SECTOR 05 // Legal Protocols
Regulatory Framework
Last updated: July 2026
Privacy Policy
Data Controller. brightstackdev, located at Avinguda de les Corts Valencianes 20, València, Benicalap, España, España (hereinafter "the Controller"), is the data controller responsible for the processing of personal data collected through this website and associated services.
Legal Basis for Processing. The Controller processes personal data under the following legal bases as defined in Article 6 of the EU General Data Protection Regulation (GDPR): (a) the data subject has given consent to the processing of their personal data for one or more specific purposes; (b) processing is necessary for the performance of a contract to which the data subject is party; (c) processing is necessary for compliance with a legal obligation to which the Controller is subject.
Categories of Data Collected. The Controller may collect and process the following categories of personal data: identification data (full name, email address, telephone number), technical data (IP address, browser type and version, operating system, device identifiers), usage data (pages visited, time spent on pages, navigation patterns), and communication data (messages sent through contact forms, email correspondence).
Purpose of Processing. Personal data is collected and processed for the following purposes: (a) to respond to inquiries and provide requested services; (b) to perform contractual obligations related to web development and microservices engineering services; (c) to comply with applicable legal and regulatory obligations; (d) to improve website functionality and user experience through anonymized analytics; (e) to maintain communication regarding active projects and service updates.
Data Retention. Personal data shall be retained for the duration necessary to fulfill the purposes for which it was collected. Contract-related data shall be retained for a period of six (6) years following the conclusion of the contract, in accordance with Spanish commercial and tax legislation. Contact form data shall be retained for a maximum of twelve (12) months from the date of submission unless a contractual relationship is established.
International Data Transfers. The Controller does not transfer personal data to countries outside the European Economic Area (EEA) without implementing appropriate safeguards as required by Chapter V of the GDPR, including Standard Contractual Clauses (SCCs) or adequacy decisions.
Data Subject Rights. In accordance with Articles 15 through 22 of the GDPR, data subjects have the following rights: the right of access (Article 15), the right to rectification (Article 16), the right to erasure (Article 17), the right to restriction of processing (Article 18), the right to data portability (Article 20), the right to object (Article 21), and the right not to be subject to automated decision-making (Article 22). To exercise these rights, contact the Controller at [email protected].
Security Measures. The Controller implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption of personal data, regular testing and evaluation of security measures, and the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems.
Supervisory Authority. Data subjects have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) at C/ Jorge Juan, 6, 28001 Madrid, España, if they believe their data protection rights have been infringed.
Refund Policy
General Policy. brightstackdev, headquartered at Avinguda de les Corts Valencianes 20, València, Benicalap, España, España, is committed to delivering professional web development and microservices engineering services that meet agreed-upon specifications. Refunds are evaluated according to the terms set forth in this policy.
Pre-Project Cancellation. If a project is cancelled before any work has commenced, the client is entitled to a full refund of any advance payment within fourteen (14) business days of the cancellation request. Cancellation must be communicated in writing to [email protected].
Mid-Project Cancellation. Projects cancelled after work has begun are subject to payment for all completed milestones up to the date of cancellation. Any advance payment exceeding the value of completed work shall be refunded proportionally within thirty (30) business days. Milestone deliverables completed prior to cancellation remain the property of brightstackdev until full payment is received for those milestones.
Completed Project Disputes. If the delivered work materially deviates from the agreed-upon technical specification, the client must notify brightstackdev in writing within fourteen (14) calendar days of delivery. brightstackdev will assess the claim and, if valid, will either (a) rectify the deviations at no additional cost within a reasonable timeframe, or (b) issue a partial refund proportional to the scope of the deviation. brightstackdev reserves the right to request independent technical assessment in case of dispute.
Non-Refundable Items. The following are not eligible for refund: (a) consultation and audit fees for work already performed; (b) third-party license fees, hosting charges, or domain registration costs incurred on behalf of the client; (c) work completed under change orders approved in writing by the client; (d) hosting and maintenance fees for periods during which the service was active and operational.
Refund Process. Refund requests must be submitted in writing to [email protected] with the subject line "REFUND REQUEST — [Project Name]". The Controller will acknowledge receipt within five (5) business days and process approved refunds via the original payment method or bank transfer within thirty (30) business days.
Terms of Service
Acceptance of Terms. By accessing and using the services provided by brightstackdev, located at Avinguda de les Corts Valencianes 20, València, Benicalap, España, España (hereinafter "the Provider"), the client (hereinafter "the Client") agrees to be bound by these Terms of Service. These terms constitute a legally binding agreement between the parties.
Scope of Services. The Provider offers web development, microservices architecture, cloud infrastructure, and related technical services as described on this website and in individual project proposals. The specific scope, deliverables, timeline, and pricing for each project shall be defined in a separate written agreement or statement of work (SOW) mutually accepted by both parties.
Client Obligations. The Client shall: (a) provide timely access to necessary systems, accounts, and information required for project execution; (b) designate a primary point of contact with decision-making authority; (c) review and approve deliverables within the timeframes specified in the SOW; (d) ensure that all content provided to the Provider does not infringe upon third-party intellectual property rights.
Intellectual Property. Upon full payment of all applicable fees, the Client shall receive full ownership of all custom code, designs, and documentation specifically created for the Client's project. The Provider retains ownership of general tools, libraries, frameworks, and methodologies developed independently or used across multiple projects. Pre-existing technologies and open-source components remain subject to their original license terms.
Confidentiality. Both parties agree to maintain the confidentiality of proprietary information exchanged during the course of the engagement. This obligation survives the termination of the agreement for a period of three (3) years. Confidential information shall not be disclosed to third parties without prior written consent, except as required by law.
Payment Terms. Invoices are payable within fourteen (14) calendar days of issuance unless otherwise specified in the SOW. Late payments accrue interest at a rate of 0.05% per day on the outstanding balance. The Provider reserves the right to suspend work if payment is overdue by more than twenty-one (21) days. All prices are exclusive of applicable taxes (VAT/IVA), which shall be borne by the Client.
Limitation of Liability. To the maximum extent permitted by applicable law, the Provider's total aggregate liability under any agreement shall not exceed the total fees paid by the Client for the specific project giving rise to the claim. The Provider shall not be liable for indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, data, or business opportunities.
Force Majeure. Neither party shall be liable for delays or failures in performance resulting from causes beyond its reasonable control, including but not limited to acts of God, natural disasters, pandemics, government actions, power outages, or internet infrastructure failures.
Governing Law & Jurisdiction. These Terms shall be governed by and construed in accordance with the laws of España. Any disputes arising from or relating to these Terms or the services provided shall be subject to the exclusive jurisdiction of the courts of València, España.
Modifications. The Provider reserves the right to modify these Terms at any time. Material changes shall be communicated to the Client via email at least thirty (30) days before taking effect. Continued use of the services after such modifications constitutes acceptance of the updated Terms.