Legal
Privacy Policy
Sep 18, 2026
Policies
Who we are
This Privacy Notice is issued by Beacon Quest Partners SL, CIF B22551154, with registered address Calle de Francisco Silvela 88, 5ºE, 28002 Madrid, Spain (the “Company”, “we”, “us”).
For any questions about your personal data or to exercise your rights, you may contact us at: support@dguard.ai (or phone: +34 655 203 582).
If appointed, our Data Protection Officer (DPO) can be contacted at: dpo@dguard.ai (if relevant).
Data controller & DPO
Data Controller
Name: Beacon Quest Partners SL (operating as “DGuard”)
CIF: B22551154
Address: C/ Príncipe de Vergara 132, 9º, 28002 Madrid, Spain
Email: contact@dguard.ai
Data Protection Officer (DPO)
Email: dpo@dguard.ai
Need to provide Personal Data
The use of certain services or functionalities of the Website requires you to provide certain personal data and implies their processing for the purposes and on the legal basis indicated in this Privacy Policy unless otherwise indicated. Refusal to provide the data required in these cases may make it impossible to provide you with certain services or functionalities or to process the requests or contracts made, especially in those cases in which they are identified as mandatory.
Which data we collect
We may collect or process the following personal data when you interact with us:
Identity & Contact Data: name, surname, email address, telephone, job title, company, etc., when you submit inquiries, applications, or contact us.
Usage & Technical Data: IP address, browser type, operating system, language preferences, referring URLs, device identifier, cookie identifiers, analytics/tracking data, as well as other data collected automatically when you visit our website or use our services.
Other data you voluntarily provide: e.g. messages via contact form, service requests, correspondence, attachments, documents (if relevant: e.g. CVs, company documents, vendor info, etc.), depending on the context of your interaction with us.
Why and how we use your data — Legal basis
We use your personal data for the following purposes, with the corresponding legal basis according to the GDPR:
Purpose | Data used | Legal basis |
|---|---|---|
To provide and maintain our services (e.g. consulting, recruitment, vendor-due-diligence, client support) | Identity & Contact Data, Contractual Data, Correspondence | Performance of a contract or pre-contractual measures (Art. 6.1.b) |
To communicate with you (respond to inquiries, send project updates, administrative notices) | Contact Data, Correspondence | Legitimate interest (our need to manage business relationships) or consent (if marketing communications) |
For marketing or promotional communications (e.g. newsletters, offers) | Contact Data, Behavioral Data | Your explicit consent (Art. 6.1.a) — only if you opt-in; you may withdraw consent at any time. |
To analyze website usage, improve user experience and performance (analytics) | Usage & Technical Data, Cookies/tracking data | Legitimate interest (to improve our website and services), or consent where required by law |
To comply with legal obligations (e.g. accounting, tax, contractual archiving) | Contractual Data, Client/Project Data | Legal obligation (Art. 6.1.c) |
With whom we share data / data transfers
We may share your personal data with:
Trusted third-party service providers (processors) such as hosting/cloud providers, IT service vendors, analytics providers, email/SaaS vendors, payroll or invoicing systems, etc. — only under a written Data Processing Agreement (DPA), ensuring they process data only per our instructions and apply adequate safeguards.
Authorities or courts when required by law, subpoena, regulatory or judicial request, or to protect legal rights (fraud prevention, investigations, compliance).
In the event of a business transaction (e.g. merger, acquisition, sale), your personal data may be transferred — provided the new entity commits to apply the same privacy obligations.
Outside the European Economic Area (EEA) only when strictly necessary and with appropriate safeguards in place (e.g. Standard Contractual Clauses, or other GDPR-approved mechanisms).
Your personal data may be communicated to Public Bodies and Administrations, Courts and Tribunals, or Security Forces and Corps when it is necessary to comply with a legal obligation. Additionally, in the event that Sapira contracts with third parties for the provision of services, such as software and technology companies that help us to carry out our services efficiently and within the legal framework, may access your personal data when necessary to comply with the purposes indicated above. We inform you that your personal data will be communicated to Amazon Web Services EMEA Sarl, Sucursal en España, with registered office at Calle Ramírez de Prado 5, 28045-Madrid and CIF W0185696B, who provides Sapira with the Platform hosting services. In any case, Sapira guarantees that this access will be carried out in accordance with data protection regulations and in compliance with all the technical and organisational measures necessary to guarantee the security and confidentiality of your personal information.
Notwithstanding the foregoing, when the user is redirected to third-party websites (to make payments for products and services or to request an appointment with Sapira for a real-time demonstration of the Software) the user will be subject to the Privacy Policy and Terms and Conditions of such third parties.
Retention period
We retain personal data only as long as necessary for the purposes for which it was collected (e.g. for the duration of the business relationship, or until a user withdraws consent), and as required by applicable laws (e.g. tax or accounting retention obligations). Once personal data is no longer needed, we securely delete or anonymize it.
Your rights
Right of Access
You have the right to be informed by the Data Controller whether or not they are processing your personal data and, if so, to have access to such data and to receive information on the purposes for which they are processed, the categories of data affected by the processing, the recipients to whom your personal data were disclosed, and the intended period of retention of the data, among other information.
Right of Rectification
At any time you may ask the Data Controller to rectify without undue delay any inaccurate personal data concerning you, as well as to complete the data undergoing processing.
Right to Withdraw Consent
You may revoke the consents granted at any time and without the need for any justification. The revocation will not affect the lawfulness of the processing previously carried out.
Right to Object in Whole or in Part to the Processing
You have the right to object to the processing of your personal data in certain circumstances and on grounds relating to your particular situation. In such cases, the Data Controller will stop processing the personal data unless it can demonstrate legitimate grounds for the processing which override your interests, rights, and freedoms, or for the formulation, exercise, or defence of claims.
Right to Portability of Your Data
You have the right to receive the personal data you have provided in a structured, commonly used, and machine-readable format and to be able to transmit them to another data controller without being prevented from doing so by the data controller to whom you have provided them in the cases legally provided for this purpose.
Right to Restriction of Processing
In certain circumstances (for example, in the event that you contest the accuracy of your data while the accuracy of your data is being verified), you may request that we restrict the processing of your personal data, which will only be processed for the exercise or defence of claims.
Right of Erasure
You have the right to request the deletion of your personal data, provided that the applicable legal requirements are met, inter alia, that they are no longer necessary for the purposes for which they were collected.
If you believe that any of your rights regarding personal data protection have been violated, you may file a complaint with the Spanish Data Protection Agency (www.aepd.es).
Data security
We implement appropriate technical and organisational measures to protect your personal data against unauthorized access, disclosure, alteration or destruction — including access controls, encryption, secure storage, pseudonymization where feasible, secure communication channels (TLS), and internal policies ensuring data minimization, access limitation, and audit logging.
We also regularly review and update our security practices in light of evolving risks and standards (e.g. as described by supervisory-authority guidelines).
Automated decision-making / profiling
We do not use automated decision-making or profiling that produces legal effects or significantly affects you. If this changes in the future, we will inform you, explaining the logic involved and your rights.
Cookies and tracking / Cookie Policy
Our website may use cookies or other tracking technologies (analytics, pixels, similar). We will provide a clear cookie banner or consent tool at first visit (or when required by law), explaining the categories of cookies, their purpose, and allowing you to accept, reject or manage preferences. For more details, please consult our Cookie Policy.
Changes to this policy
We may update this Privacy Notice from time to time to reflect changes in our practices, services or legal obligations. The “Last updated” date at the top indicates when this version was published. We encourage you to review this page regularly. If we make significant changes, we will notify you (e.g. via email or prominent banner), especially if this may affect your rights or processing of your personal data.
Contact / Complaints
If you have any questions, requests, or complaints regarding your personal data or this policy, you can contact us at: dpo@dguard.ai (or phone: +34 655 203 582). You also have the right to file a complaint with the applicable supervisory authority in your country.




Ready to Protect Your Clients' Digital World?
Offers DGuard to your most valuable customers now.