Compliance Matrix

Legal Protocols

Comprehensive regulatory frameworks governing data sovereignty, service engagement, and operational compliance under EU GDPR standards.

Protocols

Last updated: July 2026
Applicable jurisdiction: Spain / EU

CedarBeaconForge
Calle de Ona 183, 28050 Madrid, Spain

01

Privacy Directive

1. Data Controller Identification

The data controller responsible for the processing of personal data collected through this digital infrastructure is CedarBeaconForge, registered at Calle de Ona 183, 28050 Madrid, Spain. All inquiries regarding data processing activities, rights requests, or compliance concerns should be directed to [email protected].

2. Categories of Personal Data Processed

We process the following categories of personal data in the course of delivering our digital engineering services:

  • Identity Data: Full name, professional designation, and organizational affiliation provided through contact forms or direct communication channels.
  • Contact Data: Email address, telephone number, and postal address submitted for project engagement or service inquiry purposes.
  • Technical Data: Internet Protocol (IP) address, browser type and version, operating system, device identifiers, and access timestamps automatically collected through standard server logging mechanisms.
  • Project Data: Technical specifications, business requirements, and strategic documents voluntarily provided by clients for the purpose of service delivery.
  • Financial Data: Billing information, payment references, and transaction records necessary for invoice processing and financial compliance under applicable Spanish tax legislation.

3. Legal Bases for Processing

All personal data processing activities conducted by CedarBeaconForge are grounded in the following lawful bases as defined under Article 6 of the EU General Data Protection Regulation (GDPR):

  • Contractual Necessity (Art. 6(1)(b)): Processing of identity, contact, project, and financial data is necessary for the performance of service agreements and the fulfillment of contractual obligations between CedarBeaconForge and its clients.
  • Legitimate Interest (Art. 6(1)(f)): Technical data collection through server logging is conducted under legitimate interest for the purposes of security monitoring, service optimization, abuse prevention, and system integrity assurance.
  • Consent (Art. 6(1)(a)): Where processing extends beyond the purposes outlined above, explicit, informed, and freely given consent will be obtained through clearly articulated opt-in mechanisms.

4. Data Retention Periods

Personal data is retained exclusively for the duration necessary to fulfill the purposes for which it was collected:

  • Client Project Data: Retained for the duration of the active service engagement plus a mandatory 6-year retention period in accordance with Spanish commercial record-keeping obligations under the Code of Commerce (C\u00f3digo de Comercio, Art. 30).
  • Contact Inquiry Data: Retained for a maximum of 24 months from the date of last communication, after which it is securely anonymized or deleted.
  • Server Log Data: Automatically purged after 90 days from collection, except where retention is required for ongoing security investigations.
  • Cookie Consent Records: Retained for 36 months to demonstrate compliance with GDPR accountability requirements.

5. Data Subject Rights

Under the GDPR and applicable Spanish data protection legislation (Ley Org\u00e1nica 3/2018), data subjects are entitled to exercise the following rights:

  • Right of Access (Art. 15): Obtain confirmation of whether personal data is being processed and receive a complete copy of all data held.
  • Right to Rectification (Art. 16): Request correction of inaccurate personal data or completion of incomplete data records.
  • Right to Erasure (Art. 17): Request deletion of personal data where processing is no longer necessary, consent is withdrawn, or processing is unlawful, subject to mandatory legal retention obligations.
  • Right to Restriction (Art. 18): Request limitation of processing activities under specific circumstances including contested accuracy or pending objection assessment.
  • Right to Data Portability (Art. 20): Receive personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
  • Right to Object (Art. 21): Object to processing based on legitimate interests, including profiling, at any time.
  • Right to Lodge a Complaint: File a complaint with the Spanish Data Protection Authority (Agencia Espa\u00f1ola de Protecci\u00f3n de Datos \u2013 AEPD) at www.aepd.es.

6. International Data Transfers

CedarBeaconForge processes all primary data within the European Economic Area (EEA). Where third-party service providers are located outside the EEA, data transfers are safeguarded through Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent adequacy decisions ensuring an adequate level of data protection as required under Chapter V of the GDPR.

7. Security Measures

CedarBeaconForge implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including but not limited to: encryption of personal data in transit (TLS 1.3) and at rest (AES-256), regular security assessments and penetration testing, strict access controls with principle of least privilege enforcement, comprehensive audit logging of all data access events, and mandatory data protection training for all personnel with access to personal data.

02

Cookie Protocol

1. Cookie Technology Overview

Cookies are small text files placed on your device when you access our digital infrastructure. They serve essential technical functions and enable us to maintain the structural integrity of your browsing session. This protocol outlines the specific categories of cookies deployed, their purposes, and the controls available to you.

2. Essential Cookies (Strictly Necessary)

These cookies are fundamental to the operation of our digital infrastructure and cannot be disabled without impairing core functionality:

  • Session Identifier: Maintains your browsing session state across page transitions. Expires at session termination.
  • Cookie Consent Record: Stores your cookie preference selection (Accept/Decline) to prevent repeated consent requests. Retained for 36 months.
  • Security Token: Protects against Cross-Site Request Forgery (CSRF) attacks during form submissions. Expires at session termination.
  • Load Balancer Affinity: Ensures your session is consistently routed to the same server instance during high-traffic periods. Expires at session termination.

3. Analytics Cookies (Consent Required)

Analytics cookies collect anonymized usage data that helps us understand how visitors interact with our digital infrastructure, enabling us to optimize performance and user experience. These cookies are only activated upon your explicit consent through the cookie consent banner. All analytics data is aggregated and does not enable identification of individual users.

4. Cookie Management Controls

You may manage your cookie preferences at any time through the following mechanisms:

  • Our cookie consent banner (accessible via the persistent indicator in the page footer).
  • Your browser settings, which allow you to block or delete cookies from specific or all websites.
  • Direct communication to [email protected] requesting manual deletion of stored cookie data.

Disabling essential cookies may impair the functionality of certain features on this digital infrastructure.

5. Third-Party Cookie Disclosures

CedarBeaconForge does not deploy any third-party tracking cookies, advertising pixels, or cross-site data collection mechanisms. Google Maps integration on the contact page may set cookies governed by Google's own privacy policy when you interact with the embedded map. We do not control these cookies and encourage you to review Google's privacy documentation for further information.

03

Refund Framework

1. General Refund Principles

CedarBeaconForge is committed to delivering enterprise-grade digital engineering services that meet or exceed the specifications outlined in each project agreement. We recognize that circumstances may necessitate the evaluation of refund requests and have established the following framework to ensure fair, transparent, and consistent handling of all refund inquiries.

2. Milestone-Based Refund Eligibility

All service engagements are structured around clearly defined project milestones as specified in the initial service agreement. Refund eligibility is assessed based on the completion status of these milestones:

  • Pre-Engagement Cancellation: Full refund of any advance payment if cancelled before the commencement of Phase 1 (Discovery & Structural Mapping) activities. Cancellation must be submitted in writing to [email protected].
  • Phase 1 Completion Refund: If cancellation occurs during or immediately following Phase 1, a refund of 75% of the remaining unallocated project budget will be issued, reflecting the completed discovery work and delivered structural blueprints.
  • Phase 2 In-Progress Refund: Cancellation during active Phase 2 (Core Engineering) is assessed on a pro-rata basis. Refunds are calculated based on the percentage of completed engineering units versus the total Phase 2 scope, with a maximum refund of 50% of the remaining unallocated budget.
  • Phase 3 & Deployment: No refunds are issued once Phase 3 (Deployment, Auditing & Final Delivery) has commenced, as this phase involves production deployment activities and irreversible infrastructure changes. All deliverables produced up to the point of cancellation remain the property of the client.

3. Quality Assurance & Dispute Resolution

If refund requests arise from quality concerns regarding delivered work, CedarBeaconForge will first engage in a structured review process:

  • Technical Review: A comprehensive audit of the disputed deliverables against the agreed-upon specifications, conducted within 10 business days of the refund request.
  • Remediation Offer: Where deliverables are found to deviate from specifications, CedarBeaconForge will offer a remediation plan at no additional cost to address identified discrepancies.
  • Independent Mediation: If the client remains unsatisfied after technical review and remediation, both parties may agree to engage an independent third-party mediator. Costs of mediation are shared equally unless the mediator determines otherwise.

4. Refund Processing

Approved refunds are processed within 14 business days of final refund approval via the original payment method. Refund amounts exclude any applicable banking fees or currency conversion charges that may be levied by the client's financial institution. Partial refunds for milestone-based cancellations are issued in Euros (\u20ac) and may be subject to exchange rate variations for international transfers.

5. Statutory Rights

Nothing in this Refund Framework affects your statutory rights under applicable Spanish and EU consumer protection legislation, including the right of withdrawal for distance contracts as defined under EU Directive 2011/83/EU, transposed into Spanish law by Real Decreto-ley 21/2019. Consumers exercising their statutory withdrawal right are entitled to a full refund within 14 calendar days of withdrawal notification.

04

Service Terms

1. Scope of Service Engagement

These Terms of Service govern all engagements between CedarBeaconForge and its clients for the provision of digital engineering, design, and consulting services. Each service engagement is initiated through a formal service agreement that specifies the scope, deliverables, timeline, pricing, and technical specifications for the project. These terms form an integral part of every service agreement unless explicitly superseded by a custom contract signed by both parties.

2. Payment Terms & Invoicing

  • Payment Schedule: Unless otherwise specified in the service agreement, payments are structured as follows: 40% upon project initiation, 30% upon completion of Phase 2, and 30% upon final delivery and acceptance of Phase 3.
  • Payment Methods: All invoices are payable via the payment link provided through our secure payment infrastructure or via direct bank transfer to the account specified on the invoice.
  • Late Payment: Invoices not settled within 30 calendar days of the issue date incur a statutory late payment interest rate of 8 percentage points above the European Central Bank base rate, as permitted under EU Directive 2011/7/EU on late payment in commercial transactions.
  • Currency: All prices and invoices are denominated in Euros (\u20ac) unless explicitly agreed otherwise in writing.

3. Intellectual Property & Deliverables

  • Pre-Existing IP: CedarBeaconForge retains full ownership of all pre-existing intellectual property, proprietary frameworks, development tools, reusable code libraries, design systems, and architectural patterns utilized during service delivery.
  • Custom Deliverables: Upon full payment of all outstanding invoices, all custom-designed assets, bespoke codebases, original creative works, and project-specific documentation produced exclusively for the client are assigned to the client, subject to CedarBeaconForge's right to reference the work in professional portfolios and case studies.
  • Third-Party Components: Deliverables incorporating open-source libraries or third-party components remain subject to the respective licenses of those components. CedarBeaconForge provides a complete dependency manifest with every deliverable detailing all third-party components and their applicable license terms.

4. Confidentiality & Non-Disclosure

Both parties agree to maintain strict confidentiality regarding all proprietary information, technical specifications, business strategies, and project details disclosed during the course of the engagement. This obligation survives the termination of the service agreement for a period of 36 months. Confidential information shall not be disclosed to third parties without prior written consent, except where required by applicable law or regulatory authority.

5. Limitation of Liability

To the maximum extent permitted by applicable law, CedarBeaconForge's total aggregate liability arising from or in connection with any service engagement shall not exceed the total fees actually paid by the client under the relevant service agreement during the 12-month period immediately preceding the event giving rise to the liability claim. CedarBeaconForge shall not be liable for indirect, incidental, consequential, or punitive damages, including but not limited to loss of revenue, loss of data, or business interruption, regardless of whether such damages were foreseeable.

6. Force Majeure

Neither party shall be liable for failure or delay in performing its obligations under a service agreement if such failure or delay results from circumstances beyond the reasonable control of the affected party, including but not limited to natural disasters, pandemics, governmental actions, cyberattacks, infrastructure failures, or acts of third parties not engaged by either party. The affected party shall notify the other party within 72 hours of becoming aware of a force majeure event and shall use commercially reasonable efforts to mitigate its impact.

7. Governing Law & Dispute Resolution

These Terms of Service and all service agreements are governed by the laws of the Kingdom of Spain and, where applicable, the regulations of the European Union. Any disputes arising from or in connection with these terms or any service agreement shall first be submitted to good-faith negotiation between the parties for a period of 30 calendar days. If negotiation fails, disputes shall be submitted to the exclusive jurisdiction of the courts of Madrid, Spain. Both parties retain the right to seek injunctive or equitable relief from any competent court to prevent irreparable harm pending resolution of the dispute.

8. Amendments & Modifications

CedarBeaconForge reserves the right to modify these Terms of Service at any time. Material changes will be communicated to all active clients via email at least 30 calendar days before taking effect. Continued engagement with CedarBeaconForge services following the effective date of any modifications constitutes acceptance of the updated terms. The applicable version of these terms is always accessible at this URL and is version-controlled for full transparency.