This Privacy Policy explains how ONETOUCH SA de CV (“Onetouch”, “we”, “us” or “our”) collects, uses, stores and otherwise processes personal data in connection with: https://onetouch.hn; contact and project enquiry forms; newsletter subscriptions; advertising and lead-generation campaigns; email and business communications; and related digital services and interactions.
ONETOUCH SA de CV is established in Honduras and provides creative and technology services internationally, including to clients and prospective clients located in the European Union (“EU”) and European Economic Area (“EEA”). Where our processing falls within the territorial scope of Regulation (EU) 2016/679 (“GDPR”), we process personal data in accordance with the GDPR and other applicable data-protection and electronic-communications requirements.
1. Data Controller
The controller responsible for the processing described in this Privacy Policy is:
ONETOUCH SA de CV
RTN: 05019019096875
Nuevos Horizontes, Avenida Principal, 21101, San Pedro Sula, Cortés, Honduras
Telephone: +504 9463-6167
Privacy contact: privacy@onetouch.hn
European privacy contact
For privacy matters relating to individuals located in the European Union or European Economic Area, you may also contact:
Alejandro Adain Navarro Gorraiz
Spain
Email: alejandro@onetouch.hn
Privacy and data-protection requests should preferably be sent to privacy@onetouch.hn. This contact point is intended to facilitate communication with individuals and European supervisory authorities. Its description may be updated if Onetouch formally designates a representative in the European Union pursuant to Article 27 GDPR or establishes an entity or establishment in the EU.
2. Personal Data We Collect
The personal data we process depends on how you interact with Onetouch.
2.1 Contact and project enquiry data
When you contact us or submit a project enquiry, we may collect: full name; business or personal email address; company or organisation name; telephone number, where provided; requested service or area of interest; project description or brief; indicative budget; indicative timeline or deadline; how you heard about Onetouch; files or documents you voluntarily attach; preferred communication information; and any other information you voluntarily include in your enquiry.
2.2 Lead-generation and advertising forms
If you submit information through a lead-generation form operated by an advertising or social-media platform, we may receive information that you chose to provide through that platform, such as: name; email address; telephone number; company; professional role; project or service interests; and campaign or lead-source information. The relevant advertising platform may separately process personal data under its own privacy terms.
2.3 Newsletter information
If you subscribe to our newsletter or marketing communications, we may process: email address; name, where provided; company, where provided; language or communication preferences; subscription source; date and time of subscription; consent status; unsubscribe status; and information reasonably necessary to demonstrate or manage your subscription preferences.
2.4 Technical and usage information
When you use our website or submit a form, we may automatically process limited technical information such as: public IP address; browser and user-agent information; device type; operating system; submission or request timestamp; referring URL; landing-page URL; current page URL; approximate country or region derived from the IP address; campaign attribution parameters, such as UTM parameters; and technical information necessary for fraud prevention, security, debugging and service availability. We seek to limit technical-data collection to information reasonably necessary for these purposes.
2.5 Communications
If you communicate with Onetouch by email, telephone, forms or other business channels, we may retain: correspondence; enquiry history; proposals and commercial discussions; follow-up communications; meeting information; and information necessary to manage the business relationship.
2.6 Special categories of personal data
Onetouch does not intentionally request special categories of personal data under Article 9 GDPR, including information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric information, health information, or information concerning a person's sex life or sexual orientation.
Please do not include sensitive personal information in project descriptions, correspondence or attachments unless it is strictly necessary and lawful to do so. Where sensitive information is provided to us unintentionally, we may delete it or restrict access to it unless its continued processing is legally necessary and permitted.
3. Purposes and Legal Bases for Processing
3.1 Responding to enquiries and potential projects
We process personal data to: respond to your request; understand your project; determine whether and how Onetouch can assist; prepare estimates or proposals; discuss services, scope, budget and timelines; arrange meetings; and take steps towards a potential contractual relationship.
Where you personally request services or pre-contractual measures, processing may be based on Article 6(1)(b) GDPR. Where you contact us in your professional capacity on behalf of a company or organisation, processing may be based on our legitimate interests under Article 6(1)(f) GDPR in responding to business enquiries, developing professional relationships and conducting our business.
3.2 Transactional communications
We may send communications necessary to: confirm that we received a request; respond to an enquiry; provide requested information; arrange a meeting; send a proposal; or continue a business conversation initiated by you. These messages are transactional or business communications and are based on the legal basis applicable to the underlying enquiry.
3.3 Newsletter and marketing communications
If you voluntarily subscribe to our newsletter or other marketing communications, we may use your contact information to send: Onetouch news; editorial content and insights; case studies; invitations; service updates; company announcements; and other marketing communications relating to Onetouch. Where required by applicable law, this processing is based on your consent under Article 6(1)(a) GDPR.
Subscribing to marketing communications is optional and is not required in order to submit a contact or project enquiry. Submitting a contact form does not automatically subscribe you to the Onetouch newsletter. You may withdraw your consent or unsubscribe at any time.
3.4 Advertising, campaign measurement and attribution
Onetouch may use search engines, professional networks, social networks and advertising platforms to promote its services and reach prospective clients. Where permitted by applicable law and subject to your consent where required, we may process limited information to: measure campaign effectiveness; determine which campaign or advertisement generated a visit or enquiry; attribute conversions; improve campaign performance; measure aggregated website activity; and understand the effectiveness of our marketing investments.
Where advertising or measurement technologies require access to or storage of information on your device, non-essential technologies will be subject to the consent requirements described in our Cookie Policy.
3.5 Website and form security
We may process technical information to: prevent spam; prevent automated abuse; apply rate limits; detect malicious requests; verify form integrity; protect files and systems; diagnose technical incidents; and maintain website availability and security. The legal basis is our legitimate interest under Article 6(1)(f) GDPR in maintaining secure and reliable digital services.
3.6 Legal claims and compliance
We may process personal data where necessary to: establish, exercise or defend legal claims; investigate fraud or unlawful activity; protect the rights and property of Onetouch; respond to valid requests from competent authorities; or comply with legal requirements that apply to us. The applicable legal basis may include Article 6(1)(c) GDPR where processing is required by a legal obligation applicable to Onetouch or Article 6(1)(f) GDPR where processing is necessary for our legitimate interests in protecting and defending our legal rights.
4. Privacy Policy Acknowledgement and Consent
Where a contact or project form asks you to confirm that you have read this Privacy Policy, that acknowledgement is intended to demonstrate that privacy information has been provided to you. It is not used as the legal basis for processing information necessary to respond to your enquiry.
Where consent is required for a separate purpose, such as newsletter subscription or certain advertising technologies, Onetouch requests that consent separately. Consent controls for marketing are intended to be: separate from mandatory contact-form fields; optional; specific to the relevant purpose; and capable of being withdrawn.
5. Service Providers and Recipients
We use selected third-party service providers to operate our website, forms, communications and digital infrastructure. Depending on the processing involved, recipients may include:
- Vercel Inc. — website hosting, content delivery, edge infrastructure, server-side execution and related technical services.
- Resend / Plus Five Five, Inc. — transactional email delivery and related email infrastructure.
- Kloudend, Inc. — ipapi.co — may be used for server-side IP-based approximate geolocation, where enabled, for purposes such as security, localisation or enquiry routing.
- Sanity — used as part of Onetouch's content-management infrastructure. Contact-form submissions are not intended to be stored in Sanity unless our implementation changes and appropriate safeguards are applied.
- Advertising and analytics providers — where enabled, Onetouch may use advertising, analytics or campaign-measurement services provided by companies such as search engines, social-media platforms or professional networks. Where these services involve non-essential cookies, pixels, local storage or similar technologies, they will be subject to applicable consent requirements. Additional information is provided through our Cookie Policy and consent-management interface.
- Professional advisers — where necessary, personal data may also be disclosed to professional advisers such as lawyers, accountants, auditors, consultants, insurers and information-security specialists.
- Public authorities — we may disclose information to courts, regulators, law-enforcement bodies or other competent public authorities where we are legally required or permitted to do so.
We do not sell personal data.
6. International Processing and Transfers
ONETOUCH SA de CV is established in Honduras. Personal data submitted to Onetouch may therefore be accessed and processed by authorised Onetouch personnel in Honduras for the purposes described in this Privacy Policy. Where the GDPR applies to our processing, Onetouch remains responsible for complying with the applicable GDPR requirements regardless of where processing takes place.
Some of our technology and service providers may process personal data in the United States or other countries outside the EEA. Where Onetouch makes personal data available to a separate controller or processor outside the EEA and the disclosure constitutes an international transfer subject to Chapter V GDPR, we use an appropriate legal transfer mechanism where required.
Depending on the provider and circumstances, safeguards may include: an applicable adequacy decision; participation in an applicable approved data-transfer framework; European Commission Standard Contractual Clauses; contractual, technical and organisational supplementary safeguards; or another lawful transfer mechanism recognised under applicable data-protection law.
You may request further information about the safeguards applicable to a particular transfer by contacting privacy@onetouch.hn.
7. Cookies and Similar Technologies
Our website may use cookies and similar technologies. Technologies that are strictly necessary for website operation, security or delivery may be used where permitted without consent. Analytics, advertising, personalisation or other non-essential technologies that require consent under applicable law will not be intentionally activated until the appropriate consent has been obtained. Where consent is requested, you should be able to manage your choices through the website's consent-management interface.
Further information about the technologies we use, their providers, their purposes, their duration, and how to withdraw or modify consent is provided in our separate Cookie Policy.
8. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected and for any applicable legal, accounting, security or claims-related requirements.
Contact and project enquiries
Enquiries that do not result in an ongoing business relationship are generally retained for up to 12 months from the last substantive interaction. After this period, the information will be deleted or anonymised unless continued retention is reasonably necessary for legal claims, security or another lawful purpose.
Client relationships
Where an enquiry results in a contractual relationship, relevant information may be retained for the duration of the relationship and thereafter for any periods required by applicable commercial, tax, accounting or limitation laws.
Newsletter subscriptions
Newsletter and marketing subscription information may be processed until: you unsubscribe; you withdraw your consent; the communication programme is discontinued; or the information is otherwise no longer reasonably required. Following an unsubscribe request, we may retain a minimal suppression record where necessary to ensure that the request continues to be respected and to demonstrate compliance.
Technical and security information
Technical logs may be retained for up to 12 months, depending on their purpose, unless a longer period is reasonably necessary to investigate a security incident, fraud, abuse or unlawful activity.
9. Your Rights
Where the GDPR applies to the processing of your personal data, you may have the right to:
- Access your personal data and obtain information about how it is processed.
- Rectify inaccurate or incomplete personal data.
- Request erasure where the requirements of Article 17 GDPR are met.
- Request restriction of processing where the requirements of Article 18 GDPR are met.
- Data portability for certain data you provided to us where Article 20 GDPR applies.
- Object to processing based on legitimate interests under Article 21 GDPR.
- Object at any time to direct marketing involving your personal data.
- Withdraw consent at any time where processing is based on consent.
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
Exercising your rights
Requests may be sent to privacy@onetouch.hn. Individuals in the EU or EEA may also contact our European privacy contact: Alejandro Adain Navarro Gorraiz, alejandro@onetouch.hn.
We may request reasonable information to verify your identity before processing a rights request. We normally respond to valid GDPR rights requests within one month. Where permitted by the GDPR, that period may be extended by up to two additional months depending on the complexity and number of requests. If an extension is required, we will inform you.
Complaints
You have the right to lodge a complaint with a competent data-protection supervisory authority. If you are located in Spain, you may contact the AEPD (Agencia Española de Protección de Datos). You may also contact the supervisory authority in the EU or EEA country of your habitual residence, place of work or the place of the alleged infringement.
10. Security
We implement technical and organisational measures designed to provide a level of security appropriate to the risks associated with our processing activities. Depending on the system and processing involved, these measures may include: encrypted transmission using HTTPS/TLS; encryption at rest where supported and appropriate; authentication and access controls; least-privilege access; restrictions on access to personal data; security logging and monitoring; secure software-development practices; dependency and vulnerability management; confidentiality obligations for employees and contractors; backup and recovery procedures; and incident-response processes.
Access to personal data is limited to personnel and service providers who reasonably require access for legitimate business purposes. No information system can guarantee absolute security. We periodically review our safeguards and adapt them according to the nature and risks of our processing.
11. Personal Data Breaches
Where a personal-data breach is subject to GDPR notification requirements, Onetouch will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. Where a breach is likely to result in a high risk to affected individuals, we will also communicate the breach to those individuals without undue delay where required by applicable law.
12. Automated Decision-Making and Profiling
Onetouch does not use contact or project enquiry information to make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning you. Advertising and social-media platforms may independently use automated systems, audience segmentation or profiling in connection with their advertising services.
Where Onetouch uses technologies requiring consent for advertising or measurement purposes, those technologies are subject to the consent requirements described in this Privacy Policy and our Cookie Policy. We do not use the content of project descriptions or confidential project attachments for behavioural advertising.
13. Children and Minors
Onetouch provides professional creative, technology and business services. Our website, project enquiries and commercial services are not directed to children or minors. We do not knowingly solicit personal data from minors through our business enquiry forms. If you believe that a minor has provided personal data to us inappropriately, please contact privacy@onetouch.hn so that we can review the matter and take appropriate action.
14. Third-Party Websites and Platforms
Our website may contain links to websites, social networks, services or platforms operated by third parties. Those third parties process personal data according to their own privacy policies and practices. Onetouch is not responsible for the privacy practices of third-party websites or services that operate independently from us. We recommend reviewing the applicable privacy information before providing personal data to a third party.
15. Changes to This Privacy Policy
We may update this Privacy Policy where: our services change; our processing activities change; we adopt new technologies or providers; our corporate structure changes; or applicable legal requirements change. The “Last updated” date at the beginning of this Policy indicates the most recent revision. Where changes materially affect how we process personal data, we will provide additional notice where required by applicable law.
16. Contact
For privacy questions, requests or complaints: privacy@onetouch.hn. For general business enquiries: hello@onetouch.hn.
Data Controller
ONETOUCH SA de CV
RTN: 05019019096875
Nuevos Horizontes, Avenida Principal, 21101, San Pedro Sula, Cortés, Honduras
Telephone: +504 9463-6167
European privacy contact
Alejandro Adain Navarro Gorraiz, Spain
Email: alejandro@onetouch.hn