Privacy Policy
PROCESSING OF PERSONAL DATA
At LEGADO DE UGARTE, we are committed to the personal data we process and to ensuring strict compliance with current personal data protection regulations, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC. Accordingly, the following matters relating to the processing of personal data carried out by LEGADO DE UGARTE are reported:Who is responsible for the processing of your personal data?
Identity: LEGADO DE UGARTE (FELICIDAD BEGOÑA UGARTE ZABALA) NIF: 16590193V Postal address: Mayor 17, 01300 Laguardia (Álava) Telephone: 945 60 01 14 Email: info@legadodeugarte.com Contact details of the Data Protection Officer All interested parties may contact our Data Protection Officer regarding any matters related to the processing of their personal data. This information may be obtained by contacting the aforementioned postal address or by sending an email to info@legadodeugarte.com.Principles relating to treatment
In the processing of personal data carried out therein, the principles required by Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter, GDPR), are respected: Principle of legality, fairness and transparency: the data we collect is processed lawfully, fairly and transparently, with the prior consent of the interested parties when necessary or, where appropriate, for the execution of a contract to which the interested party is a party or for the application at the request of this of pre-contractual measures, or, if the processing is necessary for compliance with an applicable legal obligation, to protect vital interests of the interested party or another natural person, or for the satisfaction of legitimate interests pursued by the controller or by a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the interested party which require protection of personal data, in particular when the interested party is a child. Purpose limitation principle: The personal data we process is used for the purposes indicated in the section “For what purpose do we use your personal data?” Data minimization principle: In accordance with this principle, the only personal data we collect from users is that which is strictly necessary to manage the purposes described in the section “For what purpose do we use your personal data?” Principle of accuracy: The personal data we collect will be kept accurate and, if necessary, updated. Therefore, if any personal data changes, the user must notify us so that we can update it accordingly. Principle of retention period limitation: The personal data we process will be retained for the periods indicated in the section “How long will we retain your personal data?” Principle of integrity and confidentiality: To respect this principle, personal data will be processed in a manner that guarantees adequate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, applying appropriate technical and organizational measures.For what purpose do we use your personal data (whether you are a website user or not)?
Customer data: for the proper maintenance, development, fulfillment, and monitoring of the contractual relationship with customers and the services they request. We will also use identification and contact information to conduct satisfaction surveys and to send, by electronic or other means, technical, operational, and/or commercial news and information about our company’s offers, activities, products, and services. Supplier data: for the proper maintenance, development, fulfillment, and monitoring of the contractual relationship with our suppliers and the services they provide to us. Personal data: for the maintenance, development, fulfillment, and monitoring of the contractual relationship with our employees, as well as compliance with applicable labor, social security, and occupational risk prevention regulations. Candidate data: to manage the participation of interested parties in the company’s personnel selection processes. Data collected through the contact section: to manage and respond to queries, complaints, suggestions, and requests made by users through the website. Data collected through the blog: to manage and respond to comments made by users on the blog. Data collected through the website’s ideas and opinions form: to manage and respond to user comments and opinions. Data collected through the winery tour reservation form: to manage your winery tour reservation and send commercial information about news, offers, and promotions from Marqués de Riscal.Data processing excluded by the GDPR
Recital 14 of the GDPR establishes that “the protection granted by this Regulation should apply to natural persons, regardless of their nationality or place of residence, with regard to the processing of their personal data. This Regulation does not regulate the processing of personal data relating to legal persons, and in particular to undertakings incorporated as legal persons, including the name and form of the legal person and its contact details.” This means that this regulation and the obligations and rights it provides will not apply to some of the data processing carried out by LEGADO DE UGARTE, such as those relating to clients who are legal entities and suppliers.What is the legitimacy for the processing of your personal data?
Customer data: The legal basis for processing customers’ personal data is the execution of the contract or order they place. Regarding satisfaction surveys and the sending of commercial information, the legal basis is the satisfaction of legitimate interests pursued by LEGADO DE UGARTE, as provided for in Article 6.1. f) of the GDPR, based on the provisions of AEPD Report 195/2017. This will not prejudice the customer’s right to object to the sending of such commercial information. Supplier data: The legal basis for processing suppliers’ personal data is the execution of the contract or business relationship with the company. Personal data: The basis for processing the supplier’s personal data is the execution of the employment contract between the company and its employees. Candidate data: The legal basis for processing the data subject’s personal data is the consent they provide by providing us with their resume to participate in our recruitment processes. Data collected through the contact section: The legal basis for processing your personal data is the consent given when contacting us and, therefore, the need for such processing to address and respond to your contact request. Data collected through the blog: The legal basis for processing personal data is consent when commenting on the blog. Data collected through the ideas and opinions form on marquesderiscal.com: the legal basis for processing personal data is the consent given by completing the form provided for this purpose.How did we obtain your personal data?
Todos los datos personales que tratamos en LEGADO DE UGARTE. nos los proporcionan los propios interesados o sus representantes legales. Los datos personales que recabamos a través de este sitio web han sido recabados a través de los diferentes formularios habilitados o bien mediante las direcciones de correo electrónico habilitadas para establecer contacto con nosotros.To which recipients will your personal data be communicated?
The personal data of clients, suppliers and employees will be communicated, where applicable, to the tax authorities for compliance with legal and tax obligations, as well as to the financial institution(s) through which LEGADO DE UGARTE manages collections (in the case of clients) and payments (in the case of suppliers and employees). Likewise, in accordance with the legitimate interests pursued by the data controller and/or LEGADO DE UGARTE companies, customer data may be communicated to any of them for the purpose of sending commercial information similar to products or services that the customer has contracted.How long will we retain your personal data?
Customer and supplier data: Your personal data will be retained for the duration of the corresponding contractual relationship and, once it has ended, for the duration of the liability limitation periods established by applicable legal provisions. Personal data: Employees’ personal data will be retained for the duration of the employment relationship and, once it has ended, for the duration of the liability limitation periods established by applicable legal provisions. Candidate data: Candidate personal data will be retained for a maximum period of two years. Data collected through the contact section: The personal data users provide when contacting us will be retained only while your request is being processed. Once the request is processed, it will be deleted. Data collected through the blog: The personal data of interested parties will be retained until they withdraw their consent. Data collected through the ideas and opinions form on legadodeugarte.com: the personal data of interested parties will be retained until they withdraw their consent. User data from our social media profiles: The retention periods for the personal data of our followers on social media depend on the policies of each social network, although we will only process it until they stop following us.What are your rights when you provide us with your personal data?
- Right to request access to your personal data: In order to know and verify the legality of the processing, you may request confirmation from us at any time as to whether LEGADO DE UGARTE is processing your personal data. If so, we will inform you, among other things, about what data we are processing, its purpose, origin of the data, expected data retention period, and, where applicable, recipients or categories of recipients.
- Right to request rectification: You may request that we rectify inaccurate personal data or complete incomplete data, including by submitting an additional declaration. In such cases, you must indicate in your request which data it refers to and the correction to be made. You must also include, where applicable, supporting documentation to prove the inaccuracy or incompleteness of the data being processed.
- Right to request erasure (“right to be forgotten”): You can ask us to delete and stop processing your personal data if it is no longer necessary for the purposes for which it was collected or otherwise processed, if you withdraw your consent, if it has been unlawfully processed, or if it must be erased to comply with a legal obligation. Right to request restriction of the processing of your personal data: in this case, LEGADO DE UGARTE will only retain your personal data for the formulation, exercise, or defense of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest.
- Right to data portability: You can ask us to deliver your personal data to you or another data controller you specify in a structured, commonly used, and machine-readable format.
- Right to data portability: You can ask us to deliver your personal data to you or another data controller you specify in a structured, commonly used, and machine-readable format….
More information about data protection rights and filing complaints with the Supervisory Authority can be found at www.agpd.es.
Security
In accordance with Article 32 of the GDPR, LEGADO DE UGARTE has adopted appropriate technical and organizational measures to ensure a level of security appropriate to the risk.In order to assess the adequacy of the security level, particular account has been taken of the risks posed by data processing, in particular as a result of the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to personal data transmitted, stored, or otherwise processed.
duty of secrecy
LEGADO DE UGARTE has adopted measures to ensure that any person acting under its respective authority and having access to the personal data provided by users may only process them following the company’s instructions and must also maintain the corresponding professional secrecy regarding said data, which will be valid for an indefinite period. To this end, our employees have signed a confidentiality document and a duty of secrecy regarding the information and personal data they process in connection with their employment relationship with the company.Use of the website by minors
We ask users to read the policies regarding website use by minors that we have published in the “Legal Notice” of our website.Social networks
Social media profiles: LEGADO DE UGARTE has profiles on some of the main social media platforms currently in existence, so that personal data of our followers, of people who appear in our publications (for example, photographs) and of people who send us private messages may be processed. Data processing and purpose: The data processing carried out by LEGADO DE UGARTE is limited and subject to the policies and functionalities of each social network. When a user follows us on a social network, they authorize us to use their personal data solely within the scope of the corresponding social network for managing our page or profile and for bidirectional communication with our followers through chat, messages, or other communication channels that the social network currently allows or may allow in the future. This means we will have access to the information displayed in their profile, such as, but not limited to, their username, profile picture (if the user has uploaded one), and any comments they make. We also want to inform users that when they follow us, the news we publish may appear on their timeline. If they comment on our posts, their comment, along with their profile name and, if applicable, their profile picture, will be visible to other followers. In any case, the user is responsible for how they use the social network. We will not use users’ personal data for purposes other than those stated above, nor will we send them information through a medium other than the social network. Unless the user gives explicit consent, we will not extract their personal data from the social network environment. Data Protection Rights:Regarding rights of access, rectification, deletion, restriction of processing, objection, and data portability, we can only act according to the options provided by each social network. LEGADO DE UGARTE will provide all possible assistance to help users exercise these rights. Any of our followers may unfollow our page or profile at any time, which means we will no longer have access to their personal data. However, the social network may retain the comments they previously made on our posts. In any case, the user is responsible for how they use the social network, and therefore, LEGADO DE UGARTE assumes no liability.
Cookies
Cookies are small text files stored on the hard drive or memory of a computer that accesses or visits certain websites, allowing user preferences to be recognized upon reconnecting. The cookies stored on the user’s hard drive cannot read the data contained on it, access personal information, or read cookies created by other providers.For more information about the cookies used on this website, please refer to the “Cookie Policy” section. Text Date: May 24, 2018