PRIVACY POLICY – COOKIES – LEGAL NOTICE

Legal informationPrivacy policy, legal notice and cookies

Last updated: 19 August 2026.

1. Data controller

Item Details
Controller JAYMON SECURITY, S.L.
Spanish VAT no. (NIF) B88291174
Registered address C/ Malaquita, 25 · 28224 Pozuelo de Alarcón (Madrid), Spain
Telephone +34 686 250 244
Email info@jaymonsecurity.com
Websites jaymonsecurity.es and jaymonsecurity.com
2. What we process, why, and on what legal basis

We only process data you give us or that is generated by your browsing. We do not buy databases and we do not obtain your data from third-party sources.

Activity Data Purpose Legal basis (Art. 6 GDPR)
Email or phone enquiries Name, email, phone and the content of your message Answer your enquiry and, where applicable, prepare a proposal Legitimate interest in replying, and pre-contractual measures
Meeting bookings Name, email and chosen time slot Schedule and hold the meeting Consent and pre-contractual measures
Course purchases Full name, tax ID, billing address, email, phone and order details Process the order, issue the invoice and deliver the service Performance of a contract and legal tax obligations
Payment Card details, processed directly by Stripe; we never store the full card number Collect payment for the order Performance of a contract
Training students Platform credentials, progress and exam results Deliver the course and issue the certificate Performance of a contract
Responsible disclosure Whatever data you choose to include in your report Handle the vulnerability report Legitimate interest in the security of our systems
Browsing and cookies IP address, cookie identifiers and usage data Site operation, security and measurement Legitimate interest for strictly necessary cookies, consent for the rest
3. How long we keep your data

Case Retention period
Enquiries that do not lead to a contract Up to 1 year from the last contact
Clients: invoicing and accounting 6 years (Art. 30 Spanish Commercial Code) and 4 years for tax purposes
Students: records and certificates For as long as course access lasts and thereafter as needed to evidence the certificate issued
Vulnerability reports Until the case is closed and documented
Cookies As stated in section 8, per cookie

Once those periods expire, data is blocked and remains available only to courts and competent authorities for the applicable limitation periods, after which it is deleted.

4. Who we share your data with

We do not sell or trade your data. Only the providers we need in order to deliver the service have access, all of them under a data processing agreement pursuant to Art. 28 GDPR:

Provider Purpose Location
Web hosting provider Hosting of both sites and the associated email European Union
Stripe Card payment processing USA, under appropriate safeguards
Calendly Meeting scheduling. It only loads if you press the calendar button on the contact page USA, under appropriate safeguards

We will also disclose data where legally required, for example to the Spanish tax authority, law enforcement or the courts.

5. International transfers

Some of the providers listed above are established in the United States. Those transfers rely on the Standard Contractual Clauses approved by the European Commission or on the provider’s certification under the EU-US Data Privacy Framework, together with supplementary measures. You may request a copy of the safeguards in place by writing to rgpd@jaymonsecurity.com.

6. Your rights

You may exercise the following rights at any time:

  • Access: find out what data of yours we process.
  • Rectification: correct inaccurate data.
  • Erasure: ask us to delete data that is no longer necessary.
  • Objection: object to processing based on legitimate interest.
  • Restriction: ask us to keep the data but not use it.
  • Portability: receive your data in a structured format or have it sent to another controller.
  • Withdraw consent at any time, without affecting the lawfulness of prior processing.

Write to rgpd@jaymonsecurity.com or to C/ Malaquita, 25, 28224 Pozuelo de Alarcón (Madrid), Spain, stating which right you are exercising and enclosing a copy of an identity document. We will reply within one month.

If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD, C/ Jorge Juan 6, 28001 Madrid — www.aepd.es) or with the supervisory authority of your country of residence.
7. Data security

We apply the technical and organisational measures set out in Art. 32 GDPR: TLS encryption in transit across the whole site, least-privilege access control, reinforced authentication on administration panels, activity logging, regular backups and continuous software patching.

We operate a responsible disclosure channel and publish our security contact details at /.well-known/security.txt, per RFC 9116.

8. Cookies

A cookie is a small file downloaded to your device when you visit a website. These are the ones we use:

Cookie Owner Purpose Duration
hu-consent First party Stores your cookie preferences 1 year
wevarnishpass First party Strictly necessary: server cache handling Session
wp-settings-* First party Strictly necessary: preferences for logged-in users 1 year
woocommerce_*, wp_woocommerce_session_* First party Strictly necessary: cart and checkout Session / 2 days
__stripe_mid, __stripe_sid Stripe Payment fraud prevention 1 year / 30 min

This site does not ask you to accept cookies, because it does not set any that would require it. Every cookie we use is technical or strictly necessary to deliver the service you request, and those are exempt from consent. We use no analytics, no advertising and no tracking of any kind. If you still want to remove them, you can do so from your browser: Chrome, Firefox, Safari or Edge.

Rejecting non-essential cookies does not prevent you from browsing or purchasing; we simply lose statistical information about where visits come from.

9. Links to third-party sites

Our sites contain links to third-party websites, such as those of clients, partners and the bodies we work with. We do not control their privacy policies and are not responsible for their content. We recommend reading them before providing any data.

10. Legal notice

Pursuant to Art. 10 of Spanish Act 34/2002 on information society services and electronic commerce, the owner of the sites jaymonsecurity.es and jaymonsecurity.com is JAYMON SECURITY, S.L., NIF B88291174, registered address at C/ Malaquita, 25, 28224 Pozuelo de Alarcón (Madrid), Spain, entered in the Madrid Commercial Registry.

Intellectual and industrial property. The site design, its source code, logos, trade marks and other distinctive signs belong to JAYMON SECURITY, S.L. and are protected by intellectual and industrial property law. Infographics, guides and blog articles are published under a CC BY-NC-SA 4.0 licence, allowing non-commercial reuse with attribution under the same terms.

Liability. JAYMON SECURITY, S.L. is not responsible for the lawfulness of third-party sites from which this portal may be accessed, nor of those linked from it. We reserve the right to modify the site without prior notice in order to keep its content up to date.

Governing law and jurisdiction. This policy is governed by Spanish law. Where the user qualifies as a consumer, the courts of the consumer’s domicile shall have jurisdiction; otherwise, the courts of Madrid.

11. Changes to this policy

We may update this policy to reflect legal changes or new services. The date of the latest revision appears at the top of this document. If a change materially affects how we process your data, we will notify you through the contact details you have provided.

Any questions about how we handle your data? Write to rgpd@jaymonsecurity.com and we will get back to you.
ENES