Privacy policy (PROVISIONS on the treatment and protection of personal data)

Our website address: https://vitaguru.es.

This Personal Data Privacy Policy (hereinafter – the Privacy Policy) applies to all information that the “VITAGURU” Website, located at the address – Vitaguru.es, can receive about the User during the use of the Website, the Internet store, programs and products of the Internet store

1. DEFINITION OF TERMS:

  • Personal data base — a named set of organized personal data in electronic form and/or in the form of personal data files;
  • The responsible person is a designated person who organizes the work related to the protection of personal data during their processing, in accordance with the law;
  • The owner of the personal data base is a natural or legal person who is granted the right to process this data by law or with the consent of the subject of personal data, who approves the purpose of processing personal data in this database, establishes the composition of this data and the procedures for its processing, unless otherwise determined by law;
  • The State Register of Personal Data Bases is a single state information system for collecting, accumulating and processing information on registered personal data bases;
  • Publicly available sources of personal data are directories, address books, registers, lists, catalogs, other systematized collections of open information that contain personal data, posted and published with the knowledge of the subject of personal data. Social networks and Internet resources in which the subject of personal data leaves their personal data are not considered publicly available sources of personal data (unless the subject of personal data expressly states that the personal data is posted for the purpose of their free distribution and use);
  • Consent of the subject of personal data – any documented, voluntary expression of will of a natural person regarding the granting of permission for the processing of his personal data in accordance with the formulated purpose of their processing;
  • Depersonalization of personal data — removal of information that allows identification of a person;
  • Processing of personal data — any action or set of actions performed in whole or in part in the information (automated) system and/or in personal data files, which are related to the collection, registration, accumulation, storage, adaptation, change, renewal, use and distribution (distribution, implementation, transfer), depersonalization, destruction of information about a natural person;
  • Personal data – information or a set of information about a natural person who is identified or can be specifically identified;
  • The manager of the personal data base is a natural or legal person who is authorized to process this data by the owner of the personal data base or by law. A person who is instructed by the owner and/or administrator of the personal data base to carry out technical work with the personal data base without access to the content of personal data is not a manager of the personal data base;
  • The subject of personal data is a natural person whose personal data is processed in accordance with the law;
  • A third party is any person, with the exception of the subject of personal data, the owner or manager of the personal data base and the authorized state body for the protection of personal data, to whom the owner or manager of the personal data base transfers personal data in accordance with the law;
  • Special categories of data — personal data about racial or ethnic origin, political, religious or ideological beliefs, membership in political parties and trade unions, as well as data related to health or sex life.

1.2. This Regulation is mandatory for application by the responsible person and employees of the seller who directly process and/or have access to personal data in connection with the performance of their official duties.

2. LIST OF PERSONAL DATA BASES

2.1. The company is the owner of the personal data base “Counterparties”.

2.2. The database of personal data is located at the address of the Company.

3. PURPOSE OF PERSONAL DATA PROCESSING

3.1. The purpose of processing personal data in the system is the storage and maintenance of counterparty data, in accordance with Articles 6 and 7 of the Law of Ukraine “On Personal Data Protection”.

3.2. The purpose of processing personal data is to ensure the implementation of civil law relations, the provision / receipt and implementation of payments for purchased goods / services in accordance with Spanish law.

4. PERSONAL DATA PROCESSING PROCEDURE

4.1. The consent of the subject of personal data must be a voluntary expression of the individual’s will to grant permission for the processing of his personal data in accordance with the formulated purpose of their processing. The consent of the subject of personal data can be given in the following forms:

  • a document on a paper medium with requisites, which makes it possible to identify this document and a natural person;
  • an electronic document, which must contain mandatory details that allow identification of this document and a natural person. It is expedient to certify the voluntary expression of the individual’s will regarding the granting of permission for the processing of his personal data with the electronic signature of the subject of personal data.
  • a note on an electronic page of a document or in an electronic file processed in an information system based on documented software and technical solutions.

4.2. The consent of the subject of personal data is given during the registration of civil legal relations in accordance with the current legislation.

4.3. The notification of the subject of personal data about the inclusion of his personal data in the personal data base, the rights defined by the Law of Ukraine “On the Protection of Personal Data”, the purpose of data collection and the persons to whom his personal data is transferred is carried out during the registration of civil legal relations in accordance with the current legislation.

4.4. The processing of personal data on racial or ethnic origin, political, religious or ideological beliefs, membership in political parties and trade unions, as well as data related to health or sexual life (special categories of data) is prohibited.

5. TERMS OF DISCLOSURE OF INFORMATION

5.1. The procedure for access to personal data of third parties is determined by the terms of the consent of the subject of personal data, given by the owner of the personal database for the processing of this data, or in accordance with the requirements of the law.

5.2. Access to personal data is not granted to a third party if the specified person refuses to undertake the obligation to ensure compliance with the requirements of the Spanish Law “On the Protection of Personal Data” or cannot provide them.

5.3. The subject of relations related to personal data submits a request for access (hereinafter referred to as a request) to personal data to the owner of the personal data base.

5.4. The request specifies:

  • last name, first name and place of residence (place of stay) and details of the document certifying the individual submitting the request (for an individual applicant);
  • name, location of the legal entity submitting the request, position, surname, name of the legal entity certifying the request; confirmation that the content of the request corresponds to the powers of the legal entity (for the legal entity – the applicant); 
  • surname, name and patronymic, as well as other information that allows to identify the individual in respect of whom the request is made;
  • information about the personal data base in respect of which the request is submitted, or information about the owner or manager of this database;
  • list of requested personal data;
  • the purpose of the request.

5.5. The term of examining the request for its satisfaction cannot exceed ten working days from the date of its receipt. During this period, the owner of the personal data base informs the person who submits the request that the request will be satisfied or that the relevant personal data are not subject to provision, indicating the grounds defined in the relevant regulatory legal act.

The request is satisfied within thirty calendar days from the date of its receipt, unless otherwise provided by law.

5.6. All employees of the owner of the personal data base are obliged to comply with the requirements of confidentiality regarding personal data and information regarding accounts in securities and circulation of securities.

5.7. Delaying access to personal data of third parties is allowed if the necessary data cannot be provided within thirty calendar days from the date of receipt of the request. At the same time, the total term for solving the issues raised in the request cannot exceed forty-five calendar days.

5.8. The notice of postponement is brought to the attention of the third party who submitted the request in writing with an explanation of the procedure for appealing such a decision.

5.9. The notice of postponement states:

  • surname, first name and official person;
  • the date of sending the message;
  • the reason for the delay;
  • the period during which the request will be satisfied.

5.10. Denial of access to personal data is permitted if access to it is prohibited by law.

5.11. The rejection notice states:

last name, first name, of the official denying access; 

the date of sending the message;

reason for refusal.

5.12. The decision to delay or deny access to personal data may be appealed to the authorized state body for personal data protection, other state authorities and local self-government bodies, whose powers include the protection of personal data, or to a court. 

6. PROTECTION OF PERSONAL DATA 

6.1. The owner of the personal data base is equipped with system and software and communication tools that prevent loss, theft, unauthorized destruction, distortion, forgery, copying of information and meet the requirements of international and national standards.

6.2. The responsible person organizes the work related to the protection of personal data during their processing, in accordance with the law. The responsible person is determined by the order of the Owner of the personal database. The duties of the responsible person regarding the organization of work related to the protection of personal data during their processing are specified in the job description. 

6.3. Employees / Owner who directly process and / or have access to personal data in connection with the performance of their official (labor) duties are required to comply with the requirements of Spanish legislation in the field of personal data protection and internal documents, on the processing and protection of personal data in databases personal data

6.4. Employees/Owner who have access to personal data, including their processing, are obliged not to disclose in any way personal data that they were entrusted with or became aware of in connection with the performance of professional or official or labor. responsibilities. Such an obligation is valid after the termination of their activities related to personal data, except in cases established by law.

6.7. Persons who have access to personal data, including those who process them if they violate the requirements of the Spanish Law on the Protection of Personal Data, are liable in accordance with Spanish law.

6.8. Personal data should not be stored longer than is necessary for the purposes for which such data is stored, but in any case not longer than the data storage period determined by the consent of the personal data subject to the processing of these data. 

7. RIGHTS OF THE SUBJECT OF PERSONAL DATA

7.1. The subject of personal data has the right to:

  • to know the location of the personal data base, which contains his personal data, its purpose and name, location and/or place of residence (residence) of the owner or manager of this database or to give the relevant instructions to obtain this information to persons authorized by him, except for cases established by law;
  • to receive information about the conditions for providing access to personal data, in particular information about third parties to whom his personal data contained in the relevant personal data base are transferred;
  • to access your personal data contained in the relevant personal data base;
  • to receive no later than thirty calendar days from the date of receipt of the request, except in cases provided by law, an answer on whether his personal data is stored in the relevant personal data base, as well as to receive the contents of his personal data that are stored;
  • submit a reasoned demand with an objection to the processing of your personal data by state authorities, local self-government bodies in the exercise of their powers provided for by law;
  • make a reasoned demand for the change or destruction of your personal data by any owner and administrator of this database, if these data are processed illegally or are unreliable;
  • to protect your personal data from illegal processing and accidental loss, destruction, damage due to intentional concealment, failure to provide or untimely provision of them, as well as protection from providing information that is unreliable or disgraces the honor, dignity and business reputation of a natural person ; 
  • to apply for the protection of one’s rights regarding personal data to state authorities, local self-government bodies, whose powers include the protection of personal data; 
  • apply legal remedies in case of violation of the legislation on the protection of personal data.

8. PERSONAL DATA SUBJECT REQUESTS

8.1. The subject of personal data has the right to receive any information about himself from any subject of relations related to personal data, without specifying the purpose of the request, except for cases established by law.

8.2. The access of the subject of personal data to data about himself is free of charge.

8.3. The subject of personal data submits a request for access (hereinafter – request) to personal data to the owner of the personal data base.

The request states:

  • surname, first name, place of residence (place of stay) and details of the document certifying the identity of the subject of personal data;
  • other information that makes it possible to identify the person of the subject of personal data; 
  • information about the database of personal data, in relation to which the request is submitted, or information about the owner or manager of this database;
  • list of requested personal data.

8.4. The term of examining the request for its satisfaction cannot exceed ten working days from the date of its receipt.

8.5. During this period, the owner of the personal data base shall notify the subject of personal data that the request will be satisfied or that the relevant personal data shall not be provided, indicating the grounds specified in the relevant regulatory act.

8.6. The request is satisfied within thirty calendar days from the date of its receipt, unless otherwise provided by law.

Searching results

Search query