PRIVACY POLICY
1. Introduction
This Privacy Policy has been developed in accordance with Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), as well as Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons regarding the processing of personal data and the free movement of such data (GDPR).
The purpose of this Privacy Policy is to inform data subjects whose personal data is collected about the processing of their data, the purposes of processing, contact details to exercise their rights, data retention periods, and security measures applied.
2. Data Controller
For data protection purposes, Antonia Maria Rigo Gual is considered the Data Controller in relation to the processing operations identified in this policy.
Below are the identifying details of the website owner:
- Data Controller: Antonia Maria Rigo Gual
- Postal Address: Carrer de ses Sitges 6, 07630 ILLES BALEARS, Campos, Spain
- Email: hola@guaal.com
- Website: https://guaal.com
3. Data Processing
The personal data collected will be strictly necessary to identify and manage the request made by the data subject (user).
Personal data will be collected for specific, explicit, and legitimate purposes, and will not be processed in a manner incompatible with those purposes.
The collected data will be adequate, relevant, and not excessive concerning the purpose for which they are collected, and they will be updated when necessary.
Before collecting personal data, the data subject will be informed of the general terms of this policy to provide explicit, precise, and unequivocal consent for data processing.
4. Purposes of Processing
The specific purposes for which data is collected are detailed in the informational clauses included in each data collection method (web forms, paper forms, notices, etc.).
However, in general, personal data will be processed solely for the purpose of providing an effective response to requests made by users through the website’s contact forms or other communication channels.
5. Legal Basis for Processing
The processing of personal data is based on:
- The explicit and unequivocal consent of the data subject, obtained through consent clauses included in the information collection forms.
- Compliance with a legal obligation or specific regulatory requirement that allows processing without the need for the data subject’s consent.
6. Data Recipients
As a general rule, personal data will not be disclosed or shared with third parties, except when legally required.
If the transfer of data to third parties is necessary, it will be previously communicated to the data subject through consent clauses in the relevant data collection forms.
7. Data Source
In most cases, personal data is collected directly from the data subject.
However, in certain exceptions, data may be obtained through third parties, entities, or services different from the data subject. In such cases, this will be communicated to the data subject within a reasonable period, and at the latest, within one month.
8. Data Retention Periods
Personal data will be retained as long as they are necessary to fulfill the purpose for which they were collected.
Once the purpose has been fulfilled, the data will be blocked and only available to comply with legal obligations, address potential liabilities, and respond to requests from competent authorities.
Once the legally established retention period expires, the data will be permanently deleted.
The following table shows the legal data retention periods applicable to various cases:
| Document | Retention Period | Legal Reference |
|---|---|---|
| Accounting and tax documentation (commercial) | 6 years | Art. 30 Commercial Code |
| Accounting and tax documentation (tax purposes) | 4 years | Articles 66-70 General Tax Law |
| Job applications (CVs) | Until the end of the initial selection process. Maximum of 2 years if stored in a job pool. | – |
For more details on browsing data collected through the website, please refer to the Cookie Policy.
9. Data Subject Rights
Under data protection regulations, users have the following rights:
- Right of access: To know what personal data is being processed.
- Right of rectification: To correct inaccurate or incomplete personal data.
- Right to erasure (“right to be forgotten”): To request the deletion of data in specific circumstances.
- Right to object: To object to the processing of their data, except for compelling legitimate reasons.
- Right to restriction of processing: To request the limitation of data processing in certain cases.
- Right to data portability: To receive personal data in a structured, commonly used format for transmission to another data controller.
- Right to file a complaint with the Spanish Data Protection Agency (AEPD) if they believe their rights have been violated.
To exercise their rights, users can contact us at:
📧 Email: hola@guaal.com
📍 Postal Address: Carrer de ses Sitges 6, 07630 ILLES BALEARS, Campos, Spain
Requests will be responded to as soon as possible, following the timelines established by the applicable regulations.
10. Security Measures
In accordance with Article 32 of the GDPR, the Data Controller has adopted appropriate technical and organizational measures to ensure the security of personal data.
These measures include:
- Confidentiality, integrity, and availability of the processed data.
- Rapid restoration of personal data in case of a technical or physical incident.
- Periodic evaluation of security measures to ensure their effectiveness.
- Pseudonymization and encryption of data, where applicable.