Certix

Privacy Policy

Data Controller Information

COMPANY NAME: CERTIFICACIÓN Y GESTIÓN NORMATIVA S.L.U | CERTIX (hereinafter, the "COMPANY" or the "CONTROLLER").
VAT NUMBER: B09601477
REGISTERED ADDRESS: AV. DE LOS REYES CATÓLICOS Nº44 - ENTREPLANTA OFICINA 7. 09005 BURGOS
PHONE: 611 030 124
EMAIL for Data Protection communications: soporte@certix.es

APPLICABLE REGULATIONS: Our Privacy Policy has been designed in accordance with EU General Data Protection Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights, and Law 34/2002 of 11 July on Information Society Services and Electronic Commerce (LSSI-CE).

CERTIFICACIÓN Y GESTIÓN NORMATIVA S.L.U may amend this Privacy Policy to adapt it to legislative, jurisprudential or interpretive developments by the Spanish Data Protection Agency. These privacy conditions may be supplemented by the Legal Notice, Cookie Policy and, where applicable, the General Conditions that may be established for certain products or services, if such access involves any specific data protection requirements.

Purposes and Legal Bases for Personal Data Processing

At CERTIFICACIÓN Y GESTIÓN NORMATIVA S.L.U we collect and process your personal information in general to manage the relationship we have with you. The main purposes are as follows:

  1. To respond to enquiries, requests for information, suggestions, professional contact, process orders, appointments, bookings, demonstrations, requests or any type of petition made by the data subject through any of the contact methods made available by the Controller on this website or other means. - To manage our commercial relationship. - To send you communications about products similar to those you have previously purchased, as well as updates on our products or services that may be of interest to you. - To conduct market research, statistical analysis, surveys or satisfaction assessments. The legal basis is the legitimate interest of the Controller.
  2. To send you news about our organisation, promotions, advertising, newsletters, updates to our product and service catalogue by any electronic or physical means, present or future, that make such commercial communications possible. The legal basis is the consent of the data subject.
  3. To carry out the contractual or pre-contractual formalities required with data subjects for the hiring and provision of professional services offered by the Controller, and to manage, maintain, improve and develop a commercial, mercantile or administrative relationship at all levels with our clients, users, suppliers and other data subjects, as well as the proper supervision of services provided. The legal basis is the performance of a contract or pre-contract to which the data subject is a party, as well as compliance with legal obligations applicable to the Controller.
  4. For the invoicing and accounting of products or services provided. The legal basis is compliance with legal obligations.
  5. Management of the data subject's application in the Controller's selection processes in line with their professional profile that may arise within the activities of the Controller. The legal basis is the express consent given through a positive and affirmative act at the time of providing us with their data.
  6. Regarding the use of cookies for various purposes (technical, analytical, etc.) by this website, as specified in the cookies section which we invite you to consult. The legal basis will be the consent given for cookies that require it.

Data Retention Period

Personal data processed for purposes (A), (B), (C) and (D) will be retained for no longer than is necessary to maintain the purpose of the processing or where legal retention requirements apply, and when it is no longer necessary, it will be deleted with adequate security measures to ensure the anonymisation of the data or its total destruction.

Personal data obtained for purpose (E) will be retained for the time necessary for the purpose of the processing or for a maximum of 12 months, after which it will be blocked or destroyed.

In any case, and as a general rule, we will retain your personal information for as long as a commercial, pre-contractual or contractual relationship binds us to you, to comply with legal obligations, or until you exercise your right to erasure and/or restriction of processing. In such cases, the information may be blocked without use beyond its retention, while it may be necessary for the exercise or defence of claims or any type of liability may arise that needs to be addressed.

Regarding cookies used (F), as specified in the cookies section of this website.

Categories of Data

We collect your personal information through different means. In general, the personal information we process relates to identifying, contact and financial data categories, such as: name and surnames, national ID number, telephone, postal address, email, payment and billing data, as well as the IP address from which you access the data collection form.

Data processed within a contractual, pre-contractual, commercial or mercantile relationship may also include, in addition to the above: goods and services transaction data, social circumstances, personal characteristics, commercial information, economic, financial and insurance data, legal representative, banking data, manual or electronic signature, professional and academic data or other categories required by the nature of the products and services provided by the Controller.

CERTIFICACIÓN Y GESTIÓN NORMATIVA S.L.U uses social networks as another way to reach you. Information collected through messages and communications you publish may contain personal information that is available online and publicly accessible. These social networks have their own privacy policies explaining how they use and share your information, and CERTIFICACIÓN Y GESTIÓN NORMATIVA S.L.U recommends that you consult them before using these networks to confirm that you agree with the way your information is collected, processed and shared.

Data collected for purpose (E) will relate to professional and contact details: name, surnames, telephone, email, CV, cover letter and any other personal data associated with the CV or professional profile.

International Transfers

No international data transfers are envisaged. If for certain services technological providers with servers outside the European Economic Area are used, these guarantee an adequate level of data protection in accordance with the GDPR, through adequacy decisions or standard contractual clauses.

Mandatory Nature of Providing Data

USERS, by ticking the corresponding boxes and entering data in fields marked with an asterisk (*) in the contact form or forms presented for download, expressly and freely and unequivocally accept that their data is necessary to attend to their request by the provider, while the inclusion of data in the remaining fields is voluntary. The USER guarantees that the personal data provided to the CONTROLLER is true and takes responsibility for communicating any changes to it. The CONTROLLER informs that all data requested through the website is mandatory, as it is necessary for the provision of an optimal service to the USER. If all data is not provided, it cannot be guaranteed that the information and services provided will be completely suited to your needs.

Data Disclosure

As a general rule, no transfers or international transfers of your data are envisaged. However, those authorised by fiscal, commercial or telecommunications legislation may be made, as well as those required by judicial authorities, law enforcement bodies, or public administrations in the exercise of their competences. Identification and financial data may be communicated to banking entities or payment platform managers, as well as to insurance companies, transport companies or intermediaries, if necessary to achieve the purposes of the processing.

Data subjects are informed that for the proper business management, sale or provision of services, CERTIFICACIÓN Y GESTIÓN NORMATIVA S.L.U has contracted external service providers, such as specialised external advisors, auditors, legal services, hosting services, marketing, web development and email, software companies, IT support and maintenance, document management, security companies or similar when necessary for the purposes of the processing or the occasional or recurring needs of CERTIFICACIÓN Y GESTIÓN NORMATIVA S.L.U. Legally required contracts are entered into with these providers under which compliance with their obligations as Data Processors is guaranteed.

In the event of sharing your data with third parties for any other purpose, the Data Controller will inform and obtain the prior consent of the data subject.

In the case of use of third-party cookies, those provided for in the section dedicated to "cookies" information on this website.

User Rights

Every person whose personal data is processed has the following rights:

  • Right of access: allows you to know whether we process your personal data and to obtain information about how and for what purpose we use it, as well as to receive a copy of the data processed.
  • Right of rectification: allows you to request the correction of inaccurate or incomplete personal data so that it is correctly updated.
  • Right to erasure: allows you to request the deletion of personal data when it is no longer necessary, consent has been withdrawn, processing is unlawful or other legally provided grounds, unless there is a legal obligation to retain it.
  • Right to object: allows you to object to the processing of your personal data for reasons related to your particular situation. It may also be exercised at any time to prevent the use of data for direct marketing purposes, including profiling.
  • Right to restriction of processing: allows you to request, in certain circumstances, that the processing of your data be restricted to its retention or to specific purposes, such as the exercise or defence of claims, the protection of third parties or for public interest.
  • Right to data portability: allows you to receive the personal data provided, in digital format, and to transmit it to another controller, when the processing is based on consent or a contract and is carried out by automated means.
  • Right not to be subject to automated decisions (including profiling): allows you not to be subject to decisions based solely on the automated processing of data, which produce legal effects or significantly affect you, except in cases permitted by regulations or where explicit consent exists.
  • Right to withdraw consent: allows you to revoke consent given at any time, without affecting the lawfulness of processing carried out prior to withdrawal.

Furthermore, and especially if you consider that you have not obtained full satisfaction in the exercise of your rights, we inform you that you may lodge a complaint with the national supervisory authority by contacting the Spanish Data Protection Agency, C/ Jorge Juan, 6 – 28001 Madrid. (www.aepd.es).

To facilitate processing, it is recommended to clearly state in the email subject or letter heading: "EXERCISE OF PERSONAL DATA RIGHTS"

The Controller has model forms available to facilitate the exercise of your rights, which can be requested through the available means (email or post) or by telephone, indicating an address for their delivery. The use of these forms is voluntary.

The data subject may also use, if they wish, the forms prepared by the Spanish Data Protection Agency, available on its website:
https://www.aepd.es/reglamento/derechos/index.html

Contact details to exercise your rights:
CERTIFICACIÓN Y GESTIÓN NORMATIVA S.L.U B09601477 | C/ALFONSO X EL SABIO, 4 - 1 IZ 09005 BURGOS (Burgos) SPAIN | 672739409 | soporte@certix.es

How Do We Protect Your Information?

At CERTIFICACIÓN Y GESTIÓN NORMATIVA S.L.U we are committed to protecting your personal information. We use reasonably reliable and effective physical, organisational and technological measures, controls and procedures aimed at preserving the integrity and security of your data and ensuring your privacy. Furthermore, all staff with access to personal data has been trained and is aware of their obligations in relation to the processing of personal data.

The contracts we enter into with our providers include clauses requiring them to maintain the duty of confidentiality with respect to personal data they have accessed by virtue of the assignment, as well as to implement the necessary technical and organisational security measures to guarantee the permanent confidentiality, integrity, availability and resilience of personal data processing systems and services.

All these security measures are reviewed periodically to ensure their adequacy and effectiveness. However, absolute security cannot be guaranteed and there is no security system that is impenetrable. Therefore, in the event that any information subject to processing and under our control is compromised as a result of a security breach, we will take appropriate measures to investigate the incident, notify the supervisory authority and, where applicable, those users who may have been affected so that they can take appropriate action.

User Responsibility

By providing us with their data, the user guarantees that the data provided to the Controller is true, accurate, complete and up to date. To this end, the user confirms that they are responsible for the accuracy of the data communicated and will keep said information duly updated so that it reflects their actual situation, taking responsibility for any false and inaccurate data they may provide, as well as direct or indirect damages that may arise.