IDYLLICA (hereinafter referred to as the Entity) is committed to due diligence and compliance with Data Protection regulations.
Below is detailed information on the confidentiality and personal data protection policy in compliance with the provisions of Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council, of April 27, 2016, regarding the protection of natural persons concerning the processing of personal data and the free movement of such data (General Data Protection Regulation or GDPR) and Article 11 of Organic Law 3/2018, on the Protection of Personal Data and Guarantee of Digital Rights (LOPD GDD).
Data of the Data Controller and contact details for the Data Protection Officer (DPO):
- Identity: Idyllica
- Address / ZIP Code: Rambla de Prat 11, 08012, Barcelona
- Phone: 934151725
- Contact details of the DPO: online@idyllica.es
- Data Protection Channel: www.dataprotect-line.com/tgd
PURPOSES OF DATA PROCESSING
The Entity will process the information provided by data subjects for the following purposes:
- To manage their attention, visits, and meetings at our facilities.
- To manage the provision and delivery of the contracted services and products.
- To handle any requests, suggestions, complaints, or inquiries about our professional services submitted by data subjects; ensuring proper management and referral, if necessary, to the relevant department to comply with the applicable regulatory framework.
- Informational and commercial communications: processing of their data to inform them about activities, articles of interest, and general information related to our activity and the contracted services/products.
- Manage data provided by job applicants via Curriculum Vitae (CV) or other means for the purpose of selection and recruitment.
- To ensure the security of offices, facilities, and individuals through access controls, video surveillance systems, and other identification/control systems.
- To comply with the legal provisions applicable to the Entity and its activities in terms of health, equality, and occupational risk prevention.
- To manage and address communications submitted by informants through the Data Protection Channel.
- All data processing required to comply with regulations and official/sectoral requirements applicable to our activity.
For the effective management and development of the above purposes, the processing of your data for the relevant purposes will be carried out under strict compliance with Data Protection regulations and the Policy detailed herein. At any time, you may exercise your rights (see specific section).
DATA RETENTION CRITERIA
- Management of contracted services/products: personal data provided in contracts, offers, and/or service proposals, as well as data from other individuals involved, will be retained while the contracted services are active. Upon completion of the services, personal data will be retained in cases where liabilities with the Entity may arise and/or to comply with other regulatory frameworks applicable to the Entity or a legal requirement to retain such data. Personal data will be maintained in a way that ensures the identification and exercise of the data subjects’ rights, under the necessary technical, legal, and organizational measures to guarantee their confidentiality and integrity.
- Management of Curriculum Vitae: the Entity generally retains CVs for a maximum period of one year; after this period, they will be automatically deleted in compliance with the principle of data quality.
- Management of Employment Contracts: personal data will be retained as long as the employment relationship is active and, after its conclusion, if liabilities between the parties could arise or when required by legal provisions.
- Others: other data and information provided by the user through any means will be retained as long as necessary to fulfill the purpose for which it was collected.
LEGAL BASIS
The legal basis that enables the Entity to process personal data of users, customers, and potential customers is based on the following grounds:
- The consent of data subjects to process and handle any request for information or inquiries about our services and products.
- The consent provided by job applicants for selection and recruitment purposes.
- The framework for the provision and/or contracting of services/products with the Entity.
- Legitimate interest to send informational, commercial communications, and/or promotional offers related to the Entity’s activity and contracted services/products via email or other means.
- Compliance with legal obligations and internal compliance procedures.
- Legitimate interest to ensure the security of offices, facilities, and individuals.
RECIPIENTS
Personal data is not shared with third parties unless required by law.
ORIGIN
Personal data is obtained directly from data subjects and our collaborators. The categories of personal data provided to us are as follows:
- Identification data.
- Postal or email addresses.
- Data provided and/or consented to by data subjects related to and necessary for managing and fulfilling the requested service/product.
RIGHTS
Right of Access, Rectification, and Erasure: Data subjects have the right to obtain confirmation of whether the Entity is processing personal data concerning them. They have the right to access their personal data, as well as to request the rectification of inaccurate data or request their erasure when, among other reasons, the data is no longer necessary for the purposes for which it was collected.
Right to Restriction and Objection: In certain circumstances, data subjects may request the restriction of the processing of their data, in which case it will only be kept for the exercise or defense of claims. In certain circumstances, and for reasons related to their particular situation, data subjects may object to the processing of their data. In such a case, the Entity will cease to process the data, except for compelling legitimate grounds or for the exercise or defense of possible claims.
Right to Withdraw Consent: Data subjects have the right to withdraw their consent at any time, except in cases of personal data processing provided for under Data Protection regulations or necessary for the provision of the contracted service, which do not require such consent. However, this withdrawal will not have a retroactive effect and will not affect the lawfulness of the processing based on consent previously given.
These rights may be exercised through our Data Protection Channel, whose access details are provided at the beginning of this Policy.
SECURITY AND CONTROL MEASURES
General
In compliance with data protection regulations, the Entity will process personal data by applying the appropriate technical, legal, organizational, and security measures to ensure the confidentiality and integrity of the information managed, as required by current regulations.
We encourage you to report to the Data Protection Officer (DPO) any security risks that you become aware of, which could compromise the integrity and confidentiality of personal data or confidential information. Please use the contact details/Channel provided in this Privacy Policy to notify us so we can take the necessary measures to prevent unauthorized processing, loss, destruction, or accidental damage.
Cybersecurity
As a specific and complementary concept, the Entity applies cybersecurity measures to prevent and manage potential attacks and fraud by cybercriminals against the privacy and protection of the data processed and accessed in the context of its activities and operations.
We advise you to exercise caution with communications whose content or format raises doubts about authenticity. Please contact the Data Protection Officer via the contact details in this Privacy Policy to verify such communications.
Furthermore, any request received from our Entity involving changes in payment methods, contact details, confidential (non-public) information, bank account details, credit card information, or other official data should not be acted upon without direct confirmation from our Entity through an alternative channel. We appreciate and rely on your cooperation in reporting and flagging such notifications or potential cybersecurity risks involving our Entity.
Supervisory Authority
In the event of discrepancies with the Entity regarding the processing of your data, you have the right to file a complaint with the corresponding Data Protection Supervisory Authority. In Spain, this authority is the Spanish Data Protection Agency (www.aepd.es).
Support and Assistance
Interested parties can address any doubts about the processing of their personal data or the interpretation of our Policy by contacting the Data Protection Officer (DPO) at the address provided at the beginning of this Privacy Policy.