Security Policy
Last updated: July 2026
1. Purpose
The purpose of this policy is to describe the security measures implemented by CORTI BEL to protect the information processed through its website.
2. Infrastructure
The website is hosted on a private server (VPS) managed directly by CORTI BEL and contracted from an external cloud infrastructure services provider.
3. Technical Security Measures
The website uses a secure HTTPS connection to protect data transmission. In addition, secure server configuration measures, regular system updates and access controls using credentials are implemented.
4. Data Processing and Storage
Data received through the contact form (name, email address and telephone number) is received by email, a system that has its own security measures. Users' data who have consented to receive commercial communications is stored in the database of the Listmonk email delivery platform, hosted on the same server managed by CORTI BEL, with restricted access. In both cases, data is retained only for the periods described in the Privacy Policy, and users may request its deletion at any time.
5. Backups
Regular backups of systems and databases are performed and stored securely, with the aim of ensuring the availability and recovery of information in the event of an incident.
6. Access to Information
Access to the information received is restricted exclusively to authorized CORTI BEL personnel.
7. External Providers
The cloud infrastructure provider acts, in its capacity as a data processor, under a contract that guarantees the confidentiality, integrity and security of the data processed, in accordance with Article 28 of the GDPR.
8. Incident Prevention
Technical and organizational measures are implemented to prevent unauthorized access, data loss or misuse of information.
9. Notification of Security Breaches
In the event that a personal data security breach is detected that poses a risk to the rights and freedoms of users, CORTI BEL will notify the Spanish Data Protection Agency within a maximum period of 72 hours from becoming aware of the breach, as established by Article 33 of the GDPR. If the risk is high, the affected users will also be informed directly, in accordance with Article 34 of the GDPR.
10. Security Limitations
Despite the measures adopted, no system connected to the internet can guarantee absolute security.
11. Contact
For any matter relating to information security, you may contact info@modacortibel.com.
