PERSONAL DATA PROTECTION POLICY
SOTOCONSTRUCCIONES 5 PROYECTOS S.L. (the “Company”) is an Organization where personal data processing activities take place, which attributes to it an important responsibility in the design and organization of procedures so that they are aligned with legal compliance in this matter. In the exercise of these responsibilities and with the aim of establishing the general principles that must govern the processing of personal data in the company, approve this Personal Data Protection Policy, which notifies the its employees and makes available to all Interest groups.
1. Purpose
The Personal Data Protection Policy is a measure of proactive responsibility that aims to ensure compliance with the applicable legislation in this matter and in relation to it, respect for the right to honor and privacy in the treatment of the personal data of all the people who relate to the company. In development of the provisions of this Personal Data Protection Policy, it is established which are the Principles that govern the processing of data in the organization and consequently, the procedures, and the organizational and security measures that the affected persons for this Policy they undertake to implement in their area of responsibility. To this end, the Management will assign responsibilities to the personnel involved in data processing operations.
2. Scope of application
Aquesta Política de protecció de dades de caràcter personal és aplicable a l’Empresa, als seus administradors, directius i empleats, així com a totes les persones que s’hi relacionin, amb inclusió expressa dels proveïdors de servei amb accés a dades (“ Encarregats del tractament”)
3. Principis del tractament de les dades de caràcter personal
As a general principle, the Company shall scrupulously comply with the legislation on the protection of personal data and must be able to demonstrate this (Principle of “proactive responsibility”), paying special attention to those treatments that may pose a greater risk to the rights of those affected (Principle of “risk approach”). In relation to the above, SOTOCONSTRUCCIONES 5 PROYECTOS S.L. shall ensure compliance with the following Principles:
- Legality, loyalty, transparency and limitation of purpose. Data processing must always be informed to the affected person through clauses and other procedures; and it will only be considered legitimate if there is consent for the processing of data (with special attention to that given by minors), or it has another valid legitimation and the purpose is in accordance with the Regulations.
- Data minimization. The processed data must be adequate, relevant and limited to what is necessary in relation to the purposes of the treatment.
- Accuracy. The data must be accurate and, if necessary, updated. In this sense, the necessary measures will be taken to delete or rectify without delay the personal data that are inaccurate with respect to the purposes of the treatment.
- Limitation of the conservation period. The data will be kept in such a way as to allow the identification of the interested parties for no longer than is necessary for the purposes of the treatment.
- Integrity and Confidentiality. The data will be processed in such a way as to ensure adequate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, through the application of technical or organizational measures appropriate
- Data transfers. It is prohibited to purchase or obtain personal data from illegitimate sources or in those cases where these data have been collected or transferred in violation of the law or their legitimate origin is not sufficiently guaranteed.
- Hiring suppliers with access to data. Only suppliers who offer sufficient guarantees to apply appropriate technical and security measures in data processing will be chosen for contracting. With these third parties the due Agreement on this will be documented.
- International data transfers. Any processing of personal data subject to European Union regulations that involves a transfer of data outside the European Economic Area must be carried out in strict compliance with the requirements established in the applicable law.
- Rights of those affected. The Company will make it easier for those affected to exercise their rights of access, rectification, deletion, limitation of processing, opposition and portability, establishing for this purpose the internal procedures, and in particular the models for their exercise that are necessary and appropriate, which must satisfy, at least, the legal requirements applicable to each case.
The company will promote that the principles contained in this personal data protection policy are taken into account (i) in the design and implementation of all work procedures, (ii) in the products and services offered (iii) in all the contracts and obligations that they formalize or assume and (iv) in the implementation of all systems and platforms that allow access by employees or third parties and/or the collection or processing of personal data.
4. Commitment of workers
The workers are informed of this Policy and declare that they are aware that personal information is an asset of the Company, and in this sense they adhere to it, committing to the following:
- Carry out the Data Protection awareness training that the Company makes available to you.
- Apply the security measures at the user level that apply to the workplace, without prejudice to the design and implementation responsibilities that may be attributed to him based on his role within SOTOCONSTRUCCIONES 5 PROYECTOS S.L..
- Use the established formats for the exercise of rights by those affected and inform the Company immediately so that the response can be effective.
- Inform the Company, as soon as it becomes aware of it, of deviations from what is established in this Policy, in particular “Breaches of security of personal data”, using the format established for this purpose.
5. Control and evaluation
An annual verification, evaluation and assessment will be carried out, or whenever there are significant changes in data processing, of the effectiveness of the technical and organizational measures to guarantee the security of the treatment.
SOTOCONSTRUCCIONES 5 PROYECTOS S.L.