// LEGAL_FRAMEWORK

LEGAL PROTOCOLS

Last updated: July 2026

PRIVACY_POLICY

1. DATA CONTROLLER IDENTIFICATION

The data controller for this website is brimlance, located at Carrer del Mar 18, València, Ciutat Vella, España. For any privacy-related inquiries, contact us at [email protected].

2. DATA COLLECTION SCOPE

brimlance collects personal data solely for the purpose of providing cybersecurity services. The following data categories may be processed:

  • Identity data: Name, professional designation
  • Contact data: Email address, telephone number
  • Technical data: IP address, browser type, operating system
  • Service data: Security requirements, application architecture details

3. LEGAL BASIS FOR PROCESSING

Personal data processing under GDPR Article 6(1) is based on:

  • (a) Consent: When you submit contact forms or subscribe to communications
  • (b) Contract performance: When processing is necessary for service delivery
  • (c) Legitimate interest: For security monitoring and fraud prevention

4. DATA RETENTION POLICY

Personal data is retained only for the duration necessary to fulfill the purposes for which it was collected. Service-related data is retained for 24 months after contract completion. Contact form submissions are deleted after 12 months if no business relationship is established.

5. INTERNATIONAL DATA TRANSFERS

brimlance operates within the European Economic Area (EEA). Any data transfers outside the EEA are conducted under Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring adequate protection under GDPR Chapter V.

6. YOUR RIGHTS UNDER GDPR

As a data subject, you have the following rights:

  • Right of access (Article 15): Request copies of your personal data
  • Right to rectification (Article 16): Request correction of inaccurate data
  • Right to erasure (Article 17): Request deletion of your personal data
  • Right to restriction (Article 18): Request limitation of processing
  • Right to data portability (Article 20): Receive your data in structured format
  • Right to object (Article 21): Object to processing based on legitimate interest

7. DATA SECURITY MEASURES

brimlance implements appropriate technical and organizational measures including encryption, access controls, regular security assessments, and incident response protocols to protect personal data against unauthorized access, alteration, or destruction.

8. DATA PROTECTION SUPERVISORY AUTHORITY

If you believe your data protection rights have been infringed, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) at https://www.aepd.es.

COOKIES_POLICY

1. COOKIES DEFINITION

Cookies are small text files placed on your device when you visit brimlance websites. They help us recognize your browser and remember certain information.

2. ESSENTIAL COOKIES

brimlance deploys strictly necessary cookies for website functionality:

  • session_id: Maintains user session state (expires on browser close)
  • cookie_consent: Stores your cookie preference (expires: 365 days)
  • csrf_token: Prevents cross-site request forgery attacks (expires: 24 hours)

3. NO TRACKING OR ANALYTICS

brimlance does not use Google Analytics, Facebook Pixel, or any third-party tracking cookies. We do not engage in behavioral advertising or cross-site tracking. The cookie consent banner reflects this commitment.

4. MANAGING COOKIES

You can control and manage cookies through your browser settings. Disabling essential cookies may impair website functionality. To manage cookies in your browser:

  • Chrome: Settings > Privacy and Security > Cookies
  • Firefox: Options > Privacy & Security > Cookies
  • Safari: Preferences > Privacy > Cookies
  • Edge: Settings > Privacy, Search, and Services > Cookies

5. COOKIE CONSENT MECHANISM

Upon your first visit, a cookie consent banner appears. By clicking "CONNECT_TO_HOST," you acknowledge the use of essential cookies. This preference is stored locally on your device and does not transmit data to external servers.

REFUND_POLICY

1. SERVICE DELIVERY TERMS

brimlance provides cybersecurity services including vulnerability audits, penetration testing, security patching, and compliance assessments. Service delivery timelines are specified in individual project agreements.

2. REFUND ELIGIBILITY

Refund requests are evaluated under the following conditions:

  • Service not commenced: Full refund within 14 days of payment
  • Service partially completed: Pro-rata refund based on completed milestones
  • Service defective: Full refund if deliverables fail to meet agreed specifications
  • Client cancellation: Refund minus administrative fees (15%) if cancelled before work begins

3. NON-REFUNDABLE ITEMS

The following are non-refundable:

  • Emergency response services already initiated (EMERGENCY_PATCH)
  • Consultation hours already delivered
  • Third-party software licenses procured on behalf of client
  • Compliance audit reports already generated

4. REFUND PROCESS

To request a refund, contact [email protected] with your project reference number. Refund requests are processed within 5-10 business days. Refunds are issued to the original payment method.

5. DISPUTE RESOLUTION

Any disputes arising from refund decisions shall first be addressed through direct communication. If unresolved, disputes may be submitted to mediation in València, España, in accordance with Spanish consumer protection laws.

TERMS_OF_SERVICE

1. SERVICE AGREEMENT

By engaging brimlance for cybersecurity services, you agree to these Terms of Service. brimlance, headquartered at Carrer del Mar 18, València, Ciutat Vella, España, provides web application security services under the terms outlined herein.

2. SCOPE OF SERVICES

brimlance provides the following service categories:

  • Vulnerability Assessment and Penetration Testing
  • Web Application Firewall Configuration
  • Emergency Incident Response and Patching
  • SSL/TLS Certificate Deployment and Hardening
  • Third-Party Dependency Security Scanning
  • Authentication System Fortification
  • Regulatory Compliance Auditing
  • Security Monitoring Infrastructure Setup

3. CLIENT OBLIGATIONS

Clients must:

  • Provide accurate and complete information about target systems
  • Obtain necessary authorization for testing activities
  • Maintain secure communication channels for sensitive data exchange
  • Review and approve deliverables within agreed timeframes

4. INTELLECTUAL PROPERTY

All reports, documentation, and security assessments produced by brimlance remain the intellectual property of brimlance. Clients receive a perpetual, non-exclusive license to use deliverables for their internal security purposes. Custom security tools and methodologies remain proprietary.

5. CONFIDENTIALITY

brimlance maintains strict confidentiality regarding all client information, vulnerability data, and security findings. All team members are bound by non-disclosure agreements. Data handling follows ISO 27001 information security management standards.

6. LIMITATION OF LIABILITY

brimlance liability is limited to the total value of the specific service engagement. brimlance shall not be liable for indirect, consequential, or incidental damages. Security testing carries inherent risks; clients acknowledge that no security measure provides absolute protection.

7. GOVERNING LAW

These Terms are governed by Spanish law. Any disputes shall be resolved in the courts of València, España. For consumer protection matters, applicable EU directives and Spanish transposing legislation apply.

8. CONTACT INFORMATION

For questions regarding these Terms of Service, contact brimlance at:

  • Email: [email protected]
  • Phone: +34 623 14 09 56
  • Address: Carrer del Mar 18, València, Ciutat Vella, España