Privacy and Data Protection Policy

Privacy and Data Protection Policy of PROFTEX

 

Having regard the applicable regulations in data protection, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), the Organic Law 3/2018 of Personal Data Protection and safeguarding of digital rights (LOPDPGDD) and other implementing regulations, we hereby inform you about our Privacy and Data Protection Policy.

 

Controller of personal data

The controller of personal data is the legal person which determines the purposes and means of the processing of the said personal data. In other words, the controller decides how and why personal data is processed.

Within the processing provided under this Policy, the controller is

–    Legal name: PROFTEX

–    VAT number: ES-A15077761

–    Legal address: Lugar de Extramundi, S/N, 15.910 – Padrón (A Coruña), SPAIN.

–    Email address of DPO: rgpd@proftex.com

–    Telephone number: +34 981804213

–    Activity: manufacturer and distributor of aluminium and PVC systems.

 

What personal data do we process and how do we protect it?

Personal data is any information relating to an identified or identifiable natural person.

For the purposes established in this Privacy Policy, the controller collects and processes the personal data described in each type of processing, and that will depend on the different services requested or the contractual relationship existing with our company.

Our company commits to treat personal data with confidentiality and to apply all needed security measures, whether physical, technical or organizational, for the protection of your personal data.

You take full responsibility, in any case, for the truthfulness, accuracy, validity and authenticity of the personal data communicated and you undertake to keep it duly updated.

 

Data Processing of “Customers”

1.- What type of personal data do we process?

  • Identification data: name, ID, address, telephone number, email address.
  • Professional data: job and position.
  • Commercial data: products and services supplied.

2.- Which are the purposes of the processing?

We process the personal data that you provide us to manage customers data, to keep the commercial relationship, for accounting, administrative and invoicing purposes and for the legal and tax obligations.

The purpose of advertising and commercial research has also been expected, for which the express consent of the data subject is requested.

The personal data provided will be kept as long as the commercial relationship exists. If you decide to erase your personal data, these may be kept in our databases for the periods provided by the law in order to comply with tax and accounting obligations, and will be erased once said legal periods or those that are applicable have prescribed.

3.- Which is the basis of the processing?

The legal base for the processing of your data is the performance of a contract, as well as the compliance with a legal obligation of the controller.

The communication of offers and promotions that could be of your interest is based on the express consent requested to you.

4.- Will your personal data be transferred or communicated?

Personal data may be communicated to other companies of the Group and/or Affiliates and invested companies, based on the express consent of the data subject.

Personal data may also be communicated, if applicable, to public organisms due to a legal obligation.

Transfer of personal data to third countries is not expected, except to companies of the Group that may be located abroad, United Kingdom included.

 

Data Processing of “Contacts and potential customers”

1.- What type of personal data do we process?

  • Identification data: name, address, telephone number, email address.
  • Professional data: job, position and company.

2.- Which are the purposes of the processing?

We process the personal data that you provide us in the contact form to manage the contact data of contacts, commercial contacts and potential customers.

The purpose of advertising and commercial research has also been expected, for which the express consent of the data subject is requested.

The personal data provided will be kept as long as the commercial relationship exists. If you decide to erase your personal data, these will be erased from our contacts databases.

3.- Which is the basis of the processing?

The legal base for the processing of your data is the express consent of the data subject, as well as the pursue of the legitimate interests of controller.

4.- Will your personal data be transferred or communicated?

Personal data may be communicated to other companies of the Group and/or Affiliates and invested companies, as well as installers, based on the express consent of the data subject.

Transfer of personal data to third countries is not expected, except to companies of the Group and/or installers that may be located abroad, United Kingdom included.

 

Data Processing of “Suppliers”

1.- What type of personal data do we process?

  • Identification data: name, ID, address, telephone number, email address.
  • Bank details: bank account number.
  • Professional data: job, position and degrees.
  • Commercial data: products and services supplied.

2.- Which are the purposes of the processing?

We process the personal data that you provide us to manage the contact data of suppliers, to keep the commercial relationship, the accounting, administrative and payment management, as well as for management of tax obligations.

The personal data provided will be kept as long as the commercial relationship exists. If you decide to erase your personal data, these may be kept in our databases for the periods provided by the law in order to comply with tax and accounting obligations, and will be erased once said legal periods or those that are applicable have prescribed.

3.- Which is the basis of the processing?

The legal base for the processing of your data is the performance of a contract, as well as the compliance with a legal obligation of the controller.

4.- Will your personal data be transferred or communicated?

Personal data won’t be communicated to any entities others than public organisms in case of a legal obligation.

Transfer of personal data to third countries is not expected.

 

Data Processing of “Employees and agency workers”

1.- What type of personal data do we process?

  • Identification data: name, ID, date of birth, address, telephone number, email address, signature, image.
  • Personal characteristics: gender, civil status, nationality, age, date and place of birth, family data.
  • Social conditions: leaves.
  • Bank and economic details: bank account number, payslip, tax deductions, wage withholding.
  • Professional and academic data: job and position, background, degree.
  • Control of presence and biometric data (fingerprint).
  • Health data: medical history, analysis, medical leave, general medical supervision.

2.- Which are the purposes of the processing?

We process the personal data you provide us with for the management of the employment relationship, payroll management, administrative and payment management, compliance with the company’s tax and labour obligations, access and presence control, professional training and development management, and the risk-prevention management.

The fingerprint of the employees and agency workers will be processed in a biometric identification system to facilitate the control of access to the facilities and the registration of the working day. The fingerprint reader obtains a template from the fingerprint of each registered user, but it does not save the complete image of the fingerprint. From this biometric template it is impossible to reconstruct the user’s fingerprint, so in no case will the user’s identity be compromised.

In addition, the processing of health data is also carried out for the purposes of preventive or occupational medicine, and for the evaluation of the employees’ work capacity.

The personal data provided will be kept as long as the employment relationship exists. Once the employment relationship has ended, if you decide to erase your personal data, data will be kept until expiration of the periods provided by the law and by accounting, tax and labour regulations, and once these periods have elapsed, your data will be deleted from our system.

3.- Which is the basis of the processing?

The legal base for the processing of your data is the performance of an employment contract, as well as the compliance with a legal obligation of the controller and/or the express consent of data subject.

In addition, with the express consent of the data subject, health data will be processed by the physiotherapy service provided free of charge by the company at its facilities.

Also, with the express consent of the data subject, the image could be processed in any picture or video relating to a company’s event.

4.- Will your personal data be transferred or communicated?

Personal data may be communicated to other companies of the Group and/or Affiliates and invested companies, based on the express consent of the data subject.

Personal data may also be communicated, if applicable, to public organisms due to legal obligations, such as tax authority, Social Security, Mutual Insurance Company, Labour inspection, etc.

Data can be communicated due to purposes of the legitimate interests pursued by the controller such as:

–    Bank details (ID, name and surname, bank account number) shall be communicated to the bank entities for payroll payments.

–    In case staff expenditures must be proven due to a subsidy, a training activity or a project funded with public sources, payroll data might be communicated to the Public Administrations in charge of evaluating the funds or the project, in accordance to the applicable regulations.

–    The picture of the employee or agency worker might be used in a publication or website with the purpose of making public a certain event related to the company’s activities, with the express consent of the data subject.

Transfer of personal data to third countries is not expected, except to companies of the Group that may be located abroad, including the United Kingdom.

 

Data Processing of “Users of APP PROFTEX – GESTIÓN MOVILIDAD”

1.- What type of personal data do we process?

  • Identification data: name, ID, telephone number, email address.
  • Professional data: job, position, company.
  • Control of presence data: route and geolocation.
  • Functional data: suggestions and events in the route.

2.- Which are the purposes of the processing?

We process the personal data for the complete functioning and operating of the APP. Based on the assigned route and the geolocation of the user, tracking of the deliveries may be made and relevant information may be provided to the users of the application.

The personal data provided will be kept as long as the route has not been completed or until expiration of limitation periods stablished under the applicable law, in which case the data will be erased after expiration.

3.- Which is the basis of the processing?

Processing is lawful based on the express consent given by the data subject as well as the legitimate interests of controller.

4.- Will your personal data be transferred or communicated?

Personal data may be communicated to other companies of the Group and/or Affiliates, based on the express consent of the data subject.

Transfer of personal data to third Countries is not expected, except to companies of the Group that might be stablished abroad, including the United Kingdom.

 

Data Processing of “Geolocation”

1.- What type of personal data do we process?

  • Identification data: name, telephone number, email address, number plate.
  • Professional data: job, position, company.
  • Control of presence data: route and geolocation.

2.- Which are the purposes of the processing?

We process the personal data for the tracking of employees’ movements and the corresponding routes within the management of the labour relationship.

The personal data provided will be kept as long as the labour relationship exists and until expiration of limitation periods stablished under the applicable law, in which case the data will be erased after said expiration.

3.- Which is the basis of the processing?

Processing is lawful based on the express consent given by the data subject, the legitimate interests of controller and due to compliance with a legal obligation of the controller within the framework of the labour relationship.

4.- Will your personal data be transferred or communicated?

Personal data may be communicated to other companies of the Group and/or Affiliates, based on the express consent of the data subject.

Transfer of personal data to third Countries is not expected, except to companies of the Group that might be stablished abroad, including the United Kingdom.

 

Data Processing of “Job candidates”

1.- What type of personal data do we process?

  • Identification data: name, ID, date of birth, address, telephone number, email address, image.
  • Personal characteristics: gender, civil status, nationality, age, date and place of birth.
  • Professional and academic data: job and position, background, degree.

2.- Which are the purposes of the processing?

We process the personal data you provide us with for the management of the hiring processes.

The personal data provided will be kept for future hiring processes until withdrawal of consent by the data subject. If you decide to erase your personal data, data will be deleted from our candidate database.

 

3.- Which is the basis of the processing?

Processing is lawful based on the express consent given by the data subject.

4.- Will your personal data be transferred or communicated?

Personal data may be communicated to other companies of the Group and/or Affiliates and invested companies, as well as temporary work agencies, based on the express consent of the data subject.

Transfer of personal data to third Countries is not expected, except to companies of the Group that might be stablished abroad, including the United Kingdom.

 

Data Processing of “Video-surveillance”

1.- What type of personal data do we process?

  • Identifying data: image.

2.- Which are the purposes of the processing?

We process your personal data for the recording of images by video-surveillance at company’s facilities due to security reasons.

Personal data will be kept for the periods provided under applicable law (one month).

3.- Which is the basis of the processing?

Processing is lawful based on the legitimate interests pursued by the controller.

4.- Will your personal data be transferred or communicated?

Personal data won’t be communicated to any entities others than State security forces and Tribunals due to a legal obligation.

Transfer of personal data to third Countries is not expected.

 

Data Processing of “Course attendees”

1.- What type of personal data do we process?

  • Identification data: name, ID, address, telephone number, email address.
  • Professional and academic data: job and position, degree.

2.- Which are the purposes of the processing?

We process the personal data you provide us with for the registration of attendees to the courses organized by the company.

The personal data provided will be kept until a request to erasure by the data subject. In case you decide to erase your personal data, it will be removed from our course attendees database.

3.- Which is the basis of the processing?

The legal base for the processing of your data is the performance of a contract, as well as the compliance with a legal obligation of the controller.

4.- Will your personal data be transferred or communicated?

Personal data may be communicated to public entities such as Xunta de Galicia or Fundación Tripartita, due to a legal obligation, and also to other companies of the Group and/or Affiliates and invested companies, based on the express consent of the data subject.

Transfer of personal data to third Countries is not expected, except to companies of the Group that might be stablished abroad, including the United Kingdom.

 

What are your rights when providing us with your data?

In accordance with the applicable regulations on data protection, you have a series of rights in relation to the processing of your personal data. The exercise of these rights will be free for you, except in cases manifestly unfounded or if excessive requests are made, especially repetitive ones.

These rights are the following:

  1. Right to information: You have the right to be informed in a concise, transparent, intelligible and easily accessible manner, with clear and simple language, about the use and processing of your personal data.
  2. Right of access: You have the right to ask us at any time to confirm whether we are processing your personal data, to provide you with access to it and to information about the processing and to obtain a copy of the said data. The copy of your personal data that we provide will be free of charge, although the request for additional copies may be subject to the charge of a reasonable amount based on administrative costs. For our part, we may ask you to prove your identity or require more information necessary to manage your request.
  3. Right to rectification: You have the right to request the rectification of inaccurate, outdated or incomplete personal data concerning you. You may also request incomplete personal data to be completed, including through a supplementary statement.
  4. Right to erasure: You have the right to request the erasure of your personal data when, among other reasons, the data is no longer necessary for the purposes for which it was collected. However, this right is not absolute, our organization may continue to keep them duly blocked in the cases provided for by the applicable regulations.
  5. Right to restriction of processing: You have the right to request the restriction of the processing of your personal data, which means that we can continue to store it, but not continue to process it if any of the following conditions are met:
  • that you contest the accuracy of the data, for a period enabling the controller to verify the accuracy of the data;
  • the processing is unlawful and you oppose to the erasure of the data and request instead the restriction of its use;
  • our company no longer needs the data for the purposes of the processing, but you need it for the establishment, exercise or defence of legal claims;
  • You have objected the processing, while it is verified if the legitimate reasons of our entity prevail over yours.
  1. Right to data portability: You have the right to have your data transmitted to another data controller in a structured, commonly used and machine-readable format. This right applies when the processing of your personal data is based on consent or the execution of a contract and such processing is carried out by automated means.
  2. Right to object: This right allows you to object the processing of your personal data, including profiling. We will not be able to attend to your right when we process your data if we prove legitimate reasons for the processing or in case of establishment, exercise or defence of legal claims.
  3. Right not to be subject to automated decisions, including profiling: This right allows you not to be the subject of a decision based solely on automated processing, including profiling, which produce -said decisions- legal effects or similarly affect you. Unless said decision is necessary for the conclusion or execution of a contract, is authorized by law or is based on consent.
  4. Right to withdraw consent: In cases where we have obtained your consent for the processing of your personal data in relation to certain activities (for example, in order to send you commercial communications), you may withdraw it at any time. In this way, we will stop carrying out that specific activity for which you had previously consented, unless there is another reason that justifies the continuity of the processing of your data for these purposes, in which case, we will notify you of this situation.
  5. Right to lodge a complaint with a supervisory authority: You have the right to file a complaint with the Spanish Agency for Data Protection, C/ Jorge Juan, 6, 28001 Madrid, 901 100 099 – 912 663 517 (www.agpd.es), or at the web address: https://sedeagpd.gob.es/sede-electronica-web/vistas/formQuejasSugerencias/seleccionarQuejaSugerencia.jsf

You may exercise the aforementioned rights by sending a communication to our Customer Service Department, or by sending an email to the DPO at the address rgpd@proftex.com, attaching a document proving your identity and providing the necessary details to process with your request.

Interested parties can obtain additional information on their rights on the website of the Spanish Agency for Data Protection, www.agpd.es.