In Pistamed, we are interested in ensuring that the processing of personal data of users is carried out in a transparent and secure manner, so that our users know at all times how we treat their personal data and how they can exercise their rights and freedoms.
1. Data controller.
2. What personal data do we process?
3. For what purpose and on what grounds do we process Users’ personal data?
4. For how long do we process and keep the User’s personal data?
5. Who can access the User’s personal data?
6. What security measures Pistamed applies?
7. What rights can Users exercise?
1. Responsible for data processing.
1.1. The responsible for the collection and processing of your personal data on the Website is PISTAMED INTERNACIONAL, S.L. (“Pistamed”), with tax identification number B-42696583, address at Plaza Gabriel Miró, 4, 03001, Alicante, and e-mail address contact LOPD@masa.eu. Pistamed is duly registered in the Mercantile Register of Alicante in Volume 4283, Folio 110, Page 169173, Section 8 and Inscription I/A 1.
2. What personal data we process?
2.1. Pistamed collects and processes various information from users. This information may constitute, in many cases, personal data of Users.
This information will be considered personal data when it can directly identify or allow us to identify a natural person, such as name and surname or contact details.
2.2. This personal data may have been directly provided by the User, when interacting on the Website or completing any of the available forms.
2.3. Specifically, the personal data that may be processed by Pistamed on the Website consist of:
– Identification and contact details of the Users, including your name and surname, telephone, email, national identity card, NIF or passport.
– Additional information (contractual data) that Users may provide when making purchases of products through the Website, including personal data relating to the processing and management of the purchase, personal or professional address and data related to payment.
2.4. Also, Pistamed may record the visits you make on the Website and its links or when you click on content, interact, or otherwise make use of the Website, through cookies and other similar technologies. For more information in this regard, Users can refer to our Cookies Policy.
2.5. We remind Users that they are responsible for ensuring that the personal data they provide is true and accurate, and undertake to notify us of any changes or modifications. Any loss or damage caused to the Website, Pistamed or any third party through the communication of erroneous, inaccurate or incomplete information, shall be the responsibility of the User.
2.6. In case of not providing the data considered necessary, it may not be possible to proceed with the request for information or the management of your reservation in our hotel establishments, in general, the management of requests intended by the User.
3. For what purpose and under what legitimacy we treat the personal data of the Users?
3.1. Pistamed treats the personal data of users for different purposes depending on the steps they take on the Website. Below, we indicate the specific purposes for which we treat the personal data of Users, as well as the legal basis that legitimizes its use in each case:
(a) Contracting our services and managing bookings.
Legal basis: Execution of pre-contractual measures and the subsequent contract and legitimate interest of Pistamed. The refusal to provide personal data for these purposes entails the impossibility to properly process and manage your orders of the products offered by Pistamed.
When you place an order for products offered by Pistamed through its Web Site, through the completion of forms and acceptance of the appropriate box, Pistamed may process your personal data for purposes related to the management and processing of the order: send reminders electronically in case you had started the order process, without finishing it, manage the order, billing and shipping of purchased products, analyze possible fraud and fraudulent activities (including money laundering and terrorist financing), answer your queries and requests, conduct quality or satisfaction surveys, communicate with you in relation to the products purchased, and exercise and defense of legal actions that assist Pistamed.
(b) Attention of the formulated consultations and requests.
Legal basis: The consent of the User to direct queries to Pistamed for the attention of requests through the various channels of contact and the legitimate interest of Pistamed in processing and managing the User’s queries.
Pistamed may process the User’s personal data to address queries that the User directs when contacting us through any of the channels of care available to the User, in relation to products or services offered or contracted with Pistamed.
(c) Compliance with legal obligations and requirements of various agencies.
Legal basis: Compliance with legal obligations applicable to Pistamed.
Pistamed also treat the User’s personal data to comply with any legal obligations are applicable and enforceable, meet requirements of any agency, court or public administration.
(d) Management of the Website and analysis of its use.
Legal basis: Legitimate interest in analyzing the use of the Website, to improve the services provided to users and provide greater security.
Pistamed may process the User’s personal data also through the conduct of analysis, studies, statistics, surveys, usage metrics, study of market trends, use of data for fraud prevention, either by itself or through third parties. As far as possible, the information used for this purpose will be aggregated information at a statistical level, without identification of the User.
(e) Sending commercial communications.
Legal basis: Legitimate interest in the case of customers or consent in the case of potential customers, users who complete the form provided on the Website for the receipt of commercial communications or those who have ceased to be customers.
Pistamed will be able to treat the personal information of the User with the purpose of realizing commercial communications of offers and discounts of products and products related to the nuts and with recipes of kitchen. To make commercial communications, Pistamed may use the User’s personal data and those collected during the provision of services to personalize commercial information and send the User those communications that may be of interest and fit their needs and preferences.
In accordance with applicable regulations, Pistamed also consult advertising exclusion lists (such as the Robinson List).
3.2 Pistamed will not make automated decisions based solely on the automated processing of personal data of the User, without human intervention and that produce legal effects or affect Users significantly, which may fall within the cases provided for in Article 22 of Regulation 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and the free movement of such data, as well as the regulations supplementing or replacing it. Nor does it carry out complex or automated profiling. Any automated decisions or complex profiling shall be subject to the explicit, express and separate consent of the User.
4. How long do we treat and keep the User’s personal data?
4.1. Pistamed will not store the User’s personal data for a period longer than necessary to fulfill the purposes stated above.
4.2. Subsequently, your data will be retained for the legal periods that apply in each case, taking into account the type of data and the purpose of processing. On the other hand, once the purposes are fulfilled, Pistamed retain personal data properly blocked, to the extent that may result in liability for Pistamed or otherwise required by applicable law.
5. Who can access the User’s personal data?
(a) Group of companies.
Pistamed may disclose the personal data of Users to the entities of its group of companies listed in the following hyperlink: https://pistamed.com/en/group-companies/
The purposes of communication are as follows:
– For internal administrative and management purposes of the group, based on the legitimate interest of Pistamed established in the applicable regulations.
– To the extent that any of the requests you make refer to other group companies, for the attention of the User’s request, based on our legitimate interest and the execution of the request made.
– For the provision of ancillary services necessary for the correct execution of the services offered on the Website.
(b) Service providers.
Pistamed may use other companies to provide certain services under its guidelines, for example, customer service, collection, sales, consulting, auditing, or IT-maintenance.
Pistamed ensures that, in such cases, such third parties will have limited access to personal data of Users to the extent necessary to perform the tasks entrusted, sign a contract for processing or commitments in each case are necessary in accordance with current regulations and shall be obliged not to disclose the information or use it for purposes other than the provision of the corresponding service.
(c) Disclosures required by law.
Pistamed may disclose the personal data of Users when so required by law, in a judicial proceeding, to investigate suspicious activity, or otherwise to protect their own rights and those of the Users.
5.2. In those cases in which Pistamed works with service providers located outside the European Economic Area, will implement with such service providers the necessary safeguards and guarantees, in accordance with applicable regulations at all times, prior to making the international transfer of data (e.g., verification of the existence of adequacy decisions, subscription of standard contractual clauses, conducting risk analysis / impact of the transfer).
6. What security measures applies Pistamed?
6.1. Pistamed take the necessary technical and organizational measures to ensure the confidentiality, integrity and security of personal data, and avoid its loss, alteration, treatment or unauthorized access, given the state of technology and the nature of the data stored. Also, Pistamed periodically monitors its systems to detect potential vulnerabilities and attacks.
6.2. However, Users are aware that Internet security is not impregnable and that there is no guarantee that personal data can not be accessed, disclosed, altered or destroyed if there is a leak in any of the security measures installed.
7. What rights can Users exercise?
7.1. In accordance with the legislation applicable at any given time, Users may request the exercise of their rights of access to personal data, rectification or deletion, limitation of processing, opposition to processing, as well as the right to the portability of their data, and the right to withdraw the consent given. In particular, Users have the following rights:
Access to data The User may request access to your personal data and the treatment that Pistamed is doing at any time, along with a copy of the processed information.
Rectification of data The User may request the modification of their personal data when they are inaccurate or incomplete.
Deletion of data The User may request deletion of his personal data if: (i) they are no longer necessary for the purposes for which they were collected or otherwise processed, (ii) if he withdraws his consent, (iii) when he understands that they have been unlawfully processed or (iv) otherwise legally established.
Limitation of processing You may request the limitation of the processing of your personal data in particular while contesting the accuracy of your personal data, when you understand that the processing is unlawful, when your personal data are no longer necessary for the purposes for which they were collected, but are necessary for the formulation, exercise or defence of claims, or in case of opposition while we verify the applicability of your right.
Opposition to processing The User may object to the processing of their personal data, for reasons related to their particular situation, when their personal data are processed based on legitimate interest, including profiling. In such a case, Pistamed will be obliged to stop processing your personal data, unless there are overriding legitimate reasons or your personal data is necessary for the formulation, exercise or defense of claims.
Portability The User may request the receipt of their personal data in a structured format, commonly used and machine-readable, and its transmission to another controller, when the processing of their personal data is based on consent or the performance of a contract and the processing is carried out by automated means.
7.3. If necessary for the unequivocal identification of the User, Pistamed may request a copy of your ID card, passport or other valid document that identifies you.
7.4. In any case, Users may also file a complaint with the competent supervisory authority which, in the case of Spain, is the Spanish Data Protection Agency (www.aepd.es).