BLUEPRINT_006 // LEGAL_FRAMEWORK

LEGAL
DOCUMENTATION

SEC_001

PRIVACY_POLICY

Last Updated: July 2026

NexSystemdev, registered at Gran Via de les Corts Catalanes, 584, Piso 3º 1ª — 08011, Barcelona, Barcelona, España (hereinafter "the Company"), is committed to protecting the privacy and personal data of all visitors, clients, and users of our digital platforms and services.

RESPONSIBLE_ENTITY: NexSystemdev // DPO_CONTACT: [email protected]

1. Data Controller Information

The data controller responsible for the processing of personal data collected through this website and related services is NexSystemdev, located at Gran Via de les Corts Catalanes, 584, Piso 3º 1ª — 08011, Barcelona, Barcelona, España. All data processing activities are conducted in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR) and the Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).

2. Data We Collect

We may collect and process the following categories of personal data:

  • Identity Data: Full name, username, or similar identifiers provided through contact forms or account registration.
  • Contact Data: Email address, telephone number, and postal address submitted via inquiry forms or direct communication.
  • Technical Data: Internet Protocol (IP) address, browser type and version, time zone setting, operating system, and platform through automatic collection via server logs and analytics tools.
  • Usage Data: Information about how you use our website, including pages visited, time spent on pages, click patterns, and navigation paths.
  • Project Data: Information provided in the course of engaging our services, including project specifications, business requirements, and communication records.

3. Legal Basis for Processing

We process personal data under the following legal bases as defined in Article 6 of the GDPR:

  • Consent (Art. 6(1)(a)): Where you have given explicit consent for specific processing purposes, such as subscribing to newsletters or accepting non-essential cookies.
  • Contractual Necessity (Art. 6(1)(b)): Where processing is necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract.
  • Legitimate Interest (Art. 6(1)(f)): Where processing is necessary for the purposes of our legitimate interests, such as improving our services, ensuring network security, and preventing fraud, provided these interests are not overridden by your fundamental rights.
  • Legal Obligation (Art. 6(1)(c)): Where processing is necessary for compliance with a legal obligation to which we are subject.

4. Data Retention

Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected. Project-related data is retained for a minimum of 5 years following the conclusion of the contractual relationship to comply with tax and accounting obligations under Spanish law. Contact form submissions are retained for a maximum of 24 months from the date of submission unless an ongoing business relationship has been established.

5. Your Rights Under GDPR

Under the GDPR and applicable Spanish data protection legislation, you have the following rights:

  • Right of Access (Art. 15): You may request a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): You may request correction of inaccurate or incomplete personal data.
  • Right to Erasure (Art. 17): You may request deletion of your personal data where there is no compelling reason for its continued processing.
  • Right to Restriction (Art. 18): You may request restriction of processing in certain circumstances.
  • Right to Data Portability (Art. 20): You may request to receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to Object (Art. 21): You may object to processing based on legitimate interests, including profiling.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.

To exercise any of these rights, please contact us at [email protected] or by post to Gran Via de les Corts Catalanes, 584, Piso 3º 1ª — 08011, Barcelona, Barcelona, España. We will respond to all requests within 30 days.

6. International Data Transfers

Some of our service providers may be located outside the European Economic Area (EEA). Where personal data is transferred to countries outside the EEA, we ensure that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, or other valid transfer mechanisms as defined in Chapter V of the GDPR.

7. Data Security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption of data in transit (TLS 1.3), access controls, regular security audits, and employee training on data protection obligations.

8. Supervisory Authority

If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD — Agencia Española de Protección de Datos) at www.aepd.es.

SEC_002

COOKIES_POLICY

Last Updated: July 2026

This Cookies Policy explains how NexSystemdev, registered at Gran Via de les Corts Catalanes, 584, Piso 3º 1ª — 08011, Barcelona, Barcelona, España, uses cookies and similar tracking technologies when you visit our website.

1. What Are Cookies

Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work efficiently, to provide information to site owners, and to improve user experience. Similar technologies include web beacons, pixel tags, and local storage.

2. Cookies We Use

We use the following categories of cookies:

  • Strictly Necessary Cookies: These cookies are essential for the website to function correctly. They enable core functionality such as security, network management, and account access. These cookies do not require consent under Article 5(3) of the ePrivacy Directive as transposed by LSSI-CE (Spanish Law 34/2002).
  • Analytics Cookies: These cookies collect information about how visitors use our website, such as which pages are visited most often and any error messages encountered. All data collected is aggregated and anonymized. We use Google Analytics with IP anonymization enabled.
  • Functional Cookies: These cookies enable enhanced functionality and personalization, such as remembering your preferences and language settings.
  • Third-Party Cookies: Some cookies are placed by third-party services that appear on our pages. We do not control these cookies. Please refer to the respective third-party privacy policies for further information.

3. Managing Cookies

You can manage your cookie preferences at any time through the cookie consent banner displayed on your first visit, or by adjusting your browser settings. Most browsers allow you to refuse or delete cookies. Please note that disabling certain cookies may affect the functionality of this website.

4. Changes to This Policy

We may update this Cookies Policy from time to time to reflect changes in technology, legislation, or our business operations. The updated policy will be posted on this page with an updated revision date.

SEC_003

REFUND_POLICY

Last Updated: July 2026

This Refund Policy applies to all services provided by NexSystemdev, registered at Gran Via de les Corts Catalanes, 584, Piso 3º 1ª — 08011, Barcelona, Barcelona, España. By engaging our services, you agree to the following refund terms.

1. General Refund Terms

Refunds are evaluated on a case-by-case basis according to the project milestones completed at the time of cancellation. The following conditions apply:

  • Pre-Project Cancellation: If a project is cancelled before any work has commenced, a full refund of any advance payment will be issued within 14 business days, minus any non-recoverable third-party costs already incurred.
  • Partial Completion: If a project is cancelled after work has commenced, the client is entitled to a proportional refund based on the percentage of undelivered milestones as defined in the project scope document. Completed milestone deliverables remain the property of the client.
  • Post-Delivery: No refunds will be issued after the final project delivery has been accepted in writing by the client. This does not affect your statutory rights under applicable consumer protection law.
  • Defective Deliverables: If deliverables do not conform to the agreed specifications and NexSystemdev is unable to remedy the defects within 30 calendar days, the client is entitled to a proportional refund or full refund, depending on the severity of the non-conformity.

2. Non-Refundable Items

The following are non-refundable:

  • Third-party software licenses or hosting fees already paid on behalf of the client.
  • Work completed and accepted by the client under signed milestone approvals.
  • Consulting fees for sessions already delivered.
  • Domain name registrations or SSL certificate purchases.

3. Refund Request Process

To request a refund, contact us at [email protected] with your project reference number and a written description of the reason for the refund request. We will acknowledge receipt within 3 business days and provide a resolution within 14 business days.

4. Statutory Rights

This refund policy does not affect your statutory rights as a consumer under Spanish Royal Decree-Law 1/2007 and EU Directive 2011/83/EU on consumer rights.

SEC_004

TERMS_OF_SERVICE

Last Updated: July 2026

These Terms of Service govern the provision of digital infrastructure, web development, and related consulting services by NexSystemdev, registered at Gran Via de les Corts Catalanes, 584, Piso 3º 1ª — 08011, Barcelona, Barcelona, España (hereinafter "the Company"). By engaging our services, you agree to the following terms.

1. Scope of Services

The Company provides custom web development, cloud infrastructure deployment, e-commerce integration, API engineering, UI/UX design, SEO optimization, business process automation, data pipeline configuration, security auditing, and DevOps services. The exact scope, deliverables, and timelines for each engagement are defined in a separate project proposal or Statement of Work (SOW) mutually agreed upon by both parties.

2. Service Execution and Milestones

All projects are executed according to the milestones defined in the project SOW. The Company will provide regular progress updates at agreed intervals. Client feedback is required within 5 business days of each milestone delivery. Failure to provide feedback within this period constitutes acceptance of the delivered milestone.

3. Payment Terms

Unless otherwise specified in the SOW, the following payment schedule applies:

  • Advance Payment: 40% of the total project fee is due upon signing the SOW and before work commences.
  • Milestone Payments: 30% upon delivery of the primary prototype or first major milestone.
  • Final Payment: 30% upon final delivery and client acceptance of all deliverables.
  • All invoices are payable within 14 calendar days of invoice date. Late payments incur an interest charge of 2% per month on the outstanding balance, as permitted under Spanish civil code provisions on commercial obligations.

4. Intellectual Property

Upon receipt of full and final payment, all intellectual property rights for the custom deliverables produced under the project SOW are transferred to the client. The Company retains the right to use anonymized project data, methodologies, and general technical approaches for portfolio and case study purposes, unless explicitly restricted in writing by the client. Third-party libraries, frameworks, and tools used in the project remain subject to their respective open-source or commercial licenses.

5. Confidentiality

Both parties agree to maintain the confidentiality of all proprietary information disclosed during the course of the engagement. This obligation survives the termination of the agreement for a period of 24 months. Confidential information includes, but is not limited to, business strategies, technical architectures, source code, database schemas, and client lists.

6. Limitation of Liability

The Company's total liability under any engagement shall not exceed the total fees paid by the client for the specific project giving rise to the claim. The Company shall not be liable for indirect, incidental, consequential, or punitive damages, including but not limited to loss of profits, data, or business opportunities.

7. Force Majeure

Neither party shall be liable for any failure or delay in performance due to circumstances beyond its reasonable control, including but not limited to acts of God, natural disasters, war, terrorism, pandemics, government actions, internet infrastructure failures, or third-party service disruptions.

8. Governing Law and Jurisdiction

These Terms of Service are governed by and construed in accordance with the laws of Spain. Any disputes arising out of or in connection with these terms shall be subject to the exclusive jurisdiction of the courts of Barcelona, Spain.

9. Amendments

The Company reserves the right to modify these Terms of Service at any time. Material changes will be communicated to active clients via email with a minimum of 30 days notice. Continued use of services after the effective date of changes constitutes acceptance of the modified terms.

10. Severability

If any provision of these Terms of Service is found to be invalid or unenforceable, the remaining provisions shall continue in full force and effect. The invalid provision shall be modified to the minimum extent necessary to make it valid and enforceable.