Privacy Policy

RESPONSIBLE FOR THE TREATMENT

The Data Controller is Isabel Cabrera Álvarez with ID/NIF/NIE 51095280K on behalf of 51095280K.

Privacy Principles

At Isabel Cabrera Álvarez, we commit to continuously work with you to ensure privacy in the processing of your personal data, and to offer you the most comprehensive and clear information we can always. We encourage you to carefully read this section before providing us with your personal data.

If you are under fourteen years of age, please do not provide us with your data without the consent of your parents.

In this section, we inform you how we process the data of individuals related to our organization. Starting with our principles:

– We do not request personal information unless it is necessary to provide you with the services you require.
– We never share personal information with anyone, except to comply with the law, or if we have your express authorization.
– We will never use your personal data for purposes other than those expressed in this privacy policy.
– Your data will always be treated with a level of protection appropriate to data protection legislation, and we will not subject them to automated decisions.

We have drafted this privacy policy considering the requirements of current data protection legislation:
– Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons (GDPR).
– Organic Law 3/2018, of December 5, on the Protection of Personal Data and guarantee of digital rights (LOPD).
– Royal Decree 1720/2007, of December 21 (RLOPD).

This privacy policy is drafted as of December 6, 2018. To facilitate understanding or to adapt it to current legality, we may modify this privacy policy. We will update its date so you can check its validity.

PROCESSING OF CONTACTS

Legal Basis: Consent of the interested party

Processing Purposes: Attend to your request, send you information, and follow up on the request.

Collective: Contact persons, clients, suppliers

Data Categories: Name and surname, telephone, email address

Recipient Categories: No data transfers to third parties are contemplated.

International Transfers: No international transfers of data are foreseen.

Retention Period: Contact data will be kept for an indefinite period, or until the interested party requests their deletion.

Security Measures: Adapted to the requirements of Regulation (EU) 2016/679, General Data Protection Regulation.

PROCESSING OF ATTENTION TO THE RIGHTS OF INDIVIDUALS (ARCO)

Legal Basis: GDPR: 6.1.c) Processing necessary for compliance with a legal obligation applicable to the data controller.
General Data Protection Regulation.
Processing Purposes: Address requests in the exercise of the rights established by the General Data Protection Regulation.

Right to: Access, recification, suppression, limitation, portability and opposition to automated decision making.

Collective: Individuals requesting it (employees, clients, suppliers, contact persons).

Data Categories: Name and surname, address, signature, and telephone.

Recipient Categories: Personal data may be communicated to the Control Authority (Spanish Data Protection Agency) as part of an investigation for the protection of rights initiated by the interested party.

International Transfers: No international transfers of data are foreseen.

Retention Period: They will be kept for a period of five years from the moment of the request.

Security Measures: Adapted to the requirements of Regulation (EU) 2016/679, General Data Protection Regulation.

PROCESSING OF CANDIDATES IN SELECTION PROCESSES (HR)


Legal Basis: GDPR 6.1.a) The interested party gave their consent for the processing of their personal data for one or more specific purposes. GDPR: 6.1.b) Processing necessary for the performance of a contract to which the data subject is party or for the application at the request of the data subject of pre-contractual measures.

Processing Purposes: Staff selection and job provision.

Collective: Candidates submitted to job provision procedures.

Data Categories: – Name and surname, ID/NIF/Identification document, personal registration number, address, signature, and telephone.
– Personal characteristics data: Gender, marital status, nationality, age, date and place of birth, and family data.
– Academic and professional data: Degrees, training, and professional experience.
– Employment detail data.

Recipient Categories: No data transfers to third parties are foreseen.

International Transfers: No international transfers of data are foreseen.

Retention Period: They will be kept for as long as necessary to fulfill the purpose for which they were collected and to determine the possible responsibilities that may arise from said purpose and from the processing of the data.

Security Measures: Adapted to the requirements of Regulation (EU) 2016/679, General Data Protection Regulation.

PROCESSING OF SUPPLIERS

Legal Basis: GDPR: 6.1.b) Processing necessary for the performance of a contract to which the data subject is party or for the application at the request of the data subject of pre-contractual measures. GDPR: 6.1.c) Processing necessary for compliance with a legal obligation applicable to the data controller.
Royal Legislative Decree 2/2015, of October 23, approving the revised text of the Workers’ Statute Law.
Law 58/2003, of December 17, General Taxation.

Processing Purposes: – Acquisition of products and/or services that we need for the development of our activity.
– Control of subcontractors if applicable.

– Collective: Suppliers.

– Persons working for our suppliers.

Data Categories:

– Name and surname, ID/NIF/Identification document, address, signature, and telephone.
–Employment detail data: job position. Occupational safety training.
–Economic, financial, and insurance data: Bank details.

Recipient Categories:

– Financial entities. (Payment of invoices)

– State Tax Administration Agency.

International Transfers: No international transfers of data are foreseen.

Retention Period: They will be kept for as long as necessary to fulfill the purpose for which they were collected and to determine the possible responsibilities that may arise from said purpose and from the processing of the data, in accordance with Law 58/2003, of December 17, General Taxation. Security Measures: Adapted to the requirements of Regulation (EU) 2016/679, General Data Protection Regulation.

PROCESSING OF CLIENTS.
Legal Basis:

GDPR: 6.1.a) The interested party gave their consent for the processing of their personal data for one or more specific purposes.

GDPR: 6.1.b) Processing necessary for the performance of a contract to which the data subject is party or for the application at the request of the data subject of pre-contractual measures.

GDPR: 6.1.c) Processing necessary for compliance with a legal obligation applicable to the
data controller.

GDPR: 6.1.f) Processing necessary for the fulfillment of legitimate interests pursued by the data
controller.

Royal Legislative Decree 2/2015, of October 23, approving the revised text of the Workers’ Statute Law.

Law 58/2003, of December 17, General Taxation.

Processing Purposes: Provision of our products/services.

Collective: Clients

Data Categories: – Name and surname, ID/NIF/Identification document, address, signature, and telephone.

 Economic, financial and insurance data: Bank data

Recipient Categories:

– Financial entities.

– State Tax Administration Agency.

International Transfers: No international transfers of data are foreseen.

Retention Period: They will be kept for as long as necessary to fulfill the purpose for which they were collected and to determine the possible responsibilities that may arise from said purpose and from the processing of the data, in accordance with Law 58/2003, of December 17, General Taxation.

Security Measures: Adapted to the requirements of Regulation (EU) 2016/679, General Data Protection Regulation.


SECURITY BREACH NOTIFICATION PROCESSING
Legal Basis:

GDPR: 6.1.c) Processing necessary for compliance with a legal obligation applicable to the data controller.

General Data Protection Regulation. Articles 33 and 34.

Processing Purposes: Management and evaluation of security breaches that may occur in our organization.

Collective: Variable: Employees, Clients, Suppliers, Contact Persons (depending on the security breach)

Data Categories: Variable. (Depending on the security breach)

Recipient Categories:

– Spanish Data Protection Agency.

– State Security Forces and Corps.

International Transfers: No international transfers of data are foreseen.

Retention Period: They will be kept for as long as necessary to fulfill the purpose for which they were collected and to determine the possible responsibilities that may arise from said purpose and from the processing of the data. The provisions of the archives and documentation regulations shall apply.

Security Measures: Adapted to the requirements of Regulation (EU) 2016/679, General Data Protection Regulation.


YOUR RIGHTS

You have the right to request a copy of your personal data, to rectify inaccurate data or complete them if they are incomplete, or, where appropriate, to delete them when they are no longer necessary for the purposes for which they were collected.

You also have the right to limit the processing of your personal data and to obtain your personal data in a structured and readable format.

You may object to the processing of your personal data under certain circumstances (in particular, when we do not have to process them to comply with a contractual or other legal requirement, or when the purpose of the processing is direct marketing).

When you have given us your consent, you may withdraw it at any time. At that time, we will stop processing your data or, where appropriate, stop doing so for that specific purpose. If you decide to withdraw your consent, this will not affect any processing that has taken place while your consent was valid.

These rights may be limited; for example, if to comply with your request we would have to disclose data about another person, or if you ask us to delete some records that we are required to keep by a legal obligation or legitimate interest, such as defending against claims. Or even in those cases where the right to freedom of expression and information must prevail.

You can contact us through any of the means indicated in the Responsible for Treatment section of this privacy policy, providing a copy of a document proving your identity (usually your ID).

Another of your rights is not to be subject to a decision based solely on automated processing, including profiling that produces legal effects or affects you.

In case of any violation of your rights, such as, for example, if we have not addressed your request, you have the right to lodge a complaint with the Data Protection Authority. This can be the one in your country (if you live outside of Spain) or the Spanish Data Protection Agency (if you live in Spain).

Links to third-party websites.
Our website may, on occasion, contain links to other websites. It is your responsibility to ensure that you read the data protection policy and the legal conditions that apply to each site.

Third-party data.
If you provide us with third-party data, you assume the responsibility of informing them beforehand as established in article 14 of the GDPR.

Skip to content