ICONOS FINALES-TRAZADOS

Privacy Policy

INDEX

  1. Purpose of the Privacy Policy
  2. Definitions
  3. Identity of the Data Controller
  4. Applicable laws and regulations
  5. Principles applicable to the processing of personal data
  6. Data processing activities carried out
  7. Necessary and up-to-date information
  8. Personal data of minors
  9. Technical and organisational security measures
  10. Rights of data subjects
  11. Complaints to the Supervisory Authority
  12. Acceptance of and changes to the Privacy Policy

1.- PURPOSE OF THE PRIVACY POLICY

This "Privacy and Data Protection Policy" is intended to make known the conditions governing the collection and processing of personal data by ECONOMIC BUSINESS SYSTEMS CONSULTING, S.L., making every effort to safeguard the fundamental rights, honour and freedoms of the persons whose personal data is processed, complying with the regulations and laws in force that govern the Protection of Personal Data according to the European Union and the Spanish Member State and, specifically, those set out in the "Processing Activities" section of this Privacy Policy.

Accordingly, in this Privacy and Data Protection Policy, users of the Website http://www.ebserco.com are informed of all the details of interest to them regarding how these processes are carried out, for what purposes, which other entities might have access to their data and what the users' rights are.

2.- DEFINITIONS

"Personal data":
Any information relating to an identified or identifiable natural person ("the Website user"); an identifiable natural person is one whose identity can be determined, directly or indirectly, in particular by means of an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person.
"Processing":
any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
"Restriction of processing":
the marking of stored personal data with the aim of limiting their processing in the future.
"Profiling":
any form of automated processing of personal data consisting of using personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
"Pseudonymisation":
the processing of personal data in such a way that they can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
"Filing system":
any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis.
"Data controller" or "controller":
the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
"Data processor" or "processor":
the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
"Recipient":
the natural or legal person, public authority, agency or other body to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.
"Third party":
a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
"Consent of the data subject":
any freely given, specific, informed and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
"Personal data breach":
a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;
"Genetic data":
personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that person and which result, in particular, from an analysis of a biological sample from the natural person in question.
"Biometric data":
personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that person, such as facial images or dactyloscopic data.
"Data concerning health":
personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about their health status.
"Main establishment":
a) as regards a controller with establishments in more than one Member State, the place of its central administration in the Union, unless the decisions on the purposes and means of the processing are taken in another establishment of the controller in the Union and the latter establishment has the power to have such decisions implemented, in which case the establishment having taken such decisions is to be considered the main establishment; b) as regards a processor with establishments in more than one Member State, the place of its central administration in the Union or, if it has no central administration in the Union, the establishment of the processor in the Union where the main processing activities take place in the context of the activities of an establishment of the processor to the extent that the processor is subject to specific obligations under this Regulation.
"Representative":
a natural or legal person established in the Union who, designated by the controller or processor in writing pursuant to Article 27 of the GDPR, represents the controller or processor with regard to their respective obligations under this Regulation.
"Enterprise":
a natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity.
"Supervisory authority":
the independent public authority established by a Member State pursuant to Article 51 of the GDPR. In the case of Spain, this is the Spanish Data Protection Agency (Agencia Española de Protección de Datos).
"Cross-border processing":
a) the processing of personal data which takes place in the context of the activities of establishments in more than one Member State of a controller or processor in the Union where the controller or processor is established in more than one Member State, or b) the processing of personal data which takes place in the context of the activities of a single establishment of a controller or processor in the Union but which substantially affects or is likely to substantially affect data subjects in more than one Member State.
"Information society service":
any information society service, that is to say, any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient of services.

3.- IDENTITY OF THE DATA CONTROLLER

The Data Controller is the natural or legal person, of a public or private nature, or administrative body which, alone or jointly with others, determines the purposes and means of the processing of personal data; in the event that the purposes and means of the processing are determined by the law of the European Union or of the Spanish Member State.

For the purposes set out in this Data Protection Policy, the identity and contact details of the Data Controller are:

ECONOMIC BUSINESS SYSTEMS CONSULTING, S.L. - Tax ID (CIF) B25382995
Calle Sant Pelegri, 109. 25300, Tàrrega (Lleida), Spain

DATA PROTECTION OFFICER:

We have a person or entity specialised in data protection, responsible for ensuring the correct compliance with the legislation and regulations in force regarding data protection. This role is known as the Data Protection Officer (DPO) and their contact details are:

Email: dpo@eriaconsultores.com - Telephone: 678208629

4.- APPLICABLE LAWS AND REGULATIONS

This Privacy and Data Protection Policy is developed on the basis of the following data protection regulations and laws:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. Hereinafter GDPR.
  • Organic Law 3/2018 of 5 December on the Protection of Personal Data and the Guarantee of Digital Rights. Hereinafter LOPD/GDD.
  • Law 34/2002 of 11 July on Information Society and Electronic Commerce Services. Hereinafter LSSICE.

5.- PRINCIPLES APPLICABLE TO THE PROCESSING OF PERSONAL DATA

The personal data collected and processed through this Website will be processed in accordance with the following principles:

  • Principle of lawfulness, fairness and transparency: All processing of personal data carried out through this Website will be lawful and fair, making it entirely clear to the user when the personal data concerning them is being collected, used, consulted or processed. Information regarding the processing carried out will be provided in advance, in an easily accessible and easy-to-understand form, using clear and plain language.
  • Principle of purpose limitation: All data will be collected for specified, explicit and legitimate purposes, and will not be further processed in a manner incompatible with the purposes for which it was collected.
  • Principle of data minimisation: The data collected will be adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.
  • Principle of accuracy: The data will be accurate and, where necessary, kept up to date, taking all reasonable steps to ensure that personal data which is inaccurate with respect to the purposes for which it is processed is erased or rectified without delay.
  • Principle of storage limitation: The data will be kept in a form that permits the identification of data subjects for no longer than is necessary for the purposes of the processing of the personal data.
  • Principle of integrity and confidentiality: The data will be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss or damage, using appropriate technical or organisational measures.
  • Principle of accountability: The entity owning the Website will be responsible for compliance with the principles set out in this section and will be able to demonstrate it.

6.- DATA PROCESSING ACTIVITIES

The data processing activities carried out through the Website are detailed below, specifying each of the following sections:

  • Activity: Name of the data processing activity
  • Purposes: Each of the uses and processing carried out with the data collected
  • Legal basis: The legal basis that legitimises the processing of the data
  • Data processed: Type of data processed
  • Source: Where the data is obtained from
  • Retention: Period during which the data is kept
  • Recipients: Third-party persons or entities to whom the data is provided
  • International transfers: Cross-border transfers of the data outside the European Union

6.1 MAIN PROCESSING ACTIVITIES

These are the data processing activities whose purposes are necessary and essential for the provision of the services.

6.2 OPTIONAL PROCESSING ACTIVITIES (if the user has indicated their acceptance)

These are the personal data processing activities whose purposes are not essential for the provision of the service and which are only carried out if the user has ticked YES in the consent for carrying out these activities.

WEBSITE MANAGEMENT
Legal bases (Art. 6.1.a GDPR) Consent of the data subject; (Art. 6.1.f GDPR) Legitimate interest of the Data Controller or third parties; Organic Law on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD) 3/2018, Regulation (EU) 2016/679 on the protection of personal data
Purposes Management of and contact with users; The data requested through the contact form, sent by email or provided by telephone published on our website will be used to answer your enquiry and to send you information about our organisation and services. The consequences of not providing us with this data will be the impossibility of contacting you and providing a response to your request. You have the right to receive a response to any question, enquiry or clarification arising from this form or from the other means of contact published on the corporate website, by calling us, sending us an email or visiting our premises.
Categories of data and groups Website users (Identification data)
Source of data The data subject themselves or their legal representative
Category of recipients We do not transfer your data to anyone, but we may allow its processing by third parties solely for technical, legal and/or service-provision reasons.
International transfer Not envisaged
Retention period Other. We keep your data only for the time necessary to handle the information request or if there is any legal obligation or legitimate interest in this respect.
Security measures The security measures implemented correspond to those described in the documents that make up the organisation's Data Protection and Information Security Policy.

7.- NECESSARY AND UP-TO-DATE INFORMATION

All fields marked with an asterisk (*) in the Website forms are mandatory, in such a way that the omission of any of them could make it impossible to provide the requested services or information.

You must provide truthful information. In order for the information provided to always be up to date and free of errors, you must notify the Data Controller as soon as possible of any modifications and corrections to your personal data as they occur, by email to the address: nfernandez@ebserco.com.

Likewise, by clicking on the "I accept" button (or equivalent) included in the aforementioned forms, you declare that the information and data provided therein are accurate and truthful, and that you understand and accept this Privacy Policy.

8.- PERSONAL DATA OF MINORS

In compliance with the provisions of Article 8 of the GDPR and Article 7 of the LOPD/GDD, only persons over 14 years of age may lawfully give their consent for the processing of their personal data by ECONOMIC BUSINESS SYSTEMS CONSULTING, S.L..

In view of the above, minors under 14 years of age may not use the services available through the Website without the prior authorisation of their parents, guardians or legal representatives, who will be solely responsible for all acts carried out through the Website by the minors in their charge, including the completion of the online forms with the personal data of such minors and the ticking, where applicable, of the boxes accompanying them.

9.- TECHNICAL AND ORGANISATIONAL SECURITY MEASURES

The Data Controller adopts the organisational and technical measures necessary to guarantee the security and privacy of your data, to prevent its alteration, loss, unauthorised processing or access, depending on the state of the technology, the nature of the stored data and the risks to which it is exposed.

Among others, the following measures stand out:

  • Ensuring the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
  • Restoring the availability of and access to personal data in a timely manner in the event of a physical or technical incident.
  • Regularly verifying, assessing and evaluating the effectiveness of the technical and organisational measures implemented to ensure the security of the processing.
  • Pseudonymising and encrypting personal data, where sensitive data is involved.

Furthermore, the Data Controller has decided to manage information systems in accordance with the following principles:

  • Principle of regulatory compliance: All information systems will comply with the applicable legal, regulatory and sector-specific rules affecting information security, especially those related to the protection of personal data and the security of systems, data, communications and electronic services.
  • Principle of risk management: Risks will be minimised to acceptable levels, seeking a balance between security controls and the nature of the information. Security objectives must be established, reviewed and consistent with the information security aspects.
  • Principle of awareness and training: Training, awareness and information-security awareness programmes and campaigns will be organised for all users with access to information.
  • Principle of proportionality: The implementation of controls to mitigate the security risks of assets will be carried out seeking a balance between the security measures, the nature of the information and the risk.
  • Principle of responsibility: All members of the Data Controller will be responsible for their conduct regarding information security, complying with the established rules and controls.
  • Principle of continuous improvement: The degree of effectiveness of the security controls implemented in the organisation will be reviewed on a recurring basis to increase the capacity to adapt to the constant evolution of risk and of the technological environment.

10.- RIGHTS OF DATA SUBJECTS

The data protection regulations in force protect the user with a series of rights in relation to the use made of their data. Each and every one of these rights is personal and non-transferable, meaning that they can only be exercised by the data owner, following verification of their identity.

The rights of Website users are detailed below:

  • Right of access: This is the right of the Website user to obtain confirmation as to whether or not the Data Controller is processing their personal data and, if so, to obtain information about their specific personal data and the processing that the Data Controller has carried out or is carrying out, as well as, among other things, the available information about the origin of such data and the recipients of the communications made or planned.
  • Right to rectification: This is the right of the Website user to have their personal data modified where it is inaccurate or, taking into account the purposes of the processing, incomplete.
  • Right to erasure: Commonly known as the "right to be forgotten", this is the right of the Website user, provided that the legislation in force does not establish otherwise, to obtain the erasure of their personal data when it is no longer necessary for the purposes for which it was collected or processed; the User has withdrawn their consent to the processing and it has no other legal basis; the User objects to the processing and there is no other legitimate ground to continue with it; the personal data has been unlawfully processed; the personal data has been obtained as a result of a direct offer of information society services to a minor under 14 years of age. In addition to erasing the data, the Data Controller, taking into account the available technology and the cost of its application, will take reasonable measures to inform other possible controllers who are processing the personal data of the data subject's request for erasure of any link to such personal data.
  • Right to restriction of processing: This is the right of the Website User to restrict the processing of their personal data. The Website User has the right to obtain the restriction of processing when they contest the accuracy of their personal data; the processing is unlawful; the Data Controller no longer needs the personal data, but the User needs it to make claims; and when the Website User has objected to the processing.
  • Right to data portability: In those cases where the processing is carried out by automated means, the Website User will have the right to receive their personal data from the Data Controller in a structured, commonly used and machine-readable format, and to transmit it to another data controller. Where technically possible, the Data Controller will transmit the data directly to that other Controller.
  • Right to object: This is the right of the User for the processing of their personal data not to be carried out or for such processing to be stopped by the Data Controller.
  • Right not to be subject to automated decisions and/or profiling: This is the right of the Website User not to be subject to an individualised decision based solely on the automated processing of their personal data, including profiling, unless the legislation in force establishes otherwise.
  • Right to withdraw consent: This is the right of the Website User to withdraw, at any time, the consent given for the processing of their data.

The Website user may exercise any of the aforementioned rights by contacting the Data Controller and following identification of the User, using the following contact information:

You may also exercise your rights before the Data Protection Officer:

Email: dpo@eriaconsultores.com - Telephone: 678208629

11.- RIGHT TO LODGE A COMPLAINT WITH THE SUPERVISORY AUTHORITY

If the Website user considers that the Data Controller is not processing their personal data appropriately, they may contact the Data Protection Officer:

Email: dpo@eriaconsultores.com - Telephone: 678208629

Notwithstanding the above, the Website User is informed that they have the right to lodge a complaint with the Spanish Data Protection Agency if they consider that an infringement of data protection legislation has been committed regarding the processing of their personal data.

Contact information of the supervisory authority:

Spanish Data Protection Agency (Agencia Española de Protección de Datos)
Email: info@aepd.es
Telephone: 900293183
Website: https://www.aepd.es
Address: C/. Jorge Juan, 6. 28001, Madrid (Madrid), Spain

12.- ACCEPTANCE OF AND CHANGES TO THE PRIVACY POLICY

It is necessary that the Website user has read and agrees with the data protection conditions contained in this Privacy Policy, and that they accept the processing of their personal data so that the Data Controller may proceed with it in the manner, periods and for the purposes indicated.

The Data Controller reserves the right to modify this Privacy Policy, at its own discretion, or as a result of a legislative, jurisprudential or doctrinal change by the Spanish Data Protection Agency. Any changes or updates made to this Privacy Policy that affect the purposes, retention periods, transfers of data to third parties, international data transfers, as well as any right of the Website User, will be explicitly communicated to the user.

Contact request

* Required fields

DATA PROTECTION INFORMATION

Controller

ECONOMIC BUSINESS SYSTEMS CONSULTING, S.L.

Purposes

Management of and contact with users; The data requested through the contact form, sent by email or provided by telephone published on our website will be used to answer your enquiry and to send you information about our organisation and services. The consequences of not providing us with this data will be the impossibility of contacting you and providing a response to your request. You have the right to receive a response to any question, enquiry or clarification arising from this form or from the other means of contact published on the corporate website, by calling us, sending us an email or visiting our premises.

Legal basis

(Art. 6.1.a GDPR) Consent of the data subject; (Art. 6.1.f GDPR) Legitimate interest of the Data Controller or third parties. Organic Law on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD) 3/2018, Regulation (EU) 2016/679 on the protection of personal data

Retention

Other. We keep your data only for the time necessary to handle the information request or if there is any legal obligation or legitimate interest in this respect.

Recipients

We do not transfer your data to anyone, but we may allow its processing by third parties solely for technical, legal and/or service-provision reasons.

International transfers

There is no provision to carry out international transfers of your personal data

Rights & more info

the email nfernandez@ebserco.com or at our premises located at Calle Sant Pelegri, 109, 25300 Tàrrega (Lleida) Spain.

You can access the legal notice and the full information here


Drag the arrow into the white box to activate the button

 

 

consulting services

  • <center>Tax area

    Tax area


  • <center>Labor Area

    Labor Area


  • <center>Accounting Area

    Accounting Area


  • <center>Legal Area

    Legal Area


  • <center>Área Servicios Financieros</center>

    Área Servicios Financieros

  • <center>Professional diesel return</center>

    Professional diesel return

  • <center>Tax Representative</center>

    Tax Representative