Privacy Policy
1. Data controller
Risk Resilience Security Group S.L.U. (RRSG) · Spanish VAT No. B-23985773 · Calle Costa Rica 18, 28691 Villanueva de la Cañada, Madrid (Spain) · Email: contact@rrsg.eu
2. Why do we process your data?
We process the data you provide through the contact form or by email in order to:
- Handle and respond to your request or enquiry.
- Advise you on the courses, options and certification that best match your goal.
- Manage, where applicable, the relationship arising from enrolling in a course or service.
- Manage appointment bookings when you schedule one (via Calendly).
- With your consent, send you the requested resource and email communications (newsletter, content and information about our training). You can withdraw your consent at any time.
- Issue the invoice for your purchase and comply with our accounting and tax obligations.
3. What is the legal basis?
The legal basis for processing is your consent (Art. 6.1.a GDPR), which you give by ticking the acceptance box and submitting the form. In the event of enrolment, the basis will be the performance of a contract (Art. 6.1.b GDPR).
When you make a purchase, processing your billing data also responds to the compliance with a legal obligation (Art. 6.1.c GDPR): Spanish law requires us to issue the invoice and to keep it.
4. What data do we process?
The identification and contact data you provide: name, email address and the information you choose to include in your message. We do not request special categories of data; please do not include any in the free-text message field. If you book an appointment via Calendly, we also process your name, email and the time slot you choose.
If you make a purchase, we also process the data needed to issue your invoice: full name or company name, VAT number where applicable, and address. You can provide them on the payment confirmation page or by email. Without these details the invoice cannot be issued.
5. How long do we keep it?
We keep your data for as long as the relationship or interest in our services continues and, thereafter, for the periods legally required. When it is no longer necessary, it is securely deleted. Form submissions are processed directly on our own website and retained in our email and internal systems.
Billing data is kept for the periods required by tax and accounting rules: four years for tax purposes and six years for accounting purposes.
6. Who do we share your data with?
We do not transfer your data to third parties, except where legally required. To operate the site and the form, we use providers acting as data processors:
| Provider | Purpose | Safeguards and location |
|---|---|---|
| Holded | Contact management and enquiry follow-up (CRM) | Data processor. Provider established in Spain, servers in the European Union. |
| Make (Celonis) | Automation of confirmation and reply emails | Data processor. Processing in European Union data centres. |
| Google (Gmail) | Email system for handling enquiries | Data processor. Servers in the United States. International transfer to the US covered by the safeguards of Chapter V of the GDPR (EU-US Data Privacy Framework). |
| DonDominio | Web hosting | Servers in Spain / EU |
| Calendly | Appointment booking | Data processor. Servers in the United States. The transfer is covered by the European Commission's standard contractual clauses and, where applicable, by the EU-US Data Privacy Framework. |
| Revolut | Online payment processing | Payment service provider. Payment is made on a secure payment page hosted by Revolut; card data is processed directly by Revolut and never passes through RRSG. Revolut acts as an independent data controller for that data (servers within the EEA / United Kingdom). |
| PECB Group Inc. | Issuing the exam voucher and the official certification | Data recipient. Certification body established in Canada. International transfer covered by Chapter V of the GDPR. |
Some of these providers process data outside the European Economic Area (United States). These transfers are carried out with the safeguards provided for in Chapter V of the GDPR.
7. What are your rights?
You can exercise at any time your rights of access, rectification, erasure, objection, restriction of processing and portability, by writing to contact@rrsg.eu and stating the right you wish to exercise. If you consider that the processing does not comply with the regulations, you may lodge a complaint with the supervisory authority of your Member State of residence or, as the controller is established in Spain, with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD, www.aepd.es).
8. Cookies
This site does not use tracking or advertising cookies. If an audience measurement solution is added in the future, a consent banner and a specific cookie policy will be put in place beforehand.
9. Security
We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss or alteration, in line with the state of the art.