Legal & Data Governance
Chronological compliance framework governing all data handling, client rights, and operational protocols.
Privacy Policy
At PixelStackLabs, located at 09400, Calle Principal 1, Aranda de Duero, Spain, we are committed to protecting the privacy and security of your personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679.
Data Controller: PixelStackLabs is the data controller responsible for your personal data collected through this website and our service engagements.
Data Collection: We collect personal data including but not limited to: full name, email address, phone number, company information, and project specifications. This data is collected directly through our onboarding forms, email correspondence, and service agreements.
Purpose of Processing: Your data is processed solely for: (a) executing requested web development and MarTech services; (b) project communication and management; (c) billing and financial record-keeping; (d) compliance with legal obligations.
Data Retention: Personal data is retained for the duration of the service engagement plus 24 months post-completion for legal and accounting purposes. Data is then securely deleted from all systems.
Third-Party Sharing: We do not sell or rent personal data. Data may be shared with trusted service providers (hosting, payment processing) solely for service execution under strict data processing agreements.
Security Measures: All data is encrypted in transit (TLS 1.3) and at rest. Access is restricted to authorized personnel only, with regular security audits conducted quarterly.
Privacy Policy
At PixelStackLabs, located at 09400, Calle Principal 1, Aranda de Duero, Spain, we are committed to protecting the privacy and security of your personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679.
Data Controller: PixelStackLabs is the data controller responsible for your personal data collected through this website and our service engagements.
Data Collection: We collect personal data including but not limited to: full name, email address, phone number, company information, and project specifications.
Purpose of Processing: Your data is processed solely for: (a) executing requested web development and MarTech services; (b) project communication and management; (c) billing and financial record-keeping; (d) compliance with legal obligations.
Data Retention: Personal data is retained for the duration of the service engagement plus 24 months post-completion for legal and accounting purposes.
Third-Party Sharing: We do not sell or rent personal data. Data may be shared with trusted service providers solely for service execution under strict data processing agreements.
Security Measures: All data is encrypted in transit (TLS 1.3) and at rest. Access is restricted to authorized personnel only, with regular security audits conducted quarterly.
Data Handling Protocol
Ingestion & Classification
All client data received through forms, emails, or API integrations is immediately classified by sensitivity level and logged in our secure data management system.
Encryption & Storage
Data is encrypted using AES-256 at rest and TLS 1.3 in transit. Storage occurs on EU-based servers exclusively, in compliance with GDPR data residency requirements.
Processing & Access Control
Access is granted on a strict need-to-know basis via role-based permissions. All access events are logged with timestamps and user identifiers.
Deletion & Purging
Upon data retention period expiry or client request, data is permanently deleted from all primary and backup systems within 30 calendar days.
Security Audit Framework
PixelStackLabs maintains a rigorous security audit schedule to ensure continuous compliance with industry standards and GDPR requirements.
Quarterly Internal Audit
Automated vulnerability scanning, access log review, and encryption validation across all client project environments.
Annual External Penetration Test
Third-party security firm conducts full-scope penetration testing of all production systems and data handling infrastructure.
Incident Response Protocol
Documented breach notification procedures ensuring supervisory authority notification within 72 hours and affected party communication.
Security Audit Framework
PixelStackLabs maintains a rigorous security audit schedule to ensure continuous compliance with industry standards and GDPR requirements.
Quarterly Internal Audit
Automated vulnerability scanning, access log review, and encryption validation.
Annual External Penetration Test
Third-party security firm conducts full-scope penetration testing.
Incident Response Protocol
Breach notification within 72 hours and affected party communication.
Terms of Service
By engaging PixelStackLabs for web development, MarTech, or data pipeline services, you agree to the following terms governing all project engagements.
Article 5.1 — Service Scope
All services are defined in the project onboarding agreement. Scope changes require written approval and may incur additional fees as outlined in the revised proposal.
Article 5.2 — Payment Terms
Invoices are issued per project milestones. Payment is due within 14 calendar days of invoice date. Late payments incur a 2% monthly surcharge after a 7-day grace period.
Article 5.3 — Intellectual Property
Upon full payment, all custom-developed code, designs, and documentation are transferred to the client. PixelStackLabs retains the right to display anonymized case studies.
Article 5.4 — Limitation of Liability
PixelStackLabs liability is limited to the total value of the project agreement. We are not liable for indirect, incidental, or consequential damages arising from third-party service failures.
Article 5.5 — Governing Law
These terms are governed by the laws of Spain. Any disputes shall be resolved in the competent courts of Aranda de Duero, Burgos province.
Terms of Service
By engaging PixelStackLabs for web development, MarTech, or data pipeline services, you agree to the following terms.
Article 5.1 — Service Scope
All services are defined in the project onboarding agreement. Scope changes require written approval.
Article 5.2 — Payment Terms
Invoices are issued per project milestones. Payment is due within 14 calendar days of invoice date.
Article 5.3 — Intellectual Property
Upon full payment, all custom-developed code, designs, and documentation are transferred to the client.
Article 5.4 — Limitation of Liability
Liability is limited to the total value of the project agreement.
Article 5.5 — Governing Law
Governed by the laws of Spain. Disputes resolved in Aranda de Duero courts.
Refund & Reimbursement Policy
PixelStackLabs maintains a transparent refund policy structured around project milestones to ensure fairness for both parties.
Pre-Development Cancellation
If the project is cancelled before any development work has commenced, a full refund of any deposits paid will be issued within 14 business days.
Mid-Project Cancellation
Work completed up to the cancellation date will be invoiced and is non-refundable. Any advance payments exceeding completed work value will be refunded proportionally.
Deliverable Non-Conformance
If deliverables do not match the agreed specifications outlined in the project onboarding document, PixelStackLabs will remediate at no additional cost within 30 calendar days. If remediation is not possible, a proportional refund will be issued.
Refund Processing
All refunds are processed to the original payment method within 14 business days of approval. Refund requests must be submitted in writing to [email protected].
Client Rights Under GDPR
Under the General Data Protection Regulation (EU) 2016/679, you have the following rights regarding your personal data processed by PixelStackLabs:
Right of Access (Art. 15)
You may request a copy of all personal data we hold about you, including the purposes of processing and retention periods.
Right to Rectification (Art. 16)
You may request correction of inaccurate personal data or completion of incomplete data.
Right to Erasure (Art. 17)
You may request deletion of your personal data where there is no compelling legal ground for continued processing.
Right to Data Portability (Art. 20)
You may request your data in a structured, commonly used, machine-readable format for transfer to another controller.
Right to Lodge a Complaint
You have the right to lodge a complaint with the Spanish Data Protection Authority (AEPD) if you believe your data protection rights have been infringed.
To exercise any of these rights, contact our Data Protection Officer at [email protected]. All requests will be processed within 30 calendar days.
Client Rights Under GDPR
Under GDPR (EU) 2016/679, you have the following rights regarding your personal data processed by PixelStackLabs:
Right of Access (Art. 15)
Request a copy of all personal data we hold about you.
Right to Rectification (Art. 16)
Request correction of inaccurate personal data.
Right to Erasure (Art. 17)
Request deletion of your personal data.
Right to Data Portability (Art. 20)
Request your data in a structured, machine-readable format.
Right to Lodge a Complaint
Lodge a complaint with the Spanish Data Protection Authority (AEPD).
Contact our Data Protection Officer at [email protected] to exercise any of these rights.