Privacy Policy – PatrolTech
Last updated: 13 July 2026 · v1.1
Courtesy translation. In case of discrepancy, the Spanish version of this document prevails.
This Privacy Policy provides information on the processing of personal data carried out by Ingenieros Web SL through the PatrolTech platform and the website https://patroltech.online.
1. Identity of Ingenieros Web SL
Ingenieros Web SL, owner of the PatrolTech brand, may act as Data Controller or as Data Processor depending on the specific nature of the processing.
Company name: Ingenieros Web SL
NIF: ESB86699436
Address: Calle General Arrando 9, Madrid, España
Privacy email: rgpd@ingenierosweb.co
General email: info@patroltech.online
2. Data protection roles
2.1. Data processed on behalf of Clients
When a company or organization uses PatrolTech to manage patrols, users, incidents, evidence, location or other operational data of its activity, that company or organization acts, as a general rule, as Data Controller. Ingenieros Web SL acts as Data Processor and processes the data exclusively in accordance with the Client's documented instructions and the Data Processing Agreement.
2.2. Data processed directly by Ingenieros Web SL
Ingenieros Web SL acts as Data Controller with respect to the data necessary to manage information requests, commercial relationships, contracting, billing, compliance with legal obligations, the security of its systems, the handling of enquiries and the use of the public website.
2.3. Users designated by the Client
The users designated by the Client, including administrators, supervisors, patrollers or operational staff, should normally address their employer, company or organization to exercise their rights with respect to the processing carried out on behalf of the Client. PatrolTech shall cooperate with the Client in accordance with the Data Processing Agreement.
3. Categories of data processed
- Identification and contact data: first name, surname, email, telephone, company, position and other contact data.
- Account and access data: username, identifiers, protected credentials, roles, permissions and authentication records.
- Operational data: patrols, checkpoints, verifications, incidents, reports, forms, evidence, observations and timestamps.
- Location data: GPS coordinates associated with scanning, verification or activity events when that functionality is enabled by the Client.
- Technical and security data: IP address, device, browser, operating system, logs, traces, audit events and fraud-prevention measures.
- Billing and contracting data: tax data, payment data, order history, subscribed plan and contractual communications.
- Data voluntarily included in information requests, contact forms, commercial communications or technical support.
4. Purposes and legal basis
4.1. Processing as Controller
- Management of requests, demonstrations, commercial contacts and enquiries: consent, application of pre-contractual measures or legitimate interest, as applicable.
- Management of contracting, the Client account, billing, collections and support: performance of the contract.
- Compliance with legal, tax, accounting and administrative obligations: compliance with a legal obligation.
- Security, fraud prevention, continuity, auditing and defence of claims: legitimate interest and, where applicable, compliance with legal obligations.
- B2B commercial communications about similar services: legitimate interest, provided that a prior relationship exists and a simple and free objection mechanism is provided; in other cases, consent.
- Non-necessary cookies and analytics or marketing technologies: consent, in accordance with the Cookie Policy.
4.2. Processing as Processor
Where PatrolTech processes data on behalf of the Client, the purposes and legal bases shall be determined by the Client as Data Controller. PatrolTech shall process the data solely to provide the Service, offer support, ensure security, follow documented instructions and comply with applicable legal obligations.
4.3. Geolocation
The geolocation of staff, collaborators or other users within the platform is processed on behalf of the Client. It is the Client's responsibility to determine and document the applicable legal basis, inform the affected persons and ensure the proportionality of the processing. PatrolTech does not itself determine the essential purposes of that processing.
5. Use of Artificial Intelligence
PatrolTech may incorporate artificial intelligence functions to support the classification, summarization, prioritization or drafting of operational content.
- The AI functionalities are of an assistive nature and require human review by the Client.
- AI outputs shall not be used as the sole basis for decisions with legal, labour or equivalent effects on persons.
- The Client's personal data, content, prompts and outputs shall not be used to train its own or third-party general models except with specific, documented authorization and an applicable legal basis.
- The AI providers acting on behalf of PatrolTech must be subject to adequate confidentiality, security and data protection obligations.
- Where an AI functionality entails a substantial change in categories of data, providers, international transfers or purpose, PatrolTech shall inform the Client in accordance with the Data Processing Agreement and the Terms.
6. Data retention
6.1. Data processed as Controller
Contractual, billing, contact and support data shall be retained during the contractual relationship and, subsequently, for the periods required by the applicable regulations or for as long as legal liabilities may arise.
6.2. Data processed on behalf of the Client
Data processed on behalf of the Client shall be retained during the term of the contractual relationship and shall be returned or deleted in accordance with the Client's instructions and the Data Processing Agreement. Following cancellation, an ordinary period of thirty (30) days shall be provided for export, save for a duly justified legal, technical or security impossibility.
6.3. Backups
Deleted data may remain temporarily in rotating backups during the technical period necessary for their overwriting. During that period they shall remain blocked and shall not be processed for purposes other than security, recovery and continuity.
6.4. Logs and technical records
Security and audit logs shall be retained for the period necessary to ensure security, investigate incidents and handle possible liabilities, in accordance with the Service configuration and the legally applicable periods.
7. Rights of data subjects
Persons may exercise, where applicable, the rights of access, rectification, deletion, objection, restriction of processing, portability and withdrawal of consent.
7.1. Data processed on behalf of the Client
Where data is processed on behalf of a Client, the request should preferably be addressed to the Client acting as Data Controller. PatrolTech shall cooperate with the Client in accordance with the Data Processing Agreement.
7.2. Data processed by Ingenieros Web SL as Controller
To exercise rights with respect to contact, contracting, billing, commercial communications, web form data or other processing of Ingenieros Web SL itself, you may contact rgpd@ingenierosweb.co.
7.3. Complaint before a supervisory authority
Where the data subject considers that their rights have not been adequately addressed, they may lodge a complaint with the competent supervisory authority.
8. Sub-processors
PatrolTech may use providers that process personal data on behalf of the Client in order to provide the Service. Such providers shall be subject to adequate confidentiality, security and data protection obligations.
- OVHcloud or an equivalent infrastructure provider in the European Union: hosting and infrastructure.
- Amazon Web Services, where used for infrastructure components in the European Union: infrastructure, storage or messaging services.
- Amazon SES or another equivalent provider: transactional email.
- Artificial intelligence providers, where AI functionalities are enabled for the Client: processing limited to the contracted functions and in accordance with the applicable safeguards.
- Support, monitoring, security or analytics providers strictly necessary for the platform, where their involvement is necessary.
8.1. Authorization and changes
The complete and up-to-date list of sub-processors applicable to the Service must be available to the Client. PatrolTech shall communicate substantial changes in the addition or replacement of sub-processors with reasonable notice, save for a security urgency or a legal obligation, and shall grant the Client the objection mechanism provided for in the Data Processing Agreement.
8.2. Public website providers
Providers used exclusively for the public website, marketing, cookies, analytics or commercial management shall be governed by this Policy and by the Cookie Policy. They should not automatically be considered sub-processors of the operational data processed within the SaaS platform.
9. International transfers
PatrolTech shall endeavour to host and process the operational data of the platform within the European Economic Area. If a provider involves an international data transfer, PatrolTech shall apply the required transfer mechanism and the supplementary safeguards that prove necessary in accordance with the applicable regulations.
Analytics, advertising, user experience or delivery services of the public website that may involve accesses from outside the European Economic Area shall be activated, where applicable, only after the user's cookie consent and in accordance with the Cookie Policy.
Before enabling AI providers that involve international transfers with respect to the Client's data, PatrolTech shall identify the provider, the location of the processing and the applicable safeguards in the corresponding contractual or privacy documentation.
10. Security
PatrolTech applies appropriate technical and organizational measures to protect the data, taking into account the nature, scope, context, purposes and risks of the processing.
- Access controls and permission management.
- Credential protection and authentication.
- Encryption in transit and, where applicable, at rest.
- Activity logging, auditing and traceability.
- Backups and recovery mechanisms.
- Vulnerability and incident management procedures.
- Confidentiality measures applicable to authorized personnel and to the providers involved.
Certifications, conformities or security standards shall only be claimed with respect to their effective scope, validity and supporting documentation.
11. Automated decisions
PatrolTech does not, by itself, adopt automated decisions with legal or significantly equivalent effects on persons through the ordinary functionalities of the Service. The AI, classification or prioritization tools are of an auxiliary nature and must be subject to human review by the Client.
12. Minors
The Service is neither designed for nor directed at minors. The Client shall not use the Service to process data of minors unless it has a valid legal basis and has adopted the specific measures that apply.
13. Modifications to the Policy
This Policy may be updated to reflect regulatory, technical, organizational or functional changes. Where the changes substantially affect the processing carried out as Controller or the conditions of processing on behalf of the Client, PatrolTech shall communicate this through the appropriate channels.
14. Contact
For privacy and data protection matters: rgpd@ingenierosweb.co.