Privacy Policy
Data Controller
- Data Controller: FIGRUPO MARINAS S.L.
- NIF: B15997794
- Address: Paseo Marítimo Alcalde Francisco Vázquez, S/N, 15001, A Coruña
- E-mail for exercising data protection rights: marina@marinacoruna.es
- Data Protection Officer: NorQuality Consultores, S.L.
- E-mail: protecciondedatos@norquality.es
Purposes and Legal Bases
In addition to the basic data protection information provided through each of the data collection channels, the following additional information is provided regarding the purposes, legal bases and other information relating to the following files or processing activities:
- Customers: Personal data will be processed for the purpose of providing the contracted service or product, as well as for invoicing, collections, payments, delivery or shipment of products, accounting, tax and administrative management, including the maintenance of the commercial relationship. The lawfulness of the processing is based on Article 6.1.b of the GDPR: “processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract”.
- Potential customers: Personal data will be processed for the purpose of presenting quotations/offers for products or services and responding to information requests in accordance with the customer’s requirements. The lawfulness of the processing is based on Article 6.1.a of the GDPR: “the data subject has given consent to the processing of his or her personal data for one or more specific purposes”.
- Professional contacts: Data will be processed for the purpose of maintaining the professional or commercial relationship between our organisation and the entity (natural or legal person) to which the relevant individuals belong. This includes identifying the contact person, managing communications necessary for the development of the relationship, coordinating activities, responding to enquiries, as well as locating the contact person through the means provided. The lawfulness of the processing is based on Article 6.1.f of the GDPR: “processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child”, in accordance with the provisions implementing Article 19 of the LOPDGDD.
- Suppliers: Data will be processed for the proper management and monitoring of suppliers and the provision of contracted services, purchased products, or the receipt, shipment and handling of enquiries. This includes the management of commercial reports, delivery notes and payment of supplier invoices, as well as accounting, tax and administrative management and maintenance of the commercial relationship. The lawfulness of the processing is based on Article 6.1.b of the GDPR: “processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract”.
- Job applications: Where CVs are received, they will be reviewed to determine whether the applicant’s profile matches any of our available positions.
The lawfulness of the processing is based on Article 6.1.a of the GDPR: “the data subject has given consent to the processing of his or her personal data for one or more specific purposes”.
- Contact: Contact details will be used to manage your request or enquiry. The lawfulness of the processing is based on Article 6.1.a of the GDPR: “the data subject has given consent to the processing of his or her personal data for one or more specific purposes”.
- Video surveillance: Personal data will be processed for the purpose of ensuring the security of facilities, property and individuals. The lawfulness of the processing is based on Article 6.1.f of the GDPR: “processing is necessary for the purposes of the legitimate interests pursued by the controller” and Article 22.1 of the LOPDGDD: “Natural or legal persons, public or private, may process images through camera or video surveillance systems for the purpose of preserving the security of persons and property, as well as their facilities”.
- Website users: Personal data collected as a result of visiting our website will be processed for the following purposes:
- Contact section for submitting enquiries, complaints, suggestions or claims
- Analysis of browsing habits through analytics cookies (see the Cookie Policy published on the website).
Where your data is received as a result of using the contact form or submitting CVs, the lawfulness of the processing is based on Article 6.1.a of the GDPR: “the data subject has given consent to the processing of his or her personal data for one or more specific purposes”.
- Social media: Data will be processed for the dissemination of activities/events organised by the company, the promotion of our services/products and/or the presentation of employees in the performance of their activities through the public social media profiles associated with FIGRUPO MARINAS S.L.
The lawfulness of the processing is based on Article 6.1.a of the GDPR: “the data subject has given consent to the processing of his or her personal data for one or more specific purposes”.
- Rights Management: Personal data will be processed for the management, analysis and response to data protection rights exercised by data subjects within the framework of the applicable legislation. The lawfulness of the processing is based on Article 6.1.c of the GDPR: “processing is necessary for compliance with a legal obligation to which the controller is subject”.
- Regulation (EU) 2016/679 of the European Parliament and of the Council
- Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights
- Data transfers or disclosures.
For the management of certain services offered by the entity, it is necessary to allow certain data to be accessed by third-party service providers contracted for this purpose. In this regard, the entity enters into the relevant data processing agreements and has provided the necessary instructions to the various service providers or data processors to ensure the security and integrity of the data to which they have access in connection with the provision of the contracted service.
Except in the cases described above, your personal data will not be disclosed to third parties, except where legally required.
Data Retention Period
In addition to the basic data protection information provided through each of the data collection channels, the following additional information is provided regarding the purposes and legal bases of the following files or processing activities:
- Customers: the data will be retained until the end of the contractual relationship and will remain, duly blocked, for the statutory limitation periods applicable to any liabilities that may arise (6 years).
- Potential customers: the data will be retained for 1 year.
- Suppliers: the data will be retained for as long as necessary to fulfil the purpose for which it was collected.
- Professional contacts: the data will be retained until the end of the professional relationship with the data subject.
- Employees: the data will be retained for the legally established retention periods.
- Job applications: the data will be retained for 1 year.
- Video surveillance: the data will be retained for 30 days.
- Website users: the data will be retained for as long as their request is being processed (contact).
- Social media: the data will be retained for as long as the consent granted by the data subject remains valid, without prejudice to their right to withdraw it at any time.
- Rights management: the data will be retained for as long as necessary to fulfil the purpose for which it was collected and to determine any potential liabilities that may arise from that purpose and from the processing of the data.
Profiling and International Data Transfers
No automated profiling will be carried out. The company uses tools such as Microsoft 365, which may involve potential international transfers of data outside the European Economic Area. These transfers are always carried out on the basis of adequacy decisions that provide a level of data protection equivalent to that guaranteed by EU legislation.
In the absence of an adequacy decision, transfers will be carried out through the signing of Standard Contractual Clauses approved by the European Commission, which guarantee an adequate level of protection for personal data.
Likewise, the company will implement appropriate technical and organisational measures to ensure the security of the personal data transferred, with the aim of ensuring its confidentiality, integrity and availability, while minimising the potential risks arising from processing in those third countries.
Withdrawal of Consent
In cases where the processing of personal data is based on consent, data subjects are informed of their right to withdraw their consent at any time, easily and free of charge, by written notice addressed to the Data Controller or via marina@marinacoruna.es. Withdrawal of consent shall not affect the lawfulness of processing based on consent prior to its withdrawal.
Rights of Data Subjects
Data protection legislation grants data subjects or data owners a number of rights. These rights are as follows:
- Right of access: the right to obtain information as to whether their personal data is being processed, the purpose of the processing being carried out, the categories of data concerned, the recipients or categories of recipients, the retention period and the source of such data.
- Right to rectification: the right to obtain the rectification of inaccurate or incomplete personal data.
- Right to object: the right to object to a specific processing activity based on the consent given.
- Right to erasure: the right to obtain the erasure of data in the following circumstances:
- When the data is no longer necessary for the purpose for which it was collected
- When the data subject withdraws their consent
- When the data subject objects to the processing
- When the data must be erased in compliance with a legal obligation
- When the data has been obtained in connection with an information society service pursuant to Article 8(1) of the European Data Protection Regulation.
- Right to restriction of processing: the right to obtain restriction of the processing of data where any of the following circumstances apply:
- When the data subject contests the accuracy of the personal data, for a period enabling the company to verify its accuracy.
- When the processing is unlawful and the data subject opposes the erasure of the data.
- When the company no longer needs the data for the purposes for which it was collected, but the data subject requires it for the establishment, exercise or defence of legal claims.
- When the data subject has objected to processing while verification is pending as to whether the legitimate grounds of the company override those of the data subject.
- Right to data portability: the right, where processing is carried out by automated means, to receive personal data in a structured, commonly used, machine-readable and interoperable format and to transmit it to another controller, provided that the processing is based on consent or is necessary for the performance of a contract.
- By its nature, this right does not apply where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
- Right not to be subject to automated individual decision-making: the right not to be subject to a decision based solely on the processing of personal data, including profiling, which produces legal effects concerning the data subject or similarly significantly affects them.
This right shall not apply where:
- It is necessary for entering into or performing a contract between you and the controller
- The processing of your data is based on your prior consent
*In these first two cases, the controller must guarantee the data subject’s right to obtain human intervention, express their point of view and contest the decision.
- It is authorised by Union or Member State law and appropriate measures are established to safeguard the data subject’s rights, freedoms and legitimate interests.
*Furthermore, these exceptions shall not apply to special categories of data (Article 9.1), unless Article 9.2(a) or (g) applies and the appropriate safeguards referred to in the preceding paragraph have been adopted.
Data subjects may exercise the aforementioned rights by contacting the entity in writing at marina@marinacoruna.es, indicating in the subject line the right they wish to exercise, or, if preferred, by sending their request to the company’s postal address: Paseo Marítimo Alcalde Francisco Vázquez, S/N, 15001, A Coruña. The entity will respond to your request as soon as possible and within the time limits established by data protection legislation.
FIGRUPO MARINAS S.L. has appointed a Data Protection Officer, who can be contacted at protecciondedatos@norquality.es.
If you consider that your rights have not been properly addressed, you have the right to lodge a complaint with the Spanish Data Protection Agency at www.aepd.es
Security
The security measures adopted by the entity are those required in accordance with Article 32 of the GDPR. In this regard, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the entity has established appropriate technical and organisational measures to ensure a level of security appropriate to the existing risk.
In any event, the entity has implemented sufficient mechanisms to:
- Ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
- Restore the availability of and access to personal data quickly in the event of a physical or technical incident.
- Regularly verify, assess and evaluate the effectiveness of the technical and organisational measures implemented to ensure the security of the processing.
- Pseudonymise and encrypt personal data, where appropriate.
- Limit and control access to personal data.
Cookies
A cookie is a file or device that is downloaded to the user’s terminal equipment for the purpose of storing data that may be updated and retrieved by the entity responsible for its installation. In other words, it is a file that is downloaded to your computer when you access certain websites. For more information, please consult our Cookie Policy.