The purpose of this policy is to inform data subjects about the different processing activities carried out by this organisation through the website that affect their personal data, in accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and Organic Law 3/2018 of 5 December on the Protection of Personal Data and the guarantee of digital rights.
1 – Identification details
BAÑOS 10, S.L., with registered office at CARRETERA VILLARREAL-ONDA KM 12.6 (12200 ONDA), CASTELLÓN (Spain), Tax Identification Number B12291167, contact telephone +34 964 626 300, and email address rgpd@b10.es.
2 – Data Protection Officer
SEGURIDAD Y PRIVACIDAD DE DATOS, S.L., contact telephone +34 963 122 868, email address infodpo@forlopd.es.
3 – Purposes of the processing of personal data
With regard to users and visitors of the website, we process the personal data provided for the following purposes:
Handling requests, complaints and incidents submitted through the contact channels available on the website.
Understanding user browsing behaviour on the website in order to detect potential cyberattacks.
Complying with the legal obligations directly applicable to us and governing our activity.
Protecting and exercising our rights or responding to claims of any nature.
Where applicable, sending commercial communications relating to the goods or services that form part of our activity and/or news or newsletters related to our sector. Refusal to provide consent will make it impossible to send such information.
Where applicable, managing participation in competitions and promotions organised by the entity. Refusal to provide consent will make participation impossible.
Where applicable, sending satisfaction and/or quality surveys. Refusal to provide consent will make it impossible to evaluate the service provided.
In addition to the purposes indicated in the section “users/website visitors”, we process the personal data of customers for the following purposes:
Managing the commercial relationship.
Managing the provision of technical support services for our products.
Carrying out administrative, accounting and tax management.
We process the personal data of whistleblowers and affected persons (whistleblowing channel) for the following purposes:
Prevention, detection, investigation and prosecution of infringements and enforcement of sanctions.
Compliance with legal obligations directly applicable to us.
Informing the competent authorities of acts or conduct that may be contrary to the applicable regulations.
Processing communications submitted by whistleblowers.
4 – Legal basis for processing
With regard to users and website visitors:
The consent you have given us to process your data for the purposes indicated. Refusal to provide personal data will make it impossible to process them for such purposes.
Compliance with legal obligations applicable to us. In this case, the data subject may not object to the processing.
Our legitimate interest in protecting our image, business and track record by preventing attacks on our website. In this case, the data subject may not object to the processing, although they may exercise the rights recognised in the section “Rights” of this policy.
In addition to the purposes indicated in the section “users/website visitors”, customers:
Performance of a contract to which the data subject is a party or application of pre-contractual measures. Refusal to provide personal data will make it impossible to process them for such purposes.
The consent you have given us to process your data for purposes unrelated to the performance or execution of the existing contract. Refusal to provide personal data will make it impossible to process them for such purposes.
Compliance with legal obligations applicable to us. In this case, the data subject may not object to the processing.
Our legitimate interest in protecting our image, business and track record by preventing attacks on our website.
Whistleblowers and affected persons (whistleblowing channel):
Processing necessary for compliance with a legal obligation applicable to the data controller.
Processing necessary for reasons of substantial public interest, on the basis of Union or Member State law, which must be proportionate to the aim pursued, respect the essence of the right to data protection and provide appropriate and specific measures to safeguard the fundamental rights and interests of the data subject.
5 – Website add-ons and tools
We use Google Maps (API) in order to display interactive maps directly on our website and allow you to use its functions. In this regard, you should be aware that Google will collect and store information about your use of the service. The use of Google may involve International Data Transfers not based on an adequacy decision of the European Commission nor on the provision of appropriate safeguards, and therefore do not provide an adequate level of protection in accordance with the GDPR. This may entail certain risks for the protection of your personal data, including the absence of an equivalent supervisory authority and/or equivalent data protection principles and rights. We therefore recommend that you carefully read the privacy policy of our provider beforehand.
Our website uses plugins from the YouTube platform, a service provided by Google. YouTube will only associate your browsing behaviour with your personal profile if you are logged into your account. You can prevent this by logging out beforehand.
We recommend that you carefully read the privacy policy of our provider beforehand.
6 – Data retention periods or criteria
The personal data provided will be retained for as long as necessary to fulfil the purposes for which they were initially collected.
Once the data are no longer necessary for the relevant processing, they will be duly blocked and, where appropriate, made available to the competent Public Administrations and Bodies, Judges and Courts or the Public Prosecutor’s Office, during the statutory limitation periods of any actions that may arise from the relationship maintained with the customer and/or the legally established retention periods.
Data blocking period: CIVIL CODE. Between 1 and 5 years, depending on the case, in accordance with Articles 1964.2 and 1968.2 thereof.
7 – Recipients
During the period of processing of your personal data, the organisation may disclose your data to the following recipients:
Judges and Courts.
State Security Forces and Bodies.
Other competent public authorities or bodies, where there is a legal obligation to provide personal data.
Where applicable, data processors providing services to us.
8 – International data transfers
The organisation does not carry out any International Data Transfers. Should it become necessary to carry out such transfers in the future, the level of protection of the destination country will be verified and the safeguards required by law will be adopted.
9 – Social media
In order to keep you informed of our activities and updates, BAÑOS 10 S.L. has profiles on social media platforms.
All users may join our social media networks or groups. However, unless we request your data directly (for example, through marketing actions, competitions or promotions), your data will belong to the relevant social network. We therefore recommend that you carefully read their terms of use and privacy policies and configure your data processing preferences accordingly.
10 – Rights
Data subjects may request further information about the processing of their personal data and may exercise, at any time and free of charge, their rights of access, rectification and erasure, as well as request the restriction of processing, object to processing, request data portability (where technically possible), withdraw consent, and, where applicable, not to be subject to a decision based solely on automated processing, including profiling.
To this end, you may use the forms provided by the organisation or send a written request to the postal or email address indicated above. You may be required to provide your ID card or equivalent document in order to verify your identity, where this cannot be done by less intrusive means.
If you consider that your rights relating to the protection of your personal data have been infringed, particularly where you have not obtained satisfaction in exercising your rights, you may lodge a complaint with the competent Data Protection Authority (Spanish Data Protection Agency) via its website: www.aepd.es.
In accordance with Article 21 of Law 34/2002 on Information Society Services and Electronic Commerce, if you do not wish to receive further information about our services, you may unsubscribe by sending an email to rgpd@b10.es with the subject line “UNSUBSCRIBE”.
11 – Accuracy of data
The data subject guarantees that the data provided are true, accurate, complete and up to date, and undertakes to inform the organisation of any changes through the channels provided for this purpose. The data subject shall be liable for any direct or indirect damage or loss arising from failure to comply with this obligation.
Where the user provides data relating to third parties, they declare that they have obtained the consent of the data subjects and undertake to inform them of the content of this clause, releasing the organisation from any liability arising from failure to comply with this obligation.
12 – Amendments and updates
This Privacy Policy may be modified or updated in accordance with applicable legal requirements or to adapt it to instructions issued by the Spanish Data Protection Agency, or as a result of changes to our website. Users are therefore advised to review this Privacy Policy periodically.
If you have any questions regarding this policy, you may contact BAÑOS 10, S.L. via the forms provided by the organisation or by sending a written request to the postal or email address indicated above.