s serial number, will be included in the public key directory for electronic signatures—which is necessary to verify the validity of the electronic certificate—as well as in the directory of revoked certificates. Consequently, this data will be processed automatically so that it is accessible for consultation by all users of the system, that is, those who voluntarily rely on and use electronic certificates, always in accordance with the provisions of VINTEGRIS’s Certification Policies.
In accordance with the applicable regulations, the mechanics of the certification system require that its users (relying third parties, both private individuals and public authorities) be able to access your personal data from anywhere in the world, and you are therefore informed that if you contract the service, you must consent to your data, as well as your certificate’s serial number, being made available for consultation by users of the system, with VI
NTEGRIS being exempt from any liability arising from the misuse of such data by third parties.
Your data will also be processed to comply with the legal obligations applicable to the respective services, in particular:
• its incorporation into IT security and regulatory compliance products,
• sending reminders regarding service expiry dates,
• its retention for the required legal period, and
• its use in the event of a defence in legal proceedings.
VINTEGRIS may delegate registration tasks (e.g. to Registration Authorities or In-Person Verification Points) to a third party or entity, as well as the development, hosting/cloud storage and maintenance of the applications and platforms that manage personal data and, where applicable, biometric data (technology providers). Personal Data may only be disclosed to (i) third-party support and consultancy service providers for VINTEGRIS, in relation to activities in (for example) the technology, accounting, administrative, legal, insurance and/or IT sectors; (ii) companies controlled by and/or affiliated with VINTEGRIS, which are responsible for the maintenance of information systems or operate in the IT sector; (iii) companies providing support services to Clients; (iv) companies that collaborate with VINTEGRIS in the marketing, distribution and promotion of its products and services; and (v) authorities whose right of access to Clients’ Personal Data is expressly recognised by the competente authorities.
These entities shall be regarded as “Data Processors” as they have access to the data provided by VINTEGRIS, solely and exclusively for the purpose of fulfilling the obligations entrusted to them and the instructions issued by VINTEGRIS, or where such access is necessary to provide the contracted service or to fulfil the contracted obligations.
Is data processed by third parties?
If it is possible to access content and services from this website that are located on external websites or social media platforms which are not under the control or responsibility of VINTEGRIS, users should be aware that these sites may collect information about their online activities. When you click on a link, these sites record this action and may use the information collected. Please consult the respective privacy policies of each site to find out exactly how they use the information collected and how you can disable or delete such information.
Can we send you marketing communications?
We will only process your data to send you information about our services, offers and other commercial information where you have given us your express consent to do so, or where this information relates to products or services similar to those you have already contracted with us, in accordance with the provisions of Article 21 of the Law on Information Society Services (LSSI).
You may ask us at any time to stop sending you such information, should you wish to do so.
What rights do data subjects have when they provide us with their data?
At any time, the data subject may submit a request to exercise their rights of access, rectification, erasure and data portability in relation to the personal data processed by VINTEGRIS, as well as their rights to object to and restrict the processing of their data.
These rights may be exercised free of charge by the data subject, and where applicable by their representative, by means of a written and signed request, accompanied by a copy of their national identity card or equivalent document proving their identity, addressed to:
By email: dpo@vintegris.com
By post: Calle Pallars 99, 08018 Barcelona (Spain)
In the case of representation, proof must be provided in writing, accompanied by a copy of the ID card or equivalent document proving the representative’s authority.
VINTEGRIS reminds the data subject that they have the right to lodge a complaint with the relevant supervisory authority (Spanish Data Protection Agency).
Updating your details
It is important that you inform us of any changes so that we can keep your personal data up to date. If you are a registered user, you can update your details yourself in ‘My Profile’, within your private area of the shop.
Data relating to minors
The services provided by VINTEGRIS are not intended for minors; therefore, we do not accept requests made by them. VINTEGRIS is not responsible for unauthorised access or for personal data – whether its own or that of third parties – that may be provided by minors.
Security in data processing and storage
VINTEGRIS implements all the security measures required by the regulations applicable to trust services for a qualified service provider. Compliance with these measures is audited by third parties on an annual basis.
Relevant information
All our trust services are subject to the applicable European eIDAS and Electronic Signature regulations. In accordance with current regulations, you may consult the ‘Personal Data Protection’ section in the Certification Practice Statement (CPS) available at https://www.vincasign.net/policy/es/DPC/Vintegris-DPC-ES.pdf or in the Privacy Policy at https://www.vincasign.net/privacy.html
You can access the Terms of Use for each type of electronic certificate and the terms and conditions governing their use at https://www.vincasign.net/
Validity of the Policy
The Privacy Policy in force and applicable shall be the one published at the time you visit this website.
VINTEGRIS expressly reserves the right to amend this Privacy Policy without prior notice. Consequently, you should read this Privacy Policy carefully each time you use VINTEGRIS’s websites, as this Privacy Policy may be subject to change. Any changes will take effect immediately from the date indicated at the top of this page.
Cookies
For information on the use of cookies on this website, please refer to our Cookies Policy, which can be found at the bottom of the shop page.