Art. 1 – Confidentiality Rules
The General Data Protection Regulation of April 27, 2016 (“GDPR”) has been in force since May 25, 2018. It imposes strict rules and conditions on companies regarding the processing of personal data of their clients and prospects, with the aim of protecting their privacy.
For this reason, we aim to provide you with clear and precise information about the processing of your personal data.
Art. 2 – Data Controller
The data controller of your personal data is the person responsible for the website you used and to whom you provided your information.
Art. 3 – Legal Basis for Data Processing and Use
We may only use your personal data for legitimate and necessary purposes (Article 6 of the GDPR). This means, in practice, that we process your data—whether electronic or otherwise—for lawful purposes in the context of contractual, commercial, and security-related relationships. These purposes include, but are not limited to:
Sharing information, offers, and promotional materials;
Communications related to the execution of a contract.
Art. 4 – What Is Personal Data
Personal data includes any information related to you by which you can be identified. Anonymous data that does not identify you is not considered personal data. Your personal data may include:
Identity information (last name, first name, address, tax ID, etc.);
Contact details (phone number, personal email, etc.);
Financial data (bank account number, billing details, etc.);
Contractual information (contract details, billing address, professional data, etc.);
Data related to electronic equipment usage (passwords, login credentials, electronic identifiers, etc.).
Sensitive Data:
The processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, as well as genetic data, biometric data for unique identification, or data concerning sexual life or orientation, is strictly prohibited. We are committed to complying with this prohibition.
How Do We Use Your Information?
Who Do We Share Your Information With?
Art. 5 – Source and Origin of Personal Data
In general, the data we collect comes directly from you.
If you choose not to provide certain required information, you may lose access to some benefits and/or we may be forced to terminate the services we provide to you.
Art. 6 – Access to Personal Data
Your data is primarily for internal use. However, for legitimate reasons, your data may be disclosed or processed by third parties. We will ensure that our subcontractors comply with GDPR requirements. The processing of your data by these parties is regulated under a strict legal framework.
Art. 7 – Data Retention Period
We implement necessary measures to ensure that personal data is retained no longer than legally permitted for the purposes described above.
Art. 8 – What Are Your Rights?
We are committed to taking appropriate technical and organizational measures to ensure the security of personal data processing (Article 32 of the GDPR).
Right of Access (Article 15 of the GDPR):
You have the right to access your personal data and to request a reasonable copy.
Right to Rectification (Article 16 of the GDPR):
You may request the correction of inaccurate or incomplete data.
Right to Erasure (Article 17 of the GDPR) & Right to Restriction of Processing (Article 18 of the GDPR):
You may request the deletion of your personal data, especially in the following cases:
The data is no longer necessary for the purposes it was collected for;
You object to the processing;
The data was processed unlawfully.
Right to Lodge a Complaint (Article 77 of the GDPR):
You may file a complaint at any time with the Spanish Data Protection Agency if you believe that your data has been processed in violation of the GDPR.
Art. 9 – Our Commitment
Our goal is to implement security processes to protect stored data against unauthorized access, misuse, unlawful or accidental destruction, and accidental loss.
Art. 10 – Procedure in Case of Data Breach
There is always a risk that personal data processed in the context of a contractual relationship may fall into the wrong hands due to human error, system failure, etc.
If the breach poses a high risk to the rights and freedoms of individuals, we will inform you immediately and detail the measures taken. We will also notify the Spanish Data Protection Agency within 72 hours of becoming aware of the breach, unless the breach does not pose a high risk (Articles 32–34 of the GDPR).
Your Acceptance
Art. 11 – Consent
You give your explicit and unequivocal consent for the processing of your personal data as described in this Privacy Policy. You may withdraw your consent at any time by submitting a written request.
We reserve the right to update or modify this Privacy Policy at any time.
