Privacy Policy

Last updated: 21 May 2026

1. Data Controller

TriStiX S.L. NIF: B-26925016 Av. Maisonnave 41, 3º, 03003 Alicante, España Registro Mercantil de Alicante Email: [email protected] Website: https://netsenx.com

2. Data Protection Officer (DPO)

You may contact our Data Protection Officer at any time:

  • Email: [email protected]
  • Postal: TriStiX S.L., Attn: DPO, Av. Maisonnave 41, 3º, 03003 Alicante, España

3. Legal Basis for Processing

We process personal data under the following legal bases pursuant to GDPR Art. 6(1):

Legal BasisPurpose
Art. 6(1)(b) — ContractProviding the NetSenX SaaS platform, account management, billing, and support
Art. 6(1)(f) — Legitimate InterestSecurity monitoring, fraud prevention, service improvement, and analytics
Art. 6(1)(a) — ConsentMarketing communications, non-essential cookies, newsletter
Art. 6(1)(c) — Legal ObligationTax records, regulatory compliance, law enforcement requests

4. Categories of Personal Data

4.1 Account Data

  • Name, email address, company name, job title
  • Billing information (processed by Stripe; we do not store full payment card numbers)
  • Authentication credentials (hashed)

4.2 Usage Data

  • IP addresses (anonymized after 30 days)
  • Browser type, device information, operating system
  • Pages visited, features used, session duration
  • Referral source

4.3 Network Telemetry Data (Customer-Controlled)

  • Network flow metadata processed by the NetSenX platform
  • Destination names read on the monitored host from the TLS handshake (server name) and from DNS answers; sent to NetSenX and stored only for a random sample of about 1 in 1,000 flow records, together with the name of the program that made the connection
  • Industrial control commands, decoded on the monitored host into a read/write verdict and a function code; the command bytes are never transmitted
  • If the optional crypto inventory sensor is enabled: server names and the certificate subject, issuer, expiry date and public key from TLS/SSH handshakes
  • If the optional signature inspection engine is switched on by an explicit setting on the host: up to 500 characters of the packet that matched a signature, transmitted with the alert and not stored
  • Threat detection alerts and incident reports
  • This data is processed on behalf of the customer as a Data Processor (see our DPA)

4.4 Support Data

  • Support ticket content, chat transcripts
  • Feedback and survey responses

5. Data Retention Periods

Data CategoryRetention PeriodJustification
Account dataDuration of contract + 5 yearsSpanish commercial law (Codigo de Comercio Art. 30)
Billing records5 years after transactionSpanish tax law (Ley General Tributaria)
Usage analytics26 monthsLegitimate interest; anonymized after 30 days
Network telemetryCustomer-defined (default 90 days)Data Processing Agreement terms
Support tickets3 years after resolutionService improvement
Marketing consent recordsDuration of consent + 3 yearsAccountability obligation

6. Data Recipients and Transfers

We share personal data only with the following categories of recipients:

RecipientPurposeLocationSafeguards
Cloudflare, Inc.CDN, DDoS protection, DNSEU (with global edge)EU SCCs, DPA
Stripe, Inc.Payment processingUSAEU SCCs, PCI DSS
Resend, Inc.Transactional emailUSAEU SCCs, DPA
PostHog, Inc.Product analytics (opt-in)EU (Frankfurt)DPA, cookieless mode available
Hetzner Online GmbHInfrastructure hostingGermanyGDPR-compliant, DPA

All international data transfers are governed by Standard Contractual Clauses (SCCs) pursuant to GDPR Art. 46(2)(c) or adequacy decisions per Art. 45.

7. Data Breach Notification

In the event of a personal data breach:

  • Customer DPO notification: Within 24 hours of confirmed breach
  • Supervisory authority notification: Within 72 hours per GDPR Art. 33
  • Data subject notification: Without undue delay where required per GDPR Art. 34

Our incident response procedure includes:

  1. Immediate containment and assessment
  2. Classification of severity and affected data categories
  3. Notification to affected parties with details of the breach, likely consequences, and mitigation measures
  4. Post-incident review and remediation report

8. Your Rights (GDPR Articles 15-22)

You have the following rights regarding your personal data:

  • Right of Access (Art. 15) — Obtain a copy of your personal data
  • Right to Rectification (Art. 16) — Correct inaccurate data
  • Right to Erasure (Art. 17) — Request deletion ("right to be forgotten")
  • Right to Restriction (Art. 18) — Limit processing in certain circumstances
  • Right to Data Portability (Art. 20) — Receive your data in a structured, machine-readable format
  • Right to Object (Art. 21) — Object to processing based on legitimate interest
  • Right not to be subject to Automated Decision-Making (Art. 22)

To exercise any of these rights, contact: [email protected]

We will respond within 30 days (extendable to 90 days for complex requests per Art. 12(3)).

9. Complaints

EU Supervisory Authority

You have the right to lodge a complaint with your local data protection authority.

Spanish Authority (AEPD)

As TriStiX S.L. is registered in Spain, our lead supervisory authority is:

Agencia Espanola de Proteccion de Datos (AEPD) C/ Jorge Juan 6, 28001 Madrid, Spain Website: https://www.aepd.es Phone: +34 901 100 099

You may file a complaint directly with the AEPD via their electronic office: https://sedeagpd.gob.es

10. Cookies

For detailed information about our use of cookies, please see our Cookie Policy.

11. Children's Privacy

NetSenX is a B2B enterprise platform. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, please contact [email protected] immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to account holders and posted on this page with an updated revision date.


TriStiX S.L. — NIF B-26925016 Registered in the Registro Mercantil de Alicante, Spain