Privacy Policy

Privacy Policy

Responsible for the processing of personal data

In compliance with the provisions of Regulation (EU) 2016/679, General Data Protection Regulation (GDPR), and Organic Law 3/2018, on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), the user is informed that the personal data collected through this website will be processed by:

Owner: Jordi Atienza Sala
Address: Apdo. de Correos, 49 – 17255 Begur (Girona), España
Website: https://jordiatienza.com
Contact email: jordi@jordiatienza.com

The responsible party guarantees the application of the necessary technical and organizational measures to ensure the confidentiality, integrity and availability of the information, in accordance with current regulations.

Purpose of processing personal data

The personal data collected through this website may be processed for the following purposes:

  • Handling inquiries and communications: Responding to requests for information, inquiries, or any other type of communication submitted by users through the forms available on the website or via email.
  • Providing contracted services: Managing the contractual, administrative, and accounting relationship arising from the purchase of products or services offered by the owner.
  • Sending commercial communications: Sending information related to products, services, news, or promotions, provided the user has given their express consent.
  • Website statistics and improvement: Conducting statistical analyses of website traffic and usage to optimize the browsing experience and improve the content and services offered.
  • Compliance with legal obligations: Responding to requests from competent authorities and complying with applicable legal obligations regarding tax, commercial, and data protection matters.

Under no circumstances will personal data be used for purposes other than those expressly indicated in this Privacy Policy, unless the user’s prior and express consent is obtained.

Legal basis for processing personal data

The processing of the user’s personal data by the controller is based on the following legal grounds:

  • Express user consent: When users provide their data through the forms available on the website, check the acceptance boxes, or subscribe to marketing communications, they give their free, specific, informed, and unambiguous consent for the processing of their data.
  • Performance of a contract: Processing is necessary for the management and provision of the services contracted by the user, as well as for the administrative, accounting, and tax procedures arising from this relationship.
  • Compliance with legal obligations: The data controller must process certain data to comply with obligations imposed by current regulations, such as tax, commercial, or data protection legislation.
  • Legitimate interest of the data controller: In certain cases, data processing may be based on the legitimate interest of the data controller, for example, to ensure network and information security, or to conduct market research to improve the services offered.

In any case, the responsible party undertakes to respect the principles of lawfulness, fairness and transparency established in the GDPR, guaranteeing that personal data will only be processed in accordance with the purposes described and with the corresponding legal bases.

Personal data retention period

The personal data provided by the user will only be kept for as long as necessary to fulfill the purpose for which it was collected. Specifically:

  • Contractual data: This data will be retained for the duration of the contractual relationship and, subsequently, for the legally required periods to address any potential liabilities arising from it.
  • Communications and inquiries data: This data will be retained as long as necessary to address the request made and, where applicable, until the user requests its deletion.
  • Data for commercial or promotional purposes: This data will be retained until the user revokes their consent or requests to unsubscribe from such communications.
  • Browsing and analytics data: This data will be retained for a reasonable period to allow for statistical analysis, always in anonymized form, and never longer than strictly necessary for the purposes described.
  • Website comments data: This data will be retained as long as necessary to fulfill the intended purpose and, subsequently, for the legally required periods to address any potential liabilities..

In any case, the data will be kept blocked while legal, administrative or tax liabilities may arise, and will be securely deleted once these periods have elapsed.

Communication of data to third parties

The data controller informs that users’ personal data will not be transferred to third parties, except in the following cases:

  • Legal obligation: When the transfer is based on a law or required by a competent authority in the exercise of its functions.
  • Provision of necessary services: When essential for the proper provision of the contracted services, which may involve access to the data by external providers acting as data processors (for example, web hosting services, technical support, management tools, or communication platforms).
  • Explicit user consent: In cases where the user has explicitly authorized the transfer of their data to third parties for specific purposes.

In all cases, the controller guarantees that the third parties with whom data is shared comply with current data protection regulations, signing the corresponding processing agreements and applying the appropriate technical and organizational measures to protect personal information.

Furthermore, certain services used on this website may involve the communication of data to third parties, such as the Gravatar service for displaying profile pictures in comments, or automated spam detection systems (e.g., Akismet). In these cases, data processing is carried out in accordance with the privacy policies of those providers.

Users' rights regarding data protection

The user has the right to exercise at any time the following rights recognized by Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD):

  • Right of access: To obtain confirmation as to whether your personal data is being processed and, if so, to access it.
  • Right to rectification: To request the correction of inaccurate or incomplete data.
  • Right to erasure (“right to be forgotten”): To request the deletion of your data when, among other reasons, it is no longer necessary for the purposes for which it was collected.
  • Right to object: To object to the processing of your data in certain circumstances, for example, for commercial or direct marketing purposes.
  • Right to restriction of processing: To request that the processing of your data be restricted in certain cases, with it being retained only for the exercise or defense of legal claims.
  • Right to data portability: To receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another data controller.

You may exercise these rights by sending a written request to the data controller via email at jordi@jordiatienza.com, accompanied by a copy of a valid identification document.

You also have the right to file a complaint with the Spanish Data Protection Agency (AEPD) if you believe that the processing of your personal data violates current regulations.

Security measures in the processing of personal data

The data controller declares that it has adopted the necessary technical and organizational measures to guarantee the security of personal data and prevent its alteration, loss, unauthorized processing or access, in accordance with the provisions of Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD).

The measures implemented include:

  • Access control: Restricting access to personal data to authorized personnel only.
  • Confidentiality: A confidentiality agreement signed by all individuals involved in the data processing process.
  • Technological protection: Use of cybersecurity systems, encrypted communications, and regular backups.
  • Monitoring and auditing: Periodic review of security procedures and updating of measures in accordance with technological and regulatory advancements.
  • Incident management: Protocols for detecting, reporting, and responding to potential security breaches.

The data controller undertakes to maintain and update these security measures to ensure at all times the adequate protection of the personal data processed.

Updates and modifications to the Privacy Policy

This Privacy Policy may be modified at any time to adapt to legislative or regulatory changes, or to instructions issued by the Spanish Data Protection Agency or other competent authorities.

In the event of substantial modifications, users will be notified through notices on the website itself or, in the case of registered users, via email.

Users are advised to periodically review the content of this Privacy Policy to stay informed about how their personal data is protected.

wpChatIcon
wpChatIcon
We are using cookies to give you the best experience. You can find out more about which cookies we are using or switch them off in privacy settings.
AcceptPrivacy Settings

GDPR