Privacy Policy

PRIVACY: DATA CONTROLLER

The Data Controller is CLARA AURA ESTEVE, C/ Roger de Llúria nº2, bajo izda,, 03801, Alcoy (ALICANTE).

 

Privacy Principles

At CLARA AURA ESTEVE, we are committed to continuously ensuring privacy in the processing of your personal data and to providing you with the most complete and clear information at all times. We encourage you to read this section carefully before providing your personal data to us.
If you are under the age of fourteen, we kindly ask that you do not provide us with your data without the consent of your parents.
In this section, we explain how we handle the data of individuals who have a relationship with our organization. Starting with our principles:
• We do not request personal information unless it is necessary to provide the services you require.
• We never share personal information with anyone, except to comply with the law, or if we have your express authorization.
• We will never use your personal data for purposes other than those outlined in this privacy policy.
• Your data will always be processed with a level of protection in line with data protection laws, and will not be subject to automated decision-making.

This privacy policy has been drafted with consideration of the current data protection legislation:
• Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 regarding the protection of individuals (GDPR).
• Organic Law 3/2018 of 5 December, on the Protection of Personal Data and the Guarantee of Digital Rights (LOPD).
• Royal Decree 1720/2007 of 21 December (RLOPD).

Due to changes in processing criteria, to facilitate understanding or to adapt to current legal requirements, we may modify this privacy policy. We will update the date of this policy so you can check its validity.

 

Treatments We Perform

Employee Data Processing
Legal Basis: GDPR 6.1(b) Processing necessary for the performance of a contract to which the data subject is a party or for the application of pre-contractual measures at the data subject's request.
GDPR 6.1(c) Processing necessary for compliance with a legal obligation to which the data controller is subject.
Royal Legislative Decree 2/2015 of 23 October, approving the consolidated text of the Workers’ Statute.
Processing Purposes:
• Employee management.
• Personal file. Time control. Training. Pension plans. Occupational risk prevention.
• Issuance of employee payroll.
• Union activity management.

Data Subject: Employees

Categories of Data:
• Name and surname, DNI/CIF/Identification document, personal registration number, social security number, address, signature, and phone number.
• Special categories of data: health data (sick leave, work accidents, and disability degree, excluding diagnoses), union membership (solely for union fee payment purposes, if applicable), union representative (if applicable), attendance certificates for employees and third parties.
• Personal characteristics: gender, marital status, nationality, age, date, and place of birth, family data.
• Employment data: Titles, training, and professional experience.
• Employment history: job details and administrative career. Incompatibilities.
• Time control data: entry/exit date/time, absence reasons.
• Financial data: payroll data, credits, loans, guarantees, tax deductions, previous job salary (if applicable), judicial withholdings (if applicable), other withholdings (if applicable), bank details.

Recipients of Data:
• Entity responsible for managing occupational risks.
• Social Security General Treasury.
• Trade unions.
• Financial entities.
• Spanish Tax Agency.
• Main contractors for whom we provide services as subcontractors.

International Data Transfers: No international data transfers are planned.
Data Retention Period: Data will be kept for as long as necessary to fulfill the purpose for which it was collected and to determine potential liabilities arising from that purpose and data processing.
The financial data will be retained in accordance with the provisions of Law 58/2003 of 17 December, the General Tax Law.
Security Measures: Adapted to the requirements of Regulation (EU) 2016/679, General Data Protection Regulation.

 

Contact Data Processing
Legal Basis: Consent of the data subject
Processing Purposes: To attend to your request, send information, and follow up on the request.
Data Subject: Contact persons, clients, suppliers
Categories of Data: Name and surname, phone number, email address
Recipients of Data: No data transfers to third parties are envisaged.
International Data Transfers: No international data transfers are planned.
Data Retention Period: Contact data will be retained indefinitely or until the data subject requests its deletion.
Security Measures: Adapted to the requirements of Regulation (EU) 2016/679, General Data Protection Regulation.

 

Processing of Rights of Data Subjects (ARCO)
Legal Basis: GDPR 6.1(c) Processing necessary for compliance with a legal obligation to which the data controller is subject.
General Data Protection Regulation.
Processing Purposes: To address requests related to the rights under the General Data Protection Regulation: Access, rectification, deletion, limitation, portability, and opposition to automated decision-making.
Data Subject: Individuals making requests (employees, clients, suppliers, contact persons)
Categories of Data: Name and surname, address, signature, and phone number.
Recipients of Data: Personal data may be communicated to the Control Authority (Spanish Data Protection Agency) as part of an investigation initiated by the data subject for the protection of rights.
International Data Transfers: No international data transfers are planned.
Data Retention Period: Data will be retained for five years from the date of the request.
Security Measures: Adapted to the requirements of Regulation (EU) 2016/679, General Data Protection Regulation.

 

Candidate Data Processing (HR Selection Processes)
Legal Basis: GDPR 6.1(a) The data subject has consented to the processing of their personal data for one or more specific purposes.
GDPR 6.1(b) Processing necessary for the performance of a contract to which the data subject is a party or for the application of pre-contractual measures at the data subject’s request.
Processing Purposes: Recruitment and provision of job positions.
Data Subject: Candidates for job positions

Categories of Data:
• Name and surname, DNI/CIF/Identification document, personal registration number, address, signature, and phone number.
• Personal characteristics: gender, marital status, nationality, age, date, and place of birth, family data.
• Academic and professional data: Titles, training, and professional experience.
• Employment history: job details.

Recipients of Data: No data transfers to third parties are envisaged.
International Data Transfers: No international data transfers are planned.
Data Retention Period: Data will be kept for as long as necessary to fulfill the purpose for which it was collected and to determine potential liabilities arising from that purpose and data processing.
Security Measures: Adapted to the requirements of Regulation (EU) 2016/679, General Data Protection Regulation.

 

Supplier Data Processing
Legal Basis: GDPR 6.1(b) Processing necessary for the performance of a contract to which the data subject is a party or for the application of pre-contractual measures at the data subject’s request.
GDPR 6.1(c) Processing necessary for compliance with a legal obligation to which the data controller is subject.
Royal Legislative Decree 2/2015 of 23 October, approving the consolidated text of the Workers’ Statute.
Law 58/2003 of 17 December, the General Tax Law.
Processing Purposes:
• Acquisition of products and/or services required for the development of our activity.
• Control of subcontractors, if applicable.

Data Subject:
• Suppliers
• Individuals working for our suppliers

Categories of Data:
• Name and surname, DNI/NIF/Identification document, address, signature, and phone number.
• Employment details: job position, workplace safety training.
• Financial and insurance data: Bank details.

Recipients of Data:
• Financial entities (payment of invoices)
• Spanish Tax Agency.

International Data Transfers: No international data transfers are planned.
Data Retention Period: Data will be kept for as long as necessary to fulfill the purpose for which it was collected and to determine potential liabilities arising from that purpose and data processing, in accordance with Law 58/2003 of 17 December, the General Tax Law.
Security Measures: Adapted to the requirements of Regulation (EU) 2016/679, General Data Protection Regulation.

 

Client Data Processing
Legal Basis: GDPR 6.1(a) The data subject has consented to the processing of their personal data for one or more specific purposes.
GDPR 6.1(b) Processing necessary for the performance of a contract to which the data subject is a party or for the application of pre-contractual measures at the data subject’s request.
GDPR 6.1(c) Processing necessary for compliance with a legal obligation to which the data controller is subject.
GDPR 6.1(f) Processing necessary for the satisfaction of the legitimate interests of the data controller.

Royal Legislative Decree 2/2015 of 23 October, approving the consolidated text of the Workers’ Statute.
Law 58/2003 of 17 December, the General Tax Law.
Processing Purposes: Provision of our products/services
Data Subject: Clients

Categories of Data:
• Name and surname, DNI/NIF/Identification document, address, signature, and phone number.
• Financial and insurance data: Bank details.

Recipients of Data:
• Financial entities.
• Spanish Tax Agency.

International Data Transfers: No international data transfers are planned.
Data Retention Period: Data will be kept for as long as necessary to fulfill the purpose for which it was collected and to determine potential liabilities arising from that purpose and data processing, in accordance with Law 58/2003 of 17 December, the General Tax Law.
Security Measures: Adapted to the requirements of Regulation (EU) 2016/679, General Data Protection Regulation.

 

Security Breach Notification Processing
Legal Basis: GDPR 6.1(c) Processing necessary for compliance with a legal obligation to which the data controller is subject.
General Data Protection Regulation, Articles 33 and 34
Processing Purposes: Management and evaluation of any security breaches that occur within our organization.
Data Subject: Variable – Employees, Clients, Suppliers, Contacts (depending on the security breach)

Categories of Data:
• Variable (depending on the security breach).

Recipients of Data:
• Spanish Data Protection Agency.
• Law enforcement agencies.

International Data Transfers: No international data transfers are planned.
Data Retention Period: Data will be kept for as long as necessary to fulfill the purpose for which it was collected and to determine potential liabilities arising from that purpose and data processing. The provisions of file and documentation regulations will apply.
Security Measures: Adapted to the requirements of Regulation (EU) 2016/679, General Data Protection Regulation.

 

Your Rights

You have the right to request a copy of your personal data, to rectify inaccurate data or complete incomplete data, or, where applicable, to delete it when it is no longer necessary for the purposes for which it was collected.

You also have the right to limit the processing of your personal data and to obtain your personal data in a structured, commonly used, and machine-readable format.

You may object to the processing of your personal data under certain circumstances (in particular, when we are not required to process it to fulfill a contractual or other legal obligation, or when the purpose of the processing is direct marketing).

When you have given us your consent, you may withdraw it at any time. At that time, we will stop processing your data or, if applicable, stop processing it for that specific purpose. If you decide to withdraw your consent, this will not affect any processing that took place while your consent was valid.

These rights may be subject to limitations; for example, if in order to comply with your request we would need to disclose data about another person, or if you ask us to delete records we are legally required to keep, or due to legitimate interests such as defending against claims. Similarly, in cases where freedom of expression and information must prevail.

You can contact us by any of the means indicated in the "Data Controller" section of this privacy policy, providing a copy of a document that proves your identity (usually your ID card).

Another right you have is not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or significantly affects you.

If your rights are violated, such as if we do not address your request, you have the right to file a complaint with the Data Protection Authority. This could be the authority in your country (if you live outside of Spain) or the Spanish Data Protection Agency (if you live in Spain).

 

Links to Third-Party Websites

Our website may, on occasion, contain links to other websites. It is your responsibility to ensure that you read the privacy policy and legal conditions applicable to each site.

 

Data of Third Parties
If you provide us with data of third parties, you assume the responsibility of informing them in advance as set out in Article 14 of the GDPR.