Inicio / Privacy policy
Privacy policy
Please read the Terms and Conditions set out below carefully, as use of this website constitutes your express and full acceptance of them in the version published when you access the website. We recommend that you reread this sectiony each time you access the website to check whether the terms of use have changed and leave the website if you do not agree with any such changes. If we consider certain amendments to be significant, we will update the “Last modified” date at the top of this page. You are responsible for reviewing and familiarising yourself with any amendments made.
LEGISLATION INCORPORATED INTO THIS PRIVACY POLICY
This policy has been adapted to the following legislation currently in force in Spain and Europe:
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR).
Organic Law 3/2018 of 5 December on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD).
Law 34/2002 of 11 July on Information Society Services and Electronic Commerce (LSSI-CE).
1. IDENTIFICATION
In compliance with the duty to provide information laid down in Article 10 of Law 34/2002 of 11 July on Information Society Services and Electronic Commerce, and with current data protection legislation, specifically Organic Law 3/2018 of 5 December on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD), which gives full effect to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR), the following information is provided:
Data Controller: DIAL GROUP (hereinafter, THE COMPANY).
Trading name: DIAL GROUP
2. CONTACT
To contact us regarding any matter relating to the processing of personal data, you may use any of the contact methods set out below:
Telephone: +34 881 103 292
Email: dial@grupodial.es
Registered office: Rúa Marisqueira, 10, 15670 Acea da Má, A Coruña
Website: https://grupodial.es
All notices and communications made using any of the methods set out in this section will be deemed effective for all purposes.
We understand that the privacy and security of your personal information are extremely important. This policy therefore explains what we do with your information and how we keep it secure. It also explains where and how we collect your personal information and your rights in relation to any personal information we hold about you.
Principles applicable to the processing of personal data
The processing of the User’s personal data will be subject to the following principles set out in Article 5 of the GDPR and Article 4 et seq. of Organic Law 3/2018 of 5 December on Personal Data Protection and Guarantee of Digital Rights:
- Lawfulness, fairness and transparency: the User’s consent will be required at all times, after fully transparent information has been provided about the purposes for which the personal data is collected.
- Purpose limitation: personal data will be collected for specified, explicit and legitimate purposes.
- Data minimisation: the personal data collected will be limited to what is strictly necessary in relation to the purposes for which it is processed.
- Accuracy: personal data must be accurate and kept up to date at all times.
- Storage limitation: personal data will be kept in a form that permits identification of the User only for as long as necessary for the purposes of processing.
- Integrity and confidentiality: personal data will be processed in a manner that ensures its security and confidentiality.
- Accountability: the Data Controller will be responsible for ensuring compliance with the above principles.
What measures have we taken to ensure the confidentiality, integrity and security of your data?
- We request only the minimum amount of information required, collecting only what we consider essential for conducting business or for the relevant specific transaction;
- We have entered into confidentiality agreements with all our suppliers, staff and collaborators;
- We have specialist advisers who not only provide us with ongoing support in this area but also carry out regular checks to ensure proper compliance with this legislation;
- We have implemented a range of IT security measures to protect us against potential external attacks;
- We have reviewed all our documentation to ensure that it complies with the requirements of the new Regulation;
- We have assessed the impact that our procedures may have on the protection of your personal data;
- We have trained our staff so that we can all act diligently and ethically and comply with all the requirements of the new Regulation.
Principles we will apply to your personal information
When processing your personal data, we will apply the following principles, which comply with the requirements of the new European data protection regulation:
- Lawfulness, fairness and transparency: We will always require your consent to process your personal data for one or more specific purposes, of which we will inform you in advance with complete transparency.
- Data minimisation: We will only request the data that is strictly necessary for the purposes for which it is required; it will be the minimum data possible.
- Storage limitation: the data will be kept for no longer than necessary for the purposes of processing. Depending on the purpose, we will inform you of the relevant retention period. In the case of subscriptions, we will periodically review our lists and delete records that have remained inactive for a considerable period.
- Integrity and confidentiality: Your data will be processed in a manner that ensures appropriate security and confidentiality. You should be aware that we take all necessary precautions to prevent unauthorised access to or misuse of our users’ data by third parties.
LEGAL BASES FOR COLLECTING AND USING INFORMATION
If you are an individual in the European Economic Area (EEA), our lawful basis for collecting and using information depends on the personal information concerned and the context in which we collect it. Most of our information collection and processing activities are generally based on: 1) contractual necessity; 2) one or more legitimate interests of THE COMPANY or a third party that are not overridden by your data protection interests; or 3) your consent. In some cases, we will be legally required to collect your information or will need your personal information to protect your vital interests or those of another person.
PROCESSING ACTIVITIES
We explain below how we collect, use, disclose, transfer and store your information. This Privacy Policy applies to personal information collected through our website. It is important that you review the Privacy Policy regularly in case it has been updated.
All users who access our website may view all its content without providing any personal information. Your personal data will only be collected when you voluntarily complete our form(s). In this case, the user guarantees the authenticity, accuracy and truthfulness of the information provided and undertakes to keep the personal data up to date so that it reflects their actual circumstances at all times. The user will be solely responsible for any false or inaccurate statements and any loss or damage they may cause. By using this method of communication, you expressly agree to receive periodic communications solely from the entity, which will keep all personal data received from users through the website strictly confidential and will adopt the technical measures required to prevent any alteration, loss, misuse or unauthorised access to such data.
We also inform you that all data provided through electronic forms and/or by email is strictly necessary to identify the sender correctly. This information will be treated in strict confidence and solely for the purpose of managing requests for information, managing requests relating to our products and services and the other purposes specified below. You are informed of this and give your full and express consent for your data to be used for activities related to the entity’s corporate purpose.
The consent given both to the processing and to the disclosure of data subjects’ data may be withdrawn at any time by notifying dial@grupodial.es in accordance with the terms established in this Policy for exercising rights. Withdrawal will under no circumstances have retroactive effect.
How we use your data
We may use your personal data as follows: the information you provide may help us to make decisions, respond to requests, improve services, identify new needs, create promotions, understand your expectations and provide you with a better service. We may also use your data for the following purposes.
Processing your order and providing your products and services
- To process orders for the products and services you have purchased from us and keep you informed of their progress;
- To provide you with the relevant product or service.
Billing and Customer Service
- To invoice or charge you for using our products and services;
- To contact you if the billing information you provided is not up to date, is due to expire or we are unable to accept payment;
- To respond to any questions or concerns you may have about our products or services.
Service information messages
- We will contact you to keep you up to date with information about the products and services you have with us.
Other purposes:
Specific purpose: If you provide your personal data for a particular purpose, we will use it for matters related to the purpose for which it was provided. For example, if you contact us by email, we will use the personal data you provide to answer your question or resolve the issue and will reply to the email address from which the message was sent.
Internal purposes. We may use your personal data for internal purposes, for example to improve the content and functionality of the services, better understand our customers’ needs, improve the services, protect against, identify or address fraudulent activities, enforce our terms of service, manage your account, provide customer service and generally manage the services and our business activities, among other purposes.
Commercial communications. Where we have your express consent, obtained through a dedicated box in our forms, we may use your personal data to contact you in the future with commercial communications that may be of interest to you and that are always related to the products and/or services offered by the company. You will always have the option to “unsubscribe” from these electronic messages using the link at the bottom of the messages or by notifying us by email at dial@grupodial.es You may nevertheless continue to receive notices and emails where these are necessary and essential for maintaining our contractual transactions. In accordance with Law 34/2002 of 11 July on Information Society Services and Electronic Commerce (LSSICE), THE COMPANY does not send SPAM and undertakes not to send commercial communications without identifying them properly.
Please note that, even if you choose not to subscribe or unsubscribe from promotional or commercial electronic communications, THE COMPANY may still need to contact you as a User with important information concerning transactions relating to your account and purchases of products, bookings of activities or engagement of other services.
The categories of data collected and processed and their purposes are explained in more detail below:
| CATEGORY | PURPOSE |
| Website visitor | Usability and quality analysis to improve our services. |
| User who contacts us | To respond to the user’s requests; answer any questions, complaints, comments or concerns relating to information included on the website, services provided through the website, the processing of personal data, matters concerning the legal texts included on the website and any other queries they may have that are not subject to contractual terms.
The legal bases are linked to the purposes set out in the previous point.
| CATEGORY | PURPOSE |
| Website visitor | Consent given by accepting cookies or continuing to browse our website. (GDPR Art. 6.1.a) |
| User who contacts us | Our legitimate interest in responding to the data subject’s queries and requests, justified by the interest shown in contacting us and receiving information, the minimal intrusion into their privacy and the use of limited data provided by the user. (GDPR Art. 6.1.a) |
Data provided voluntarily by the data subject
| CATEGORY | DATA COLLECTED |
| Website visitor | IP address and browsing data. |
| User who contacts us | Data provided by the data subject (normally: first name, surname, email address and telephone number). |
Possible consequences of not providing this data
| CATEGORY | CONSEQUENCES |
| Website visitor | No consequences. |
| User who contacts us | If the user who contacts us does not provide their data, we will be unable to respond adequately to their query or queries. |
Possible disclosures of data to third parties
| CATEGORY | POSSIBLE DISCLOSURES |
| Website visitor | No data is collected from the website visitor. |
| User who contacts us | We will not disclose personal data relating to this type of user to third parties without their consent. |
International transfers
| CATEGORY | INTERNATIONAL TRANSFERS |
| Website visitor | No data is collected from the website visitor. |
| User who contacts us | No personal data is transferred to a third country or international organisation. |
Retention periods
| CATEGORY | RETENTION PERIOD |
| Website visitor | No data relating to the website visitor is stored. |
| User who contacts us | Data will be retained for as long as necessary to fulfil the purpose for which it was collected |
OTHER ASPECTS RELATING TO DATA DISCLOSURE
As a general rule, the data you provide is not disclosed to third parties without your consent, except where required by law, for example in response to a court order or a request from a government body, or where we believe in good faith that such action is necessary: a) to comply with a legal obligation; b) to protect or defend our rights, interests or property, or those of a third party; c) to prevent or investigate potential unlawful acts in connection with the Services; d) to act in urgent circumstances to protect your personal safety; or e) to protect against legal liability.
STORAGE
We may store your data or transfer it to a third party that will store it in accordance with this Privacy Policy. We take measures that we consider reasonable to protect personal data against loss, misuse, unauthorised use, unauthorised access, inadvertent disclosure, alteration and destruction. However, no network, server, database or Internet or email transmission is completely secure or error-free. If a personal data breach occurs involving data in our custody, we will take all measures necessary to mitigate its consequences and notify the Supervisory Authority, together with all relevant information for documenting and reporting the incident.
CONSENT
Under data protection legislation, consent by the data subject is a freely given indication through which the data subject agrees to the processing of their data for a specific purpose and under certain conditions of which they must have been informed in advance.
Can you amend or withdraw your consent at any time?
Por supuesto que sí. La información de los tratamientos que ha consentido estará siempre accesible. Podrá modificarla o retirarla siempre que quiera a través de nuestro correo electrónico.
Así mismo, puede darse de baja de nuestra BBDD en el momento que lo desee, enviándonos un mail a: dial@grupodial.es
AUTOMATED DECISION-MAKING
THE COMPANY does not make any decisions based solely on automated processing of your data.
STATISTICAL STUDIES
THE COMPANY ndoes not carry out studies for scientific, historical or statistical purposes. If it were to do so, it would seek to anonymise the data used for the study in order to preserve its confidentiality.
NOTICE OF PERSONAL DATA BREACHES OR SECURITY BREACHES
A personal data breach is a breach of the security of THE COMPANY’s information systems that causes or may cause the destruction, alteration, loss, unauthorised disclosure of or access, whether accidental or otherwise, to personal data transmitted, stored or otherwise processed in connection with the provision of our services. If the personal data stored and/or processed by THE COMPANY is compromised in any way, we will notify the affected persons in due time and in accordance with Article 34 of the GDPR.
DATA PROTECTION RIGHTS
Users may send a written communication to THE COMPANY’s registered office or to the email address stated at the beginning of this Privacy Policy to request the exercise of the following rights:
- Right to rectification of personal data. You have the right to have information held about you rectified if it is inaccurate. If the information we hold needs to be updated or you believe that it may be incorrect, you may update it whenever necessary.
- Right of access to personal data. You have the right to request a copy of the personal data we hold about you.
- Right to data portability. You have the right, in certain circumstances, to transfer the data you have provided to us.
- Right to object to the use of personal data. You have the right to object to the processing of your personal information.
- Right to erasure. We endeavour to process and retain your data only for as long as we need it. You also have the right to request the erasure of the personal data we hold about you. The data will be kept blocked and accessible only to certain persons if we need it to handle a claim or meet our obligations.
- Right to restriction. You have the right to request restriction of the processing of your data so that we may store it but not use it.
In addition to the specific means established for each right, you may exercise your rights of access, rectification, erasure, objection, restriction and portability and withdraw consent previously given by writing, with the reference “Data Protection”, to the postal or email address stated at the beginning of this Policy.
These rights are personal and must be exercised by the data subject, subject only to the limitations provided for by applicable legislation. The legal representative of an interested user may nevertheless act where the user lacks capacity or is a minor and is therefore unable to exercise the rights personally. The Data Controller will give effect to the exercise of these rights within thirty days of receiving the request. If the Data Controller considers that the request should not be granted, it will give the reasons for its decision within the period specified in this section. Where erasure of the data is appropriate but physical deletion is not possible for technical reasons or because of the storage medium used, we will block the data to prevent its use until it can be completely removed from the information systems.
COLLECTION OF CHILDREN’S DATA
Our website is not intended for children under the age of 16. We do not intentionally collect information, including Personal Data, about children or any other persons who are not legally permitted to use our services. If we become aware that we have collected personal data relating to a child under the age of 16, we will delete it as soon as possible unless we are legally required to retain it. Please contact us if you believe that we have collected information relating to a child under the age of 16 by mistake or unintentionally by emailing dial@grupodial.es
PROCESSING OF SPECIAL CATEGORIES OF PERSONAL DATA AND PERSONAL DATA RELATING TO CRIMINAL CONVICTIONS AND OFFENCES
Free-text fields must not be used to enter personal information concerning personal data that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, or genetic data, biometric data used for the purpose of uniquely identifying a natural person, health data or data concerning a natural person’s sex life or sexual orientation, or personal data relating to criminal convictions and offences. If any information relating to these matters is entered in any of our forms or sent by email, it will be deleted immediately from our information systems and we will be unable to respond to the query, as such data is neither necessary nor relevant for the purposes specified in the processing activities of this Website.
COMPLAINT TO THE SUPERVISORY AUTHORITY
If you believe that our organisation has failed to respect your rights, you may lodge a complaint with the Spanish Data Protection Agency by any of the following means:
Online office: www.agpd.es
Postal address: Agencia Española de Protección de Datos, C/ Jorge Juan, 6, 28001 Madrid
Telephone: +34 901 100 099 / +34 91 266 35 17 91 266 35 17
Lodging a complaint with the Spanish Data Protection Agency is free of charge and does not require the assistance of a lawyer or court representative.
DIAL GROUP has adapted this website to the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons (GDPR), Organic Law 3/2018 of 5 December on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD), and Law 34/2002 of 11 July on Information Society Services and Electronic Commerce (LSSICE or LSSI).
© All rights reserved: DIAL GROUP