SICA · Legal

SICA Privacy Policy

Version 1.0 — 9 September 2026

This English text is a courtesy translation. The binding version is the Spanish version; in case of discrepancy, the Spanish text prevails.

1. Data controller

The controller of the personal data processed through SICA is:

VISUALNACERT, S.L.
Tax ID (CIF): B98655889
C/ Mayor 41
46138 Rafelbuñol, Valencia, Spain.

Privacy e-mail and Data Protection Officer contact: privacy@visualnacert.com

This Policy describes how VisualNACert collects, uses, retains, shares and protects the personal data processed through SICA.

2. What SICA is

SICA is a technology platform for recording, managing, locating and analysing information related to incidents, phenomena and events that may affect farms, livestock holdings and the land.

SICA Campo is mainly intended for users to record declarations and information.

SICA Geo and SICA Analytics are environments restricted to users expressly authorised by the relevant organisations.

3. Personal data we may process

Depending on the features used, SICA may process the following categories of information.

Identification and contact data

Account and authentication data

Farm and agricultural activity data

Incident data

Location data

Photographs and metadata

SICA may process photographs provided by the user and their associated metadata, including, where available:

Photographs are intended to document incidents and their main purpose is not to identify or photograph people.

However, a photograph may accidentally contain people or other identifiable elements.

Technical data

The following may also be processed:

4. What we use the data for

VisualNACert may process personal data for the following purposes.

A. Creating and managing the account

Includes:

B. Recording and managing incidents

Includes:

C. Territorial representation and analysis of the information

Data may be used for:

D. Analysing climatic and agronomic phenomena

SICA may use the information to study, among other things:

E. Prevention, surveillance and early-warning systems

The information may be used to develop or improve methods intended to:

F. Research and statistical analysis

The information may be used for:

Wherever possible, these activities will rely on aggregated, anonymised or pseudonymised information.

G. Planning and public policy

Results obtained through SICA may contribute to:

H. Improving SICA

Data may be used, with appropriate safeguards, to:

Anonymised or pseudonymised information will be used whenever the purpose can be achieved without identifying users.

I. Security and fraud prevention

We may process information to:

J. Compliance with legal obligations

VisualNACert may retain or disclose certain information where necessary to comply with legal obligations or valid requests from competent authorities.

5. Compatible further uses

VisualNACert may carry out further processing related to the above purposes where it is compatible with the purpose for which the data were originally collected.

To assess that compatibility the following will be taken into account, among other aspects:

Where a new use is not compatible with the original purposes, VisualNACert must have another valid legal basis and provide the data subject with the additional information required by law.

The existence of this clause does not constitute a blanket authorisation to use personal data for any purpose.

6. Legal bases

The main applicable legal bases are:

Provision of the service

Account management, authentication, use of SICA Campo and provision of the requested features are based mainly on the need to perform the relationship with the user and provide the requested service.

Legitimate interest

VisualNACert may base certain processing on its legitimate interest where proportionate and where users' rights do not prevail.

Among others:

Consent

Consent will be requested where necessary, particularly for optional features requiring device permissions and where required by law.

The user may withdraw permissions from their device's operating system.

Withdrawal of consent does not affect the lawfulness of processing carried out beforehand.

Legal obligation

Certain processing may be necessary to meet legal obligations applicable to VisualNACert.

Research and statistics

Further processing for scientific, historical or statistical purposes will be carried out in accordance with applicable law and with the necessary safeguards, especially minimisation, pseudonymisation or anonymisation where appropriate.

VisualNACert will not, on its own, base processing on the exercise of public powers merely because a Public Administration uses SICA.

7. Geolocation

SICA may request permission to access the device's location.

Location will be used only for SICA-related features, mainly:

SICA does not use geolocation to continuously track the user's movements.

The user can control and withdraw location permissions in their device settings.

VisualNACert recommends allowing location access only while the app is in use, where the operating system offers that option.

8. Photographs

Photographs provided will be used to document recorded incidents.

It is neither necessary nor advisable to photograph people when not required.

Where an image accidentally includes third parties' personal data, VisualNACert may take measures to limit its processing, hide it or delete it where clearly unnecessary or inappropriate.

Coordinates, date, time and other metadata associated with photographs may be used to verify and contextualise the incident.

9. Who can access the data

The user

Each user may access their own communications and the features enabled for their profile.

VisualNACert

Expressly authorised staff may access the information where necessary to:

Authorised organisations

Public Administrations, cooperatives, associations or other organisations using SICA may have authorised users with access to SICA Geo, SICA Analytics or other restricted modules.

Access will be limited to the scope of information and level of detail corresponding to their authorisation.

Wherever the purpose can be achieved without identifying the user, aggregated or pseudonymised information will be provided where possible.

Where a recipient organisation subsequently processes personal data for purposes it determines independently, that organisation may become an independent controller of that processing and will be subject to its own data protection obligations.

10. Service providers

VisualNACert may use technology providers acting as processors where necessary to operate SICA.

These may include providers of:

These providers are bound by the contractual obligations required by data protection law.

11. Hosting and international transfers

SICA's main infrastructure is hosted on Amazon Web Services, Frankfurt region, Germany.

SICA is configured so that its operational data remain within the European Union or the European Economic Area.

Should an international transfer of personal data become necessary in the future, VisualNACert will only carry it out where an appropriate legal mechanism exists under the GDPR and will provide data subjects with the necessary information.

12. Retention periods

VisualNACert applies the following retention criteria, unless a legal obligation, claim or justified circumstance requires a different period.

Account data

Retained while the account remains active.

After cancellation, data needed to evidence the relationship and address potential liabilities may be kept duly blocked for a general maximum of five years, after which they will be deleted or anonymised, unless another legal period applies.

Incidents and data linked to the user

Incidents directly linked to an identified person may be kept for five years from their recording or from the last relevant action on them, unless additional retention is justified.

After that period, the direct link to the user will be removed where possible, retaining only the information needed for historical, territorial, scientific or statistical analysis through anonymisation or, where necessary, pseudonymisation and reinforced measures.

Photographs

Identifiable photographs will be kept while needed to document the incident and, as a general rule, for a maximum of five years.

After that period they will be deleted, unless a legal, scientific, technical or claims-defence reason justifies additional retention with appropriate safeguards.

Anonymised information

Information that has been effectively anonymised and no longer allows a person to be reasonably identified may be retained without a predetermined period for statistical, scientific, historical, agronomic or territorial purposes.

Security logs

Ordinary technical logs are kept, as a general rule, for up to 12 months.

They may be kept longer where related to a security incident, investigation, fraud or claim.

Obligations and claims

Where necessary, certain information may be blocked for the applicable statutory limitation periods.

13. Minors

Where processing is based on consent:

SICA may set up a specific procedure for these cases.

Information aimed at minors will be provided in clear and understandable language.

14. Automated decisions

SICA may use automated tools to classify, group, detect patterns or generate analyses.

SICA is not designed to make, solely by automated means, decisions that produce legal effects on the user or similarly significantly affect them.

Nor does SICA's information by itself constitute an administrative decision, recognition of a right, claim notification or decision on compensation.

15. Security

VisualNACert applies technical and organisational measures aimed at protecting data against:

These measures include access controls, profile and permission management, authentication mechanisms, communications security, backups, monitoring and incident-management procedures.

No system can guarantee absolute security, so the measures will be reviewed and updated according to risk and technological developments.

16. Users' rights

Where applicable, the user may exercise the rights of:

Requests may be sent to: privacy@visualnacert.com

VisualNACert may request reasonable information to verify the identity of the requester where necessary.

The user may also lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos) if they consider that the processing of their data does not comply with the law.

17. Deleting an account

The user may request the cancellation of their account.

Deleting the account does not necessarily mean the immediate deletion of all information previously provided where:

Where possible, the user's identity will be unlinked from historical information that must be kept.

18. Changes to this Policy

VisualNACert may update this Policy as a result of regulatory, technological, functional or data-processing changes.

Where changes are material, the user will be informed through SICA, e-mail or another appropriate means.

Where new processing requires consent, it will be requested expressly.

19. Contact

For any enquiry about the processing of personal data:

Data Protection Officer
VISUALNACERT, S.L.
privacy@visualnacert.com
C/ Mayor 41
46138 Rafelbuñol
Valencia, Spain.