Privacy Policy
1. Identification of the Data Controller
In accordance with the provisions of REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and the free movement of such data (hereinafter GDPR), we inform you that your personal data will be processed by the following Data Controller:
- Company name: Gellida Asociados SC
- CIF: J09873811
- Direction: Camino Donación, 484, 12100 Castellón
- Email to exercise rights: ximo@gellida.work
2. General Privacy Principles
When collecting and processing your personal information, we are guided by the following practical principles:
- Personal data is processed fairly, legally, and transparently.
- Personal data is collected for specific, explicit, and legitimate purposes and is not processed in a manner incompatible with those purposes.
- The personal data are adequate, relevant, and limited to what is necessary in relation to the purposes for which the processing is carried out.
- Personal data must be accurate and up-to-date. Inaccurate data will be updated or deleted.
- Personal data must be kept in an identifiable format and only for what is strictly necessary.
- Personal data is kept secure through appropriate and effective technical and organizational measures against unauthorized or unlawful processing and against accidental loss, destruction, or damage, by applying appropriate technical or organizational measures (“integrity and confidentiality”).
- We are committed to the principles of data protection by design and data protection by default.
3. Purposes of the collection of personal data
The purposes according to the treatments are the following:
-
-
- Contact with customers and users (customers, potential customers, other interested parties): whether through telephone support, web forms, or email, responding to their requests for information, suggestions, and complaints.
-
4. Legitimation for the treatment
Contact, requests for information, suggestions, complaints: execution of a contract to which the data subject is a party, if they are customers (art. 6.1.b GDPR) or the legitimate interest of the controller in other cases (art. 6.1.f GDPR).
5. Recipients and international transfers
Communication to third parties is not planned, except where legally required, and with the exception of our data processors. No international data transfers will be made, as all data is processed within the European Economic Area. In the event of necessary transfers, these may be made to banks, tax authorities, collection agencies, among others, depending on the type of processing.
6. Storage periods
Data of users who have used any contact method: as long as the data is necessary to manage your request.
7. Rights of the interested party
As a data subject, you may direct your communications and exercise your rights by following the formalities imposed by REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
In all our operations related to your privacy, we strive to comply with current regulations, which contain a series of rights for data subjects, as listed below:Como interesado, podrá dirigir sus comunicaciones y ejercitar sus derechos siguiendo las formalidades impuestas por el REGLAMENTO (UE) 2016/679 DEL PARLAMENTO EUROPEO Y DEL CONSEJO de 27 de abril de 2016 relativo a la protección de las personas físicas en lo que respecta al tratamiento de datos personales y a la libre circulación de estos datos.
En todas nuestras operaciones relacionadas con su privacidad, nos esforzamos por cumplir con la normativa actual, la cual contiene una serie de derechos para el interesado que a continuación enumeramos:
| Your rights | What does it mean? |
| Right to information | You have the right to receive clear, concise, transparent, and easy-to-understand information about how we use your personal data and your rights. |
| Right of access | You have the right to access the personal data we hold about you (within certain limits). Manifestly unfounded, excessive, or repetitive requests may not be honored. |
| Right to rectification | You have the right to have your personal data rectified when it is inaccurate or no longer valid, or to have it completed when it is incomplete.erecho a hacer que se rectifiquen sus datos personales cuando sean inexactos o hayan dejado de ser válidos o a hacer que se completen cuando sean incompletos. |
| Right to erasure / right to be forgotten | In certain cases, you have the right to request that your personal data be deleted or removed. It should be noted that this is not an absolute right, as we may have legal or legitimate reasons to retain it. |
| Right to object to receiving advertising | You can unsubscribe from our marketing communications at any time. The easiest way to unsubscribe is by clicking the “unsubscribe” link in any email or communication we send you. You can also email us at ximo@gellida.work. |
| Right to withdraw consent at any time when data processing is based on consent If consent has been given for any of the purposes reported and determined in the |
processing referred to above, we inform you that you have the right to withdraw consent at any time, without affecting the legality of the processing based on consent prior to its withdrawal. |
| Right to object to processing based on legitimate interests | You may object at any time to our processing of your data when the processing is based on legitimate interests. |
| Right to lodge a complaint with a supervisory authority | We also inform you that if you are not satisfied with the exercise of your rights or how to exercise them, you may file a complaint with the Supervisory Authority. If you would like more information about this right and how to exercise it, you can contact the Spanish Data Protection Agency at www.aepd.es. Tel. 901 100 099 and 91 266 35 17. C/Jorge Juan, 6, 28001 Madrid. |
| Right to data portability | You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, so that we can transmit it to another data controller when the processing is based on the performance of a contract or on your consent and the processing is carried out by automated means. |
| Right to restriction of processing | You have the right to obtain restriction on the processing of your data, although this exercise has two aspects: You can request suspension of the processing of your data:
|
8. Exercise of rights
You can exercise your rights by writing to ximo@gellida.work with the subject line “GDPR. RIGHTS.” You can use the AEPD templates: https://www.aepd.es/reglamento/derechos/index.html
9. Security
The security measures adopted are those required, in accordance with Article 32 of the GDPR. In this regard, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the Data Controller has established appropriate technical and organizational measures to ensure a level of security appropriate to the existing risk.
The Data Controller has implemented sufficient mechanisms to:
- Ensure the ongoing confidentiality, integrity, availability, and resilience of treatment systems and services.
- Restore availability and access to personal data quickly in the event of a physical or technical incident.
- Regularly verify, evaluate, and assess the effectiveness of the technical and organizational measures implemented to ensure the security of the processing.
- Pseudonymize and encrypt personal data, where applicable.