Skip to content
JX Systems

Legal

Privacy policy

What data we collect through this website, what for and what choices you have, in plain language and according to how this site actually works.

Last updated:

Who we are

This policy explains how MAGNA GLOBAL LLC ("JX Systems", "we") handles the personal data it collects through this website, including the Digital Growth Audit, the contact form, the quote form, the consultation request and the conversations you start on WhatsApp from the site. We decide how and why that data is used, so we are responsible for it.

Our services are aimed at entrepreneurs, professionals and companies. Even so, the data of the people who write to us, including when they do so on behalf of their business, is personal data and this policy applies to it. The data of our clients' customers that we process on their behalf follows other rules; see When we process data on behalf of a client.

If you have questions about this policy or about your data, use our contact form or message us on WhatsApp.

What data we collect

We collect what you type into a form or send us on WhatsApp, what is needed for the site to work securely and, only with your consent, analytics data.

When you request a Digital Growth Audit

  • Your business: company name, website address (optional), country, sector and company size.
  • Your current systems: approximate monthly volume of leads, the CRM you use, the channels leads come through, how follow-up works and how you measure results.
  • Your goals: your main challenge and any details you add, the areas you are interested in, your timeline and, if you choose to share it, a budget range.
  • Your contact details: your name and your email address.
  • Your consent: recorded with the date and time, the text you accepted and its version.
  • The audit result: the full report is shown in your browser. With your request we save its main priorities and whether the website review could be run.

When you use the contact form

  • Your name and your email address.
  • Company and website (both optional).
  • The area you are interested in, a description of your situation, the result you expect (optional) and your timeline (optional).
  • Your consent, recorded in the same way.

When you ask for a quote

  • Your name, your email address and, if you choose to provide it, your phone number.
  • Your company and your country.
  • The systems or membership you are interested in, your budget, your timeline and the message you write.
  • How you prefer us to contact you: by WhatsApp, by email or with a call.
  • Your consent, recorded in the same way.

When you request a consultation

  • Your name and your email address.
  • The day and time you choose, your time zone and what you would like to solve (optional).
  • Your consent, recorded in the same way.

If the booking page shows the calendar of an external service, what you enter in that calendar is received by that service; see Service providers.

When you pay

  • If you pay by transfer (Mercury or Wise), we receive the details your bank includes in the transfer, such as the name of the payer, the amount and the reference.

When you message us on WhatsApp

Your phone number, your profile name and the messages you send us. We explain this in the WhatsApp section.

Attribution data

When you submit any of the forms, information about how you arrived at the site is included: the UTM parameters of the link you followed, if it had any (source, medium, campaign, content and term), the page you entered through, the address of the website that referred you (without query parameters) and when they were recorded. This covers your first visit and, if different, your most recent visit from a campaign or a referring site.

Information we derive

From your answers we calculate a priority score using fixed rules (for example, the timeline, the company size and the areas you are interested in) and a suggested next step for our team. If AI processing is enabled, we may also create an internal preparation summary; see AI processing.

Technical data

To limit repeated submissions, our server uses your IP address and keeps it only in the memory of the process, during the 10-minute window of the submission limit. Expired entries are deleted in a cleanup that runs at least once a minute. The IP address is not saved with your request. Our application logs record operational events (for example, that an audit finished or that an email could not be delivered) with email addresses masked. As on most websites, our hosting infrastructure may also record standard data about each request, such as the IP address, the browser type, the page requested and the time, for security and operational reasons.

We do not ask you for sensitive information, such as health data, financial account data or identity documents. Please do not include it, or personal data of other people, in the free-text fields or in your WhatsApp messages.

How we use your data

  • To prepare your audit: run the automatic website checks and generate the report from them and from your answers.
  • To prepare your quote: understand what you need and prepare a quote for you with the scope defined in writing.
  • To respond to you: answer your inquiry and discuss your audit or your quote by email or, if you tell us so in the quote form or message us that way, by WhatsApp or with a call.
  • To qualify and follow up: save your request in our CRM, notify our team by email, prioritize the review using the score described above and, if enabled, send you a confirmation email. The score orders our work; it does not decide whether we respond to you.
  • To provide the services you hire: communicate with you during the project, the maintenance plan and support, and send you the written minutes of each conversation.
  • To collect payment and invoice: record your payments, issue invoices and meet accounting and tax obligations.
  • To improve the site: understand which pages and channels generate inquiries, using attribution data and, only with your consent, analytics.
  • To keep the site secure: prevent spam and abuse, and investigate errors.

Legal bases

The rules that apply depend on where you live.

If you are in Spain, in another country of the European Economic Area or in the United Kingdom

The General Data Protection Regulation (GDPR) or its UK equivalent applies, and we rely on:

  • Consent: to process your audit, contact or quote request as described here, and for analytics cookies. You can withdraw your consent at any time; this does not affect the processing that has already taken place.
  • Performance of a contract: to provide, collect payment and invoice for the services you hire. If you hire them on behalf of a company, we process your business contact details on the basis of our legitimate interest in maintaining that relationship.
  • Legal obligation: to keep the payment records required by accounting and tax rules.
  • Legitimate interest: to keep the site secure, understand which channels generate inquiries, prepare our follow-up internally, respond to the conversations you start on WhatsApp and keep a record of the consent you gave. You can object to this processing (see your rights).

If you are in the United States, in Latin America or in another country

The data protection laws of your country or state apply. We use your data only for the purposes described in this policy and, when the law requires it, with your consent, which we record when you submit a form.

Automatic website checks

When you enter a website address in the audit, our server downloads public resources from that site once: the HTML of the page at that address (normally the home page), the robots.txt file and the XML sitemap (at /sitemap.xml or at the location declared in robots.txt). The requests identify themselves as "JXSystemsAudit". We do not sign in, we do not submit forms and we do not run the site's JavaScript, and we block requests to private networks and to non-standard ports. With those same requests, we measure, from our own server, how long the site takes to start responding.

If Google PageSpeed Insights is enabled on our side, the website address is also sent to Google's PageSpeed Insights service to measure performance. That request contains only the website address, not your name, your email or your answers.

What the checks read is used only to generate the findings of your audit.

WhatsApp

If you message us on WhatsApp, from a button on this site or directly, the conversation takes place on WhatsApp, a Meta service, and is governed by WhatsApp's terms and privacy policy.

The WhatsApp buttons on the site open WhatsApp with an opening message already written, which you can edit or delete. Nothing is sent until you send it from WhatsApp. If you accepted analytics, we record that you clicked the button, but never the content of your messages.

When you message us, we receive your phone number, your WhatsApp profile name and the messages and files you send us. We use them to respond to you and we may record your inquiry in our CRM (for example, your name, your number and a summary of what you need) to follow up on it like any other request. WhatsApp conversations are not sent to any AI provider.

If you ask us to delete the conversation, we will delete our copy and the record in our CRM. What remains on your device or on WhatsApp's services is governed by their own terms.

AI processing

If AI processing is enabled on our side, the business context of your request may be sent to an AI provider to create an internal preparation summary for our team. Depending on the form you use, that context may include: the type of form; your company, website, country, sector and company size; the areas, systems or membership you are interested in; the problem or need you described, including the message of your quote; the result you expect, if you stated it in the contact form; your timeline and your budget range; your contact preference; your answers about your current systems; the priority score and selected findings from the audit. Your name, your email address and your phone number are not included. If you type personal data in the free-text fields, it is sent as well, so please do not include it.

The summary is marked as an AI-generated draft, is saved with your request for internal review and is never sent to you. It supports our preparation; it does not make decisions about you. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.

The Digital Growth Audit itself is generated by a deterministic rules engine, not by AI.

Service providers

We use service providers to operate the site and manage requests. Because the specific providers may change, we describe them here by category:

  • Hosting and infrastructure: serves the site and runs the audit and the processing of the forms.
  • CRM, database or integration platform: stores the records of the requests.
  • Email sending: delivers the notices to the team and, if enabled, the confirmation emails.
  • Messaging: WhatsApp (Meta), only if you choose to message us that way.
  • Payments: Mercury and Wise, if you pay by transfer. They handle payment data under their own terms as financial institutions.
  • Analytics: Google Analytics 4, only if you accept analytics cookies.
  • AI: creates internal preparation summaries, if enabled.
  • Performance measurement: Google PageSpeed Insights, if enabled; it only receives the website address.
  • Booking calendar: if enabled, the service that hosts the calendar on the booking page. It loads only if you ask for it; it then receives your visit, may use its own cookies and receives the details you enter in it.

Providers that process personal data on our behalf may use it only to provide their service to us. WhatsApp handles conversation data under its own terms. You can ask us for the current list of providers. We do not sell personal data. Apart from these providers, we disclose it only when the law requires us to.

When we process data on behalf of a client

This policy covers the data we are responsible for. When we build or maintain a client's system (for example, its website, its forms or its CRM), we process the personal data of its customers and contacts as a processor, on behalf of that client, which is the controller: we only follow its instructions, with a duty of confidentiality and with the safeguards of the data processing agreement we sign with it (Article 28 of the GDPR, where it applies).

If your data reached us through the website or the system of one of our clients, see that client's privacy policy and send your requests to it. If you write to us, we will pass them on.

Cookies and local storage

The site only stores something in your browser when analytics is enabled: that is when the cookie notice appears. This is everything it stores, what it contains and how long it lasts.

Strictly necessary

  • jx_consent (this site's local storage): your choice about analytics (accept or reject), the date you made it and the version of the notice. It is kept for 12 months from that date; after that, or if the version of the notice changes, it is deleted and we ask you again. It is necessary for the consent notice to work and it does not identify you.

Analytics (only if you accept it)

If you accept analytics, the site loads Google Analytics 4, which sets its own cookies to measure visits and interactions; for example, page views, button clicks (including WhatsApp ones) and whether a form was started or submitted. The details of each event describe the interaction; form contents, names and email addresses are not sent to Google Analytics. If you reject it, Google Analytics is not loaded.

  • _ga and _ga_<ID> (Google Analytics 4 cookies): they distinguish visits and sessions. They last up to 2 years, which is the duration Google Analytics 4 gives them by default. They are deleted if you reject analytics or when your choice expires.

Attribution data

Attribution data (described above) is kept in memory while you browse and is only written to your browser's storage if you accept analytics:

  • jx_first_touch (local storage): your first visit, with the campaign parameters of the address, the site you came from (its domain and path only), the entry page and the date. It is deleted if you reject analytics or when your choice expires (12 months).
  • jx_last_touch (session storage): the same for your most recent visit from a campaign or a referring site. It is deleted when the browser session ends.

Changing your choice

When analytics is enabled, the "Cookie settings" link in the footer lets you change your choice at any time. You can also delete this site's data from your browser settings. When analytics is not enabled, no analytics cookies are set, the notice is not shown and the site stores nothing in your browser.

Booking calendar (if enabled)

If the site shows an external calendar to book the consultation, it only loads when you press "View the calendar". The service that hosts it then receives your visit and may use its own cookies, under its own terms.

We do not use advertising cookies.

How long we keep data

  • Data from requests, audits, quotes and WhatsApp inquiries (including consent records and internal summaries): up to 24 months after our last interaction with you, unless a client relationship requires keeping them longer; for example, to deliver a project or to meet legal, tax or accounting obligations.
  • Payment records and invoices: for the period required by the applicable accounting and tax rules.
  • IP address for the submission limit: only in the memory of the server process, during the 10-minute window; after that it is deleted in the next cleanup, which runs at least once a minute.
  • Technical logs: for a shorter period, only as long as needed for security, troubleshooting and abuse prevention.
  • Analytics data: according to the data retention setting of our analytics account.
  • Browser storage and cookies: your choice about cookies is kept for 12 months from the day you make it; after that it is deleted and we ask you again. The attribution of your first visit, saved only with consent, is kept while your choice remains valid or until you reject analytics; that of your most recent visit is deleted when the browser session ends. Google Analytics cookies last up to 2 years and are deleted if you reject analytics or when your choice expires.

Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and receive a copy;
  • correct inaccurate data;
  • delete your data;
  • object to processing based on legitimate interest, including follow-up;
  • restrict how we use your data;
  • receive your data in a portable format;
  • withdraw your consent at any time.

In several Latin American countries, the rights of access, rectification, cancellation and objection are known as ARCO rights. To exercise any of these rights, use our contact form or message us on WhatsApp. We may need to confirm your identity before handling a request, and we will respond within the period required by applicable law.

You also have the right to lodge a complaint with a data protection authority; normally, the one in the country where you live or work, or where you believe the problem occurred (in Spain, the Spanish Data Protection Agency, Agencia Española de Protección de Datos). We would appreciate it if you first gave us the opportunity to resolve it.

International transfers

Our service providers may store or process data in countries other than yours, including the United States. When personal data is transferred from the European Economic Area, the United Kingdom or Switzerland to a country that is not recognized as providing an adequate level of protection, we rely on appropriate safeguards, such as the European Commission's standard contractual clauses or the equivalent UK mechanisms.

Security

We protect personal data with technical and organizational measures proportionate to the data we handle, including:

  • encrypted connections (HTTPS) between your browser and the site;
  • server-side validation of every submission, submission limits and spam protection;
  • a website checker that only connects to public addresses on standard web ports and re-checks every redirect;
  • credentials and API keys stored in the server configuration, never in the browser;
  • email addresses masked in the application logs;
  • access to request data limited to the people who need it.

No system is completely secure. If we detect a security breach that affects your data, we will notify you and the competent authorities when the law requires it.

Minors

This site is aimed at businesses and is not intended for minors under 16. We do not knowingly collect their personal data. If you believe a minor has sent us information, use our contact form or message us on WhatsApp and we will delete it.

Changes to this policy

When we change how we handle personal data, we will update this page and the date shown above. Each form submission saves the version of the consent text you accepted, so we know which version applied to your data.