Privacy policy
How personal data obtained through the Blindium site, its forms, the initial assessment, the client area and the associated technical security controls is processed, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018.
Data controller
The e-mail address indicated is a privacy channel for exercising rights. It is not presented as a data protection officer unless BOMONTE TECNOLOGIAS, S.L. formally appoints and publishes one.
| Item | Information |
|---|---|
| Controller | BOMONTE TECNOLOGIAS, S.L. |
| Tax ID (NIF) | B83820696 |
| Registered address | C.C. El Palacio, local 26, Ctra. de Majadahonda 50, 28660 Boadilla del Monte (Madrid), España |
| Privacy channel | gdpr@bomontec.net |
| Website | https://blindium.com |
Data we may process
- Identification and contact data: name, surname, e-mail address and organisation.
- Professional and project data: position, entity, sector, interest, approximate number of devices, current architecture and requirements communicated voluntarily.
- Content of enquiries: message, documentation or information the user chooses to send.
- Client area data: account identifier, roles, permissions, authentication events, access and actions needed to provide and protect the service.
- Technical and security data: IP address, date and time, URL, HTTP method, user agent, technical identifiers, web application firewall and anti-abuse events, errors and security logs.
- Communication preferences, where the data subject asks to receive commercial information.
Purposes and legal bases
| Purpose | Description | Legal basis |
|---|---|---|
| Handling enquiries and requests | Managing the enquiry, replying, preparing meetings and coordinating contact. | Art. 6.1.b GDPR (requested pre-contractual measures); art. 6.1.f GDPR to manage legitimate professional relationships where applicable. |
| Initial assessment | Preparing and delivering the requested technical session and drawing up preliminary conclusions. | Art. 6.1.b GDPR, pre-contractual measures at the request of the data subject or the entity they represent. |
| Proposals and B2B relationship | Preparing offers, coordinating pre-sales, support and the professional relationship. | Art. 6.1.b GDPR and, for professional contacts linked to a legal entity, legitimate interest within legal limits. |
| Client area | Creating and managing accounts, authenticating users, applying roles, providing functionality and keeping traceability. | Art. 6.1.b GDPR and art. 6.1.f GDPR for security and access control. |
| Site security | Detecting abuse, fraud, malware and intrusion attempts, investigating incidents, generating evidence and protecting the infrastructure. | Art. 6.1.f GDPR: legitimate interest in ensuring confidentiality, integrity, availability and defence against attacks. |
| Legal compliance and defence of claims | Meeting obligations and valid requests and keeping the necessary evidence. | Art. 6.1.c GDPR and art. 6.1.f GDPR. |
| Optional commercial communications | Sending news, invitations or information about Blindium and related services. | Consent (art. 6.1.a GDPR) where required, and the Spanish LSSI rules on commercial communications. |
Mandatory nature of the data
Fields marked as mandatory are needed to process the relevant request. Failure to provide the minimum data may prevent us from handling it. Subscribing to commercial communications is voluntary and does not condition the handling of an enquiry or assessment.
Retention
Data is kept for as long as necessary for the relevant purpose and thereafter for the applicable limitation or legal retention periods, duly blocked where appropriate. Enquiries that do not lead to a professional relationship are reviewed and deleted when no longer needed. Technical and security logs are kept for a period proportionate to their purpose and may be kept longer when linked to an incident, investigation, legal obligation or defence of claims. In the contact form the IP address is stored only as a cryptographic digest (hash) for abuse control.
Recipients and processors
Data is not sold. It may be accessed by providers that render services to BOMONTE TECNOLOGIAS, S.L. as data processors (hosting, infrastructure, e-mail, support, security or corporate tools), under the contractual obligations set out in the GDPR.
Data may also be disclosed to authorities, courts, law enforcement or other bodies where there is a legal obligation, a valid request or a need to bring, exercise or defend claims.
Where a request requires the involvement of Samsung SDS, Samsung or another manufacturer or integrator, only the necessary data will be disclosed, on an appropriate legal basis and under the applicable contractual framework. If this involved an international transfer, the safeguards of Chapter V of the GDPR would be applied beforehand and you would be informed where appropriate.
International transfers
In its current deployment, the site uses no advertising analytics or third-party resources, so no international transfers are expected from its use. This will be reviewed if new providers, cloud services, external sources, videos, maps, third-party captchas, analytics or marketing tools are added.
Automated decisions and profiling
The site takes no decisions with legal or similarly significant effects based solely on automated processing. Automatic security measures (for example, traffic blocking by firewall rules) serve a technical protective purpose and can be reviewed where there is a legitimate issue.
Your rights
You may exercise the rights of access, rectification, erasure, objection, restriction and portability, where applicable, and withdraw consent without affecting prior lawfulness, by writing to gdpr@bomontec.net or to the controller's registered address. The request must reasonably allow identity to be verified; additional documentation will only be requested where necessary and proportionate.
You may also lodge a complaint with the Spanish Data Protection Agency (AEPD) if you consider that the processing infringes applicable law.
Commercial communications
Where sending is based on consent, that consent will be specific, free and unambiguous and may be withdrawn at any time through the mechanism indicated in each communication or by writing to the privacy channel. Withdrawal does not affect the handling of services already requested.
Minors
Blindium is a professional and business guidance service and is not aimed at minors. We do not knowingly collect data from minors through the commercial forms.
Security
BOMONTE TECNOLOGIAS, S.L. applies reasonable technical and organisational measures for access control, logging, perimeter protection, updates, backups and incident management according to risk. Communications with the site are encrypted with TLS and the site applies strict security headers. No Internet-connected system can guarantee absolute security; users must protect their credentials and report unauthorised use.
Do not send classified information
Public forms and ordinary e-mail must not be used for classified information, keys, passwords, third-party secrets, sensitive indicators of compromise, operational configurations or documentation subject to special restrictions. Where a project requires it, an authorised channel and the corresponding processing regime will be agreed beforehand.
External links
Links to manufacturers, certification bodies or other third parties lead to external services with their own policies. A mere link does not mean that those third parties receive data from Blindium before the user accesses their site.
Changes to this policy
The policy may be updated when the site, the processing, the providers or the law change. The date of the current version is shown at the end of the document.
Version 1.0. Last updated: 28 September 2026.


