In compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and repealing Directive 95/46/EC (hereinafter, the GDPR), with Law 34/2002, of 11 July, on information society services and electronic commerce (hereinafter, the LSSI-CE), and with Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights, Madeplagas S.L. guarantees the protection and confidentiality of personal data of any type provided to us by our clients, in accordance with the provisions of the General Data Protection Regulation.
Toti Cuesta’s Data Protection Policy is based on the principle of proactive accountability, under which the Data Controller is responsible for compliance with the applicable legal and case-law framework and is able to demonstrate such compliance to the relevant supervisory authorities.
The data provided will be processed under the terms set out in the GDPR. In this regard, Toti Cuesta has adopted the legally required levels of protection and has implemented all technical measures within its reach to prevent loss, misuse, alteration, and unauthorized access by third parties, as set out below. Nevertheless, the user should be aware that Internet security measures are not impregnable.
Data Controller: Who are we?
Name: Toti Cuesta
Phone: +34 667 52 46 27
Email: hola@toticuesta.com
Purpose of processing: What will we use your data for?
All data provided by our clients and/or visitors on the Toti Cuesta website or to its staff will be included in the record of processing activities for personal data, created and maintained under the responsibility of Toti Cuesta. Such data are essential to provide the services requested by users or to address questions or issues raised by our visitors. Our policy is not to create profiles of the users of our services.
Lawful basis for processing: Why do we need your data?
a) Contractual relationship: This applies when you purchase one of our products or contract any of our services.
b) Legitimate interest: To handle the queries and complaints you submit to us and to manage the collection of amounts owed.
c) Your consent: If you are a user of our website, by checking the box in the contact form, you authorize us to send you the communications necessary to respond to the query or request for information submitted.
Recipients: With whom do we share your data?
We do not share your personal data with anyone, except for public or private entities to which we are legally required to provide your personal data in order to comply with a law. For example, tax law requires that certain information on economic transactions exceeding a given amount be provided to the Tax Agency.
If, outside of the cases mentioned, we need to disclose your personal information to other entities, we will request your permission in advance through clear options that will allow you to decide in this regard.
Transfers: Where might we send your data?
We will not carry out international transfers of your personal data for any of the purposes indicated.
Retention: How long will we keep your data?
We will only retain your personal data for as long as necessary to achieve the purposes for which they were collected. When determining the appropriate retention period, we assess the risks involved in processing, as well as our contractual, legal and regulatory obligations, our internal data retention policies, and our legitimate business interests described in this Privacy Notice and Cookies Policy.
In this respect, Toti Cuesta will retain personal data, once your relationship with us has ended, duly blocked, for the limitation period of any actions that may arise from the relationship maintained with the data subject.
Once blocked, your data will be inaccessible to Toti Cuesta and will not be processed except to make them available to public administrations, judges and courts, to address any liabilities arising from the processing, as well as for the exercise and defense of claims before the Spanish Data Protection Agency.
Security: How will we protect your data?
We use all reasonable efforts to maintain the confidentiality of personal information processed in our systems. We maintain strict security levels to protect the personal data we process against accidental loss and against unauthorized access, processing or disclosure, taking into account the state of the art, the nature of the data and the risks to which they are exposed. However, we cannot be held responsible for the use you make of the data (including username and password) that you use on our website. Our staff follows strict privacy standards and, if we hire third parties to provide support services, we require them to comply with the same standards and allow us to audit them to verify compliance.
Your rights: What rights can you exercise as a data subject?
We inform you that you may exercise the following rights:
- Right of access to your personal data, to know which data are being processed and the processing operations carried out on them;
Right to rectification of any inaccurate personal data;
Right to erasure of your personal data, where possible (for example, due to a legal obligation);
Right to restriction of processing of your personal data where the accuracy, lawfulness or necessity of the processing is in doubt, in which case we may retain the data for the exercise or defense of claims;
Right to object to the processing of your personal data where the legal basis enabling us to process it is our legitimate interest. Madeplagas S.L. will stop processing your data unless it has a legitimate interest or it is necessary for the defense of claims;
Right to data portability where the legal basis enabling us to process your data is the existence of a contractual relationship or your consent;
Right to withdraw the consent granted to Toti Cuesta.
To exercise your rights, you may do so free of charge and at any time by contacting us at hola@toticuesta.com and attaching a copy of your national ID.
Enforcement of rights: Where can you lodge a complaint?
If you believe that your rights have not been duly addressed by our entity, you may lodge a complaint with the Spanish Data Protection Agency through any of the following means:
- Online office: https://www.aepd.es/
- Postal mail: Agencia Española de Protección de Datos, C/ Jorge Juan, 6, 28001, Madrid, Spain.
- Phone: 901 100 099 or 91 266 35 17
Lodging a complaint with the Spanish Data Protection Agency involves no cost and the assistance of a lawyer or legal representative is not required.
Updates: What changes may be made to this Privacy Policy?
Toti Cuesta reserves the right to modify this policy to adapt it to legislative or case-law developments that may affect compliance with it.