Art. 1 Confidentiality rules
The General Data Protection Regulation of April 27, 2016 (“GDPR”; “RGPD” in Spanish), has applied since May 25, 2018. It imposes strict rules and conditions on companies within the scope of processing the personal data of their customers and prospects, in order to protect their privacy.
For this reason, we aim to provide you with clear and precise information about the processing of your personal data.
Art. 2 Data controller
The controller of your personal data is the person in charge of the website you used and to whom you provided the data.
Art. 3 Legal basis for data processing and use
We may only use your personal data for legitimate and necessary purposes (Article 6 of the GDPR). In practice, this means that we process your personal data, whether in electronic format or not, for legitimate purposes in the context of the contractual, commercial, and security relationship. These purposes include, among others, the following:
Providing information, offers, and marketing materials;
Communications related to the performance of a contract;
Art. 4 What constitutes personal data
Personal data includes any information relating to you on the basis of which you can be identified. Anonymous data that does not identify you is not considered personal data. Your personal data may therefore include:
Data related to your identity (surname, first name, address, tax ID, etc.);
Data related to you (phone number, personal email, etc.);
Financial data (bank account number, billing details, etc.);
Data related to the performance of the contract entered into with us (subject of the contract, billing address, professional data, etc.);
Data related to the use of electronic equipment, such as computers (password, log data, electronic identification data, billing details, etc.);
Sensitive data:
The processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, as well as the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, and data concerning a natural person’s sex life or sexual orientation is prohibited. We are committed to strictly complying with this prohibition.
How do we use your information?
Who do we share your information with?
Art. 5 Source and origin of personal data
Normally, the data we hold comes from you.
If you do not intend to provide the required or necessary information, you may lose the benefit of certain advantages and/or we may decide to terminate the services we provide to you.
Art. 6 Access to personal data
Your data is primarily for internal use. For certain legitimate reasons, your personal data may be disclosed to or even processed by third parties. However, we will ensure our subcontractors comply with GDPR rules. The processing of data by the latter is governed by a strict legal framework.
Art. 7 Data retention period
We take the necessary measures to ensure that the retention of personal data for the purposes described above does not exceed the legal periods.
Art. 8 What are your rights?
We undertake to take appropriate technical and organizational measures to ensure the security of the processing of everyone’s personal data (Article 32 of the GDPR).
Right of access (Article 15 of the GDPR)
We grant everyone the right to access their own personal data and the right to obtain or make a reasonable copy of it.
Right to rectification (Article 16 of the GDPR)
We acknowledge the possibility of requesting the rectification of incorrect data.
Right to be forgotten (Article 17 of the GDPR) and right to restriction of processing (Article 18 of the GDPR)
We undertake to delete your personal data, particularly in the following cases:
Data that is no longer necessary for the purposes for which it was collected or processed
You object to the processing
The personal data has been subject to unlawful processing
Right to lodge a complaint (Article 77 of the GDPR)
The customer has the right to lodge a complaint with the Spanish Data Protection Agency at any time if they consider that the processing of their personal data constitutes a violation of the GDPR.
Art. 9 Our commitment
Our goal is to implement security processes to protect stored data against unauthorized access, misuse, tampering, unlawful or accidental destruction, and accidental loss.
Art. 10 Procedure in the event of a breach
There is always the possibility that personal data processed in the context of the contractual relationship may fall into the wrong hands as a result of human error, computer error, etc.
When the breach poses a high risk to people’s rights and freedoms, we will inform you immediately of the facts and the measures considered. We will ensure that the Spanish Data Protection Agency is notified within 72 hours of becoming aware of the breach in question, unless the breach does not pose a high risk to people’s rights and freedoms (Articles 32–34 of the GDPR).
Your acceptance:
Art. 11 Consent
You give your express and unequivocal consent to the processing of personal data as described in this Privacy Policy. You have the right to withdraw your consent at any time upon written request. We reserve the right to modify this Privacy Policy.
