Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJEU L 119/1, 04-05-2016) (henceforth GDPR), provides a modernised framework based on accountability for data protection in Europe.
In this regard, article 12 of GDPR, under the epigraph “Transparent information, communication and modalities for the exercise of the rights of the data subject”, stipulates the following in section 1:
The controller shall take appropriate measures to provide any information referred to in Articles 13 and 14 and any communication under Articles 15 to 22 and 34 relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child. The information shall be provided in writing, or by other means, including, where appropriate, by electronic means. When requested by the data subject, the information may be provided orally, provided that the identity of the data subject is proven by other means.
In order to reconcile the increased demand on information introduced by the GDPR and concision and understanding in the way it is presented, the Data Protection Authorities recommend adopting an information model with layers or levels.
The multi-level information approach consists of the following:
In Europe and Spain there are data protection rules designed to protect your personal information that our company must comply with.
Therefore, it is very important for us that you perfectly understand what we are going to do with the personal data that we request from you.
Thus, we will be transparent and give you control over your data, with simple language and clear options that will enable you to decide what we will do with your personal information.
If you have any doubts after reading this information, please do not hesitate to ask us. Many thanks for your collaboration.
In general, your personal data will be used in order to interact with you and provide our services. Likewise, it may also be used for other activities, such as sending you advertising or promoting our activities.
Your personal data is needed in order to interact with you and provide our services. In this regard, we will provide you with a series of boxes that will enable you to decide clearly and simply how your personal information is used.
Generally, only the staff from our company who are duly authorised will be informed of the information that we request from you.
Likewise, your information may be disclosed to companies that need to have access to it in order for us to provide our services to you. For example, our bank will find out your data if the payment of our services is carried out via card or bank transfer.
Likewise, your information will be disclosed to the public and private entities that we are obliged to provide your personal data to in order to comply with a law. For instance, the Tax Law makes it necessary to provide the Tax Agency with certain information about economic transactions that exceed a certain amount.
In the event that, aside from the situations outlined, we need to disclose your personal information to other entities, we will ask for your consent beforehand through clear options that will allow you to decide on this matter.
We will protect your data with effective security measures according to the risks entailed by the use of your information.
To do so, our company has approved a Data Protection Policy and annual checks and audits are carried out to verify that your personal data is secure at all times.
We will keep your data during our relationship and for as long as we are required to do by law. Once the applicable legal deadlines have ended, we will eliminate the data in a way that is secure and environmentally friendly.
You can contact us at any point in order to find out what information we hold about you, rectify it if it is incorrect and eliminate it after the end of our relationship, if that is legally possible.
You also have the right to request the transfer of your information to another company. This right is called “portability” and can be useful in certain situations.
In order to request any of these rights, you should make a written request to our address, along with a photocopy of your National ID Number, in order to identify yourself.
In the offices of our company we have specific forms for requesting these rights and we offer our assistance to fill them out.
In order to find out more about your data protection rights, you can consult the website of the Spanish Data Protection Agency (www.agpd.es).
You can withdraw your consent at any time if you change your mind about the use of your data. For example, if you were once interested in receiving advertising about our products and services, but you no longer wish to receive advertising, you can inform us through the form for opposing processing which is available in the offices of our company.
If you believe that your rights have been neglected by our company, you can make a complaint at the Spanish Data Protection Agency, through any of the following means:
Making a complaint at the Spanish Data Protection Agency is free and the attendance of a lawyer or solicitor is not necessary.
Our policy is to not use your data for purposes other than those which we have explained. If, however, we need to use your data for different activities, we will always ask for your consent beforehand through clear options that will enable you to decide on this matter.
The Management / Governing Body of The Honest Make Tank, SL (henceforth the data controller), assumes full responsibility and undertakes to establish, implement and maintain this Data Protection Policy, guaranteeing the continuous improvement of the data controller with the aim of attaining excellence in relation to compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJEU L 119/1, 04-05-2016), and Spanish personal data protection legislation (Organic Law, specific sectoral legislation and its implementation regulations).
The Data Protection Policy of The Honest Make Tank, SL is based on the principle of proactive responsibility, according to which the data controller is responsible for compliance with the regulatory and jurisprudential framework that governs the Policy, and is able to demonstrate this to the competent control authorities.
In this regard, the data controller will be governed by the following principles which must serve all of its staff as a guide and reference framework for the processing of personal data:
The Data Protection Policy of The Honest Make Tank, SL is communicated to all the staff of the data controller and provided to all the parties concerned.
Consequently, this Data Protection Policy involves all the staff of the data controller, who must know it and accept it, considering it as their own. Each member is responsible for applying it and for verifying the data protection rules that apply to their activity, and also for identifying and providing opportunities for improvement that they consider appropriate with the aim of attaining excellence in relation to compliance.
This Policy will be reviewed by the Management / Governing Body of The Honest Make Tank, SL, as many times as it deems necessary, in order to comply, at all times, with the current provisions on personal data protection.