Privacy Policy

1.1  Identity of the Data Controller  

The entity responsible for processing the collected personal data: MERCADO IT, SL.  

Tax ID: B-98339005    

Hereinafter,  Data Controller.  

Your contact information is as follows:  

Address: CALLE CIUDAD DE CARTAGENA, 19-23 – 46980 – PATERNA (VALENCIA).  

Contact phone number: 96.150.10.80  

 Contact email:  cllorens@gote.com  

1.2 Data Protection Officer (DPO)  

The Data Protection Officer (DPO) is responsible for ensuring compliance with the data protection regulations to which the company is subject. MERCADO IT, SL, in accordance with current regulations, is not required to have a DPO.  

1.3  Personal Data Registry   

The personal data collected by MERCADO IT, SL, through the forms provided on its web pages, will be entered into an automated database under the responsibility of the data controller, which has been duly declared and registered with the General Registry of the Data Protection Agency and can be consulted on the website of the Spanish Data Protection Agency ( http://.agpd.es ) in order to facilitate, expedite, and fulfill the commitments established between MERCADO IT, SL, and the user; to maintain the relationship established in the forms the user fills out; or to respond to a request or inquiry from the user.  

2.  CATEGORIES OF PERSONAL DATA

The categories of data processed by MERCADO IT, SL, consist solely of identifying data. It does not process special categories of personal data as defined in Article 9 of the GDPR.  

2.1 Principles Applicable to the Processing of Personal Data  

The processing of the user’s personal data will be subject to the following principles     set forth in Article 5 of the GDPR:  

  • Principle of Lawfulness, Fairness, and Transparency: The User’s consent shall be required at all times, following the provision of additional information and full transparency regarding the purposes for which personal data is collected.  
  •  Principle of Purpose Limitation: Personal data shall be collected for specified, explicit, and legitimate purposes.  
  • Data Minimization Principle: The personal data collected will be limited to what is strictly necessary for the purposes for which it is processed.  
  • Principle of Accuracy: Personal data must be accurate and kept up to date.  
  • Principle of Data Retention Limitation: Personal data will only be retained in a form that allows for the identification of the User for as long as necessary to fulfill the purposes of its processing.  
  • Principle of Integrity and Confidentiality: Personal data will be processed in a manner that ensures its security and confidentiality.  
  • Principle of Proactive Responsibility: The data controller is responsible for ensuring that the above principles are complied with.

2.2 Legal Basis for the Processing of Personal Data  

The legal basis for the processing of personal data is unequivocal and express consent, and the company undertakes to obtain such consent by verifying the user’s agreement to the processing of their personal data for one or more specific purposes.  

Users have the right to withdraw their consent at any time. Withdrawing consent is just as easy as giving it. As a general rule, withdrawing consent will not affect the use of the website.  

On occasions when the user must or may provide their data via forms to make inquiries, request information, or for reasons related to the website’s content, they will be informed if filling out any of these forms is mandatory because such information is essential for the proper execution of the requested operation.  

2.3 Retention Periods for Personal Data  

 Personal data will only be retained for the minimum time necessary for the purposes of its processing, or until the User requests its deletion.  

At the time the personal data is collected, the User will be informed of the period for which the personal data will be retained, or, when that is not possible, the criteria used to determine this period.  

2.4 Recipients of Personal Data  

In order to properly manage the services provided and the personal data of its users, MERCADO IT, SL will rely on third-party service providers who may have access to your personal data on behalf of MERCADO IT, SL as a result of their provision of services. MERCADO IT, SL undertakes to enter into the corresponding data processing agreement with them, through which it will impose, among others, the following obligations: to implement appropriate technical and organizational measures; to process personal data only for the agreed-upon purposes and strictly in accordance with the documented instructions of MERCADO IT, SL; and to delete or return the data to MERCADO IT, SL once the provision of services has ended.  

If the data controller intends to transfer personal data to a third country or international organization, at the time the personal data is collected, the user will be informed of the third country or international organization to which the data is intended to be transferred, as well as whether or not there is an adequacy decision by the Commission.  

2.5 Personal Data of Minors  

In accordance with the provisions of Article 8 of the GDPR and Article 13 of the RDLOPD, only individuals 14 years of age or older may lawfully give consent to the processing of their personal data. In the case of a child under 14 years of age, the consent of the parents or legal guardians is required for the processing, and such processing is considered lawful only to the extent that they have authorized it.  

2.6 Confidentiality and Security of Personal Data  

MERCADO IT, SL undertakes to adopt the necessary technical and organizational measures, in accordance with the level of security appropriate to the risk posed by the data collected, so as to ensure the security of personal data and prevent the accidental or unlawful destruction, loss, or alteration of all personal data transmitted, stored, or otherwise processed, as well as unauthorized disclosure of or access to such data.  

However, since MERCADO IT, SL cannot guarantee Internet security or the complete absence of hackers or others who fraudulently access personal data, the data controller undertakes to notify the User without undue delay whenever a personal data breach occurs that is likely to result in a high risk to the rights and freedoms of natural persons. In accordance with Article 4 of the GDPR, a personal data breach is defined as any breach of security leading to the accidental or unlawful destruction, loss, or alteration of personal data transmitted, stored, or otherwise processed, or to the unauthorized disclosure of or access to such data.  

Personal data will be treated as confidential by the Data Controller, who undertakes to inform and ensure, through a legal or contractual obligation, that such confidentiality is respected by its employees, associates, and any person to whom the information is made available.  

 

3.  RIGHTS ARISING FROM THE PROCESSING OF PERSONAL DATA  

The User may exercise the following rights recognized in the GDPR at any time with the Data Controller:  

  • Right of Access : This is the User’s right to obtain confirmation as to whether MERCADO IT, SL is processing their personal data or not and, if so, to obtain information about their specific personal data and the processing that MERCADO IT, SL has carried out or is carrying out, as well as, among other things, the available information regarding the origin of such data and the recipients of any communications made or planned regarding the data.  
  •   Right to Rectification : This is the User’s right to have their personal data corrected if it is found to be inaccurate, taking into account the purposes of the processing, or incomplete.  
  • Right to erasure  (“the right to be forgotten”): This is the User’s right—unless otherwise provided by applicable law—to have their personal data erased when such data is no longer necessary for the purposes for which it was collected or processed;    the User has withdrawn consent to the processing and there is no other legal basis for it; the User objects to the processing and there is no other legitimate reason to continue it; the personal data has been processed unlawfully; the personal data must be erased to comply with a legal obligation; or the personal data was obtained as a result of a direct offer of information society services to a child under 14 years of age. In addition to erasing the data, the Data Controller, taking into account available technology and the cost of implementation, must take reasonable measures to inform the controllers who are processing the personal data of the data subject’s request to remove any links to such personal data.  
  • Right to Restriction of Processing : This is the User’s right to restrict the processing of their personal data. The User has the right to obtain restriction of processing when they contest the accuracy of their personal data; the processing is unlawful; the Data Controller no longer needs the personal data, but the User needs it to assert legal claims; and when the User has objected to the processing.  
  • Right to Data Portability : If the processing is carried out by automated means, the User has the right to receive their personal data from the Data Controller in a structured, commonly used, and machine-readable format, and to transmit that data to another data controller. Whenever technically possible, the Data Controller will transmit the data directly to that other data controller.  
  • Right to object:  This is the user’s right to prevent the processing of their personal data or to have such processing by MERCADO IT, SL cease.  
  • Right not to be subject to a decision based solely on automated processing, including profiling:  This is the User’s right not to be subject to an individualized decision based solely on the automated processing of their personal data, including profiling, unless otherwise provided by applicable law.  

 Therefore, the user may exercise their rights by sending a written request to the data controller, MERCADO IT, SL, specifying:  

  • The user's first and last names and a copy of their national ID card. In cases where representation is permitted, the person representing the User must also provide identification using the same method, as well as a document proving the authority to act on the User’s behalf. A photocopy of the ID card may be replaced by any other legally valid means of proving identity.  
  • Request stating the specific reasons for the request or the information you wish to access.  
  • Address for service of process.  
  • Date and signature of the applicant.  
  • Any document supporting the request being made.  

This request and any other attached documents may be sent to the following address and/or email    address:  

Mailing Address: CALLE CIUDAD DE CARTAGENA, 19-23 – 46980 – PATERNA (VALENCIA).  

Email:  cllorens@gote.com  

3.1 Links to Third-Party Websites.  

This website may include hyperlinks or links that provide access to third-party websites other than MERCADO IT, SL, and are therefore not operated by MERCADO IT, SL. The owners of these websites have their own data protection policies and are, in each case, responsible for their own data files and privacy practices.  

3.2 Complaints to the supervisory authority.  

If the User believes there is a problem or a violation of applicable law regarding the way their personal data is being processed, they have the right to effective judicial protection and to file a complaint with a supervisory authority, specifically, in the country where they have their habitual residence, place of work, or where the alleged violation occurred. In the case of Spain, the supervisory authority is the Spanish Data Protection Agency (http://www.agpd.es).