We work with a lot of sensitive data on a daily basis. Therefore, we have established a privacy policy that explains how we handle your data.
Purpose of the Privacy Policy.
In accordance with the provisions of the General Data Protection Regulation (GDPR) and the Spanish Organic Law 3/2018 of December 5 on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD), by accepting this Privacy Policy, you give your informed, explicit, free and unambiguous consent to the processing of personal data collected through the Gestoraz websites or iOS app, hereinafter collectively the “Platform” or the “Website”).
The provision of personal data requires a minimum age of 18 years or, if applicable, having sufficient legal capacity to enter into a contract.
Therefore, this Privacy Policy applies to users who browse the Platform, as well as natural persons (consumers) or legal entities who register and purchase services from Gestoraz (hereinafter collectively “Users”).
Identification data of the administrator of the Platform
Your duty to notify us of changes.
It is important that the personal data we hold about you is accurate and up to date. Please keep us informed if your personal data changes during your relationship with us.
Links to third parties
The Websites may contain links to third-party websites, plug-ins and applications. If you click on these links or activate these connections, third parties may collect or share data about you. We have no control over these third-party websites and are not responsible for their privacy statements. When you leave our Websites, we encourage you to read the privacy policy of each website you visit.
The personal data we collect about you
Personal data is any information about an individual that identifies that person. It does not include data whose identity has been removed (anonymous data).
We may collect, use, store and transfer different categories and types of personal data about you.
We also collect, use and share aggregate data, such as statistical or demographic data, for any purpose. Aggregate data may be derived from your personal data, but is not considered personal data under the law, as it does not directly or indirectly reveal your identity. However, if we combine or link aggregated data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data that will be used in accordance with this Privacy Policy.
Obligation to provide us with your personal data and consequences if you fail to do so
The personal data requested is necessary to manage your requests and/or provide you with the services you may purchase. If you do not provide this information to us, we may not be able to properly serve you or provide you with the services you have requested.
How is your personal data collected?
We use various methods to collect data from and about you, including:
How we use your personal data (bases for processing).
We will only use your personal data where the law allows us to do so. Generally, we will use your personal data in the following circumstances:
Purposes for which we will use your personal data
Below you will find, in tabular form, a description of all the ways in which we intend to use your personal data, and the legal basis on which we do so. We have also identified our legitimate interests, where applicable.
Choice to object to processing.
You can ask us to stop sending you marketing messages at any time by following the opt-out link in any marketing message sent to you or by contacting us at hola@gestoraz.com.
Recipients of your personal data
We may share your personal data with third parties for the purposes set out in the table above. Specifically, these may be external third parties in the following categories:
We require all third parties to respect the security of your personal data and treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only allow them to process your personal data for specific purposes and in accordance with our instructions.
International transfers
Some of our third party external service providers are located outside the European Economic Area (EEA), so processing your personal data may involve a transfer of data outside the EEA.
Whenever we transfer your personal data outside the EEA, we ensure that a comparable level of protection is provided by ensuring that at least one of the following safeguards is implemented:
Please contact us if you would like more information about the specific mechanism we use when transferring your personal data outside the EEA.
Security of Personal Data
We have implemented appropriate security measures to prevent the accidental loss, use or unauthorized access, alteration or disclosure of your personal data. In addition, we restrict access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They process your personal data only according to our instructions and are subject to a duty of confidentiality.
We have established procedures to address any suspected personal data breaches and will notify you and any applicable supervisory authorities of a breach when we are legally required to do so.
How long will we use your personal data?
We will keep your personal data only as long as reasonably necessary to fulfill the purposes for which we collected it, including to comply with legal, regulatory, tax, accounting or reporting requirements. We may keep your personal data longer in the event of a complaint or if we reasonably believe there is a risk of legal action regarding our relationship with you.
In determining the appropriate retention period for personal data, we take into account the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes by other means, and applicable legal requirements.
Your rights
You have the right to:
Where and how to exercise your rights
You can exercise your rights by contacting us at our mailing address or email address (listed in Section 1), using the reference “Personal Data”, specifying the right you wish to exercise and with respect to which personal data.
If you are not satisfied with the way we process your data, you may file a complaint with the Spanish Data Protection Authority (www.aepd.es).
Deadline to respond
We try to respond to all legitimate requests within one month. Sometimes it may take longer than a month if your request is particularly complex or if you have made multiple requests. In that case, we will notify you and keep you informed.
Physical Documents.
Physical documents that we receive but do not use, or that later prove to be unnecessary, are destroyed by us according to the guidelines of security level P-4 (DIN 66399).
Cookies
Cookies are very small files designed to recognize the user when they visit the Website. They help us provide you with a good experience, improve our website, and analyze performance. We only use them if you give your consent. Rejecting cookies may limit the functionality of the website.
Below, you will find a table overview of the cookies we may place. You can always change your cookie preferences via the button below.
We understand that the information can be overwhelming. Things often work differently abroad than you are used to. That's why we are here to answer your questions.