Privacy policy
WEBSITE PRIVACY POLICY · pdsinternacional.com
I. Privacy and data protection policy
In compliance with the provisions of the legislation in force, Pablo Di Santo Internacional S.L. (hereinafter, also the Website) undertakes to adopt the technical and organisational measures necessary, in accordance with the level of security appropriate to the risk of the data collected.
Laws incorporated into this privacy policy
This privacy policy is adapted to the Spanish and European regulations in force regarding the protection of personal data on the Internet. Specifically, it complies with the following rules:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR).
- Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and the guarantee of digital rights (LOPD-GDD).
- Royal Decree 1720/2007 of 21 December, approving the Regulation implementing Organic Law 15/1999 of 13 December on the Protection of Personal Data (RDLOPD).
- Spanish Law 34/2002 of 11 July on Information Society Services and Electronic Commerce (LSSI-CE).
Identity of the data controller
The controller of the personal data collected is Pablo Di Santo Internacional S.L., holder of Tax ID (NIF/CIF) B93147494 and registered with the Commercial Registry of Málaga, whose representative is Pablo Di Santo (hereinafter, the Data Controller). Its contact details are as follows:
- Address: Calle La Fuente n.º 18, 29610 Ojén (Málaga), Spain
- Contact telephone: 951 56 23 87
- Contact email: info@pdsinternacional.com
Registration of personal data
In compliance with the provisions of the GDPR and the LOPD-GDD, we inform you that the personal data collected by Pablo Di Santo Internacional S.L., through the forms provided on its pages, will be incorporated into and processed in our file in order to facilitate, expedite and fulfil the commitments established between Pablo Di Santo Internacional S.L. and the User, or to maintain the relationship established in the forms that the User completes, or to deal with a request or query from the User. Likewise, in accordance with the provisions of the GDPR and the LOPD-GDD, unless the exception provided for in Article 30.5 of the GDPR applies, a record of processing activities is kept that specifies, according to their purposes, the processing activities carried out and the other circumstances established in the GDPR.
Principles applicable to the processing of personal data
The processing of the User’s personal data shall be subject to the following principles set out in Article 5 of the GDPR and in Article 4 et seq. of Organic Law 3/2018 of 5 December on the Protection of Personal Data and the guarantee of digital rights:
- Principle of lawfulness, fairness and transparency: the User’s consent will be required at all times following completely transparent information about the purposes for which the personal data are collected.
- Principle of purpose limitation: personal data will be collected for specified, explicit and legitimate purposes.
- Principle of data minimisation: the personal data collected will be only those strictly necessary in relation to the purposes for which they are processed.
- Principle of accuracy: personal data must be accurate and always kept up to date.
- Principle of storage limitation: personal data will only be kept in a form that permits identification of the User for as long as is necessary for the purposes of their processing.
- Principle of integrity and confidentiality: personal data will be processed in a manner that guarantees their security and confidentiality.
- Principle of accountability: the Data Controller will be responsible for ensuring that the foregoing principles are complied with.
Categories of personal data
The categories of data processed at Pablo Di Santo Internacional S.L. are solely identification data. Under no circumstances are special categories of personal data within the meaning of Article 9 of the GDPR processed.
Legal basis for the processing of personal data
The legal basis for the processing of personal data is consent. Pablo Di Santo Internacional S.L. undertakes to obtain the express and verifiable consent of the User for the processing of their personal data for one or more specific purposes.
The User shall have the right to withdraw their consent at any time. It shall be as easy to withdraw consent as to give it. As a general rule, the withdrawal of consent will not condition use of the Website.
On occasions where the User must or may provide their data through forms to make queries, request information or for reasons related to the content of the Website, they will be informed if completing any of these is mandatory because such data are essential for the correct development of the operation carried out.
Purposes of the processing of personal data
Personal data are collected and managed by Pablo Di Santo Internacional S.L. for the purpose of facilitating, expediting and fulfilling the commitments established between the Website and the User, or maintaining the relationship established in the forms that the latter completes, or dealing with a request or query.
Likewise, the data may be used for a commercial purpose of personalisation, operations and statistics, and activities pertaining to the corporate purpose of Pablo Di Santo Internacional S.L., as well as for data extraction and storage and marketing studies in order to adapt the Content offered to the User, as well as to improve the quality, operation and navigation of the Website.
At the time the personal data are obtained, the User will be informed about the specific purpose or purposes of the processing for which the personal data will be used; that is, about the use or uses that will be made of the information collected.
Retention periods for personal data
Personal data will only be retained for the minimum time necessary for the purposes of their processing and, in any event, only for the period legally established or until the User requests their deletion.
At the time the personal data are obtained, the User will be informed about the period during which the personal data will be kept or, where this is not possible, the criteria used to determine this period.
Recipients of personal data
The User’s personal data will not be disclosed to third parties, except where required by law. Should the Data Controller intend to transfer personal data to a third country or international organisation, at the time the personal data are obtained the User will be informed about the third country or international organisation to which it is intended to transfer the data, as well as about the existence or absence of an adequacy decision by the Commission.
Personal data of minors
In compliance with the provisions of Article 8 of the GDPR and Article 7 of Organic Law 3/2018 of 5 December on the Protection of Personal Data and the guarantee of digital rights, only persons over 14 years of age may give their consent to the lawful processing of their personal data by Pablo Di Santo Internacional S.L. In the case of a minor under 14 years of age, the consent of parents or guardians will be required for processing, and this will only be considered lawful to the extent that they have authorised it.
Secrecy and security of personal data
Pablo Di Santo Internacional S.L. undertakes to adopt the technical and organisational measures necessary, in accordance with the level of security appropriate to the risk of the data collected, so as to guarantee the security of personal data and prevent the accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed, or the unauthorised communication of or access to such data.
The Website has an SSL (Secure Socket Layer) certificate, which ensures that personal data are transmitted securely and confidentially, as the transmission of data between the server and the User, and back, is fully encrypted.
However, because Pablo Di Santo Internacional S.L. cannot guarantee the impregnability of the Internet or the total absence of hackers or others who fraudulently access personal data, the Data Controller undertakes to notify the User without undue delay when a personal data security breach occurs that is likely to result in a high risk to the rights and freedoms of natural persons. In accordance with the provisions of Article 4 of the GDPR, a personal data security breach is understood to mean any breach of security leading to the accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed, or the unauthorised communication of or access to such data.
Personal data will be treated as confidential by the Data Controller, who undertakes to inform of and to guarantee, by means of a legal or contractual obligation, that such confidentiality is respected by its employees, associates and any person to whom it makes the information accessible.
Rights arising from the processing of personal data
The User has the following rights against Pablo Di Santo Internacional S.L. and may therefore exercise the following rights recognised in the GDPR and Organic Law 3/2018 of 5 December against the Data Controller:
- Right of access: the User’s right to obtain confirmation of whether or not their personal data are being processed and, if so, to obtain information about their specific data and the processing carried out, as well as, among other things, the available information about the origin of such data and the recipients of the communications.
- Right of rectification: the right to have their personal data modified if they are found to be inaccurate or, taking into account the purposes of the processing, incomplete.
- Right of erasure (“right to be forgotten”): the right to obtain the erasure of their personal data when these are no longer necessary for the purposes for which they were collected, among other cases provided for in the regulations.
- Right to restriction of processing: the right to restrict the processing of their personal data in the cases legally provided for.
- Right to data portability: in the event that the processing is carried out by automated means, the right to receive their personal data in a structured, commonly used and machine-readable format, and to transmit them to another controller.
- Right to object: the right to have the processing of their personal data not carried out or to have it cease.
- Right not to be subject to a decision based solely on automated processing, including profiling, unless the legislation in force provides otherwise.
The User may exercise their rights by means of a written communication addressed to the Data Controller with the reference “GDPR-pdsinternacional.com”, specifying: the User’s first name and surname and a copy of their national ID document (or any other legally valid means proving their identity); the request with the specific reasons for the application or the information they wish to access; an address for the purposes of notifications; the date and signature of the applicant; and any document supporting the request. This request may be sent to:
- Postal address: Calle La Fuente n.º 18, 29610 Ojén (Málaga), Spain
- Email: info@pdsinternacional.com
Links to third-party websites
The Website may include hyperlinks or links that allow access to web pages of third parties other than Pablo Di Santo Internacional S.L., and which are therefore not operated by it. The owners of such websites will have their own data protection policies, being themselves, in each case, responsible for their own files and their own privacy practices.
Complaints to the supervisory authority
Should the User consider that there is a problem or infringement of the regulations in force in the way in which their personal data are being processed, they shall have the right to effective judicial protection and to lodge a complaint with a supervisory authority, in particular in the State in which they have their habitual residence, place of work or place of the alleged infringement. In the case of Spain, the supervisory authority is the Spanish Data Protection Agency (https://www.aepd.es/).
II. Acceptance of and changes to this privacy policy
It is necessary that the User has read and agrees to the conditions on the protection of personal data contained in this Privacy Policy, and that they accept the processing of their personal data so that the Data Controller may proceed with it in the manner, for the periods and for the purposes indicated. Use of the Website will imply acceptance of its Privacy Policy.
Pablo Di Santo Internacional S.L. reserves the right to modify its Privacy Policy, at its own discretion or as a result of a legislative, case-law or doctrinal change by the Spanish Data Protection Agency. The User is recommended to consult this page periodically to keep up to date with the latest changes or updates.