Privacy Policy

Who is responsible for the processing of personal data?

Company Name: Nexus Plus Consultores S.L.
Address: Paseo de la Castellana, 118, 5º E. 28046 Madrid
Email: info@nxgovernance.com

How have we obtained your data?

You have provided it to us: either online or offline, when requesting our services in order to maintain a legal-commercial relationship with you or to send you information about our services and promotions.

When you provide us with personal data, you guarantee that you are authorized to provide this information and that it is true, accurate, and up-to-date, that it is not confidential, does not violate any contractual restrictions or third-party rights, and you agree not to impersonate other users.

We have obtained it automatically: if you have provided your data through this website or any of its subdomains and/or microsites, we collect information, for example, when you access the page, fill out any form with personal data, upload information or content (e.g., in our blog), or when you communicate with us directly via email.

When you visit our website, data is sent from your browser to our server to optimize our services and improve your user experience, for example, when you access the page or log in through third-party services such as social networks. This data may be collected and stored automatically by us or by third parties on our behalf. This data may include:

  • The user’s IP address
  • The date and time of the visit
  • The URL of the site from which the user is referred
  • The pages visited on our website
  • Information about the browser used (type and version of the browser, operating system, etc.).

We may process and record such uses, sessions, and related information, either independently or with the help of third-party services, including through the use of cookies and other tracking technologies such as flash cookies and web analytics.

In the event that our website has social media connectors, when you choose to interact with us through a social network, we cannot be responsible for the privacy settings chosen by the user. The social network may report your IP address or which page you are visiting on our website and may set a cookie to allow it to function properly. Your name will appear in the likes you give or in the comments you make on our social media page. If you do not want your personal data to be associated with those likes or comments, configure your privacy settings to prevent it, such as by pseudonymizing your data, for example, by using a nickname or alias that does not reveal your name and surname.

If you are logged in to one of these social networks during your visit to our website, the social network may add that information to your profile, and that information will be transferred to the social network. If you do not want this data transfer to take place, log out of your social network account before entering our websites or mobile applications, as we cannot influence this data collection and transfer through social connectors.

If, as a user, through our official social media page, you choose to post and/or share texts, photos, videos, and other types of information and/or content, you will be solely responsible for ensuring that such content complies with the relevant legal regulations.

In any case, we may remove any content posted on this website as well as from our social media pages if we detect that you have violated current legislation, and the terms outlined in this privacy policy and in the general conditions contained in our Legal Notice.

Social networks are not hosted directly on our services. Your interactions with them are governed by their policies, not ours. Please read the privacy policies of those social networks for detailed information on the collection and transfer of personal data, your rights, and the configuration of your privacy settings.

What age must I be to use this website?

Anyone providing data through the forms on this website and consenting to its processing declares that they are over 14 years old, as access and use of the site is prohibited to those under that age. If at any time we detect that a person under 14 has provided personal data, we will proceed to delete it. Additionally, parents or guardians can contact Nexus Plus Consultores S.L. at any time to block the access account of minors under their care who may have registered using a false identity.

What should you know before sharing third-party data?

Regarding the data of other people, you must respect their privacy, taking special care when publishing their personal information. We remind you that, as a user, you should only provide and consent to the processing of your own personal data, not those of others. If you provide us with third-party data, you are transferring personal data and are responsible for obtaining the prior and express consent of those third parties to use and provide their information. You are also responsible for informing them of the inclusion of their data in our processing activities.
The publication of third-party data without their consent may violate not only data protection regulations but also their right to honor, privacy, or personal image, rights protected under Organic Law 1/1982 of May 5, on the civil protection of the right to honor, personal and family privacy, and one’s own image.

What purposes do we give to the personal data we collect?

We may process data for various purposes, such as:

  1. Responding to your inquiries to clarify any doubts or questions you have raised.
  2. Contacting you via the means you have indicated (email, phone, etc.).
  3. Based on information automatically collected by the website from your browsing as a user, we create anonymous and aggregated data on your behavior for segmentation purposes and the development of anonymous profiles.

This interaction helps us: improve website performance, promote a more personalized experience, measure and monitor the website’s efficiency, and manage the website to ensure it becomes increasingly secure and transparent.

  1. Conduct opinion and/or satisfaction surveys and send you, via electronic communications, information about our activities, products, and/or services (including advertising and/or commercial communications under Article 21 of Law 34/2002 on Information Society Services and Electronic Commerce – LSSICE). If we already have a prior contractual relationship, such communications will be sent based on our legitimate interest (Art. 6, sec. 1, letter f of the GDPR). If there is no prior contractual relationship, we will only send you such communications if you authorize it by checking the opt-in option expressly included in the relevant forms (Art. 6, sec. 1, letter a of the GDPR). The electronic communications we send will include, within the message itself, the option to opt out of future communications.
  2. We may take photos and/or videos at activities or events we organize and/or promote, to inform about them, document them, and include them in the company’s photographic/video archive.

How long will we retain your personal data?

We will retain your personal data until you request its deletion. Even after such a request, we may keep it for the necessary time, limiting its processing (blocking it), solely to comply with legal/contractual obligations we are subject to and/or during the legal periods provided for the prescription of any liabilities on our part and/or the exercise or defense of claims arising from the relationship.

What legal bases do we use to process your data?

The legal bases are what enable and authorize us to process your personal data lawfully. There are different legal bases that allow us to process your data legally:

  1. It may be the existing legal-commercial relationship (contract, pre-contract, etc.) between the parties if you are a client or potential client.
  2. It may also be your consent if you have made a request through our website or attended one of our events. You grant this consent unequivocally by providing your data online or offline, which is considered a clear affirmative act expressing your consent. Providing the requested data is mandatory as it is essential to fulfill your request; if you do not provide it, we will not be able to proceed. You may withdraw this consent at any time by sending us an email to info@nxgovernance.com. However, this withdrawal means that we will not be able to provide the requested services or respond to your inquiries or requests.
  3. As stated in Recital 47 of the GDPR (General Data Protection Regulation 2016/679 of April 27, 2016), our legitimate interest also constitutes a legal basis for processing your data to:

Inform you about our activities, products, and/or services (including through electronic communications) or those of third-party entities with which we have signed collaboration agreements. If we already have a prior contractual relationship, such communications will be sent based on our legitimate interest. Otherwise, we will only send you such communications if you consent by checking the option expressly included in the relevant forms. In any case, the electronic communications we send will include the option to opt out of receiving them in the future.

In any case, we consider the indicated data processing to be proportionate and to have minimal impact on your privacy, but your interests, rights, or freedoms will always prevail over our legitimate interests. Therefore, if you do not wish for us to process your data for these purposes, please send us an email to info@nxgovernance.com, and we will do so, possibly keeping your data blocked for the formulation, exercise, or defense of claims. Withdrawing your consent for these purposes does not affect the processing of your data for the other purposes described in the privacy policy.

To whom may we disclose the personal data you provide?

Your personal data will not be transferred to third parties, except when:

  1. We have your express authorization.
  2. The third parties are suppliers providing us with products and services (data processors), and the disclosure is required to fulfill our contractual or pre-contractual obligations with you.
  3. A law or regulation requires us to disclose data to entities or organizations (e.g., tax authorities).
  4. The disclosure is strictly necessary to ensure compliance with our terms of use, rights, or ownership.

How do we use corporate social media?

The purpose of tools like Facebook, Twitter, LinkedIn, Instagram, and other social networks is to give visibility and promote the activities we carry out. These platforms store personal data on their respective service servers and are governed by their own privacy policies. We recommend reading and reviewing the terms of use and privacy policies of the social network when registering, considering the different configuration options related to the level of privacy of your social media profile.
We reserve the right to remove from our social media any information posted by third parties that violates the law, incites others to do so, or contains messages that attack the dignity of people or institutions. We also reserve the right to block or report the profile responsible for such messages.

Do we make international transfers of your personal data?

An international data transfer occurs when personal data processed by a controller or processor within the European Economic Area (countries of the European Union, Iceland, Liechtenstein, and Norway) is sent to a third country or international organization outside this territory.
Our service providers who may have access to personal data to provide us with auxiliary services (hosting, housing, software as a service, remote backups, IT support or maintenance, email management, email marketing, file transfers, etc.) have their data processing centers within the European Economic Area or in countries with the same level of adequacy, as established by the European Commission and the European Data Protection Board.

What rights can you exercise?

These are known as ARCO-POL rights. You can exercise them by sending an email to info@nxgovernance.com.
You may exercise your rights to access, rectification, deletion, limitation, and opposition to data processing, as well as the right not to be subject to automated decisions, by sending a written and signed request, along with a copy of your ID, passport, or other valid identification, to the postal or email address indicated at the beginning of this privacy policy. If your data changes, you must notify us at the same address. The company is not responsible for any failure to notify such changes.

  • Right of access: You can ask us what personal data we are processing, including requesting a copy of it.
  • Right of rectification: You can request that we correct inaccurate personal data or complete incomplete data, including through an additional statement.
  • Right of deletion (right to be forgotten): You can request the deletion of your personal data when it is no longer necessary for the purposes for which it was collected, when you withdraw your consent, when there has been unlawful processing, or to comply with a legal obligation.
  • Right to restrict processing: You can request that we restrict the processing of your data, in which case we will only keep it for the exercise or defense of legal claims.
  • Right to object: You can object to the processing of your data if it is based on the legitimate interest of the data controller or for advertising purposes.
    Once we receive any of the above requests, we will respond within the legally established timeframes. You can file a complaint with the Spanish Data Protection Agency (AEPD). For more information on the rights you can exercise and for form templates, you can visit the website of the Spanish Data Protection Agency at www.aepd.es

What categories of data do we process?

The GDPR establishes two categories of personal data: identifying data and special categories of data, which include: ethnic or racial origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or health data, biometric data, or data relating to sexual life or orientation.

The categories of data we process are identifying data. We do not process data considered special categories (genetic, biometric, etc.).

Juan Manuel Cadenas

Socio
 
Ingeniero de Caminos, Canales y Puertos por la UPC y PADE por IESE. Con más de 30 años de experiencia internacional en construcción e infraestructuras, ha liderado la expansión de FCC Construcción en Oriente Medio (Metro de Riad y Metro de Doha) y ha sido primer ejecutivo en Petroserv, Unicorp, Gaptek y Ollearis. Ha presidido el Spanish Business Council en Catar y fue secretario general de ASEFMA. Además, cuenta con amplia experiencia en el liderazgo, remodelación y diseño de consejos de administración en compañías de distintos sectores y países.

María de las Heras

Directora comercial 
 
Licenciada en Económicas por la Universidad Complutense y Master en Finanzas por CUNEF.  Ha completado su formación con programas de Transformación digital en ESIC.
María cuenta con más de 20 años de experiencia internacional en ventas, desarrollo de negocio y estrategia, con trayectoria en España, Reino Unido y México. Ha trabajado en multinacionales, startups y pymes, liderando procesos de crecimiento y estructuración comercial, especialmente en servicios B2B.
Actualmente compagina su actividad como asesora estratégica con la docencia y mentoría en programas de emprendimiento y desarrollo empresarial y es socia fundadora de Finanzas Lab.
 

Ferran González

Founder of Nexus Governance Partners. Author of “El arte del buen gobierno corporativo.”

Trained at business schools such as ESADE, IESE, IMD, Stanford, and Harvard Business School.

For over 25 years, he has been an active member of various Boards of Directors in different countries and sectors, serving as an executive, non-executive, or independent director, as well as the chair of the Board and various committees, including corporate governance.

He is a regular speaker on corporate governance at various forums and events, including training programs such as those at Harvard Law School.