GDPR
Dynapps España processes your environment's data in accordance with the
General Data Protection Regulation (GDPR) and Spanish data protection
law.
Roles
In most cases, the relationship is as follows:
- You are the data controller: you decide what personal data is
processed in your application and for what purpose.
- Dynapps España is the data processor: we process that data only
to provide you the service and following your instructions.
This relationship is formalized through a Data Processing Agreement
(DPA); see Data Processing Agreement.
Principles we apply
- Purpose limitation: we process data only to operate the service.
- Access minimization: our staff access personal data only when
strictly necessary for support or operation, under the principle of least
privilege and with logging.
- Security of processing: encryption, access control, and the other
measures described in the Security
section.
- Confidentiality: staff with access are bound by a duty of
confidentiality.
Data subject rights
As controller, you are the one who handles requests for rights (access,
rectification, erasure, portability, etc.) from the people whose data you
process. We, as processor, assist you by providing the necessary
technical capabilities — for example, exporting or deleting data from your
environment. See Retention and deletion.
Sub-processors
To provide the service we rely on a limited number of sub-processors,
all within Spain. See the list and their role in
Sub-processors.
Contractual documentation
The DPA, the list of sub-processors, and the specific clauses are part
of your contract. We provide them on request.