top of page

Privacy Policy 

1. INTRODUCTION

CGS CONSULTATION LLC ("CGS," "Company," "we," "us," or "our") is committed to protecting the privacy, confidentiality, integrity, and security of the personal data entrusted to us by our clients, prospective clients, website visitors, business partners, suppliers, employees, contractors, applicants, and any other individuals interacting with our services.

We recognize that privacy is a fundamental right and that the protection of personal data is essential to maintaining the trust of those who engage with our organization. Accordingly, we process personal information lawfully, fairly, transparently, securely, and only for legitimate business purposes.

This Privacy Policy explains how we collect, use, disclose, store, transfer, retain, and otherwise process personal information when you visit our website, communicate with us, purchase our services or products, subscribe to our communications, apply for employment, participate in events, or otherwise interact with CGS.

This Privacy Policy has been prepared in accordance with:

  • Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR)

  • Spanish Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD)

  • ePrivacy Directive 2002/58/EC, as amended

  • Applicable Spanish legislation

  • Applicable international privacy laws where relevant

Where local laws provide additional protections beyond those described in this Policy, we will comply with those requirements to the extent applicable.

2. DATA CONTROLLER

For the purposes of the GDPR and applicable data protection legislation, the Data Controller is:

CGS CONSULTATION LLC

Registered Address:
Madrid, Spain

Website:
www.cgsconsultation.com

Privacy Contact:
privacy@cgsconsultation.com

Tax Identification Number:
00000000

Unless otherwise specified in a separate agreement, CGS CONSULTATION LLC acts as the Data Controller for personal information collected through its website and business operations.

Where CGS processes information solely on behalf of a client under a written agreement, CGS may act as a Data Processor in accordance with Article 28 GDPR.

3. SCOPE OF THIS PRIVACY POLICY

This Privacy Policy applies to all personal information processed by CGS through:

  • Our corporate website

  • Contact forms

  • Consultation requests

  • Service inquiries

  • Client onboarding

  • Consulting engagements

  • Digital products

  • Training programs

  • Newsletters

  • Marketing campaigns

  • Customer relationship management systems

  • Artificial intelligence systems

  • Email communications

  • Telephone calls

  • Video conferences

  • Social media interactions

  • Surveys

  • Recruitment processes

  • Events

  • Business partnerships

  • Mobile devices

  • Future applications developed by CGS

This Privacy Policy also applies whenever individuals communicate with us offline if those communications involve the processing of personal information.

4. WHO THIS POLICY APPLIES TO

This Privacy Policy applies to:

  • Website visitors

  • Existing clients

  • Prospective clients

  • Business owners

  • Restaurant operators

  • Hospitality professionals

  • Suppliers

  • Vendors

  • Contractors

  • Employees

  • Job applicants

  • Strategic partners

  • Investors

  • Newsletter subscribers

  • Event attendees

  • Webinar participants

  • Social media users

  • Individuals contacting CGS by email or telephone

  • Any person whose personal information is processed by CGS

5. DEFINITIONS

For purposes of this Privacy Policy:

Personal Data means any information relating to an identified or identifiable natural person.

Processing means any operation performed on personal data including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, transmission, restriction, erasure, or destruction.

Data Subject means the individual whose personal information is processed.

Controller means the entity determining the purposes and means of processing personal data.

Processor means a third party processing personal information on behalf of the Controller.

Consent means any freely given, specific, informed and unambiguous indication of the data subject's wishes.

Sensitive Personal Data means categories of personal information requiring enhanced protection under applicable law.

Cookies means small data files stored on your device.

Services means all consulting, advisory, digital, educational, operational, analytical, software, AI-assisted, or other services provided by CGS.

6. PRINCIPLES OF DATA PROCESSING

CGS processes personal data according to the principles established under Article 5 GDPR.

Accordingly, personal data shall be:

  • processed lawfully, fairly, and transparently;

  • collected only for specified, explicit, and legitimate purposes;

  • limited to what is necessary for the stated purposes;

  • accurate and kept up to date;

  • retained no longer than necessary;

  • protected through appropriate technical and organizational security measures;

  • processed with accountability and demonstrable compliance.

These principles guide every processing activity carried out by CGS.

7. PERSONAL DATA WE COLLECT

Depending on your interaction with CGS, we may collect the following categories of personal information.

7.1 Identification Information

Including but not limited to:

  • Full name

  • Preferred name

  • Business name

  • Job title

  • Professional position

  • Employer

  • Professional license numbers where applicable

7.2 Contact Information

Including:

  • Email address

  • Telephone number

  • Mobile number

  • Mailing address

  • Billing address

  • Country

  • Region

  • City

  • Postal code

7.3 Business Information

Including:

  • Company name

  • Industry

  • Business sector

  • Number of employees

  • Revenue ranges

  • Operational structure

  • Restaurant concepts

  • Organizational charts

  • Operational procedures

  • Financial metrics voluntarily provided

  • Business objectives

  • Operational challenges

7.4 Financial Information

Where necessary for contractual purposes, we may process:

  • Billing information

  • Invoice details

  • VAT numbers

  • Tax identifiers

  • Payment confirmations

  • Transaction records

CGS does not intentionally store complete payment card numbers where payment processing is performed by authorized third-party providers.

7.5 Technical Information

When using our website, we may automatically collect:

  • IP address

  • Browser type

  • Browser version

  • Device identifiers

  • Operating system

  • Screen resolution

  • Language settings

  • Time zone

  • Device characteristics

  • Referral URLs

  • Clickstream data

  • Website interaction data

  • Log files

  • Error reports

7.6 Usage Information

We may collect:

  • Pages visited

  • Time spent on pages

  • Navigation paths

  • Scroll depth

  • Downloads

  • Button clicks

  • Forms completed

  • Session duration

  • Return visits

  • Marketing campaign interactions

7.7 Communications

Including:

  • Emails

  • Contact forms

  • Phone conversations

  • Video conference recordings where authorized

  • Meeting notes

  • Client feedback

  • Customer support requests

  • Chat communications

7.8 Marketing Information

Including:

  • Newsletter subscriptions

  • Communication preferences

  • Campaign engagement

  • Event registrations

  • Marketing survey responses

7.9 Recruitment Information

Applicants may voluntarily submit:

  • Curriculum Vitae

  • Cover letters

  • Professional certifications

  • Employment history

  • Education

  • Skills

  • References

  • Interview notes

7.10 Social Media Information

If you interact with CGS through social media platforms, we may receive:

  • Public profile information

  • Username

  • Profile photo

  • Public comments

  • Messages sent to our accounts

  • Engagement metrics

The processing of such information is also governed by the respective platform's privacy policies.

7.11 Artificial Intelligence Interactions

CGS may use artificial intelligence technologies to assist in delivering consulting services and improving operational efficiency.

Where applicable, information processed through AI systems may include:

  • Documents voluntarily uploaded by clients

  • Business reports

  • Operational procedures

  • Restaurant data

  • Performance metrics

  • Financial summaries

  • Organizational structures

  • Workflow documentation

  • Strategic plans

  • Client communications

  • Images submitted for analysis

  • Audio recordings where expressly authorized

AI-assisted processing is used to support human decision-making and does not replace professional judgment. Significant business decisions and consulting recommendations are subject to human review before delivery to clients.

7.12 Information You Voluntarily Provide

You may voluntarily provide any additional information when:

  • requesting consulting services;

  • participating in meetings;

  • responding to questionnaires;

  • downloading resources;

  • submitting forms;

  • contacting CGS;

  • purchasing products;

  • requesting proposals;

  • participating in surveys.

You should only provide information that is necessary for the relevant purpose and ensure that you have the legal authority to disclose any third-party information you submit.

8. SOURCES OF PERSONAL DATA

CGS may collect personal information from the following sources:

  • Directly from you

  • Through our website

  • Through contact forms

  • During consulting engagements

  • Through email communications

  • Through telephone calls

  • During meetings

  • Through publicly available business information

  • Through social media interactions

  • Through recruitment platforms

  • Through referrals

  • Through authorized business partners

  • Through payment providers

  • Through analytics platforms

  • Through cookies and similar technologies

  • Through lawful third-party data providers, where permitted by applicable law

Where personal information is obtained indirectly, we will provide the required notices in accordance with Articles 14 and 15 of the GDPR, unless a legal exemption applies.

9. LEGAL BASES FOR PROCESSING

CGS processes personal data only where a valid legal basis exists under Article 6 GDPR. Depending on the purpose of processing, one or more of the following legal bases may apply:

  • Your explicit consent (Article 6(1)(a))

  • Performance of a contract or steps taken at your request prior to entering into a contract (Article 6(1)(b))

  • Compliance with legal obligations applicable to CGS (Article 6(1)(c))

  • Protection of vital interests where necessary (Article 6(1)(d))

  • Performance of a task carried out in the public interest where applicable (Article 6(1)(e))

  • Legitimate interests pursued by CGS or a third party, provided such interests are not overridden by your fundamental rights and freedoms (Article 6(1)(f))

Where processing is based on consent, you may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before such withdrawal.

10. PURPOSES OF PROCESSING

CGS processes personal data for legitimate business purposes, including but not limited to:

  • Responding to inquiries and requests

  • Providing consulting services

  • Managing client relationships

  • Performing contractual obligations

  • Preparing proposals and quotations

  • Delivering reports and recommendations

  • Operating and improving our website

  • Processing payments and invoices

  • Managing customer accounts

  • Conducting analytics and business intelligence

  • Sending newsletters and marketing communications where permitted

  • Organizing webinars and events

  • Recruiting employees and contractors

  • Complying with legal and regulatory obligations

  • Protecting our legal rights and interests

  • Preventing fraud and cybersecurity threats

  • Enhancing service quality

  • Developing new products and services

  • Conducting internal research and innovation

  • Using AI-assisted tools to improve efficiency while maintaining appropriate human oversight

Personal data will not be processed for purposes incompatible with those described above unless required or permitted by applicable law or with your prior consent where required.

11. DISCLOSURE OF PERSONAL DATA

CGS CONSULTATION LLC ("CGS") treats all personal information as confidential and does not sell, rent, or lease personal data to third parties for monetary consideration. We disclose personal data only where necessary to provide our services, comply with legal obligations, protect legitimate interests, or where disclosure has been authorized by the data subject.

Recipients of personal data may include:

  • Authorized employees, officers, and contractors of CGS who require access to perform their duties.

  • Professional advisers, including legal counsel, accountants, auditors, insurers, and compliance consultants.

  • Cloud hosting providers and infrastructure providers.

  • Payment processors.

  • Customer Relationship Management (CRM) providers.

  • Email and communication service providers.

  • Appointment scheduling platforms.

  • Marketing and advertising platforms.

  • Analytics providers.

  • Artificial intelligence service providers.

  • Recruitment and human resources platforms.

  • Government authorities, regulators, courts, or law enforcement agencies where required by law.

  • Business partners involved in delivering contracted services.

  • Successors in the event of a merger, acquisition, restructuring, or sale of assets.

Each disclosure is limited to the minimum information necessary for the intended purpose and, where applicable, is governed by contractual confidentiality and data protection obligations.

12. THIRD-PARTY SERVICE PROVIDERS

To operate efficiently and deliver our services, CGS may engage trusted third-party service providers acting as Data Processors under Article 28 GDPR.

These providers may include services relating to:

  • Website hosting

  • Cloud infrastructure

  • Data storage

  • Email hosting

  • CRM systems

  • Accounting software

  • Electronic signatures

  • Payment gateways

  • Marketing automation

  • Customer support

  • Video conferencing

  • Document management

  • Artificial intelligence systems

  • Cybersecurity monitoring

  • Recruitment management

  • Business analytics

  • Backup and disaster recovery

  • Identity verification

  • Project management

All Data Processors are required to implement appropriate technical and organizational security measures and may only process personal data in accordance with documented instructions provided by CGS.

CGS performs reasonable due diligence when selecting processors and periodically reviews their compliance with applicable data protection standards.

13. INTERNATIONAL DATA TRANSFERS

CGS operates internationally and provides consulting services to clients worldwide. Consequently, personal data may be transferred to, accessed from, or stored in countries outside the European Economic Area ("EEA").

Whenever personal data is transferred internationally, CGS implements appropriate safeguards as required under Chapter V of the GDPR.

Such safeguards may include:

  • European Commission Adequacy Decisions.

  • Standard Contractual Clauses (SCCs).

  • Binding Corporate Rules (where applicable).

  • Approved Codes of Conduct.

  • Approved Certification Mechanisms.

  • Additional technical and organizational measures where required.

Where transfers occur to jurisdictions that do not benefit from an adequacy decision, CGS undertakes transfer impact assessments and implements supplementary safeguards where necessary.

By interacting with CGS, you acknowledge that your information may be processed in jurisdictions outside your country of residence where appropriate legal safeguards are in place.

14. ARTIFICIAL INTELLIGENCE PROCESSING

CGS utilizes artificial intelligence technologies to enhance operational efficiency, automate administrative tasks, improve analytical capabilities, generate documentation, support consulting engagements, and develop innovative business solutions.

AI technologies may be used for purposes including:

  • Business analysis.

  • Operational diagnostics.

  • Process optimization.

  • Financial modeling.

  • Document generation.

  • Report drafting.

  • Data summarization.

  • Customer support.

  • Language translation.

  • Predictive analytics.

  • Strategic planning assistance.

  • Educational content generation.

AI systems are intended to assist qualified professionals and are not designed to replace independent human judgment.

Whenever AI contributes to consulting recommendations, deliverables, or analyses, appropriate human oversight is maintained before final recommendations are communicated to clients.

15. AUTOMATED DECISION-MAKING

CGS does not make decisions producing legal effects or similarly significant consequences solely through automated processing without meaningful human involvement.

Should automated decision-making within the meaning of Article 22 GDPR be introduced in the future, affected individuals will receive appropriate notice regarding:

  • the existence of automated decision-making;

  • the logic involved;

  • the significance of the processing;

  • the anticipated consequences;

  • available rights, including the right to request human intervention.

16. DATA SHARING WITH AI PROVIDERS

Certain information voluntarily submitted by clients may be processed using trusted artificial intelligence platforms strictly for the purpose of providing contracted consulting services.

Before utilizing external AI systems, CGS evaluates:

  • contractual privacy commitments;

  • confidentiality protections;

  • applicable security controls;

  • international transfer mechanisms;

  • data retention practices;

  • regulatory compliance.

Where possible, CGS limits the amount of identifiable personal information submitted to AI systems through anonymization, pseudonymization, aggregation, or other privacy-enhancing techniques.

CGS does not intentionally use client confidential information to train publicly available artificial intelligence models unless expressly authorized by the client or otherwise permitted under applicable contractual arrangements.

17. CONFIDENTIAL BUSINESS INFORMATION

During consulting engagements, clients may voluntarily provide confidential commercial information including:

  • financial statements;

  • operational procedures;

  • supplier information;

  • pricing structures;

  • strategic plans;

  • recipes;

  • proprietary methodologies;

  • organizational information;

  • intellectual property;

  • trade secrets.

CGS treats such information as confidential and implements appropriate contractual, organizational, and technical safeguards to prevent unauthorized disclosure.

Confidential information is processed exclusively for purposes directly related to the consulting engagement unless otherwise agreed in writing or required by law.

18. MARKETING COMMUNICATIONS

CGS may send marketing communications concerning:

  • consulting services;

  • newsletters;

  • educational materials;

  • webinars;

  • events;

  • industry insights;

  • promotional offers;

  • digital products;

  • research publications.

Marketing communications are sent only where:

  • consent has been obtained where legally required;

  • another lawful basis exists under applicable legislation.

Recipients may withdraw consent or unsubscribe at any time using the unsubscribe mechanism provided in each communication or by contacting:

privacy@cgsconsultation.com

Withdrawal of consent does not affect prior lawful processing.

19. DIRECT MARKETING

CGS may rely upon its legitimate interests to market similar services to existing business clients where permitted under applicable law.

Individuals may object to direct marketing at any time.

Upon receiving an objection, CGS will cease processing personal information for direct marketing purposes unless another lawful basis exists.

20. NEWSLETTER SUBSCRIPTIONS

Individuals subscribing to newsletters may be asked to provide:

  • name;

  • email address;

  • organization;

  • communication preferences.

Subscription requires an affirmative action by the subscriber.

Where legally required, CGS may implement double opt-in verification.

Subscribers may unsubscribe at any time.

21. SOCIAL MEDIA

CGS maintains professional profiles on various social media platforms.

Interactions through social media are also subject to the privacy policies of the relevant platform.

CGS may process publicly available information when users:

  • comment;

  • share content;

  • send direct messages;

  • participate in campaigns;

  • engage with company publications.

CGS is not responsible for the independent privacy practices of third-party social media providers.

22. WEBSITE ANALYTICS

CGS uses analytics technologies to understand how visitors interact with the Website.

Information collected may include:

  • page visits;

  • referral sources;

  • browser information;

  • device characteristics;

  • user behavior;

  • session duration;

  • click paths;

  • conversion events;

  • aggregated usage statistics.

Analytics information assists CGS in improving website performance, usability, security, and service quality.

Where legally required, analytics cookies are deployed only after obtaining valid user consent.

23. COOKIES AND SIMILAR TECHNOLOGIES

CGS uses cookies, pixels, web beacons, local storage, SDKs, scripts, and similar technologies to operate the Website and improve user experience.

These technologies may be classified as:

  • Strictly Necessary Cookies

  • Functional Cookies

  • Preference Cookies

  • Analytics Cookies

  • Performance Cookies

  • Marketing Cookies

  • Advertising Cookies

  • Security Cookies

  • Session Cookies

  • Persistent Cookies

A detailed explanation of cookie usage is provided in the separate Cookie Policy.

Where required by applicable law, users are provided with a consent management platform allowing them to:

  • accept cookies;

  • reject non-essential cookies;

  • modify preferences;

  • withdraw consent.

Consent preferences may be updated at any time.

24. TRACKING TECHNOLOGIES

CGS may use technologies including but not limited to:

  • Google Analytics

  • Google Tag Manager

  • Google Ads

  • Google Search Console

  • Meta Pixel

  • LinkedIn Insight Tag

  • Microsoft Clarity

  • Microsoft Advertising

  • YouTube embedded services

  • CRM tracking

  • Email tracking technologies

  • Conversion measurement tools

The specific technologies deployed may change over time as business needs evolve.

Current technologies are disclosed through the Cookie Policy and cookie consent platform.

25. RETARGETING AND ADVERTISING

Subject to user consent where required, CGS may use advertising technologies to display relevant content across digital platforms.

Advertising partners may collect information concerning interactions with the Website to facilitate personalized advertising.

Users may manage advertising preferences through:

  • browser settings;

  • cookie consent tools;

  • advertising platform settings;

  • applicable opt-out mechanisms.

26. THIRD-PARTY WEBSITES

The Website may contain links to third-party websites, platforms, or services.

CGS does not control and is not responsible for the privacy practices, content, or security of external websites.

Users are encouraged to review the privacy policies of third parties before submitting personal information.

27. DATA RETENTION

CGS CONSULTATION LLC ("CGS") retains personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, enforce agreements, protect legal rights, and satisfy applicable regulatory requirements.

Retention periods vary depending on the nature of the information and the applicable legal obligations.

Illustrative retention periods include:

CategoryTypical Retention Period

Contact inquiriesUp to 24 months after the last communication

Client recordsDuration of the contractual relationship plus applicable statutory limitation periods

Financial and accounting recordsAs required by applicable tax and accounting legislation

Recruitment recordsUp to 24 months unless consent is withdrawn earlier

Marketing consent recordsUntil consent is withdrawn, plus evidence retention where required

Website analyticsAccording to configured analytics settings and applicable law

Security logsAs reasonably necessary for cybersecurity and legal compliance

Cookie consent recordsAs required under applicable ePrivacy and GDPR requirements

Where multiple legal obligations apply, CGS retains information for the longest legally required period.

When retention is no longer necessary, personal data will be securely deleted, anonymized, or irreversibly destroyed.

28. INFORMATION SECURITY

CGS maintains a comprehensive Information Security Management Program designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

Security measures may include:

  • Encryption of data in transit using TLS/SSL.

  • Encryption of stored information where appropriate.

  • Multi-factor authentication.

  • Role-based access controls.

  • Least-privilege access principles.

  • Password management policies.

  • Endpoint protection.

  • Firewalls.

  • Network monitoring.

  • Intrusion detection and prevention systems.

  • Vulnerability management.

  • Secure cloud infrastructure.

  • Secure backups.

  • Disaster recovery procedures.

  • Business continuity planning.

  • Employee confidentiality obligations.

  • Security awareness training.

  • Vendor risk assessments.

  • Regular software updates.

  • Logging and audit trails.

  • Physical security measures.

  • Access monitoring.

  • Incident response procedures.

While CGS implements commercially reasonable safeguards, no method of electronic transmission or storage can be guaranteed to be completely secure.

Accordingly, CGS cannot guarantee absolute security.

29. DATA BREACH RESPONSE

CGS maintains procedures for identifying, investigating, documenting, mitigating, and responding to personal data breaches.

Where required under Articles 33 and 34 GDPR, CGS will:

  • notify the competent supervisory authority without undue delay and, where feasible, within seventy-two (72) hours after becoming aware of a notifiable personal data breach;

  • notify affected individuals where the breach is likely to result in a high risk to their rights and freedoms;

  • document all breaches regardless of notification requirements.

CGS continuously reviews its incident response procedures to improve resilience and minimize future risks.

30. YOUR PRIVACY RIGHTS

Subject to applicable law, you may exercise the following rights regarding your personal information.

Right of Access

You may request confirmation as to whether CGS processes your personal data and obtain a copy of such information.

Right to Rectification

You may request correction of inaccurate or incomplete personal information.

Right to Erasure

You may request deletion of personal information where one of the grounds established under Article 17 GDPR applies.

Right to Restrict Processing

You may request limitation of processing under the circumstances described in Article 18 GDPR.

Right to Data Portability

You may request that certain personal information be provided in a structured, commonly used, and machine-readable format or transferred directly to another controller where technically feasible.

Right to Object

You may object to processing based upon legitimate interests, including direct marketing.

Upon receiving a valid objection, CGS will cease the relevant processing unless compelling legitimate grounds exist.

Right to Withdraw Consent

Where processing is based upon consent, you may withdraw consent at any time.

Withdrawal does not affect prior lawful processing.

Right Not to Be Subject to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing where such decisions produce legal or similarly significant effects.

Right to Lodge a Complaint

You may lodge a complaint with the competent supervisory authority if you believe your personal information has been processed unlawfully.

31. EXERCISING YOUR RIGHTS

Requests regarding privacy rights may be submitted to:

Privacy Officer

CGS CONSULTATION LLC

Email:

privacy@cgsconsultation.com

To protect personal information, CGS may require reasonable verification of identity before processing requests.

Requests will be handled within the timeframes established by applicable law.

Where requests are manifestly unfounded or excessive, CGS reserves the right to refuse the request or charge a reasonable administrative fee where permitted by law.

32. CHILDREN'S PRIVACY

The Website and services are intended primarily for businesses and adults.

CGS does not knowingly collect personal information from children under the age of sixteen (16), or the minimum age required under applicable law.

If CGS becomes aware that personal information has been collected from a child without appropriate authorization, reasonable steps will be taken to delete such information promptly.

Parents or legal guardians who believe their child has submitted personal information should contact:

privacy@cgsconsultation.com

33. BUSINESS TRANSFERS

In the event of:

  • merger;

  • acquisition;

  • corporate restructuring;

  • financing transaction;

  • bankruptcy;

  • sale of assets;

  • reorganization;

personal information may be transferred to the acquiring entity or successor organization, subject to applicable legal safeguards.

Any successor entity will remain bound by obligations substantially consistent with this Privacy Policy unless users are otherwise notified.

34. LEGAL CLAIMS

CGS may process personal information where necessary to:

  • establish legal claims;

  • exercise legal rights;

  • investigate fraud;

  • defend litigation;

  • comply with court orders;

  • enforce contractual rights;

  • protect clients, employees, and business operations.

Such processing may continue notwithstanding requests for deletion where legally permitted.

35. COMPLIANCE WITH LEGAL OBLIGATIONS

CGS may disclose personal information where required by:

  • applicable laws;

  • judicial proceedings;

  • regulatory authorities;

  • tax authorities;

  • law enforcement agencies;

  • court orders;

  • governmental requests.

Such disclosures shall be limited to the extent legally required.

36. RECORDS OF PROCESSING ACTIVITIES

Where required by Article 30 GDPR, CGS maintains records describing its personal data processing activities.

These records may include:

  • categories of processing;

  • purposes;

  • recipients;

  • international transfers;

  • retention periods;

  • security measures.

37. CHANGES TO THIS PRIVACY POLICY

CGS reserves the right to amend this Privacy Policy at any time to reflect:

  • changes in applicable law;

  • regulatory guidance;

  • technological developments;

  • business operations;

  • security improvements;

  • organizational changes.

Material modifications will be communicated through appropriate means, including publication on the Website.

The "Last Updated" date appearing at the beginning of this Policy indicates the effective date of the current version.

Continued use of the Website after modifications constitutes acknowledgment of the updated Privacy Policy where permitted by applicable law.

38. SEVERABILITY

If any provision of this Privacy Policy is determined by a court or competent authority to be invalid, illegal, or unenforceable, such provision shall be interpreted to the maximum extent permitted by law, and the remaining provisions shall remain in full force and effect.

39. NO WAIVER

Failure by CGS to enforce any provision of this Privacy Policy shall not constitute a waiver of any rights or remedies available under applicable law.

40. GOVERNING LAW

This Privacy Policy shall be governed by and interpreted in accordance with:

  • Regulation (EU) 2016/679 (GDPR);

  • Spanish Organic Law 3/2018 (LOPDGDD);

  • applicable legislation of the Kingdom of Spain;

  • other applicable international privacy legislation where relevant.

41. COMPETENT SUPERVISORY AUTHORITY

Individuals located in Spain have the right to lodge complaints with:

Spanish Data Protection Agency (Agencia Española de Protección de Datos – AEPD)

Website: https://www.aepd.es

Individuals located in other jurisdictions may also contact their local data protection authority where applicable.

CGS encourages individuals to contact us first so that we may seek to resolve privacy concerns promptly and amicably.

42. CONTACT US

If you have questions regarding this Privacy Policy or the processing of your personal information, please contact:

CGS CONSULTATION LLC

Registered Address:

Madrid, Spain

Email:

privacy@cgsconsultation.com

Website:

https://www.cgsconsultation.com

43. ENTIRE PRIVACY POLICY

This Privacy Policy constitutes the complete statement regarding the processing of personal information by CGS CONSULTATION LLC through its Website, consulting services, digital products, communications, and related business activities.

Where additional agreements (including consulting agreements, Data Processing Agreements, Master Services Agreements, Cookie Policy, or Terms and Conditions) apply, they shall supplement this Privacy Policy without limiting any rights provided under applicable data protection legislation.

FINAL STATEMENT

CGS CONSULTATION LLC is committed to maintaining the highest standards of privacy, confidentiality, transparency, and information security. We continuously review and improve our privacy practices to align with evolving legal requirements, technological developments, and internationally recognized best practices in data protection.

bottom of page