We work with public administrations and companies that handle sensitive data. Security, privacy and legal fit are non-negotiable requirements, built in from the first sprint of every project.
We are registered with the State Aviation Safety Agency (AESA) as a professional operator. All our flights comply with EU Regulation 2019/947 and national regulations for unmanned aerial operations.
Applies to: Flights over any type of area (urban, coastal, events) with the specific authorizations required.
ENS
National Security Framework
Our platforms are designed according to ENS principles and requirements from the first sprint onward. Medium or high category depending on client needs, with auditing available.
Applies to: Applicable to systems that handle public administration information.
GDPR
General Data Protection Regulation
Privacy by design across all our developments. AI-based anonymization of faces and license plates in digital twins featuring people. Data processing agreements with every provider. Minimal retention.
Applies to: Applicable to any personal data, or data that can be linked to identifiable individuals.
AI Act ready
EU AI Act
We design according to Regulation (EU) 2024/1689: transparency at the start of every interaction, traceability of decisions and human oversight of critical processes. And since the regulation does not issue "official certificates", what we deliver is what is actually required: a declaration of conformity backed by a verifiable technical file.
Applies to: Applicable to all our applied AI components.
LCSP
Spain's Public Sector Contracts Act
We know Law 9/2017 in detail. We help you choose the right procedure (low-value contract, simplified open procedure, open procedure) and draft technical tender specifications from the discovery phase.
Applies to: Applicable to any procurement with the Spanish public sector.
WCAG 2.1 AA
Web accessibility, level AA
All our platforms are built following the WCAG 2.1 level AA guidelines. Compatible with screen readers, keyboard navigation, sufficient contrast and video subtitles.
Applies to: Compliance required of public-sector entities under Royal Decree 1112/2018.
AI, with things straight
Four shortcuts the market takes that we do not
Conversational AI in the public sector is being sold on promises the regulation does not back up. Here is how we do it.
There is no such thing as an "official AI Act certificate"
Be wary of anyone who tries to sell you one: the regulation does not provide for that kind of seal. What is proper — and what we deliver — is a declaration of conformity backed by a verifiable technical file.
Visible transparency, not buried
The European Commission's guidelines (July 2026) do not impose a single fixed phrase: they require that users know they are talking to an AI before or at the start of the interaction, visibly. Never hidden in the legal notice.
Clear roles: who answers for what
If a municipal website's assistant runs on Clotitec technology, Clotitec is the provider and the municipality is the controller responsible for the deployment. Every obligation, in writing, with no gray areas.
Conversational AI has its own GDPR
An assistant processes conversations: its own record of processing activities, data-processing clauses with the model provider, minimization and defined retention periods.
How we apply it
Four auditable mechanisms
Compliance is not a box to tick. It is operating in a specific, demonstrable way.
Full traceability
Every automated decision is logged with a timestamp, the model used, inputs and outputs.
Human oversight
Critical processes (administrative, legal) always have human review before execution.
DPAs with providers
Data-processing agreements signed with Make.com, HubSpot, Resend, Vercel.
Access logs
Auditable logs of who accesses which data, when and from where.
Need detailed documentation for your tender file?
We provide certificates, declarations of conformity and technical references so you can include them in the procurement file.