Privacy Policy
Last updated: 29/04/2026
Privacy Policy
Data Controller
The data controller of your personal data is:
- Corporate name: Solbizz Canarias S.L.
- Tax ID: CIF B76607415
- Address: Calle Felix Casanova Ayala 44, 38678 Armeñime, Tenerife, Spain
- Data protection contact email: [email protected]
For any matter related to this privacy policy or the processing of your data, you may contact the address above.
Data We Collect
We only collect the data necessary to provide you with the contracted services, comply with the legal obligations applicable to a telecommunications operator, and provide you with the support you need. The categories are as follows:
- Identifying data: name, surnames, ID card (DNI) or foreigner ID (NIE), date of birth. These data are mandatory to activate telecommunications services in Spain.
- Contact data: postal address for installation and billing, email address, telephone number.
- Billing and payment data: IBAN for direct debit (managed through GoCardless), billing and payment history.
- Service identifiers: SIM card ICCID, device IMEI when applicable, assigned telephone number, technical identifier of the fiber or television installation.
- Traffic data (CDR): origin and destination numbers, date and time, call duration, cell identifier, and volume of data consumed. The retention of these data is mandated by Ley 25/2007 (Spanish data-retention law) and is detailed in the Data Retention section.
- Support data: content of your customer service tickets, WhatsApp conversations, and internal notes associated with your account.
- Browsing data: information collected through cookies. Details are in the Cookie Policy.
We do not collect specially protected data (racial origin, ideology, health, etc.), except those strictly necessary for legally regulated processes such as number portability or identity verification.
Purpose of Processing
We process your personal data solely for the following purposes:
- Provision of the contracted service: to register, maintain, and, where appropriate, terminate mobile telephony, fiber internet, television, and home installation services.
- Billing and collection: to issue invoices, manage SEPA direct debit mandates through GoCardless, and claim unpaid debts when appropriate.
- Customer service: to respond to your inquiries, manage incidents, process requests for portability or service changes, and maintain the support history to resolve future queries.
- Compliance with legal obligations: among others, the Ley General de Telecomunicaciones (General Telecommunications Law, LGT), Ley 25/2007 (Spanish data-retention law) regarding electronic communications, tax and accounting regulations, and data protection legislation.
- Security and fraud prevention: to detect and prevent fraudulent activities in the registration of services, the use of the network, or the customer area, as well as to protect the integrity of our systems.
Roxi+ does not send commercial communications or newsletters. We do not use your personal data for marketing purposes, nor do we transfer them to third parties for advertising purposes. We do not maintain commercial distribution lists and we do not collect marketing consent upon service registration.
Legal Basis for Processing
Each purpose described in the previous section is based on one of the following legal bases of the General Data Protection Regulation (GDPR):
- Performance of a contract (Art. 6.1.b GDPR): provision of the contracted service, billing, SEPA mandate management, and customer service arising from the contractual relationship.
- Compliance with a legal obligation (Art. 6.1.c GDPR): retention of traffic data (CDR) pursuant to Ley 25/2007 (Spanish data-retention law), retention of accounting books and invoices pursuant to the Commercial Code, and any other obligation imposed by telecommunications, tax, or data protection legislation.
- Legitimate interest (Art. 6.1.f GDPR): fraud prevention, network and system security, and maintenance of the technical history necessary to resolve incidents. In all cases, we have weighed this interest against your rights and freedoms, and you have the right of opposition as described below.
- Consent (Art. 6.1.a GDPR): solely for the use of non-essential (analytical) cookies, as described in the Cookie Policy. You may withdraw your consent at any time from the cookie banner or from your browser settings.
We do not process your data on the basis of "consent for marketing" because, as indicated in the previous section, Roxi+ does not send commercial communications.
Data Retention
We retain each category of data for the time strictly necessary for the purpose that justifies its processing, complying with the minimum periods imposed by applicable legislation:
- Contract, billing, and payment data: throughout the duration of the contractual relationship and, once terminated, for a minimum of 6 years, pursuant to Article 30 of the Commercial Code and the tax regulations applicable to accounting books and issued invoices.
- Traffic data (CDR): retained for 12 months from the date of the communication, pursuant to Ley 25/2007 (Spanish data-retention law) regarding electronic communications. After this period, they are deleted or anonymized, unless their further retention is required by a competent authority in the context of an ongoing legal investigation.
- Service identifying data (ICCID, IMEI, installation identifiers): retained alongside the contract during its term and, subsequently, during the statute of limitations for applicable contractual actions.
- Support data (tickets, WhatsApp conversations, calls): retained for a maximum of 2 years from the closure of the ticket or incident, unless they are necessary for an open claim or for compliance with a legal obligation.
- Browsing data (cookies): for the period indicated for each cookie in the Cookie Policy.
Once the aforementioned periods have elapsed, the data are deleted or anonymized in a manner that prevents re-identification. Some data may be kept blocked, without active processing, for the time necessary to address potential liabilities arising from the processing.
Recipients and Data Processors
To provide you with the service, Roxi+ relies on technological providers and operators that may process your data as data processors (they follow our instructions and the terms of a data processing agreement pursuant to Art. 28 GDPR) or as independent controllers (when they determine their own purposes and means regarding the essential data they need to process).
Data processors:
| Provider | Purpose | Country | Basis for transfer |
|---|---|---|---|
| Hetzner Online GmbH | Hosting of the web infrastructure and databases | Germany | Intra-Community transfer (EU → EU) |
| Cloudflare, Inc. | Content Delivery Network (CDN) and protection against attacks | United States | EU-US Data Privacy Framework |
| Mandrill (Mailchimp Transactional) | Sending transactional emails only (password resets, invoices, service notifications) | United States | EU-US Data Privacy Framework |
| GoCardless Ltd. | SEPA mandates and bank collections | United Kingdom | EU adequacy decision — United Kingdom |
| GreenAPI | WhatsApp Business gateway for support | Latvia | Intra-Community transfer |
| Holded | ERP, billing, and internal CRM | Spain | Intra-Community transfer |
| Google Workspace and Google Drive | Corporate email and encrypted backups | United States | EU-US Data Privacy Framework |
| Firebase Cloud Messaging (Google) | Push notifications for internal applications | United States | EU-US Data Privacy Framework |
Independent controller:
-
Xfera Móviles, S.A.U. (MasOrange Group, Spain) — wholesale operator of the telecommunications network over which Roxi+ provides its services. Xfera Móviles acts as an independent controller of the processing regarding the essential data for number portability, service activation on its network, and the technical operation of communications. Xfera Móviles' privacy policy applies to these processing activities.
-
Orange Espagne, S.A.U. (Spain) — provider of the VuelaTV television service, which Roxi+ resells. Orange Espagne acts as an independent controller of the processing involved in providing the television service itself (sign-up, activation, VuelaTV account management and technical support for the service), and its privacy policy applies to those activities. Roxi+, as the reseller, issues the telecommunications invoice that includes the VuelaTV amount and manages its collection; for that purpose it processes your identification and billing data solely to invoice and collect, on the basis of the performance of your contract with Roxi+ (art. 6.1.b GDPR) and on the terms described in this policy. If you need a VuelaTV invoice as such, it is requested from Orange Espagne, S.A.U. through Roxi+.
Roxi+ does not transfer your data to third parties for purposes other than those described in this policy. We do not sell, rent, or share them with advertisers.
International Transfers
Some of our data processors are established outside the European Economic Area. In such cases, international transfers are only carried out when there is an adequate legal safeguard pursuant to the GDPR:
- United States (Cloudflare, Mandrill, Google Workspace, Google Drive, Firebase Cloud Messaging): the transfer is covered by the EU-US Data Privacy Framework, an adequacy decision by the European Commission dated July 10, 2023, and all these providers are certified under this framework.
- United Kingdom (GoCardless): the transfer is covered by the European Commission's adequacy decision regarding the United Kingdom dated June 28, 2021.
The remaining providers process data within the European Economic Area (Germany, Spain, Latvia), and therefore these do not constitute international transfers.
If you wish, you may request a copy of the applicable safeguards from [email protected].
Your Rights
As a data subject whose data we process, you have the following ARCO+ rights (access, rectification, erasure, opposition, limitation, portability) recognized by the GDPR and by Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD, Spanish data-protection law):
- Right of access: to obtain confirmation as to whether we are processing your data and, if so, to receive a copy thereof.
- Right of rectification: to correct inaccurate or incomplete data.
- Right of erasure ("right to be forgotten"): to request the deletion of your data when they are no longer necessary for the purpose for which they were collected.
- Right of opposition: to object to the processing of your data on grounds relating to your particular situation, especially in processing based on legitimate interest.
- Right to limitation of processing: to request that the processing of your data be restricted under certain circumstances.
- Right to portability: to receive the data you have provided to us in a structured, commonly used, and machine-readable format, or to request that we transmit them directly to another data controller.
- Right to withdraw consent: when the processing is based on your consent (e.g., analytical cookies), you may withdraw it at any time, without affecting the lawfulness of the prior processing.
How to exercise your rights:
Send an email to [email protected] clearly indicating the right you wish to exercise, along with a copy of your ID card (DNI) or foreigner ID (NIE) to verify your identity. We will respond to your request within a maximum period of one month from its receipt, extendable by two additional months in particularly complex cases, in which case we will inform you of the extension and its reasons.
Complaint to the supervisory authority:
If you consider that the processing of your data does not comply with the regulations, or that your request to exercise your rights has not been adequately addressed, you have the right to file a complaint with the AEPD, located at C/ Jorge Juan, 6, 28001 Madrid, or through its electronic office: https://www.aepd.es.
Cookies
The Site uses its own cookies and, with your consent, analytical cookies. Details of each cookie, its purpose, its duration, and how to manage your preferences are available in the Cookie Policy.
Analytics
At the time of writing this policy, Roxi+ does not run web analytics tools on the Site.
When, in the future, Google Analytics 4 is activated to obtain aggregated and anonymous statistics on the use of the Site, it will be done exclusively with your explicit consent through the cookie banner, with an anonymized IP, and under Google's consent mode v2. Until then, no analytical measurement of any kind is performed.
Any changes to this section will be reflected in the Cookie Policy and in the date of the last update at the bottom of this policy.
Hosting and Backups
The technical infrastructure of Roxi+ — including the website, databases, and internal systems — is hosted in the data centers of Hetzner Online GmbH in Falkenstein (Saxony, Germany), within the European Economic Area. The data transfer to this provider is therefore considered intra-Community.
We perform encrypted backups on a daily basis. These backups are kept for 7 days on the infrastructure itself and are replicated for another 7 days on Google Drive (Google Workspace), in order to ensure recovery in the event of technical incidents. The transfer to Google Drive is covered by the EU-US Data Privacy Framework, as indicated in the preceding sections.
Data are encrypted both in transit (HTTPS/TLS) and at rest. Access to the servers and backups is restricted to authorized personnel of Solbizz Canarias S.L. and to providers acting as data processors under a signed contract pursuant to Article 28 of the GDPR.