Skip to content

Privacy Policy


PROCESSING OF CUSTOMER DATA

Informative clause:

Responsible: Canexel Construcciones SL
NIF: B81522062
Postal address: Calle Valle del Alberche 20E, 28440, Guadarrama (Madrid)
Telephone: 918513000
E-mail: informacion@canexel.es

In Canexel Construcciones SL we process the information you provide in order to provide the requested service. The data provided will be kept as long as the business relationship is maintained or for the years necessary to comply with legal obligations. The data will not be transferred to third parties except in cases where there is a legal obligation. You have the right to obtain confirmation as to whether we at Canexel Construcciones SL are processing your personal data, therefore you have the right to access your personal data, rectify inaccurate data or request its deletion when the data is no longer necessary.


CONTRACTS

1. Purpose of the processing order

By means of the present clauses, Francisco Javier Rubio Miguel, with address at Calle Real, 59, 28400 Collado Villalba, Madrid and NIF 51440514W is authorized as data processor to process on behalf of Canexel Construcciones SL, as data controller, the personal data necessary to provide the service specified hereinafter.
The processing will consist of Tax Advice

Identification of the affected information

For the execution of the services derived from the fulfillment of the object of this order, the entity Canexel Construcciones SL as responsible for the treatment, makes available to the entity Francisco Javier Rubio Miguel, the identification and bank data of its customers.

3. Duration

This agreement has an annual duration, being automatically renewed unless otherwise decided by either party.
Upon termination of this contract, the data processor must return to the controller or transfer to another processor designated by the controller the personal data, and delete any copies in its possession. However, it may keep the data blocked in order to meet possible administrative or jurisdictional responsibilities.

4. Obligations of the data processor

The data processor and all its personnel are obliged to:

– Use the personal data being processed, or those collected for inclusion, only for the purpose of this order. Under no circumstances may you use the data for your own purposes.

– To process the data in accordance with the instructions of the data controller.

– Keep, in writing, a record of all categories of processing activities carried out on behalf of the controller, containing:

  1. The name and contact details of the person or persons in charge and of each person responsible on behalf of whom the person in charge acts.
  2. The categories of processing carried out on behalf of each person in charge.
  3. An overview of the appropriate technical and organizational security measures you are implementing.

– Not to communicate the data to third parties, except with the express authorization of the data controller, in the legally admissible cases. If the person in charge wants to subcontract, he/she must inform the data controller and request his/her prior authorization.

– Maintain the duty of secrecy with respect to the personal data to which it has had access by virtue of this assignment, even after the end of the contract.

– Ensure that the persons authorized to process personal data undertake, expressly and in writing, to respect confidentiality and to comply with the corresponding security measures, of which they must be duly informed.

– Keep at the disposal of the person in charge the documentation accrediting compliance with the obligation established in the previous section.

– Ensure the necessary training in personal data protection for persons authorized to process personal data.

– When the affected persons exercise their rights of access, rectification, deletion and opposition, limitation of processing and data portability before the agency, the latter must communicate it by e-mail to the address indicated by the data controller. The communication must be made immediately and in no case later than the working day following receipt of the request, together, where appropriate, with other information that may be relevant to resolve the request.

– Notification of data security breaches

The processor shall notify the controller, without undue delay and via the e-mail address provided by the controller, of any breaches of security of the personal data under its responsibility of which it becomes aware, together with all relevant information for the documentation and communication of the incident.

At a minimum, the following information shall be provided:

  1. Description of the nature of the personal data security breach, including, where possible, the categories and approximate number of data subjects affected, and the categories and approximate number of personal data records affected.
  2. Contact person’s data for more information.
  3. Description of the possible consequences of the personal data breach. Description of the measures taken or proposed to be taken to remedy the personal data breach, including, if applicable, measures taken to mitigate the possible negative effects.

If and to the extent that it is not possible to provide the information simultaneously, the information shall be provided gradually without undue delay.

Francisco Javier Rubio Miguel, at the request of the data controller, will communicate such data security breaches to the data subjects as soon as possible, when the breach is likely to pose a high risk to the rights and freedoms of natural persons.

The communication must be made in clear and simple language and must include the elements indicated in each case by the person in charge, as a minimum:

  1. The nature of the data breach.
  2. Details of the point of contact of the person in charge or the person in charge where more information can be obtained.
  3. Describe the possible consequences of a breach of personal data security.
  4. Describe the measures taken or proposed by the controller to remedy the breach of security of personal data, including, if applicable, measures taken to mitigate potential adverse effects.

– Make available to the person in charge all information necessary to demonstrate compliance with its obligations, as well as for the performance of audits or inspections carried out by the person in charge or another auditor authorized by the person in charge.

– Implement the necessary technical and organizational security measures to guarantee the confidentiality, integrity, availability and permanent resilience of the processing systems and services.

– Destination of data

Return to the data controller the personal data and, if applicable, the media on which they are stored, once the service has been provided.

The return must entail the total deletion of the existing data on the computer equipment used by the person in charge.
However, the person in charge may keep a copy, with the data duly blocked, for as long as liabilities may arise from the performance of the service.

5. Obligations of the data controller

It is the responsibility of the data controller:

  1. To provide the person in charge with the necessary data to be able to provide the service.
  2. Ensure, prior to and throughout the processing, compliance with the GDPR by the processor.
  3. Supervise treatment.

DATA PROCESSING OF POTENTIAL CUSTOMERS

On behalf of the company we process the information you provide in order to send you advertising related to our products and services by any means (post, email or telephone) and to invite you to events organized by the company. The data provided will be kept as long as you do not request the cessation of the activity. The data will not be transferred to third parties except in cases where there is a legal obligation. You have the right to obtain confirmation as to whether Canexel Construcciones SL is processing your personal data, therefore you have the right to access your personal data, rectify inaccurate data or request its deletion when the data is no longer necessary for the purposes for which it was collected.


SERVICE COMPANIES

1. Purpose of the processing order

By means of the present clauses, ODOO,SA, as data processor, is authorized to process on behalf of Canexel Construcciones SL, as data controller, the personal data necessary to provide the service specified hereinafter.

Treatment will consist of Business Consulting and others.

Identification of the affected information

For the execution of the services derived from the fulfillment of the object of this order, the entity Canexel Construcciones SL as responsible for the treatment, makes available to the entity ODOO,SA the information available in the computer equipment that support the data processing carried out by the responsible.

3. Duration

This agreement has a duration of 3 years, renewable.

Upon termination of this contract, the data processor must return the personal data to the controller, and delete any copies held by the data controller. However, it may keep the data blocked in order to meet possible administrative or jurisdictional responsibilities.

4. Obligations of the data processor

The data processor and all its personnel are obliged to:

– Use the personal data to which you have access only for the purpose of this order. Under no circumstances may you use the data for your own purposes.

– To process the data in accordance with the instructions of the data controller.

If the processor considers that any of the instructions violate the GDPR or any other data protection provisions, the processor shall immediately inform the controller.

– Not to communicate the data to third parties, except with the express authorization of the data controller, in the legally admissible cases.

– Maintain the duty of secrecy with respect to the personal data to which it has had access by virtue of this assignment, even after the end of the contract.

– Ensure that the persons authorized to process personal data undertake, expressly and in writing, to respect confidentiality and to comply with the corresponding security measures, of which they must be duly informed.

– Keep at the disposal of the person in charge the documentation accrediting compliance with the obligation established in the previous section.

– Ensure the necessary training in personal data protection for persons authorized to process personal data.

– Notification of data security breaches

The processor shall notify the controller, without undue delay and via the e-mail address provided by the controller, of any breaches of security of the personal data under its responsibility of which it becomes aware, together with all relevant information for the documentation and communication of the incident.

At a minimum, the following information shall be provided:

  1. Description of the nature of the personal data security breach, including, where possible, the categories and approximate number of data subjects affected, and the categories and approximate number of personal data records affected.
  2. Contact person’s data for more information.
  3. Description of the possible consequences of the personal data breach. Description of the measures taken or proposed to be taken to remedy the personal data breach, including, if applicable, measures taken to mitigate the possible negative effects.

If and to the extent that it is not possible to provide the information simultaneously, the information shall be provided gradually without undue delay.

– Make available to the person in charge all information necessary to demonstrate compliance with its obligations, as well as for the performance of audits or inspections carried out by the person in charge or another auditor authorized by the person in charge.

– Assist the data controller to implement the necessary security measures to:

  1. a) To ensure the confidentiality, integrity, availability and resilience of processing systems and services at all times.
  2. b) Restore availability and access to personal data quickly in the event of a physical or technical incident.
  3. c) Verify, evaluate and assess, on a regular basis, the effectiveness of the technical and organizational measures implemented to ensure the security of the processing.

– Destination of data

The controller shall not retain personal data relating to the processing of the processor unless it is strictly necessary for the provision of the service, and only for the time strictly necessary for the provision of the service.

5. Obligations of the data controller

It is the responsibility of the data controller:

  • Provide the person in charge with access to the equipment in order to provide the contracted service.
  • Ensure, prior to and throughout the processing, compliance with the GDPR by the processor.
  • Supervise treatment.

1. Purpose of the processing order

By means of the present clauses, Google, as data processor, is authorized to process on behalf of Canexel Construcciones SL, as data controller, the personal data necessary to provide the service specified hereinafter.

You can download Google’s privacy policy from the following link.

Identification of the affected information

For the execution of the services derived from the fulfillment of the object of this order, the entity Canexel Construcciones SL as responsible for the treatment, makes available to the entity Google the information available in the computer equipment that support the data processing carried out by the responsible.

3. Duration

This agreement has a duration of one year, renewable.

Upon termination of this contract, the data processor must return the personal data to the controller, and delete any copies held by the data controller. However, it may keep the data blocked in order to meet possible administrative or jurisdictional responsibilities.

4. Obligations of the data processor

The data processor and all its personnel are obliged to:

– Use the personal data to which you have access only for the purpose of this order. Under no circumstances may you use the data for your own purposes.

– To process the data in accordance with the instructions of the data controller.

If the processor considers that any of the instructions violate the GDPR or any other data protection provisions, the processor shall immediately inform the controller.

– Not to communicate the data to third parties, except with the express authorization of the data controller, in the legally admissible cases.

– Maintain the duty of secrecy with respect to the personal data to which it has had access by virtue of this assignment, even after the end of the contract.

– Ensure that the persons authorized to process personal data undertake, expressly and in writing, to respect confidentiality and to comply with the corresponding security measures, of which they must be duly informed.

– Keep at the disposal of the person in charge the documentation accrediting compliance with the obligation established in the previous section.

– Ensure the necessary training in personal data protection for persons authorized to process personal data.

– Notification of data security breaches

The processor shall notify the controller, without undue delay and via the e-mail address provided by the controller, of any breaches of security of the personal data under its responsibility of which it becomes aware, together with all relevant information for the documentation and communication of the incident.

At a minimum, the following information shall be provided:

  1. Description of the nature of the personal data security breach, including, where possible, the categories and approximate number of data subjects affected, and the categories and approximate number of personal data records affected.
  2. Contact person’s data for more information.
  3. Description of the possible consequences of the personal data breach. Description of the measures taken or proposed to be taken to remedy the personal data breach, including, if applicable, measures taken to mitigate the possible negative effects.

If and to the extent that it is not possible to provide the information simultaneously, the information shall be provided gradually without undue delay.

– Make available to the person in charge all information necessary to demonstrate compliance with its obligations, as well as for the performance of audits or inspections carried out by the person in charge or another auditor authorized by the person in charge.

– Assist the data controller to implement the necessary security measures to:

  1. a) To ensure the confidentiality, integrity, availability and resilience of processing systems and services at all times.
  2. b) Restore availability and access to personal data quickly in the event of a physical or technical incident.
  3. c) Verify, evaluate and assess, on a regular basis, the effectiveness of the technical and organizational measures implemented to ensure the security of the processing.

– Destination of data

The controller shall not retain personal data relating to the processing of the processor unless it is strictly necessary for the provision of the service, and only for the time strictly necessary for the provision of the service.

5. Obligations of the data controller

It is the responsibility of the data controller:

  1. Provide the person in charge with access to the equipment in order to provide the contracted service.
  2. Ensure, prior to and throughout the processing, compliance with the GDPR by the processor.
  3. Supervise treatment.

TREATMENT ACTIVITY LOG

Processing: customers

Purpose of processing: customer relationship management.

Description of customer categories and categories of personal data: customers: persons with whom a business relationship is maintained as customers.

Categories of personal data: those necessary for the maintenance of the commercial relationship. Invoicing, sending postal or e-mail advertising, after-sales service and loyalty. Identification: name and surname, NIF, postal address, telephone numbers, e-mail. Personal characteristics: marital status, date and place of birth, age, sex, nationality Bank details: for direct debit of payments.

Categories of recipients to whom personal data were or will be communicated:

  • Tax Administration
  • Social Security
  • Banks and financial institutions
  • Gestoría

Where possible, the deadlines for the deletion of the different categories of data: those provided for by tax legislation regarding the statute of limitations for liabilities.

Processing: potential customers

Purpose of processing: management of the relationship with potential customers.

Description of the categories of potential customers and categories of personal data: potential customers: persons with whom we seek to maintain a business relationship as customers.

Categories of personal data: those necessary for the commercial promotion of the company. Identification: name and surname and postal address, telephone numbers, e-mail.

The categories of recipients to whom the personal data were or will be communicated:

  • Not contemplated

Where possible, the deadlines for the deletion of the different categories of data: one year from the first contact.

Passeig Francesc Macià, 75
08173 Sant Cugat del Vallés
Barcelona

Download Selenza brochure