privacy policy
For the purposes of the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, PERFUMS AYATS, S.L.U. (hereinafter, the Controller) with NIF B65590366 informs the User that their personal data will be processed with the purpose of providing the requested services and sending you information about our company that may be of interest to you.
Submission and registration of personal data:
The submission of personal data is mandatory to contact and receive information about the services provided by the Controller. Likewise, failure to provide the requested personal data or failure to accept this data protection policy means it will be impossible to subscribe, register, or receive information about these services.
When personal data are obtained from the data subject through electronic communications networks or within the framework of the provision of an information society service, as well as in those other cases expressly established by law or when authorized by the Spanish Data Protection Agency, the data controller may fulfill the duty of information established in Article 13 of Regulation (EU) 2016/679 by providing the data subject with at least the following basic information:
a) The identity of the data controller and their representative, if applicable.
b) The purpose of the processing.
c) The manner in which the data subject may exercise the rights established in Articles 15 to 22 of Regulation (EU) 2016/679.
However, data controllers and processors or, where applicable, their representatives must maintain the record of processing activities referred to in Article 30 of Regulation (EU) 2016/679, unless the enterprise or organization employs fewer than 250 persons, except where the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, is not occasional, or includes special categories of personal data as referred to in Article 9, paragraph 1, or personal data relating to criminal convictions and offenses referred to in Article 10 of Regulation (EU) 2016/679.
Finally, Article 5.1.f) of Regulation (EU) 2016/679 determines the need to establish adequate security guarantees against unauthorized or unlawful processing, against the loss of personal data, accidental destruction, or damage. This implies the establishment of technical and organizational measures aimed at ensuring the integrity and confidentiality of personal data and the ability (Article 5.2) to demonstrate that these measures have been put into practice (proactive responsibility).
Accuracy and truthfulness of the data provided:
The User who sends the information to the Controller is solely responsible for the truthfulness and correctness of the data included, exonerating the Controller from any liability in this regard.
Users guarantee and are responsible, in any case, for the accuracy, validity, and authenticity of the personal data provided, and undertake to keep them duly updated. The User agrees to provide complete and correct information in the registration or subscription form.
The Controller is not responsible for the truthfulness of information that is not of its own creation and for which another source is indicated, and therefore assumes no liability whatsoever for hypothetical damages that might arise from the use of this information. The Controller is exonerated from liability for any damage or harm that the User may suffer as a result of errors, defects, or omissions in the information provided by the Controller, provided that it comes from sources external to the Controller.
Transfer of data to third parties:
The Controller will not transfer personal data to third parties. However, in the event of being transferred to a third party, prior information would be provided requesting the express consent of the data subject pursuant to Article 4.11 of Regulation (EU) 2016/679.
Data retention:
In any case, the retention period will be the minimum indispensable, and at least the following must be maintained:
• 4 years: Act on Offenses and Sanctions in the Social Order (obligations regarding affiliation, registrations, deregistrations, contributions, payment of wages...); Arts. 66 et seq. General Tax Law (account books...)
• 5 years: Art. 1964 of the Civil Code (personal actions without a special term)
• 6 years: Art. 30 of the Commercial Code (account books, invoices...)
• 10 years: Art. 25 of the Prevention of Money Laundering and Terrorist Financing Act.
Exercise of rights of access, rectification, erasure, restriction, portability, and objection:
You may address your communications and exercise your rights of access, rectification, erasure, restriction, portability, and objection by post to the Controller at Carrer La Selva, Nau 15 Pol, Ind. Les Salines, 08880, Cubelles, Barcelona, or by email to: comercial@perfumsayats.com together with legally valid proof, such as a photocopy of your ID (D.N.I.), and indicating "DATA PROTECTION" in the subject line.
Acceptance and consent
The User declares to have been informed of the conditions regarding the protection of personal data, accepting and consenting to the processing thereof by the Controller, in the manner and for the purposes indicated in this Personal Data Protection Policy.
Changes to this privacy policy:
The Controller reserves the right to modify this policy to adapt it to new legislative or case-law developments, as well as to industry practices. In such cases, the Controller will announce on this page the changes introduced with reasonable notice before their implementation.