Privacy Policy

1. DATA CONTROLLER

  • Company name: VIRALGEN VECTOR CORE, S.L.U.
  • Tax ID No.: B75181040
  • Registered office: Paseo Mikeletegi, 83, 2nd floor of the San Sebastian Technology Park (Gipuzkoa)
  • Contact email: info@viralgenvc.com
  • Data Protection Officer (DPO): dpo@viralgenvc.com
  • Telephone: +34 943 47 77 33

The Data Controller informs the USER that, in compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data (GDPR), and Organic Law 3/2018 of December 5 on the Protection of Personal Data and guarantee of digital rights (LOPDGDD), it will process their data as described in this Privacy Policy.

2. DATA PROCESSED, PURPOSES, AND LEGAL BASES

Management of professional contacts, inquiries, and business development prospecting (BD):

  • Data processed: identification and professional contact data (first name, last name, company, position, email, country, and state/region) and data regarding corporate interests (type of company, contact area, and services of interest). In the case of specific campaigns, additional data related to the data subject’s research or development project may be collected (disease indication, serotype, development stage, DNA starting material needs, target dates (IND), and financing strategy).
  • Purposes: (i) To handle, route, and respond to inquiries, requests for information, quotations, or technical support; and (ii) To refer the contact to the Business Development (BD) department for follow-up and commercial prospecting regarding our services.
  • Legal basis: for handling inquiries and applying pre-contractual measures, the legal basis is Art. 6.1.b GDPR and the presumption of lawfulness of B2B contact (Art. 19 LOPDGDD and legitimate interest, Art. 6.1.f GDPR). For sending commercial communications and conducting prospecting activities (BD), the legal basis will be the data subject’s explicit consent (Art. 6.1.a GDPR), collected through the checkboxes enabled in our forms.

Real-time assistance management (Live chat):

  • Data processed: identification and contact data (name and email address, if required by the system to start the session), technical session metadata (IP address, user ID), and the full content of communications (transcripts and conversation logs) exchanged with our team or virtual assistants.
  • Purposes: to address and resolve, in real time, any questions, incidents, or inquiries raised by the user while browsing the website. In addition, the conversation history will be linked and integrated into the user’s profile within our CRM (HubSpot) to ensure traceability of the inquiry, optimize follow-up by the Business Development (BD) team, and perform quality controls of the support service.
  • Legal basis: processing to respond to the inquiry is based on the implementation of pre-contractual measures at the request of the data subject (Art. 6.1.b GDPR) and on our legitimate corporate interest in offering an agile and efficient support channel (Art. 6.1.f GDPR). For processing related to commercial prospecting or linking the lead to future marketing campaigns, the legal basis will be the data subject’s explicit consent (Art. 6.1.a GDPR).

Management of applications and recruitment processes:

  • Data processed: information contained in the résumé/CV (academic and professional profile) and data generated during the evaluation stages of the recruitment process.
  • Purposes: assessment of candidates’ suitability for current vacancies or future hiring opportunities.
  • Legal basis: for managing the current application, the implementation of pre-contractual measures (Art. 6.1.b GDPR). For storing the profile in our historical database, the explicit consent given by the data subject when providing their information or registering on our employment portal (Art. 6.1.a GDPR).

Maintenance, security, and protection of the web infrastructure

  • Data processed: technical connection and browsing metadata.
  • Purposes: to ensure the security of the networks and information of our digital assets. This includes monitoring web traffic to detect anomalies, as well as preventing, investigating, and mitigating security incidents (such as denial-of-service attacks—DDoS—unauthorized access, or malicious bot traffic), thereby ensuring the availability, resilience, and integrity of the platform.
  • Legal basis: processing is based on the legitimate interest of the Controller (Art. 6.1.f GDPR), expressly recognized in Recital 49 of the GDPR, as a strictly necessary and proportionate measure to ensure an adequate level of security against digital threats (Art. 32 GDPR). This legitimate interest does not infringe the rights and freedoms of users, as the data is collected at the technical infrastructure level and is not used to profile or directly identify individuals for purposes other than security.

Management of the Whistleblowing Channel (Internal Reporting System):

  • Data processed: identification and contact data of the reporting person (unless they choose to submit an anonymous report), data of the person affected by the information, data of third parties mentioned in the report, and any other information provided to clarify the facts. Incidentally, the report may contain special categories of data (Art. 9 GDPR) or data relating to criminal convictions and offenses (Art. 10 GDPR).
  • Purposes: receipt, management, processing, and investigation of reports concerning possible regulatory, criminal, administrative, or internal policy violations (Compliance), as well as, where applicable, the adoption of the corresponding corrective, disciplinary, or legal measures.
  • Legal basis: processing is necessary for compliance with a legal obligation applicable to VIRALGEN (Art. 6.1.c GDPR) under Law 2/2023 of February 20, regulating the protection of persons who report regulatory violations and the fight against corruption; as well as for the performance of a task carried out in the public interest (Art. 6.1.e GDPR and Art. 24 LOPDGDD). Where special categories of data are processed, the basis will be substantial public interest (Art. 9.2.g GDPR).

3. RETENTION PERIODS

The personal data provided will be retained for the time strictly necessary to fulfill each of the stated purposes, as well as to determine any potential liabilities that may arise. Specifically, we will apply the following retention criteria:

  • Professional contacts, B2B inquiries, and support (including Live chat): data linked to isolated inquiries (contact forms or chat) will be retained for the time necessary to resolve and close the request. If such interaction results in a pre-contractual or contractual relationship, the data will be retained for the duration of that relationship.
  • Business Development (BD) and commercial prospecting: data of leads integrated into our CRM for follow-up and commercial communications will be retained indefinitely until the data subject withdraws consent, exercises their right to erasure or objection, or until the organization determines that the contact has become obsolete due to prolonged inactivity (in application of the principles of data minimization and accuracy).
  • Applications and recruitment processes: résumés/CVs and candidate profiles will be retained during the recruitment process for which they were collected. If the candidate authorized their retention for future vacancies, the data will be retained for a maximum period of one (1) year from receipt or last update. Once this period has elapsed without any update, the data will be securely deleted.
  • Web maintenance and security (Logs/Metadata): security records and technical browsing metadata will be retained for the technically indispensable period required to ensure infrastructure security (generally a maximum of between 6 and 12 months), unless they are linked to the investigation of a specific cybersecurity incident, in which case they will be retained until the investigation is closed or the relevant legal actions are exercised.
  • Whistleblowing Channel: data will be retained in the reporting system only for the time strictly necessary to decide whether to initiate an investigation. In any case, if three (3) months have elapsed since receipt of the report without any investigative actions having been initiated, the data will be deleted from the whistleblowing system (although it may remain outside the system solely to provide evidence of the operation of the prevention model). Reports that are not admitted for processing will be anonymized or immediately destroyed.

Legal blocking of data: once the operational periods described above have ended, VIRALGEN will block the data in accordance with Article 32 of Organic Law 3/2018 (LOPDGDD). During this blocking period, the data will remain available exclusively to Judges and Courts, the Public Prosecutor’s Office, or the competent Public Administrations (in particular, the Spanish Data Protection Agency) to address any potential liabilities arising from the processing. Once the statutory limitation periods for such liabilities have expired, the data will be irreversibly destroyed or anonymized.

4. RECIPIENTS AND INTERNATIONAL TRANSFERS

VIRALGEN VECTOR CORE, S.L.U. will not disclose personal data to third parties, except where there is a legal obligation or a judicial request issued by a competent authority.

Notwithstanding the foregoing, for the proper operation of the web platform and the provision of the requested services, VIRALGEN collaborates with third-party providers (virtual infrastructure services, analytics tools, CRM, and IT support). These entities access the data solely and exclusively as Data Processors, and the corresponding agreements have been entered into to ensure the application of appropriate technical and organizational measures in accordance with Article 28 of the GDPR.

If the provision of these services involves the storage of or access to data from outside the European Economic Area (EEA), VIRALGEN guarantees that such International Data Transfers (IDTs) will be carried out by applying the legally required safeguards (Articles 44 et seq. GDPR), either under European Commission Adequacy Decisions or, failing that, through the execution of current Standard Contractual Clauses (SCCs) and the adoption of any necessary supplementary measures.

In particular, the web platform uses technology services provided by U.S. entities (such as HubSpot, Inc., Google LLC, LinkedIn Corp., and Cloudflare, Inc.). International transfers to these providers are fully legitimate and covered by the EU-U.S. Data Privacy Framework, an adequacy decision adopted by the European Commission to which these entities are certified, thereby ensuring a level of protection of rights and freedoms comparable to the European standard.

With respect to the Internal Reporting System, access to the data will be restricted exclusively to the System Manager and duly authorized personnel with Compliance or investigation responsibilities. The identity of the reporting person will be treated with absolute confidentiality and will under no circumstances be disclosed to the affected person (the reported party). It may only be disclosed to the Judicial Authority, the Public Prosecutor’s Office, or the competent administrative authority in the context of a criminal, disciplinary, or sanctioning investigation.

5. DATA SUBJECTS’ RIGHTS

The user has full control over their personal data and may exercise, before the Controller, their rights of access, rectification, erasure (right to be forgotten), objection, restriction of processing, portability, and the right not to be subject to individual automated decisions (including profiling).

How to exercise rights: the data subject must send a written request to the Data Protection Officer at the following email address: dpo@viralgenvc.com.

Identity verification: in strict compliance with the principles of fairness and processing security, and following the guidelines of the European Data Protection Board (EDPB), additional documentation proving the applicant’s identity (copy of ID card or passport) will only be required where there are reasonable doubts regarding the authenticity of the sender, thereby preventing fraudulent access by third parties.

If the user believes that their rights have been violated, they may file a complaint with the Spanish Data Protection Agency (AEPD) through its electronic office (www.aepd.es).

6. SECURITY MEASURES

The Controller, in accordance with the provisions of the GDPR and the LOPDGDD, has implemented all technical and organizational measures within its reach that are appropriate to ensure a level of security suitable to the risk, protecting personal data against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure or access.

 

POLÍTICA DE PRIVACIDAD

1. RESPONSABLE DEL TRATAMIENTO

  • Denominación social: VIRALGEN VECTOR CORE, S.L.U.
  • NIF: B75181040
  • Domicilio social: Paseo Mikeletegi, 83, 2nd floor of the Parque Tecnológico of San Sebastian (Guipuzcoa)
  • E-mail de contacto: info@viralgenvc.com
  • Delegado de Protección de Datos (DPD): dpo@viralgenvc.com
  • Teléfono: +34 943 47 77 33

El Responsable del Tratamiento informa al USUARIO de que, en cumplimiento del Reglamento (UE) 2016/679 del Parlamento Europeo y del Consejo, de 27 de abril de 2016, relativo a la protección de las personas físicas en lo que respecta al tratamiento de datos personales (RGPD), y la Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD), tratará sus datos tal como se refleja en la presente Política de Privacidad.

2. DATOS TRATADOS, FINALIDADES Y BASES DE LEGITIMACIÓN

Gestión de contactos profesionales, consultas y prospección comercial (BD):

  • Datos tratados: datos identificativos y de contacto profesional (Nombre, apellidos, empresa, cargo, e-mail, país y estado/región) y datos sobre intereses corporativos (tipo de empresa, área de contacto, servicios de interés). En el caso de campañas específicas, se recabarán datos adicionales relativos al proyecto de investigación o desarrollo del interesado (indicación de la enfermedad, serotipo, etapa de desarrollo, necesidades de material de partida de ADN, fechas objetivo (IND) y estrategia de financiación).
  • Finalidades: (i) Atender, canalizar y dar respuesta a las consultas, solicitudes de información, presupuestos o soporte técnico; y (ii) Derivar el contacto al departamento de Desarrollo de Negocio (BD) para seguimiento y prospección comercial sobre nuestros servicios.
  • Base de Legitimación: para la atención de la consulta y la aplicación de medidas precontractuales, la base es el Art. 6.1.b RGPD y la presunción de licitud del contacto B2B (Art. 19 LOPDGDD e interés legítimo, Art. 6.1.f RGPD). Para el envío de comunicaciones comerciales y acciones de prospección (BD), la base legitimadora será el consentimiento explícito del interesado (Art. 6.1.a RGPD) recabado a través de las casillas habilitadas en nuestros formularios.

Gestión de asistencia en tiempo real (Chat en vivo):

  • Datos tratados: datos identificativos y de contacto (nombre y correo electrónico, si son requeridos por el sistema para iniciar la sesión), metadatos técnicos de la sesión (dirección IP, ID de usuario) y el contenido íntegro de las comunicaciones (transcripciones y logs de la conversación) mantenidas con nuestro equipo o asistentes virtuales.
  • Finalidades: atender y resolver en tiempo real las dudas, incidencias o consultas planteadas por el usuario durante su navegación web. Asimismo, el historial de la conversación se vinculará e integrará en el perfil del usuario dentro de nuestro CRM (HubSpot) para garantizar la trazabilidad de la consulta, optimizar el seguimiento por parte del equipo de Desarrollo de Negocio (BD) y realizar controles de calidad del servicio de atención.
  • Base de Legitimación: el tratamiento para dar respuesta a la consulta se legitima en la aplicación de medidas precontractuales a petición del interesado (Art. 6.1.b RGPD) y en nuestro interés legítimo corporativo de ofrecer un canal de soporte ágil y eficiente (Art. 6.1.f RGPD). Para el tratamiento derivado de la prospección comercial o vinculación del lead a futuras campañas de marketing, la base legítima será el consentimiento explícito del interesado (Art. 6.1.a RGPD).

Gestión de candidaturas y procesos de selección:

  • Datos tratados: información contenida en el Currículum Vitae (perfil académico y profesional) y datos generados durante el desarrollo de las etapas evaluativas del proceso selectivo.
  • Finalidades: valoración de la idoneidad de los perfiles para cubrir vacantes actuales o futuras incorporaciones.
  • Base de Legitimación: para la gestión de la candidatura vigente, la aplicación de medidas precontractuales (Art. 6.1.b RGPD). Para el archivo del perfil en nuestra base de datos histórica, el consentimiento explícito manifestado por el interesado al facilitar su información o registrarse en nuestro portal de empleo (Art. 6.1.a RGPD).

Mantenimiento, seguridad y salvaguarda de la infraestructura web

  • Datos tratados: metadatos técnicos de conexión y navegación.
  • Finalidades: garantizar la seguridad de las redes y la información de nuestros activos digitales. Ello incluye monitorizar el tráfico web para detectar anomalías, así como prevenir, investigar y mitigar incidentes de seguridad (tales como ataques de denegación de servicio -DDoS-, accesos no autorizados o tráfico de bots maliciosos), asegurando la disponibilidad, resiliencia e integridad de la plataforma.
  • Base de Legitimación: el tratamiento se basa en el interés legítimo del Responsable (Art. 6.1.f RGPD), reconocido expresamente en el Considerando 49 del RGPD, al ser una medida estrictamente necesaria y proporcionada para garantizar un nivel de seguridad adecuado frente a las amenazas digitales (Art. 32 RGPD). Dicho interés legítimo no vulnera los derechos y libertades de los usuarios, dado que los datos se recogen a nivel de infraestructura técnica y no se utilizan para perfilar ni identificar directamente al individuo con fines distintos a la seguridad.

Gestión del Canal de Denuncias (Sistema Interno de Información):

  • Datos tratados: datos identificativos y de contacto del informante (salvo que este opte por presentar una comunicación anónima), datos de la persona afectada por la información, datos de terceros mencionados en la denuncia y cualquier otra información aportada para el esclarecimiento de los hechos. De forma incidental, la comunicación podría contener categorías especiales de datos (Art. 9 RGPD) o datos relativos a condenas e infracciones penales (Art. 10 RGPD).
  • Finalidades: recepción, gestión, tramitación e investigación de las comunicaciones relativas a posibles infracciones normativas, penales, administrativas o vulneraciones normativas internas (Compliance), así como, en su caso, la adopción de las medidas correctivas, disciplinarias o legales correspondientes.
  • Base de Legitimación: el tratamiento resulta necesario para el cumplimiento de una obligación legal aplicable a VIRALGEN (Art. 6.1.c RGPD) en virtud de la Ley 2/2023, de 20 de febrero, reguladora de la protección de las personas que informen sobre infracciones normativas y de lucha contra la corrupción; así como para el cumplimiento de una misión realizada en interés público (Art. 6.1.e RGPD y Art. 24 de la LOPDGDD). En caso de tratarse categorías especiales de datos, la base será el interés público esencial (Art. 9.2.g RGPD).

 

3. PLAZOS DE CONSERVACIÓN

Los datos personales proporcionados se conservarán durante el tiempo estrictamente necesario para cumplir con cada una de las finalidades previstas, así como para determinar las posibles responsabilidades que pudieran derivarse. En concreto, aplicaremos los siguientes criterios de retención:

  • Contactos profesionales, consultas B2B y soporte (incluyendo Chat en vivo): los datos vinculados a consultas aisladas (formularios de contacto o chat) se conservarán durante el tiempo necesario para resolver y dar por cerrada la solicitud. Si de dicha interacción se deriva una relación precontractual o contractual, los datos se mantendrán durante la vigencia de la misma.
  • Desarrollo de Negocio (BD) y prospección comercial: los datos de los leads integrados en nuestro CRM con fines de seguimiento y envíos comerciales se conservarán de manera indefinida hasta que el interesado revoque su consentimiento, ejerza su derecho de supresión u oposición, o hasta que la entidad determine la obsolescencia del contacto por inactividad prolongada (en aplicación del principio de minimización y exactitud).
  • Candidaturas y procesos de selección: los Currículum Vitae y perfiles de candidatos se conservarán durante el desarrollo del proceso selectivo para el que fueron recabados. Si el candidato autorizó su conservación para futuras vacantes, los datos se retendrán por un plazo máximo de un (1) año desde su recepción o última actualización. Transcurrido dicho plazo sin que hayan sido actualizados, se procederá a su borrado seguro.
  • Mantenimiento y seguridad web (Logs/Metadatos): los registros de seguridad y metadatos técnicos de navegación se conservarán durante el tiempo técnico indispensable para garantizar la seguridad de la infraestructura (generalmente un máximo de entre 6 y 12 meses), salvo que estén vinculados a la investigación de un incidente de ciberseguridad específico, en cuyo caso se retendrán hasta el cierre de la investigación o el ejercicio de las acciones legales pertinentes.
  • Canal de Denuncias: los datos se conservarán en el sistema de información únicamente durante el tiempo imprescindible para decidir sobre la procedencia de iniciar una investigación. En todo caso, transcurridos tres (3) meses desde la recepción de la comunicación sin que se hubiesen iniciado actuaciones de investigación, los datos se suprimirán del sistema de denuncias (pudiendo permanecer fuera de este únicamente a efectos de dejar evidencia del funcionamiento del modelo de prevención). Las denuncias que no sean admitidas a trámite se anonimizarán o destruirán de forma inmediata.

Bloqueo legal de los datos: una vez finalizados los plazos operativos anteriormente descritos, VIRALGEN procederá al bloqueo de los datos conforme al artículo 32 de la Ley Orgánica 3/2018 (LOPDGDD). Durante este periodo de bloqueo, los datos quedarán a disposición exclusiva de Jueces y Tribunales, el Ministerio Fiscal o las Administraciones Públicas competentes (en particular, la Agencia Española de Protección de Datos) para la atención de las posibles responsabilidades nacidas del tratamiento. Superados los plazos legales de prescripción de dichas responsabilidades, los datos serán destruidos o anonimizados de forma irreversible.

 

4. DESTINATARIOS Y TRANSFERENCIAS INTERNACIONALES

VIRALGEN VECTOR CORE, S.L.U no cederá datos personales a terceros, salvo existencia de obligación legal o requerimiento judicial expedido por autoridad competente.

Sin perjuicio de lo anterior, para el correcto funcionamiento de la plataforma web y la prestación de los servicios solicitados, VIRALGEN cuenta con la colaboración de terceros proveedores (servicios de infraestructura virtual, herramientas analíticas, CRM y soporte informático). Dichas entidades acceden a los datos única y exclusivamente en calidad de Encargados del Tratamiento, habiéndose suscrito los correspondientes contratos que garantizan la aplicación de medidas técnicas y organizativas apropiadas conforme al artículo 28 del RGPD.

En el supuesto de que la prestación de estos servicios implique el almacenamiento o acceso a los datos desde fuera del Espacio Económico Europeo (EEE), VIRALGEN garantiza que dichas Transferencias Internacionales de Datos (TID) se articularán aplicando las salvaguardas legales exigibles (artículos 44 y siguientes del RGPD), ya sea al amparo de Decisiones de Adecuación de la Comisión Europea o, en su defecto, mediante la formalización de Cláusulas Contractuales Tipo (SCC) vigentes y la adopción de las medidas suplementarias que resulten necesarias.

En particular, la plataforma web utiliza servicios tecnológicos prestados por entidades estadounidenses (tales como HubSpot, Inc., Google LLC, LinkedIn Corp. y Cloudflare, Inc.). Las transferencias internacionales a estos proveedores se encuentran plenamente legitimadas y amparadas en el Marco de Privacidad de Datos UE-EE. UU. (Data Privacy Framework), decisión de adecuación adoptada por la Comisión Europea a la que dichas entidades se encuentran adheridas, garantizando así un nivel de protección de los derechos y libertades equiparable al estándar europeo.

En relación con el Sistema Interno de Información, el acceso a los datos quedará restringido exclusivamente al Responsable del Sistema y al personal con funciones de Compliance o investigación debidamente autorizado. La identidad del informante será tratada con absoluta confidencialidad y en ningún caso se comunicará a la persona afectada (denunciado). Únicamente podrá ser revelada a la Autoridad Judicial, al Ministerio Fiscal o a la autoridad administrativa competente en el marco de una investigación penal, disciplinaria o sancionadora.

5. DERECHOS DE LOS INTERESADOS

El usuario ostenta el control pleno de sus datos personales y puede ejercitar ante el Responsable sus derechos de acceso, rectificación, supresión (olvido), oposición, limitación del tratamiento, portabilidad y a no ser objeto de decisiones automatizadas individuales (incluida la creación de perfiles).

Vía de ejercicio: el interesado deberá dirigir una solicitud por escrito al Delegado de Protección de Datos a la dirección electrónica: dpo@viralgenvc.com.

Acreditación de identidad: en estricto cumplimiento de los principios de lealtad y seguridad del tratamiento, y siguiendo las directrices del Comité Europeo de Protección de Datos (CEPD), solo se exigirá documentación adicional que acredite la identidad del solicitante (copia de DNI o pasaporte) en aquellos supuestos donde concurran dudas razonables sobre la autenticidad del remitente, evitando así accesos fraudulentos por parte de terceros.

Si el usuario considera vulnerados sus derechos, tiene la facultad de interponer una reclamación de tutela ante la Agencia Española de Protección de Datos (AEPD) mediante su sede electrónica (www.aepd.es).

6. MEDIDAS DE SEGURIDAD

El Responsable, de conformidad con lo dispuesto en el RGPD y la LOPDGDD, ha implementado todas las medidas técnicas y organizativas a su alcance, apropiadas para garantizar un nivel de seguridad adecuado al riesgo, que protejan los datos de carácter personal contra la destrucción, pérdida o alteración accidental o ilícita, y contra la comunicación o acceso no autorizados.