Privacy Policy
Last updated: 25 September 2026
1. Data Controller
TriStiX S.L. NIF: B-26925016 Av. Maisonnave 41, 3º, 03003 Alicante, España Registro Mercantil de Alicante Email: privacy@netsenx.com Website: https://netsenx.com
2. Data Protection Contact
You may contact us about data protection at any time:
- Email: dpo@netsenx.com
- Postal: TriStiX S.L., Attn: Data Protection, Av. Maisonnave 41, 3º, 03003 Alicante, España
3. Legal Basis for Processing
We process personal data under the following legal bases pursuant to GDPR Art. 6(1):
| Legal Basis | Purpose |
|---|---|
| Art. 6(1)(b) — Contract | Providing the NetSenX SaaS platform, account management, billing, and support |
| Art. 6(1)(f) — Legitimate Interest | Security monitoring, fraud prevention, service improvement, and analytics |
| Art. 6(1)(a) — Consent | Marketing communications, non-essential cookies, newsletter |
| Art. 6(1)(c) — Legal Obligation | Tax records, regulatory compliance, law enforcement requests |
4. Categories of Personal Data
4.1 Account Data
- Name, email address, company name, job title
- Billing information (processed by Stripe; we do not store full payment card numbers)
- Authentication credentials (hashed)
4.2 Usage Data
- IP addresses (anonymized after 30 days)
- Browser type, device information, operating system
- Pages visited, features used, session duration
- Referral source
4.3 Network Telemetry Data (Customer-Controlled)
- Network flow metadata processed by the NetSenX platform
- Destination names read on the monitored host from the TLS handshake (server name) and from DNS answers; sent to NetSenX and stored only for a random sample of about 1 in 1,000 flow records, together with the name of the program that made the connection
- Industrial control commands, decoded on the monitored host into a read/write verdict and a function code; the command bytes are never transmitted
- If the optional crypto inventory sensor is enabled: server names and the certificate subject, issuer, expiry date and public key from TLS/SSH handshakes
- If the optional signature inspection engine is switched on by an explicit setting on the host: up to 500 characters of the packet that matched a signature, transmitted with the alert and not stored
- Threat detection alerts and incident reports
- This data is processed on behalf of the customer as a Data Processor (see our Data Processing Agreement)
4.4 Support Data
- Support ticket content, chat transcripts
- Feedback and survey responses
5. Data Retention Periods
| Data Category | Retention Period | Justification |
|---|---|---|
| Account data | Duration of contract + 5 years | Spanish commercial law (Codigo de Comercio Art. 30) |
| Billing records | 5 years after transaction | Spanish tax law (Ley General Tributaria) |
| Usage analytics | 26 months | Legitimate interest; anonymized after 30 days |
| Network telemetry | Customer-defined (default 90 days) | Data Processing Agreement terms |
| Support tickets | 3 years after resolution | Service improvement |
| Marketing consent records | Duration of consent + 3 years | Accountability obligation |
6. Data Recipients and Transfers
We share personal data only with the following categories of recipients:
| Recipient | Purpose | Where the data is processed | Safeguards |
|---|---|---|---|
| Supabase, Inc. | Database and authentication | EU — Ireland (AWS eu-west-1) | DPA, EU SCCs |
| Fly.io, Inc. | Backend API | EU — Frankfurt (Germany) and Paris (France) | DPA, EU SCCs |
| Vercel Inc. | Dashboard hosting | EU | DPA, EU SCCs |
| Upstash, Inc. | Cache and rate limiting | EU | DPA, EU SCCs |
| Resend, Inc. | Transactional email | EU | DPA, EU SCCs |
| Functional Software, Inc. (Sentry) | Error tracking | EU — Germany (de.sentry.io) | DPA, EU SCCs |
| Cloudflare, Inc. | Website delivery, DNS, DDoS protection | Global edge network | DPA, EU SCCs |
| Stripe, Inc. | Payment processing | USA | EU SCCs, PCI DSS |
| PostHog, Inc. | Website analytics, only after consent | EU (Frankfurt) | DPA |
| Hetzner Online GmbH | Infrastructure hosting | Germany | DPA |
Customer data is stored in the EU. Several of these providers are companies established outside the EU, and Cloudflare serves the website from its global network, so personal data can be accessed from, or pass through, countries outside the EU. Such transfers rely on the European Commission's Standard Contractual Clauses (GDPR Art. 46(2)(c)) or, for providers that take part in it, the EU-US Data Privacy Framework adequacy decision (GDPR Art. 45).
7. Data Breach Notification
In the event of a personal data breach:
- Customer DPO notification: Within 24 hours of confirmed breach
- Supervisory authority notification: Within 72 hours per GDPR Art. 33
- Data subject notification: Without undue delay where required per GDPR Art. 34
Our incident response procedure includes:
- Immediate containment and assessment
- Classification of severity and affected data categories
- Notification to affected parties with details of the breach, likely consequences, and mitigation measures
- Post-incident review and remediation report
8. Your Rights (GDPR Articles 15-22)
You have the following rights regarding your personal data:
- Right of Access (Art. 15) — Obtain a copy of your personal data
- Right to Rectification (Art. 16) — Correct inaccurate data
- Right to Erasure (Art. 17) — Request deletion ("right to be forgotten")
- Right to Restriction (Art. 18) — Limit processing in certain circumstances
- Right to Data Portability (Art. 20) — Receive your data in a structured, machine-readable format
- Right to Object (Art. 21) — Object to processing based on legitimate interest
- Right not to be subject to Automated Decision-Making (Art. 22)
To exercise any of these rights, contact: dpo@netsenx.com
We will respond within 30 days (extendable to 90 days for complex requests per Art. 12(3)).
9. Complaints
EU Supervisory Authority
You have the right to lodge a complaint with your local data protection authority.
Spanish Authority (AEPD)
As TriStiX S.L. is registered in Spain, our lead supervisory authority is:
Agencia Espanola de Proteccion de Datos (AEPD) C/ Jorge Juan 6, 28001 Madrid, Spain Website: https://www.aepd.es Phone: +34 901 100 099
You may file a complaint directly with the AEPD via their electronic office: https://sedeagpd.gob.es
10. Cookies, Website Analytics and Embedded Videos
For detailed information about cookies and similar storage, please see our Cookie Policy. In short:
- Analytics only after consent. The website loads PostHog analytics (EU region) only after you allow the analytics category in the cookie banner. Until then the analytics code is not even downloaded. You can withdraw your consent at any time through the "Cookies" button, and measurement stops immediately.
- Videos load nothing before you click. Blog posts show YouTube videos behind a click-to-play button. Until you press play, the page loads nothing from YouTube: no player, no thumbnail and no cookie. When you press play, the video loads from youtube-nocookie.com, and Google receives your IP address and the usual browser data from that moment on. Passing your data to Google at that point rests on our legitimate interest in showing you the video you asked to watch (GDPR Art. 6(1)(f)); Google's own privacy policy governs what it does with the data.
11. Children's Privacy
NetSenX is a business-to-business platform. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, please contact dpo@netsenx.com immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to account holders and posted on this page with an updated revision date.
TriStiX S.L. — NIF B-26925016 Registered in the Registro Mercantil de Alicante, Spain