Legal notice and privacy policy

Information about the processing of personal data, the terms of use, and the legal framework applicable to gopenux.com.

Last updated: · version 3.3

Quick questions

What cookies does the Gopenux Lab website use?

Two, and both are technical: gpx_lang, which remembers the language you pick in the selector, and __cf_bm, set by the network that serves the site to tell human traffic apart from automated traffic, which lasts 30 minutes. There are no analytics or advertising cookies: site analytics run without cookies, on self-hosted Umami. Section 7 describes both.

Do I need to accept cookies to browse gopenux.com?

No. Both cookies on the site are exempt from consent under Article 22.2 of the LSSI-CE, which does not require it for cookies needed to provide a service the user has expressly requested: one stores the language preference you set yourself, and the other protects the site against automated traffic. That is why there is no banner. Section 7 describes them.

How does Gopenux Lab measure website usage without analytics cookies?

With Umami, a self-hosted open source tool, configured to minimize and anonymize the IP address through a hash function with a rotating salt. Section 7 sets out the conditions under which this analytics setup falls outside the GDPR and the legal basis that applies in the meantime.

Does Gopenux Lab use advertising or profiling cookies?

No. The website doesn't use advertising or commercial profiling cookies, or any third-party service for that purpose.

2. Privacy policy and data protection

Data controller

In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), Spain's Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), and Colombia's Statutory Law 1581 of , the data controller of your personal data is:

Controller
Gopenux Lab S.A.S.
Address
Gramalote, Norte de Santander, Colombia
Data protection email
privacidad@gopenux.com
Phone
+57 310 2141792

Data Protection Officer (DPO)

Given its size and the type of processing it carries out, Gopenux Lab isn't required to appoint a DPO under Art. 37 GDPR. Any question related to data protection can be sent to the email address given in the previous section.

Personal data collected

The personal data we may collect through this website comes from its three forms: the general contact form and the forms for the two ways to start, "You have an idea" and "You already have a product". All three are used exclusively to respond to your request.

Data categoryTypes of dataSource
Identification and contact dataName and email address; company, if you choose to provide itGeneral contact form and the forms for the two ways to start
Content of the requestThe message and the form's context fields — for example, industry sector or the system the inquiry is aboutThe same three forms
Browsing dataIP address, browser typeAutomatic (server logs)

Of the two cookies on the website, the language preference one stores nothing but a language code and contains no personal data; the one that protects against automated traffic carries an encrypted value that only our network provider can read, and calculating it involves your IP address and the technical characteristics of your request. The analytics install none. Section 7 covers all three.

Besides what you write or select, we record the domain you arrived from — for example linkedin.com, a search engine, or “direct” if you typed the address — for the sole purpose of knowing which channels bring us enquiries. We do not store the full address, so we keep neither any terms you may have searched for nor any campaign identifier, and we do not record your browser, your operating system or your IP address. The legal basis is our legitimate interest in understanding how effective our outreach channels are (Article 6(1)(f) GDPR).

Processing principles

Gopenux Lab guarantees that personal data processing is carried out in accordance with the following principles:

  • Lawfulness, fairness and transparency: data is processed lawfully, fairly and transparently
  • Purpose limitation: data is collected for determined, explicit and legitimate purposes
  • Data minimization: only the data necessary for the stated purposes is collected
  • Accuracy: data is kept accurate and up to date
  • Storage limitation: data is kept only for as long as necessary
  • Integrity and confidentiality: appropriate security of the data is guaranteed
↑ Contents

3. Purposes of data processing

Main purposes

Your personal data is processed for the following purposes:

  • Handling inquiries: responding to requests received through the website's three forms
  • Pre-contractual management: preparing proposals and quotes
  • Contract management: performance and maintenance of the business relationship
  • Billing: issuing invoices and managing collections

Website analytics

The website measures its own usage — page views, traffic source — with Umami, an open source tool self-hosted on Gopenux Lab's own infrastructure. This analytics setup doesn't install cookies, so it doesn't require your consent under Article 22.2 of the LSSI-CE. Its legal basis under the GDPR, and the conditions under which it can be considered anonymous, are explained in section 7.

Secondary purposes (with consent)

The following purposes are only carried out if you give your express consent:

  • Satisfaction surveys: assessing the quality of the service provided to clients with an active contractual relationship

Retention periods

PurposeRetention periodLegal basis
Inquiries that don't lead to a contract1 year from the last communicationLegitimate interest
Contractual relationshipDuration of the contract + 5 yearsLegal obligation (statute of limitations)
Tax and accounting data6 years from the last entryLegal obligation (Commercial Code)
↑ Contents

5. International data transfers

Destination countries

Gopenux Lab is a company incorporated in Colombia, with no establishment in the European Union, that provides services to businesses in different countries. When a person in the European Union provides us with their data through a website form, the GDPR applies directly to that processing by virtue of its Article 3.2, regardless of where the controller is established; Gopenux Lab S.A.S. is the data controller for that processing.

The website is hosted on infrastructure provided by DigitalOcean, LLC, headquartered in the United States: the server that receives the forms is located in the United States. This involves two distinct data flows.

  • When you submit a form, your data travels directly from your browser to Gopenux Lab as the data controller. There is no international transfer within the meaning of Chapter V of the GDPR in that submission, because there is no exporter making your data available to an importer: it is you who provides it directly. The applicable safeguard is that Gopenux Lab complies with the GDPR in full for this processing, wherever it is established.
  • Where there is an international transfer in the strict sense is in the hosting: Gopenux Lab entrusts DigitalOcean, LLC with storing that data in the United States. That transfer does require, and does have, a transfer instrument — see the following section.

Safeguards applied

The United States has an adequacy decision from the European Commission for entities that have joined the EU-U.S. Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 of ). DigitalOcean, LLC, the website's hosting provider, is self-certified under that framework and additionally incorporates standard contractual clauses (SCC) in its data processing agreement as a fallback safeguard, applicable if the certification or the adequacy decision itself were to cease to be in force.

This adequacy decision is being challenged before the Court of Justice of the European Union. Gopenux Lab is monitoring these proceedings and will update this section if the Court rules on the matter.

For the internal notification channel, the main safeguard is technical rather than contractual: the content travels encrypted end to end with a key Discord does not hold, so the provider has no access to any personal data in the clear. This measure applies in addition to whatever transfer safeguards are applicable, not instead of them.

Applicable Colombian regulations

In Colombia, personal data processing is governed by:

  • Statutory Law 1581 of 2012 (Personal Data Protection Law)
  • Decree 1377 of 2013 (implementing Law 1581)
  • Decree 1074 of 2015 (Single Regulatory Decree for the Commerce Sector)

Gopenux Lab S.A.S. complies with these rules in Colombia, its country of domicile. Colombia also takes part in the Ibero-American Data Protection Network (RIPD), a cooperation network among the region's data protection authorities that promotes common best-practice standards. It is a cooperation framework with no binding force and no legal equivalence to a European Commission adequacy decision under Article 45 of the GDPR: only the European Commission can produce that effect for transfers from the European Union.

Service providers

Gopenux Lab currently relies on the following providers to operate the website:

  • Hosting and storage of the forms: DigitalOcean, LLC (United States), under the safeguards described in the previous section.
  • Delivery and protection network (CDN): Cloudflare, Inc. (United States), which DigitalOcean includes as part of its hosting service. Every request to the website passes through its network before reaching our server, so it processes your IP address and the technical characteristics of the request in order to filter automated traffic and attacks. Gopenux Lab does not contract it directly: it acts as a sub-processor of DigitalOcean, which is accountable for it under Article 28(4) of the GDPR.
  • Internal notification of new enquiries: when you submit a form, Gopenux Lab receives a notification in a private Discord channel. The notification travels in two pieces: a fixed text containing no data at all — it always says the same thing — and an attached file with the contents of the form compressed and encrypted. The key that would decrypt it exists on no server and nowhere in Discord's infrastructure: only Gopenux Lab holds it. Discord, Inc. (United States) therefore stores a file it cannot open, and all it comes to know is that an enquiry was received and at what time. Email is no longer used for this notification.

If Gopenux Lab incorporates any other service provider located outside Colombia that processes personal data on its behalf in the future, it will require equivalent contractual guarantees and verify that a valid transfer mechanism is in place: a European Commission adequacy decision, standard contractual clauses (SCC), or binding corporate rules (BCR).

↑ Contents

6. Security measures

In accordance with Article 32 GDPR and Article 4, point (g), of Law 1581 of 2012, Gopenux Lab implements the following technical and organizational security measures:

Technical measures

  • Encryption in transit: all communication with the website uses HTTPS/TLS
  • Access control: the hosting provider dashboard and the mailbox where contacts are recorded are protected with two-factor authentication, and only the Gopenux Lab team has access to them
  • Durable retention: incoming contacts are recorded in the encrypted notification channel, which is the durable repository; storage on the web server is temporary and serves only to ensure no contact is lost between arrival and recording
  • Updates: the website and server dependencies are kept current
  • Minimization: the website asks for no more data than is needed to reply to you, and of the technical context of your request it keeps only the domain you arrived from. It installs no analytics or advertising cookies
  • Analytics without an external provider: aggregate usage data is processed and stored on an instance managed by Gopenux Lab, with no third-party analytics provider involved

Organizational measures

  • Confidentiality: the whole Gopenux Lab team is bound by confidentiality commitments
  • Limited access: incoming contacts are accessible only to whoever handles them
  • Erasure on request: there is a procedure to locate and delete the data of anyone exercising their right to erasure. The contact is located by its reception date and removed from the notification channel; the web server's record is temporary and is discarded by itself at the site's next update
  • Incident handling: procedure for notifying security breaches to the competent authority and, where applicable, to the people affected

Breach notification

If a security breach affecting personal data occurs, Gopenux Lab will notify the competent supervisory authority within a maximum of 72 hours, and the affected data subjects when the breach is likely to result in a high risk to their rights and freedoms.

↑ Contents

7. Cookies and analytics

What cookies are

Cookies are small files that a website can store on a user's device to remember information about their visit. The law regulates them — Article 22.2 of the LSSI-CE and Directive 2002/58/EC — because they involve storing or reading information on the user's device, not because they're inherently a risk.

The two cookies on this website

gopenux.com uses two cookies, and neither is an analytics, advertising or profiling cookie. One is written by the site itself, and only if you pick a language in the selector. The other is set automatically by the network that serves the site, to tell human traffic apart from automated traffic. No provider outside our hosting installs anything: the analytics run without cookies and the fonts are served from our own domain, so they are not requested from Google Fonts or any other external provider either.

NamePurposeDurationType
gpx_langRemember the language you select, so that version is served on later visits without asking again1 yearTechnical, first-party
__cf_bmTell human traffic apart from automated traffic, to protect the site against bots and denial-of-service attacks30 minutesTechnical security cookie, set by our network provider

It is a technical personalisation cookie: it is created only in response to an action of yours — clicking the language selector — and stores nothing but the language code. Article 22.2 of the LSSI-CE exempts from consent those cookies needed to provide a service the user has expressly requested, which is the case here, and that is why the site shows no banner. You can delete it at any time from your browser settings; the only consequence is that the site will again suggest a language based on your browser's.

The __cf_bm cookie is set by Cloudflare, the delivery and protection network through which DigitalOcean serves gopenux.com. It is written on every page, without you having to do anything, and its only function is to work out whether a request comes from a person or from an automated program, in order to stop bots and attacks. It lasts 30 minutes, it is HttpOnly — no script on the page can read it—, it is generated separately for each website, so it cannot be used to follow you from one site to another, and it does not correspond to any user identifier. It is strictly necessary for the security of the service you requested, so it is exempt from consent under Article 22.2 of the LSSI-CE, just like the previous one; we declare it here because being exempt from consent is not being exempt from disclosure. Gopenux Lab cannot switch it off: it is configured by our hosting provider, not by the website.

How website usage is measured

Website analytics run on Umami, an open source tool that Gopenux Lab hosts on its own infrastructure. Umami measures aggregate usage — page views, traffic source, device type — without installing cookies or any other persistent identifier on the user's device: for that reason, under Article 22.2 of the LSSI-CE, this analytics setup doesn't require your consent, regardless of whether the data it processes is personal data or not.

Whether it also falls outside the scope of the GDPR depends on the IP address being processed irreversibly: through a hash function with a salt that rotates often enough to prevent its reconstruction, without being combined with any other data, without generating any identifier that is stable across visits or sites, and without the server logs retaining the full IP address beyond what's necessary for security. Gopenux Lab configures the Umami instance to meet these conditions. Until they're verified, this analytics setup is treated as if it involved personal data, on the basis of Gopenux Lab's legitimate interest in knowing how the website is used (Article 6.1.f of the GDPR), balanced against the rights of visitors: the impact is minimal because there's no persistent identifier, no profiling and no disclosure to third parties.

Where the data resides

Aggregate analytics data is processed and stored on a Umami instance managed by Gopenux Lab, without being sent to any external analytics provider: no third party receives your browsing activity. That instance is hosted on the same infrastructure as the website, described in section 5.

How to check this yourself

The absence of third parties can be verified by opening the browser's developer tools — the network tab — while browsing the website: gopenux.com doesn't make any request to a third-party domain. That check demonstrates that no third party receives your browsing activity; the location of Gopenux Lab's servers is described in section 5.

↑ Contents

8. User rights

Rights under the GDPR (EU and Spanish users)

Under the GDPR and the LOPDGDD, you have the right to:

  • Access (Art. 15): obtain confirmation of whether we process your data and access it
  • Rectification (Art. 16): request the correction of inaccurate or incomplete data
  • Erasure (Art. 17): request the deletion of your data (the "right to be forgotten")
  • Restriction (Art. 18): request the restriction of processing in certain circumstances
  • Portability (Art. 20): receive your data in a structured format and transmit it to another controller
  • Objection (Art. 21): object to the processing of your data, including profiling
  • Not to be subject to automated decisions (Art. 22): not to be subject to decisions based solely on automated processing
  • Withdraw consent: withdraw consent given at any time

Rights under Law 1581 of 2012 (Colombia)

Under Colombian law, data subjects have the right to:

  • Know: access the personal data that has been processed
  • Update: update your personal data with the controller
  • Rectify: rectify information that's inaccurate or incomplete
  • Request deletion: request the deletion of data when it's no longer required for its purpose
  • Revoke authorization: revoke the authorization given for processing
  • File complaints: file complaints with the Superintendence of Industry and Commerce (SIC)

How to exercise your rights

To exercise any of these rights, write to privacidad@gopenux.com stating clearly which right you wish to exercise.

Please write from the same email address you used to contact us: that match is enough verification in most cases and we need nothing further. Only if there were reasonable doubts about your identity — for instance, if the request arrives from a different address — will we ask for additional information, strictly what is needed to resolve that doubt, in accordance with Article 12.6 of the GDPR. If checking an identity document became indispensable in that case, we will verify it without keeping a copy. If you are acting on behalf of someone else, we will need the document evidencing your authority.

We will respond within one month of receipt, extendable by two further months in particularly complex cases, informing you accordingly: that is the GDPR deadline, applicable to people in the European Union and the United Kingdom. If you exercise your rights under Colombia's Law 1581 of 2012, the deadline is ten (10) business days for inquiries and fifteen (15) business days for complaints, extendable by up to eight (8) further business days, informing you before the first deadline expires.

Right to lodge a complaint with a supervisory authority

If you are not satisfied with our response, you can complain to the supervisory authority of the country where you live or work:

  • Spain and the European Union — Spanish Data Protection Agency (AEPD): www.aepd.es. If you live in another member state, its own authority.
  • United KingdomInformation Commissioner's Office (ICO): ico.org.uk
  • Colombia — Superintendence of Industry and Commerce (SIC): www.sic.gov.co
  • CanadaOffice of the Privacy Commissioner of Canada (OPC): priv.gc.ca
  • BrazilAutoridade Nacional de Proteção de Dados (ANPD): gov.br/anpd
  • United States — there is no federal data protection authority of general scope. If your state has one, you may go to it; either way, write to us at privacidad@gopenux.com.
↑ Contents

9. Intellectual and industrial property

Ownership of rights

The contents of this website — text, graphics, illustrations, icons, logos, design and source code — belong to Gopenux Lab, except for the third-party components used under free licenses and identified as such, among them the Inter, Space Grotesk and Archivo typefaces, distributed under the OFL 1.1, whose text ships alongside the files at /assets/fonts/OFL.txt. Our own contents are protected by:

  • International law: Berne Convention, WIPO treaties, TRIPS Agreement
  • Colombian law: Law 23 of 1982 on copyright, Andean Decision 351 of 1993, Law 1915 of 2018
  • Spanish law: Royal Legislative Decree 1/1996 (Intellectual Property Act)

Prohibitions

The following actions are expressly prohibited without Gopenux Lab's written authorization:

  • Reproducing, distributing, publicly communicating or transforming the content
  • Decompiling, reverse engineering or disassembling the software or systems
  • Extracting or reusing all or a substantial part of the content
  • Using the content for commercial purposes without authorization
  • Removing, hiding or tampering with copyright notices

Trademarks and distinctive signs

The trade names, trademarks and logos appearing on the website are owned by Gopenux Lab or by third parties. Access to the website doesn't grant any right over these distinctive signs. Any use without express authorization is prohibited.

Limited license to use

Gopenux Lab grants the user a non-exclusive, non-transferable and revocable license, limited to viewing the website's content for personal, non-commercial purposes. Any other use requires prior written authorization.

↑ Contents

10. Minors

This website and Gopenux Lab's services are aimed exclusively at businesses and professionals (B2B). We don't intentionally collect data from minors.

Minimum age

  • European Union/Spain: under Article 8 GDPR and Article 7 of the LOPDGDD, the minimum age to give consent is 14 in Spain
  • Colombia: under Law 1581 of 2012, processing the data of minors requires authorization from their legal representative

Unintentional processing

If we discover that we've collected data from a minor without their legal representative's consent, we'll delete it immediately. If you're aware that a minor has provided personal data, please contact us so we can delete it.

↑ Contents

11. Changes to this policy

Gopenux Lab reserves the right to modify this privacy policy and legal notice to adapt it to legislative, case-law or business-practice developments.

Notice of changes

Any substantial change will be communicated to users through:

  • Publication of the new version on this page with an update date
  • A prominent notice on the website for a reasonable period
  • Direct email communication to registered users, where applicable

Applicable version

The current version will always be the one published at this URL. We recommend checking this page periodically to stay informed of any changes.

↑ Contents

12. Contact and complaints

Contact details

For any question, inquiry or complaint related to this legal notice, the privacy policy, or the processing of your personal data:

Legal name
Gopenux Lab S.A.S.
Address
Gramalote, Norte de Santander, Colombia
Phone / WhatsApp
+57 310 2141792

Internal complaints procedure

Before turning to the supervisory authorities, we invite you to contact us to try to resolve any dispute amicably. We commit to:

  • Acknowledge receipt of your complaint within a maximum of 5 business days
  • Diligently investigate the reported facts
  • Provide you with a reasoned response within a maximum of 15 business days

Supervisory authorities

If you are not satisfied with our response, you can complain to the supervisory authority of the country where you live or work:

  • Spain and the European Union — Spanish Data Protection Agency (AEPD): www.aepd.es. If you live in another member state, its own authority.
  • United KingdomInformation Commissioner's Office (ICO): ico.org.uk
  • Colombia — Superintendence of Industry and Commerce (SIC): www.sic.gov.co
  • CanadaOffice of the Privacy Commissioner of Canada (OPC): priv.gc.ca
  • BrazilAutoridade Nacional de Proteção de Dados (ANPD): gov.br/anpd
  • United States — there is no federal data protection authority of general scope. If your state has one, you may go to it; either way, write to us at privacidad@gopenux.com.
↑ Contents