VELOFUTUR

Privacy Policy.

 

I. PRIVACY AND DATA PROTECTION POLICY

In accordance with applicable legislation, Velofutur hereinafter also the Website, undertakes to implement the technical and organizational measures required to ensure a level of security appropriate to the risks associated with the data collected.

Legislation Covered by This Privacy Policy

This Privacy Policy complies with current Spanish and European legislation governing online personal data protection. In particular, it complies with the following rules:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons regarding the processing of personal data and on the free movement of such data (GDPR).
  • Spanish Organic Law 3/2018 of 5 December on Personal Data Protection and the Guarantee of Digital Rights (LOPD-GDD).
  • Spanish Royal Decree 1720/2007 of 21 December approving the implementing regulations for Organic Law 15/1999 of 13 December on Personal Data Protection (RDLOPD).
  • Spanish Law 34/2002 of 11 July on Information Society Services and Electronic Commerce (LSSI-CE).

Identity of the Personal Data Controller

The controller responsible for personal data collected through Velofutur is: VELOFUTUR S.L., with Tax ID: B27729920 and registered with: Registro Mercantil de Pontevedra with the following registration details: Boletín 204, Referencia 885506, whose representative is: Juan Campos Otero​ hereinafter, the Data Controller. Its contact details are as follows:

Address: C/ XOGO DA OLA, 5 PTL.2 F. 36400, PORRIÑO (O), PONTEVEDRA

Contact telephone: 986334677

Fax:

Contact email: velofutur@gmail.com

Personal Data Records

In accordance with the GDPR and LOPD-GDD, we inform you that personal data collected by Velofutur, through forms available on its pages will be incorporated into and processed in our records in order to facilitate, expedite, and fulfill the commitments established between Velofutur and the User, maintain the relationship established through forms completed by the User, or respond to a request or enquiry. In accordance with the GDPR and LOPD-GDD, unless the exception under Article 30(5) GDPR applies, a record of processing activities is maintained, describing the processing carried out according to its purposes and the other circumstances required by the GDPR.

Principles Applicable to Personal Data Processing

The processing of the User’s personal data is subject to the principles set out in Article 5 GDPR and Article 4 and subsequent provisions of Spanish Organic Law 3/2018 of 5 December on Personal Data Protection and the Guarantee of Digital Rights:

  • Lawfulness, fairness, and transparency: the User’s consent will be required after transparent information has been provided about the purposes for which personal data is collected.
  • Purpose limitation: personal data will be collected for specified, explicit, and legitimate purposes.
  • Data minimization: only personal data strictly necessary for the stated processing purposes will be collected.
  • Accuracy: personal data must be accurate and kept up to date.
  • Storage limitation: personal data will be kept in identifiable form only for as long as necessary for the purposes of processing.
  • Integrity and confidentiality: personal data will be processed in a manner that ensures appropriate security and confidentiality.
  • Accountability: the Data Controller is responsible for ensuring compliance with the above principles.

Categories of Personal Data

The categories of data processed by Velofutur consist solely of identification data. No special categories of personal data within the meaning of Article 9 GDPR are processed.

The categories of data processed by Velofutur include both identification data and special categories of personal data within the meaning of Article 9 GDPR.

Special categories of personal data are data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership, as well as genetic data, biometric data used to uniquely identify a natural person, health data, or data concerning a person’s sex life or sexual orientation.

Processing special categories of personal data always requires the User’s explicit consent for one or more specified purposes.

Legal Basis for Processing Personal Data

The legal basis for processing personal data is consent. Velofutur undertakes to obtain the User’s explicit and verifiable consent to process personal data for one or more specified purposes.

The User may withdraw consent at any time. Withdrawing consent will be as easy as giving it. As a general rule, withdrawal of consent will not affect use of the Website.

Where the User must or may provide data through forms to make enquiries, request information, or for purposes related to Website content, the User will be informed whenever completion of a field is mandatory because the data is required to complete the relevant operation.

Purposes of Personal Data Processing

Personal data is collected and managed by Velofutur to facilitate, expedite, and fulfill commitments between the Website and the User, maintain relationships established through forms completed by the User, and respond to requests or enquiries.

The data may also be used for commercial personalization, operational and statistical purposes, and activities related to the corporate purpose of Velofutur, as well as for data extraction and storage and marketing studies intended to tailor Content to the User and improve the quality, operation, and navigation of the Website.

When personal data is collected, the User will be informed of the specific purpose or purposes for which it will be processed—that is, how the collected information will be used.

Personal Data Retention Periods

Personal data will be retained only for the minimum period necessary for the purposes of processing and, in all cases, only for the following period: 18 months, or until the User requests its deletion.

When personal data is collected, the User will be informed of the retention period or, where that is not possible, the criteria used to determine it.

Recipients of Personal Data

The User’s personal data will not be shared with third parties.

When personal data is collected, the User will be informed of the recipients or categories of recipients.

The User’s personal data will be shared with the following recipients or categories of recipients:

If the Data Controller intends to transfer personal data to a third country or international organization, the User will be informed, when the data is collected, of the relevant country or organization and whether the European Commission has adopted an adequacy decision.

Personal Data of Minors

In accordance with Article 8 GDPR and Article 7 of Spanish Organic Law 3/2018 of 5 December on Personal Data Protection and the Guarantee of Digital Rights, only persons over 14 years of age may lawfully consent to the processing of their personal data by Velofutur. For a child under 14, parental or guardian consent is required, and processing will be lawful only to the extent authorized by them.

Confidentiality and Security of Personal Data

Velofutur undertakes to adopt the technical and organizational measures required to ensure a level of security appropriate to the risks associated with the data collected, safeguarding personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

The Website uses an SSL (Secure Socket Layer) certificate, ensuring that personal data transmitted between the server and the User is fully encrypted and handled securely and confidentially.

However, because Velofutur cannot guarantee that the internet is completely secure or entirely free from hackers or other fraudulent access, the Data Controller will notify the User without undue delay of any personal data breach likely to result in a high risk to individuals’ rights and freedoms. Under Article 4 GDPR, a personal data breach is a security breach leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed.

Personal data will be treated as confidential by the Data Controller, who will ensure through legal or contractual obligations that this confidentiality is respected by employees, associates, and any person given access to the information.

Rights Arising from Personal Data Processing

The User has, in relation to Velofutur and may therefore exercise before the Data Controller the following rights recognized by the GDPR and Spanish Organic Law 3/2018 of 5 December on Personal Data Protection and the Guarantee of Digital Rights:

  • Right of access: The User has the right to obtain confirmation as to whether Velofutur is processing their personal data and, if so, to obtain information about the specific personal data and the processing that Velofutur has carried out or is carrying out, including available information about the origin of the data and the recipients to whom it has been or is intended to be disclosed.
  • Right to rectification: The User has the right to have inaccurate personal data corrected or, taking account of the purposes of processing, incomplete data completed.
  • Right to erasure (“right to be forgotten”): Unless applicable law provides otherwise, the User has the right to obtain erasure of personal data where it is no longer necessary for the purposes for which it was collected or processed; the User has withdrawn consent and there is no other legal basis; the User objects and no overriding legitimate grounds exist; the data has been unlawfully processed; erasure is required by law; or the data was collected in connection with an offer of information society services directly to a child under 14. Where data is erased, the Data Controller will take reasonable measures, taking available technology and implementation costs into account, to inform other controllers processing the data that the data subject has requested erasure of links to that personal data.
  • Right to restriction of processing: The User has the right to restrict processing of personal data where the accuracy of the data is contested; processing is unlawful; the Data Controller no longer needs the data but the User requires it for legal claims; or the User has objected to processing.
  • Right to data portability: Where processing is automated, the User has the right to receive personal data from the Data Controller in a structured, commonly used, machine-readable format and to transmit it to another controller. Where technically feasible, the Data Controller will transmit the data directly to the other controller.
  • Right to object: The User has the right to object to or require the cessation of personal data processing by Velofutur.
  • Right not to be subject to a decision based solely on automated processing, including profiling: The User has the right not to be subject to an individualized decision based solely on automated processing of personal data, including profiling, unless applicable law provides otherwise.

The User may exercise these rights by sending a written communication to the Data Controller with the reference “GDPR-https://velofutur.es/”, specifying:

  • The User’s first and last name and a copy of their national identity document. Where representation is permitted, the representative must be identified in the same manner and evidence of authority must be provided. A copy of the identity document may be replaced by any other legally valid means of proving identity.
  • A request stating the specific reasons for the application or the information to be accessed.
  • Address for notification purposes.
  • Date and signature of the applicant.
  • Any document supporting the request.

This request and any supporting documents may be sent to the following postal and/or email address:

Postal address: C/ XOGO DA OLA, 5 PTL.2 F. 36400, PORRIÑO (O), PONTEVEDRA

Email address: velofutur@gmail.com

Links to Third-Party Websites

The Website may contain hyperlinks or links providing access to third-party websites other than those operated by Velofutur, and therefore are not operated by Velofutur. The owners of those websites maintain their own data protection policies and are responsible for their own records and privacy practices.

Complaints to the Supervisory Authority

If the User believes that personal data is being processed in breach of applicable law, they have the right to an effective judicial remedy and to lodge a complaint with a supervisory authority, particularly in the country of habitual residence, place of work, or the place of the alleged infringement. In Spain, the supervisory authority is the Spanish Data Protection Agency (https://www.aepd.es/).

II. ACCEPTANCE OF AND CHANGES TO THIS PRIVACY POLICY

The User must have read and accepted the personal data protection terms contained in this Privacy Policy and consented to the processing of personal data so that the Data Controller may process it in the manner, for the periods, and for the purposes stated. Use of the Website implies acceptance of its Privacy Policy.

Velofutur reserves the right to amend this Privacy Policy at its discretion or in response to legislative, judicial, or interpretative changes issued by the Spanish Data Protection Agency. Changes or updates will not be expressly notified to the User, who is advised to review this page periodically.

This Privacy Policy was updated to comply with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons regarding the processing of personal data and the free movement of such data (GDPR), and Spanish Organic Law 3/2018 of 5 December on Personal Data Protection and the Guarantee of Digital Rights.