Our team of design specialists will be happy to help.
Privacy Policy
INDEX
- Objective of the Privacy Policy
- Definitions
- Identity of the Data Controller
- Applicable laws and regulations
- Principles applicable to the processing of personal data
- Data processing activities carried out
- Necessary and updated information
- Personal data of minors
- Technical and organizational security measures
- Rights of interested parties
- Complaints to the Control Authority
- Acceptance and changes to the Privacy Policy
1.- OBJECTIVE OF THE PRIVACY POLICY
The purpose of this "Privacy and Data Protection Policy" is to disclose the conditions governing the collection and processing of personal data by Disfruta tu baño 3000, sl, making every effort to ensure the fundamental rights, honour and freedoms of the persons whose personal data is processed, in compliance with the regulations and laws in force that regulate the Protection of Personal Data according to the European Union and the Spanish Member State and, specifically, those expressed in the "Treatment Activities" section of this Privacy Policy.
For all of the above, in this Privacy and Data Protection Policy, users of the Website https://banototal.com are informed of all the details of interest to them regarding how these processes are carried out, for what purposes, what other entities may have access to their data and what the rights of the users are.
2.- DEFINITIONS
"Personal data": Any information relating to an identified or identifiable natural person ("Website User"); an identifiable natural person is any person whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
"Treatment": any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
«Treatment limitation»: the marking of stored personal data with the aim of limiting their processing in the future.
«Profiling»: any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
«Pseudonymisation»: the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
«File»: any structured set of personal data, accessible according to specified criteria, whether centralised, decentralised or distributed on a functional or geographical basis.
"Data controller" or "controller": the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing; where the purposes and means of the processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
"Data processor" or "processor": the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
"Addressee": the natural or legal person, public authority, agency or other body, to which personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the data protection rules applicable to the purposes of the processing.
"Third": natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
«Consent of the interested party»: any manifestation of free, specific, informed and unequivocal will by which the data subject, either by a statement or by a clear affirmative action, accepts the processing of personal data relating to him or her.
"Breach of personal data security": any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed;
«Genetic data»: personal data relating to inherited or acquired genetic characteristics of a natural person which provide unique information about that natural person's physiology or health, obtained in particular from analysis of a biological sample from that natural person.
«Biometric data»: personal data obtained through specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data.
"Health data": personal data relating to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status.
"Main establishment":
to) in respect of a controller with establishments in more than one Member State, the place of its central administration in the Union, unless decisions concerning the purposes and means of processing are taken at another establishment of the controller in the Union and that latter establishment has the power to enforce those decisions, in which case the establishment which has taken those decisions shall be deemed to be the main establishment;
b) in respect of a processor with establishments in more than one Member State, the place of its central administration in the Union or, if there is no such central administration, the establishment of the processor in the Union where the main processing activities in the context of the activities of an establishment of the processor are carried out to the extent that the processor is subject to specific obligations under this Regulation.
"Representative": natural or legal person established in the Union who, having been designated in writing by the controller or processor pursuant to Article 27 of the GDPR, represents the controller or processor with regard to their respective obligations under this Regulation.
"Company": natural or legal person engaged in an economic activity, regardless of its legal form, including companies or associations that regularly carry out an economic activity.
«Supervisory authority»: the independent public authority established by a Member State pursuant to Article 51 of the GDPR. In the case of Spain, this is the Spanish Data Protection Agency.
"Cross-border processing": to) the processing of personal data carried out in the context of the activities of establishments in more than one Member State of a controller or a processor in the Union, if the controller or processor is established in more than one Member State, or b) the processing of personal data carried out in the context of the activities of a single establishment of a controller or processor in the Union but which substantially affects or is likely to substantially affect data subjects in more than one Member State.
«Information society service»: any information society service, that is to say any service provided, normally in exchange for remuneration, at a distance, by electronic means and at the individual request of a recipient of the services.
3.- IDENTITY OF THE PERSON RESPONSIBLE FOR THE PROCESSING
The Data Controller is the natural or legal person, public or private, or administrative body, which alone or jointly with others determines the purposes and means of the processing of personal data; in the event that the purposes and means of the processing are determined by the Law of the European Union or of the Spanish Member State.
In the aspects expressed in this Data Protection Policy, the identity and contact details of the Data Controller are:
Enjoy your bath 3000, sl - NIF/DNI B12969309
C/ Azahar, No. 1, Serena Mar Urbanization, 1 Bl.1 Building . 12570, Alcalá de Xivert (Castellón), Spain
- Email: info@banototal.com
- Phone:
4.- APPLICABLE LAWS AND REGULATIONS
This Privacy and Data Protection Policy is developed based on the following data protection regulations and laws:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. Hereinafter GDPR.
- Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights. Hereinafter LOPD/GDD.
- Law 34/2002, of July 11, on Information Society Services and Electronic Commerce. Hereinafter LSSICE.
5.- PRINCIPLES APPLICABLE TO THE PROCESSING OF PERSONAL DATA
The personal data collected and processed through this website will be treated in accordance with the following principles:
-
Principle of legality, loyalty and transparency: Any processing of personal data carried out through this Website will be lawful and fair, and it will be completely clear to the user when personal data concerning him or her is being collected, used, consulted or processed. Information regarding the processing carried out will be transmitted in advance, in an easily accessible and easy-to-understand manner, in simple and clear language.
-
Principle of limitation of purpose: All data will be collected for specific, explicit and legitimate purposes and will not be further processed in a manner incompatible with the purposes for which they were collected.
-
Data minimisation principle: The data collected will be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
-
Accuracy principle: The data will be accurate and, if necessary, updated, taking all reasonable measures to ensure that personal data that are inaccurate with respect to the purposes for which they are processed are deleted or rectified without delay.
-
Principle of limitation of the conservation period: The data will be kept in a manner that allows identification of the interested parties for no longer than necessary for the purposes of processing the personal data.
-
Principle of integrity and confidentiality: The data will be treated in a manner that guarantees adequate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss or damage, by applying appropriate technical and organizational measures.
- Principle of proactive responsibility: The entity that owns the Website will be responsible for compliance with the principles set out in this section and will be able to demonstrate this.
6.- DATA PROCESSING ACTIVITIES
Below are the data processing activities carried out through the Website, specifying each of the following sections:
- Activity: Name of the data processing activity
- Purposes: Each of the uses and treatments that are carried out with the data collected
- Legal basis: The legal basis that legitimizes the processing of data
- Data processed: Types of data processed
- Origin: Where the data comes from
- Conservation: Period for which data is retained
- Recipients: Third parties or entities to whom the data is provided
- International transfers: Cross-border transfers of data outside the European Union
6.1 MAIN TREATMENT ACTIVITIES
These are data processing activities whose purposes are necessary and essential for the provision of services.
Customers | |
---|---|
Legal bases | (Art. 6.1.b GDPR) Existence of a contractual relationship with the interested party through a contract or pre-contract |
Purposes | Contact and commercial activities with clients |
Data categories and groups | Customers (Identification data; Economic, financial and insurance data; Transactions of goods and services) |
Data source | The interested party or his legal representative |
Category of recipients | Tax Administration; Banks, savings banks and rural banks |
International transfer | Not planned |
Conservation period | For a period of 6 years from the last confirmation of interest. Article 30 of the Commercial Code |
Potential clients | |
---|---|
Legal bases | (Art. 6.1.b GDPR) Existence of a contractual relationship with the interested party through a contract or pre-contract |
Purposes | Lead and Contact Management |
Data categories and groups | Potentials (Identification data) |
Data source | The interested party or his legal representative |
Category of recipients | Not planned |
International transfer | Not planned |
Conservation period | For a period of 2 years from the last confirmation of interest. Article 5 of the GDPR 2016/679 paragraph C |
Labor | |
---|---|
Legal bases | (Art. 6.1.b GDPR) Existence of a contractual relationship with the interested party through a contract or pre-contract |
Purposes | Control of work attendance; Labor training; Management of payrolls and labor contracts; Prevention of occupational risks; Labor supervision and control |
Data categories and groups | Employees (Identification data; Academic and professional; Personal characteristics; Economic, financial and insurance; Employment details) |
Data source | The interested party or his legal representative |
Category of recipients | Social Security Agencies; Tax Administration; Banks, savings banks and rural banks; Public administration with jurisdiction in the matter |
International transfer | Not planned |
Conservation period | For a period of 5 years from the last confirmation of interest. Articles 66 to 70 of the General Tax Law. |
Suppliers | |
---|---|
Legal bases | (Art. 6.1.b GDPR) Existence of a contractual relationship with the interested party through a contract or pre-contract |
Purposes | Customer/supplier management, accounting, tax and administration |
Data categories and groups | Suppliers (Identification data; Economic, financial and insurance data; Transactions of goods and services) |
Data source | The interested party or his legal representative |
Category of recipients | Tax Administration; Banks, savings banks and rural banks |
International transfer | Not planned |
Conservation period | For a period of 6 years from the last confirmation of interest. Article 30 of the Commercial Code |
6.2 OPTIONAL PROCESSING ACTIVITIES (if the user has indicated his/her acceptance)
These are personal data processing activities whose purposes are not essential for the provision of the service and which are only carried out if the user has checked YES in the consent for the performance of these activities.
Job board | |
---|---|
Legal basis | (Art. 6.1.a GDPR) Consent of the interested party |
Purposes | Staff selection |
Data categories and groups | Job applicants (Identification data; Academic and professional; Employment details; Social circumstances) |
Data source | The interested party or his legal representative |
Category of recipients | Not planned |
International transfer | Not planned |
Conservation period | For a period of 2 years from the last confirmation of interest. Article 5 section C RGPD 679/2016 |
Commercial communications | |
---|---|
Legal bases | (Art. 6.1.a GDPR) Consent of the interested party; (Art. 6.1.b GDPR) Existence of a contractual relationship with the interested party by means of a contract or pre-contract |
Purposes | Commercial communications; Marketing, advertising and commercial prospecting |
Data categories and groups | Ecommerce Clients (Identification data; Economic, financial and insurance data). Web contacts (Identification data) |
Data source | The interested party or his legal representative |
Category of recipients | Not planned |
International transfer | Not planned |
Conservation period | As long as its deletion is not requested by the interested party |
Ecommerce customer management | |
---|---|
Legal bases | Explicit consent of the interested party |
Purposes | E-commerce |
Data categories and groups | Ecommerce Clients (Identification data; Economic, financial and insurance data; Transactions of goods and services) |
Data source | The interested party or his legal representative |
Category of recipients | Tax Administration; Banks, savings banks and rural banks |
International transfer | Not planned |
Conservation period | For a period of 5 years from the last confirmation of interest |
7.- NECESSARY AND UPDATED INFORMATION
All fields marked with an asterisk (*) on the Website forms must be completed, so that the omission of any of them could result in the impossibility of providing you with the requested services or information.
You must provide truthful information so that the information provided is always up-to-date and does not contain errors. You must notify the Data Controller as soon as possible of any changes or corrections to your personal data by sending an email to the following address: info@banototal.com.
Likewise, by clicking on the “I accept” button (or equivalent) included in the aforementioned forms, you declare that the information and data you have provided in them are accurate and truthful, and that you understand and accept this Privacy Policy.
8.- DATA OF MINORS
In compliance with the provisions of article 8 of the GDPR and article 7 of the LOPD/GDD, only those over 14 years of age may give their consent for the processing of their personal data in a legal manner by Disfruta tu baño 3000, sl.
For the above reasons, minors under 14 years of age may not use the services available through the Website without the prior authorization of their parents, guardians or legal representatives, who will be solely responsible for all acts carried out through the Website by minors under their care, including the completion of electronic forms with the personal data of said minors and the marking, where applicable, of the accompanying boxes.
9.- TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
The Data Controller adopts the necessary organisational and technical measures to guarantee the security and privacy of your data, to prevent its alteration, loss, processing or unauthorised access, depending on the state of the technology, the nature of the data stored and the risks to which they are exposed.
Among others, the following measures stand out:
- Ensure the ongoing confidentiality, integrity, availability and resilience of treatment systems and services.
- Restore availability and access to personal data quickly in the event of a physical or technical incident.
- Regularly verify, evaluate and assess the effectiveness of the technical and organizational measures implemented to ensure the security of the processing.
- Pseudonymize and encrypt personal data, if it is sensitive data.
On the other hand, the Data Controller has made the decision to manage the information systems in accordance with the following principles:
- Principle of regulatory compliance: All information systems will comply with the applicable legal and sectoral regulations that affect information security, especially those related to the protection of personal data, system security, data, communications and electronic services.
- Risk management principle: Risks should be minimized to acceptable levels and a balance should be sought between security controls and the nature of the information. Security objectives should be established, reviewed and consistent with the security aspects of the information.
- Principle of awareness and training: Training, awareness-raising programmes and awareness campaigns will be organised for all users with access to information, in the area of information security.
- Principle of proportionality: The implementation of controls that mitigate the security risks of assets will be carried out by seeking a balance between security measures, nature and information and risk.
- Principle of responsibility: All members of the Data Controller will be responsible for their conduct regarding information security, complying with the established rules and controls.
- Principle of continuous improvement: The degree of effectiveness of the security controls implemented in the organization will be reviewed on a recurring basis to increase the capacity to adapt to the constant evolution of risk and the technological environment.
10.- RIGHTS OF INTERESTED PARTIES
Current data protection regulations protect users with a series of rights in relation to the use of their data. Each and every one of these rights are personal and non-transferable, meaning that they can only be exercised by the data owner, after verifying their identity.
The rights of Website users are detailed below:
- Right of access: This is the right of the Website user to obtain confirmation of whether or not the Data Controller is processing their personal data and, if so, to obtain information about their specific personal data and the processing that the Data Controller has carried out or is carrying out, as well as, among others, the information available on the origin of said data and the recipients of the communications made or planned therein.
- Right to rectification: This is the right of the Website user to have their personal data modified if it is found to be inaccurate or, taking into account the purposes of the processing, incomplete.
-
Right to erasure: This is usually known as the "right to be forgotten" and is the right that the Website user has, unless the current legislation establishes otherwise, to obtain the erasure of his or her personal data when these are no longer necessary for the purposes for which they were collected or processed; the User has withdrawn his or her consent to the processing and there is no other legal basis for this; the User objects to the processing and there is no other legitimate reason to continue with it; the personal data have been processed unlawfully; the personal data have been obtained as a result of a direct offer of information society services to a minor under 14 years of age. In addition to erasing the data, the Data Controller, taking into account the available technology and the cost of its application, will adopt reasonable measures to inform other potential controllers who are processing the personal data of the interested party's request to erase any link to said personal data.
- Right to data restriction: This is the right of the Website User to limit the processing of his/her personal data. The Website User has the right to obtain the restriction of processing when he/she contests the accuracy of his/her personal data; the processing is unlawful; the Data Controller no longer needs the personal data, but the User needs it to make claims; and when the Website User has objected to the processing.
-
Right to data portability: In cases where processing is carried out by automated means, the Website User shall have the right to receive from the Data Controller his/her personal data in a structured, commonly used and machine-readable format, and to transmit them to another data controller. Whenever technically feasible, the Data Controller will transmit the data directly to that other Data Controller.
-
Right to object: This is the User's right to prevent the processing of their personal data or to stop the processing of their personal data by the Data Controller.
- Right not to be subject to automated decisions and/or profiling: The right of the Website User not to be subject to an individualized decision based solely on the automated processing of his or her personal data, including profiling, unless otherwise provided by current legislation.
- Right to revoke consent: This is the right of the Website User to withdraw, at any time, the consent given for the processing of their data.
The Website user may exercise any of the aforementioned rights by contacting the Data Controller and after identifying the User using the following contact information:
- Responsible: Enjoy your bath 3000, sl
- Address: C/ Azahar, No. 1, Serena Mar Urbanization, 1 Bl.1 Building . 12570, Alcalá de Xivert (Castellón), Spain
- E-mail: info@banototal.com
- Web page: https://banototal.com
11.- RIGHT TO COMPLAIN TO THE CONTROL AUTHORITY
The user is informed of his/her right to file a complaint with the Spanish Data Protection Agency if he/she considers that a violation of data protection legislation has been committed with respect to the processing of his/her personal data.
Contact information of the supervisory authority:
Spanish Data Protection Agency
Email: info@aepd.es
Telephone: 912663517
Website : https://www.aepd.es
Address: C/. Jorge Juan, 6. 28001, Madrid (Madrid), Spain
12.- ACCEPTANCE AND CHANGES IN THE PRIVACY POLICY
It is necessary that the Website user has read and agrees to the data protection conditions contained in this Privacy Policy, as well as accepting the processing of his/her personal data so that the Data Controller can proceed with it in the manner, timeframes and purposes indicated.
The Data Controller reserves the right to modify this Privacy Policy at its own discretion or as a result of a legislative, jurisprudential or doctrinal change by the Spanish Data Protection Agency. Any changes or updates made to this Privacy Policy that affect the purposes, retention periods, transfers of data to third parties, international data transfers, as well as any rights of the Website User, will be explicitly communicated to the user.
* The user accepts that all personal data will be transferred in full to Aplazame from the moment the user has started contracting the deferred payment service offered by the latter at the time of choosing the payment method. This acceptance extends to third parties that may need to access the files for the successful completion of the contract. *Example of financing with APLAZAME for a purchase of €200.00 over 12 months and which begins to be paid 30 days after the request. A down payment of €16.65 is requested, which the user must pay using their card at the time of the transaction. The amount to be financed is the difference between the value of the basket (€200.00) and the down payment (€16.65): €183.35. 12 monthly payments of €16.65 are requested. Opening fee: €0.00. TIN: 16.19%; APR: 17.45%. Total amount owed: €199.83. Subject to approval by APLAZAME. Cash price: €200.00; Financed price: €216.48.