Amapola Biocosmetics is fully committed to complying with Spanish and European personal data protection regulations and ensuring full compliance with the obligations set forth, as well as implementing the security measures detailed in the General Data Protection Regulation (GDPR) (EU) 2016/679 and Law 3/2018, of 5th December, on Data Protection and Digital Rights (LOPD and GDD, hereinafter LOPD).
Pursuant to these regulations, you are hereby informed that use of our website may require that certain personal data be collected through contact forms, or by sending emails, that will be processed by Amapola Biocosmetics, the Data Controller, whose information is as follows:
- Company Name: Amapola Biocosmetics, S.L.U.
- Trade Name: Amapola Biocosmetics
- Tax ID Number: B40258741
- Registered Office: C/ Arado 13, 40197, San Cristóbal de Segovia (Segovia)
- Telephone: 921406859
- Email: email@example.com
Collection and processing of personal data
Personal data is any information concerning a person: name, email address, postal address, telephone number, tax ID number, etc. Additionally, when the User visits our website, certain information is automatically stored for technical reasons, such as the IP address assigned by the User’s internet service provider.
Amapola Biocosmetics, as the Data Controller, must suitably inform Users of this website about the collection of personal data that may be carried out, either by sending an email or by filling in the forms included on the site.
Only the data necessary to perform the hired service, or to be able to respond appropriately to the request for information made by the User, will be obtained. The data collected are identification data and they correspond to a reasonable minimum required to carry out the activity requested. Specifically, no specially protected data is collected at any time. Under no circumstances will Amapola Biocosmetics use the data obtained for purposes different to the purpose agreed with the User.
Contact form/email address
Purpose: To respond to the User’s request for information made through our contact form/s.
Legitimation: The legal basis that legitimises this form of processing is the User’s consent, which may be withdrawn at any time.
Data transfer: Claranet, will process data through its servers; it will do so as the Data Processor.
Purpose: To send commercial correspondence of interest to the User. As established by LSSICE, Amapola Biocosmetics agrees not to forward commercial correspondence without identifying it as such. For this purpose, information sent to customers in order to maintain an existing contractual relationship shall not be considered business correspondence.
Legitimation: The legal basis that legitimises this form of processing is the User’s consent, which may be withdrawn at any time.
Data transfer: Mailrelay, and Acumbamail will process data through its servers; they will do so as the Data Processors.
Registration/customer registration forms
- To manage your user registration on our website.
- To manage the purchases made.
- To provide information on the processing and status of purchases.
- To maintain a historic record of the purchases made on our website.
- To manage comments and contents.
- To send correspondence via email and/or communicate by telephone in order to inform the User of possible incidents, errors, issues and/or the status of orders.
Legitimation: The legal basis that legitimises this form of processing is execution of a contract.
Data transfer: Amapola Biocosmetics will not transfer or communicate your data to any third parties unless legally obliged to do so or when provision of a service involves the need for a contractual relationship with a Data Processor.
Specifically, the data may be transferred to:
– Technology service providers
– Payment service providers
– Courier and parcel companies
– Third parties or intermediaries, as service providers, operating on our own behalf.
Data transfers will occur in compliance with the strictest confidentiality, using the necessary measures, such as the signing of confidentiality contracts, or adherence to their privacy policies established on their respective websites. The User may refuse to transfer their data to the Processors, by written request, by any of the means previously referenced.
Furthermore, in some cases when necessary, customers’ data may be transferred to certain bodies in compliance with a legal obligation: Spanish Tax Administration Agency, banking entities, Labour Inspectorate, etc.
Purpose: Post your comment or review on the website.
Legitimation: The legal basis that legitimizes this processing is the consent of the User, which may revoke at any time.
Transfer of data: Personal data will be processed through the servers of this website, managed by eKomi, company that manages the specific web feedback module, and which will be considered as Data Processor.
Minimum age restriction
Only persons over 14 years of age may use this website. As required by the LOPD and GDD, in the case of children under 14 years of age, the consent of their parents or guardians will be mandatory for us to process their data.
On the other hand, only people over the age of 18 can hire our services. In case of children under 18 years of age, the consent of their parents or legal guardians will be mandatory so that we can provide the services offered, unless the minor is emancipated.
Registration of users
When the User registers using the corresponding form, the information we gather includes the following:
- Name and surname/s
- Email address and/or telephone number
- Postal addresses
- IP address
The User can also register via “social login” (Facebook or Google).
The User must provide a password, which must meet certain security requirements. They don’t expire. To recover the password the User must go to the specific recovery form and enter his/her email to continue the process and be able to modify it, by clicking on the link that will be sent to the email address entered. The User is responsible for maintaining the confidentiality of their password, as well as for all uses the User makes of it. You must inform “Amapola Biocosmetics” of any unauthorized use of your account or password as soon as possible.
Once registered, the User will have access to a private panel on which they may view certain content, a record of purchases made, etc. They may also manage account options, such as their password or data.
The User may receive the following notifications:
- When registering on the platform (account validation email).
- When making purchases. These include purchase confirmation, incidents, delivery sent, etc.
- The User will receive our store newsletter if they have subscribed to it. The User may unsubscribe from our newsletter using their user panel or the corresponding links included at the end of the newsletter.
- By comments made, and responses to them.
- To recover their password (specified in the previous section).
- When unsubscribing or deleting the account.
Amapola Biocosmetics hereby informs Users that the necessary technical, organisational and security measures available to us have been taken to prevent the loss, misuse, alteration, unauthorised access or theft of data, and thus guarantee the confidentiality, integrity, and quality of the information contained therein, in accordance with data protection regulations in force. The personal data collected using forms are processed only by the staff of Amapola Biocosmetics or designated processors.
The Amapola Biocosmetics website also has SSL encryption, which allows Users to safely send their data using the website’s contact forms.
Veracity of data
The User states that all data they provide are true and correct, and they agree to keep them up to date. The User will be responsible for the truthfulness of their data and will be solely liable for any conflicts or disputes that may result from their falsification. It is essential that, for us to keep personal data up to date, the User informs Amapola Biocosmetics whenever there has been any modification to their data.
“Amapola Biocosmetics” will not transfer or communicate to any third party your data, except in the cases legally provided or where the provision of a service implies the need for a contractual relationship with a Processor. The User accepts that some of the personal data collected will be provided to these Data Processors (payment platforms, processing agencies, intermediaries, etc.), when it’ll be necessary for the effective performance of a contracted service or product acquired. The User also agrees that, in the event of the provision of services, these may be, in whole or in part, subcontracted to other persons or companies, which will be considered as Data Processors, with which the corresponding contract of confidentiality, or adhered to their privacy policies, set out on their respective websites. The User may refuse the transfer of his/her data to the Data Processors, by written request, by any of the means mentioned above.
In addition, where necessary, the data of Clients may be transferred to certain agencies, in compliance with a legal obligation: Spanish Tax Agency, banks, Labour Inspectorate, etc.
How a User can exercise their rights
The LOPD and the GDPR grant interested parties the option of exercising several rights related to processing of their data. To do so, the User must contact us, providing a copy of documentation proving their identity (ID card or passport), by email sent to firstname.lastname@example.org, or by written communication sent to the address provided in our Legal Notice. This request should also include the following information: the User’s name and surname, request, address, and supporting data.
The User must exercise these rights himself/herself. However, they may also be exercised by a person authorised as the User’s legal representative, when documentation attesting to such representation is provided.
The User may exercise the following rights:
- The right to access personal data, which is the right to obtain information on whether their data is being processed, the purpose of any processing that is being developed, as well as the information available on the origin of such data and the communications made or planned thereof.
- The right to rectification, where personal data are incorrect or inaccurate. The User may also request that data found to be inadequate or excessive be deleted.
- The right to request limitation in relation to processing of their data, in which case said data will only be retained by Amapola Biocosmetics to exercise or defend claims.
- The right to oppose: the User has the right to request that their data not be processed or that processing be ceased in cases where their consent is not necessary for processing. Users may oppose commercial prospecting files or decisions related to the person concerned that are based solely on automatic processing of their data, unless further processing is required for legitimate reasons or to exercise or defend potential claims.
- The right to data portability: if the User would like their data to be processed by another company, Amapola Biocosmetics will provide the User with a portable copy of their data in an exportable format.
If the User grants consent for a specific purpose, they have the right to withdraw this consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
We are committed to enforcing all these rights within the maximum legal deadline of 1 month.
If the User believes there is an issue with how Amapola Biocosmetics processes their data, they can contact our data protection officer or the appropriate data protection authority. The Spanish Data Protection Agency (AEPD) is the control authority in Spain.
Requested information of Users’ personal data collected by contact form or by email will only be used strictly during the time necessary to fulfil the request for information, or until consent is withdrawn. The data of Users who subscribe to our newsletter will be kept indefinitely until the consent granted is withdrawn.
Customers’ personal data will be processed until the end of the contractual relationship. The particular data retention period shall be the minimum necessary, and it may be maintained for:
- Four years: Law on Social Infringements and Sanctions, related to obligations in matters of affiliation, contributions, payment of wages; Arts. 66 et seq. General Tax Act (accounting).
- Five years: Art. 1964 of the Civil Code (personal actions without special deadline).
- Six years: Art. 30 of the Commercial Code, related to accounting records and invoices.
- Ten years: Art. 25 of the Law on the Prevention of Money Laundering and Financing of Terrorism.
- No term: disaggregated and anonymised data.
The data of Users who have subscribed to our newsletter will be kept indefinitely until the consent granted is withdrawn.
In the case of candidates’ data processing (CVs), Amapola Biocosmetics may store CVs for up to two years and refer to them in future job vacancies, unless the candidate states otherwise.
Amapola Biocosmetics has profiles on some of the world’s major social networks (Facebook, Twitter, Youtube, Instagram, Google+), identifying itself in all cases as Data Controller processing the data of its followers, fans, subscribers, commentators and other user profiles (hereinafter, followers) published by Amapola Biocosmetics.
The purpose of data processing by Amapola Biocosmetics, when not prohibited by law, will be to inform its followers of its activities and offers, in any way that the social network allows, as well as providing a personalised user care service. The legal basis for such processing shall be the consent of the person concerned, which may be withdrawn at any time.
Under no circumstances will Amapola Biocosmetics obtain data from social networks, unless the User grants their consent in this regard (for example, to hold a contest).
An applicant who sends electronic communications to Amapola Biocosmetics applying for a job authorises us to analyse the following: the documents sent (for example, their CV), all content that is directly accessible via internet search engines (for example, Google), profiles that they have on professional social networks (for example, LinkedIn), data obtained from access testing, and the information they disclose in the job interview. Using all of this information, we will evaluate their candidacy and may be able to offer them a job when a position becomes available. If the candidate is not selected, Amapola Biocosmetics may store their CV for a maximum of two years so they may be considered in future vacancies, unless the candidate states otherwise. The legal basis for such processing shall be the consent of the person concerned, which may be withdrawn any time.
The information supplied by the User shall, in any case, be regarded as confidential and may not be used for purposes other than those described herein. Amapola Biocosmetics is obliged to refrain from disclosing information about the User’s claims, the reasons for the information requested, or the duration of its relationship with the User.
Term of validity
This privacy and data protection policy has been drafted by EXPERTOSLOPD®, a data protection company, on June 13th, 2022. It may vary depending on changes in regulations and jurisprudence. It is the responsibility of the data holder to read the updated document in order to understand their rights and obligations in this regard at any time.