Data controller
The data controller is the owner of this website, identified in the legal notice.
Privacy contact: [email protected].
Scope of application
This policy refers to personal data processed in connection with professional requests related to GSP Context.
The website is informational and commercial. It does not provide a private area, user registration, checkout, payment gateway, digital case file or document upload.
Data that may be processed
When a person contacts through the available channels, the data voluntarily provided may be processed.
- Name and surname.
- Company or organisation.
- Position or role, if provided.
- Email address.
- Telephone number, if provided.
- Team situation regarding AI use.
- Message, technical context, need or challenge voluntarily shared.
- Subsequent communications needed to assess professional fit.
Information that should not be sent
Sensitive information, secrets, credentials, third-party personal data, proprietary code, confidential documentation or regulated information should not be sent unless there is a written agreement covering it.
Purposes
Data is processed to manage the request received and any subsequent professional relationship.
- Respond to contact requests.
- Assess professional fit.
- Prepare an initial conversation.
- Understand the basic context of the team or project.
- Prepare a specific proposal, where appropriate.
- Manage communications related to a request or possible professional relationship.
- Keep reasonable evidence of communications where necessary to protect legitimate interests or address responsibilities.
Legal basis
Handling requests and preparing a proposal may be based on pre-contractual measures requested by the interested person.
Ordinary communications management and defence against possible liabilities may be based on the controller's legitimate interest, balanced against the rights and freedoms of the interested person.
Where a contractual relationship exists, certain processing may be based on performance of the contract or compliance with legal obligations.
Retention
Data will be kept for the time needed to handle the request, assess fit, prepare a proposal or manage any professional relationship that may arise.
Where no subsequent professional relationship exists, data will be deleted or blocked within a prudent period, unless it must be retained to address liabilities or evidence communications.
Recipients and providers
Personal data is not sold or disclosed to third parties for commercial purposes unrelated to the request.
Data may be processed through technical providers needed for email, hosting, security, maintenance or the contact form.
Resend may be used as a technical email delivery provider to receive and manage form requests.
No analytics, advertising, remarketing, newsletter or commercial automation is currently declared.
International transfers
No specific international transfer is declared in relation to analytics, advertising, CRM or external forms other than the email technical provider indicated.
If Resend or other providers involve access or processing outside the European Economic Area, the applicable safeguards will be reviewed and documented.
Rights
The interested person may exercise the rights of access, rectification, erasure, objection, restriction, portability and withdrawal of consent where applicable.
Requests should be sent to [email protected]. A complaint may also be lodged with the competent supervisory authority.
Security and confidentiality
The controller applies reasonable technical and organisational measures to protect data against unauthorised access, loss, alteration or misuse.
The website should not be used as a channel to send deep confidential information or sensitive material before written exchange conditions have been agreed.