Privacy Policy
1. Data Controller
- Data Controller: Loureiros Dorm, S.L.
- Tax ID (NIF): B67776062
- Address: Plaza de San Martiño, 2 – 15704 – Santiago de Compostela – A Coruña
- Email: info@loureirosdorm.com
2. Purposes and Legal Basis
In addition to the basic data protection information provided through each data collection channel, the following additional information is provided regarding the purposes, legal bases, and other relevant details of the following files or data processing activities:
- Website Users
The data collected will be processed for the purpose of managing your request.
The legal basis for processing is Article 6.1.a of the GDPR: “the data subject has given consent to the processing of their personal data for one or more specific purposes.”
3. Data Transfers or Disclosures
For the management of certain services offered by the company, it is necessary to allow access to certain data by third-party service providers. In this regard, the entity signs the necessary data processing agreements and provides appropriate instructions to these service providers to ensure the security and integrity of the data accessed for the purpose of delivering the contracted services.
Outside of these cases, your personal data will not be disclosed to third parties, except where legally required.
4. Data Retention Period
In addition to the basic data protection information provided, the following retention periods apply:
- Clients: Data will be kept until the end of the contractual relationship and will remain properly blocked for 6 years to cover potential legal obligations.
- Prospective Clients: Data will be kept for 1 year.
- Curriculum Vitae (CV): Data will be kept for 1 year.
- Suppliers: Data will be kept until the end of the contractual relationship and will remain properly blocked for 6 years to cover potential legal obligations.
- Website Users: Data will be retained while your request is being managed.
- Professional Contacts: Data will be retained as long as the data subjects remain employed by the companies with which there is a commercial relationship.
5. Profiling and International Data Transfers
No profiling or international data transfers will be carried out.
6. Withdrawal of Consent
Where the processing of personal data is based on consent, the data subjects are informed of their right to withdraw consent at any time, easily and free of charge, by writing to the data controller’s postal address or via email at: info@loureirosdorm.com. Withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.
7. Rights of Data Subjects
Under data protection laws, data subjects have the following rights:
- Right of Access: To know if their data is being processed, the purpose, categories of data, recipients, retention period, and source.
- Right of Rectification: To correct inaccurate or incomplete personal data.
- Right to Erasure (Right to be Forgotten): To request deletion of data under the following circumstances:
- When the data is no longer needed for the purposes it was collected.
- When consent is withdrawn.
- When the data subject objects to the processing.
- When deletion is required by law.
- When the data was collected through information society services under Article 8(1) of the GDPR.
- Right to Object: To object to processing based on consent.
- Right to Restriction of Processing: To request restricted processing under certain conditions:
- When the accuracy of data is contested.
- When processing is unlawful but deletion is opposed.
- When the data is no longer needed but is required for legal claims.
- When an objection to processing is pending resolution.
You may exercise these rights by writing to info@loureirosdorm.com, indicating the right you wish to exercise in the subject line. Alternatively, you may send a request to the company’s postal address.
The entity will respond to your request as soon as possible and within the timeframes established by data protection laws. Additionally, you may file a complaint with the Spanish Data Protection Agency at www.aepd.es.
8. Security
The security measures adopted comply with Article 32 of the GDPR. Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of the processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, the entity has implemented appropriate technical and organizational measures to ensure an adequate level of security.
In particular, mechanisms are in place to:
- Ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services.
- Restore availability and access to personal data in a timely manner in the event of a physical or technical incident.
- Regularly test, assess, and evaluate the effectiveness of the technical and organizational measures to ensure secure processing.
- Pseudonymize and encrypt personal data, where appropriate.
9. COOKIES
A cookie is a file or device that is downloaded to a user’s terminal equipment for the purpose of storing data that may be updated and retrieved by the entity responsible for its installation. In other words, it is a file downloaded to your computer when accessing certain websites. For more information, please refer to our Cookies Policy.