Privacy policy
Data controller: Gextiona Interproducción, S.L.
Version 1.0 · Last updated: 23 June 2026
Prior information and acceptance
The site www.cromawards.com is an information-society service owned by Gextiona Interproducción, S.L., through which the cromAwards contest is managed. This Policy informs, prior to registration and in a concise, transparent and intelligible manner, about the processing of the personal data collected.
By ticking the acceptance box —which will not be pre-ticked— and completing the registration, the participant declares that they have read and understood this Policy. Where a specific processing is based on consent, it will be obtained in a specific, informed and unambiguous way and may be withdrawn at any time without affecting the lawfulness of prior processing.
1. Data controller
- Identity: Gextiona Interproducción, S.L.
- Tax ID (CIF): B-87967592.
- Address: C/ Francisco Silvela 110, 2º — 28002 Madrid (Spain).
- Data protection contact: privacy@cromawards.com.
- Brand: the contest runs under the «cromAwards» brand.
2. Data Protection Officer (DPO)
Given the nature, scope and purposes of the processing, the controller has assessed that the cases requiring the appointment of a Data Protection Officer do not apply. You may nonetheless send any query to privacy@cromawards.com.
3. Personal data we process
Applying the principles of data minimisation and purpose limitation, the following categories of data are processed:
- Identification and contact data: full name, email address, postal address —the latter required to ship prizes to award winners— and date of birth —used to verify the minimum age (18) demanded by the rules and to produce aggregated, anonymous statistics on participation; it is never published nor shared on an individual basis—.
- Entry and artwork data: title and dimensions of the work, category entered, description and images of the work (JPG or PNG files). Works including photographs of people may contain third-party personal data, for whose lawfulness the entrant is responsible.
- Team data: when entering as a team, the names of all its members.
- Payment data: registration entails payment of a fee. Payment is made by redirection to the Stripe gateway, which directly collects and processes the card data; the Site does not store full card details, only the transaction confirmation and identifiers needed for management and invoicing.
- Press-release contacts: where applicable, the data of media or persons (max. 25) provided by the award winner for sending press releases, under their responsibility.
- Usage and security data: where an account exists, a log of sign-ins (date, time and IP address) and of actions performed on the Site.
Please note that the IP address is considered personal data.
4. Purposes and legal bases of processing
- Managing registration and participation in the Contest (basis: performance of the legal relationship arising from acceptance of the rules): processing the entry, authenticating the user and storing the submitted work.
- Jury evaluation and communication of decisions (basis: performance of the rules): selection, deliberation and notification of selected, finalist and award-winning entrants.
- Publication of selected, finalist and award-winning persons and dissemination of award-winning works (basis: performance of the rules and the licence granted therein): publication on the Site and on social media for the promotional purposes of the Contest.
- Sending prizes (basis: performance): delivery of physical recognitions, if any, to the address provided.
- Technical communications (basis: performance): registration confirmation, password recovery and service notices.
- Platform security (basis: legitimate interest): detection of anomalous access and audit logging.
- Compliance with legal obligations (basis: legal obligation): accounting, tax and authority-response obligations.
No profiling, personalised advertising or transfer of data to third parties for commercial purposes is carried out.
Legal basis: GDPR, art. 6.1 (lawfulness: b, c, f); for image dissemination, Organic Act 1/1982 (right to one's own image).
5. Retention periods
- Non-winning entries: during the Contest edition and, after the decision, blocked for the limitation periods of any claims; non-winning works are deleted or anonymised at the end of the edition, unless express authorisation is given for future editions.
- Award winners' data and winning works: retained for longer under the dissemination licence and the historical record of the Contest, without prejudice to the right to object.
- Data with accounting or tax effects: blocked for the legally applicable limitation periods (up to six years under the Commercial Code and four years for tax matters).
- Security logs (if an account exists): audit log 180 days; password-recovery tokens 30 minutes; access-attempt log 24 hours.
6. Recipients and processors (sub-processors)
To provide the service, the controller relies on providers with whom it has signed the corresponding data-processing agreement:
- Resend (transactional email) — United States.
- Hostinger (web and database hosting) — Netherlands (European Union).
- Stripe (payment gateway) — Stripe Payments Europe, Ltd. (Ireland, EU), with possible processing by Stripe, Inc. (United States). Payment is made by redirection to Stripe, which directly collects the card data as controller of such payment data.
In addition, by the very nature of the Contest, award winners' data (name and work) will be disclosed publicly on the Site and social media, and press releases will be sent to the contacts the winner may indicate. These disclosures are based on the rules and do not constitute transfers for commercial purposes.
7. International data transfers
The use of Resend involves a data transfer to the United States, covered by its certification under the EU–US Data Privacy Framework (European Commission adequacy decision of 10 July 2023) and, as an additional safeguard, by the Standard Contractual Clauses. Hosting on Hostinger is located in the Netherlands, within the EEA, so it does not constitute an international transfer. The use of Stripe may involve a data transfer to the United States (Stripe, Inc.), covered by its certification under the EU–US Data Privacy Framework and, as an additional safeguard, by the Standard Contractual Clauses.
8. Automated decisions and profiling
No decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect individuals are taken. The evaluation of works is carried out by a human jury.
9. Commercial communications
The controller does not send commercial communications by electronic means except with prior consent or a prior contractual relationship regarding similar services. In any case, you may object simply and free of charge in each communication.
10. Cookies and similar technologies
The Site uses only the strictly necessary technical cookie for its operation. Details are provided in the Cookie Policy, available separately.
11. Rights of data subjects
The data subject may exercise at any time the rights of access, rectification, erasure, restriction of processing, objection, portability, withdrawal of consent and not to be subject to automated decisions.
To exercise them, simply write to privacy@cromawards.com, indicating the right you wish to exercise. The controller will respond within a maximum of one month, extendable depending on complexity. If you consider that your rights have not been properly addressed, you may lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan, 6, 28001 Madrid; electronic office: sedeagpd.gob.es).
Legal basis: rights: arts. 15 to 22 GDPR; withdrawal of consent: art. 7.3 GDPR; procedures and deadline: art. 12 GDPR and arts. 12 to 18 LOPDGDD; complaint: art. 77 GDPR and art. 37 LOPDGDD.
12. Security measures
The controller applies technical and organisational measures appropriate to the risk, including: encryption of communications via HTTPS/TLS; storage of passwords encrypted with bcrypt; access control to works and entries; encrypted backups; audit logging of critical actions; and automatic blocking after failed access attempts. In the event of a security breach posing a risk to people's rights, the supervisory authority and, where appropriate, the affected individuals will be notified.
13. Changes to this policy
The controller may update this Policy to adapt it to regulatory or service changes. Relevant changes will be communicated by appropriate means and, where applicable, fresh consent will be requested. The date of the latest version appears in the header.
14. Applicable law
Processing is governed by Regulation (EU) 2016/679 (GDPR), Organic Act 3/2018 (LOPDGDD) and Act 34/2002 (LSSI-CE), as well as other applicable Spanish and European Union legislation.
Legal sources and references
- Regulation (EU) 2016/679 (GDPR). General Data Protection Regulation.
- Organic Act 3/2018 (LOPDGDD). Data protection and guarantee of digital rights.
- Act 34/2002 (LSSI-CE). Information-society services.
- Organic Act 1/1982. Right to honour, personal and family privacy and one's own image.
- Implementing Decision (EU) 2023/1795 and 2021/914. EU–US Data Privacy Framework adequacy and Standard Contractual Clauses.
- Commercial Code (art. 30) and Act 58/2003, General Tax Act (arts. 66 to 70). Accounting and tax retention periods.
- AEPD. Supervisory authority and guidelines.