Compliance Hub

Legal & Data Governance

Chronological compliance framework governing all data handling, client rights, and operational protocols.

1

Privacy Policy

At PixelStackLabs, located at 09400, Calle Principal 1, Aranda de Duero, Spain, we are committed to protecting the privacy and security of your personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679.

Data Controller: PixelStackLabs is the data controller responsible for your personal data collected through this website and our service engagements.

Data Collection: We collect personal data including but not limited to: full name, email address, phone number, company information, and project specifications.

Purpose of Processing: Your data is processed solely for: (a) executing requested web development and MarTech services; (b) project communication and management; (c) billing and financial record-keeping; (d) compliance with legal obligations.

Data Retention: Personal data is retained for the duration of the service engagement plus 24 months post-completion for legal and accounting purposes.

Third-Party Sharing: We do not sell or rent personal data. Data may be shared with trusted service providers solely for service execution under strict data processing agreements.

Security Measures: All data is encrypted in transit (TLS 1.3) and at rest. Access is restricted to authorized personnel only, with regular security audits conducted quarterly.

2

Data Handling Protocol

A

Ingestion & Classification

All client data received through forms, emails, or API integrations is immediately classified by sensitivity level and logged in our secure data management system.

B

Encryption & Storage

Data is encrypted using AES-256 at rest and TLS 1.3 in transit. Storage occurs on EU-based servers exclusively, in compliance with GDPR data residency requirements.

C

Processing & Access Control

Access is granted on a strict need-to-know basis via role-based permissions. All access events are logged with timestamps and user identifiers.

D

Deletion & Purging

Upon data retention period expiry or client request, data is permanently deleted from all primary and backup systems within 30 calendar days.

3

Security Audit Framework

PixelStackLabs maintains a rigorous security audit schedule to ensure continuous compliance with industry standards and GDPR requirements.

Quarterly Internal Audit

Automated vulnerability scanning, access log review, and encryption validation.

Annual External Penetration Test

Third-party security firm conducts full-scope penetration testing.

Incident Response Protocol

Breach notification within 72 hours and affected party communication.

4

Cookie Policy

PixelStackLabs uses cookies strictly necessary for website functionality. This policy outlines our cookie usage in compliance with GDPR and the ePrivacy Directive.

Essential Cookies (Required)

Session management, CSRF protection, and localStorage for consent preferences. These cookies are strictly necessary and cannot be disabled.

Analytics Cookies (Optional)

First-party analytics for performance monitoring. No third-party tracking pixels or advertising cookies are deployed without explicit consent.

You may manage your cookie preferences at any time via the cookie consent banner displayed upon your first visit, or by clearing your browser's local storage.

5

Terms of Service

By engaging PixelStackLabs for web development, MarTech, or data pipeline services, you agree to the following terms.

Article 5.1 — Service Scope

All services are defined in the project onboarding agreement. Scope changes require written approval.

Article 5.2 — Payment Terms

Invoices are issued per project milestones. Payment is due within 14 calendar days of invoice date.

Article 5.3 — Intellectual Property

Upon full payment, all custom-developed code, designs, and documentation are transferred to the client.

Article 5.4 — Limitation of Liability

Liability is limited to the total value of the project agreement.

Article 5.5 — Governing Law

Governed by the laws of Spain. Disputes resolved in Aranda de Duero courts.

6

Refund & Reimbursement Policy

PixelStackLabs maintains a transparent refund policy structured around project milestones to ensure fairness for both parties.

Pre-Development Cancellation

If the project is cancelled before any development work has commenced, a full refund of any deposits paid will be issued within 14 business days.

Mid-Project Cancellation

Work completed up to the cancellation date will be invoiced and is non-refundable. Any advance payments exceeding completed work value will be refunded proportionally.

Deliverable Non-Conformance

If deliverables do not match the agreed specifications outlined in the project onboarding document, PixelStackLabs will remediate at no additional cost within 30 calendar days. If remediation is not possible, a proportional refund will be issued.

Refund Processing

All refunds are processed to the original payment method within 14 business days of approval. Refund requests must be submitted in writing to [email protected].

7

Client Rights Under GDPR

Under GDPR (EU) 2016/679, you have the following rights regarding your personal data processed by PixelStackLabs:

Right of Access (Art. 15)

Request a copy of all personal data we hold about you.

Right to Rectification (Art. 16)

Request correction of inaccurate personal data.

Right to Erasure (Art. 17)

Request deletion of your personal data.

Right to Data Portability (Art. 20)

Request your data in a structured, machine-readable format.

Right to Lodge a Complaint

Lodge a complaint with the Spanish Data Protection Authority (AEPD).

Contact our Data Protection Officer at [email protected] to exercise any of these rights.