1. Personal Data, subjects of personal data and categories of personal data
1.1. What is personal data?
Personal data is all information of any nature, collected by any means, relating to a natural, identified or identifiable person. The set of information that can lead to the identification of a particular person is considered identifiable, namely by reference to an identifier (such as an identification number or location data).
1.2. From whom do we collect personal data?
In view of ARABESCO SIDERAL’s attributions, most of the data of legal persons (companies and associations) are processed. However, in order to carry out its duties, data from the following types of natural persons may be collected and processed (non-exhaustive list):
• Customers and their employees;
• Service providers and their employees;
• Visitors of ARABESCO SIDERAL’s website.
1.3. What personal data do we process and how do we collect it?
ARABESCO SIDERAL only collects data that are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
The collection of your data can be done orally, in writing (namely through forms and contracts), as well as through the website. As a general rule, we collect your data directly, and personal data may also be collected through public sources (such as internet sites and official public lists), as well as incentive management entities.
For different purposes, we may collect the following types of personal data:
• identification data (such as name, place of birth, citizen's card or date of birth);
• contact details (such as mobile phone, address or e-mail);
• banking, financial and transaction details (such as IBAN or tax identification number);
• location data (such as IP address).
As a rule, ARABESCO SIDERAL does not collect special data, such as health data or data referring to administrative offenses or criminal offenses.
2. Fundamentals and Purposes of the Processing of Personal Data
2. 1. Why and on what basis do we use your personal data?
All data collected and processed by ARABESCO SIDERAL are based on one of the following legal conditions.
• Consent : When the collection is preceded by your express, specific and informed consent, through written support or via the web.
• Execution of a contract or pre-contractual steps : when the processing is necessary for the performance of a contract to which you are a party or for pre-contractual steps.
• Compliance with legal obligations: when the processing is necessary for the fulfillment of a legal obligation. This includes, for example, the communication of data with public (national and community), fiscal or judicial bodies.
• Legitimate interest: when processing proves to be necessary for the pursuit of the legitimate interests of the entity responsible for the treatment or of third parties, without prejudice to the rights and freedoms of its customers and/or users.
3. Personal data retention period
ARABESCO SIDERAL processes and keeps your data only for the period that is necessary for the pursuit or completion of the purposes of the treatment for which they are intended, in respect of the maximum periods necessary to comply with contractual, legal or regulatory obligations.
As a general rule, and when there is a contract that legitimizes the processing of your data, ARABESCO SIDERAL will keep such data as long as such contractual relationship is maintained. Other circumstances exist, such as compliance with legal or regulatory obligations (for example, for the purpose of complying with tax obligations, personal data relating to invoicing must be kept for a maximum period of ten years from the date of the act), as well as the pending legal proceedings, which may legitimize your data to be kept for a longer period of time.
At the end of the storage period, ARABESCO SIDERAL will proceed with the deletion of said data.
4. Rights of data subjects
Under the terms of the legislation in force, from the moment we collect and process your data, there is a set of rights that, at any time, you can exercise with ARABESCO SIDERAL.
4.1. What are your rights?
Right of access: right that allows you to obtain information regarding the processing of your data and its characteristics (namely the type of data, the purpose of the treatment, to whom your data can be communicated, retention periods and which data you have to provide mandatory or optional).
Right of rectification: right that allows you to request the rectification of your data, demanding that they are accurate and current, for example, when you consider that they are incomplete or out of date.
Right to data erasure or “Right to be forgotten”: right that allows you to request the erasure of your data, when you consider that there are no valid grounds for the storage of data and provided that there is no other valid basis that legitimizes such treatment (such as the performance of a contract or the fulfillment of a legal or regulatory obligation).
Right to Limitation: right that allows you to suspend treatment or limit treatment to certain categories of data or purposes.
Right to Portability: right through which you can request the sending of your data, in digital format and in common use, which allows the reuse of such data. Alternatively, you may request the transmission of your data to another entity that becomes responsible for the processing of your data.
Right of Opposition: right that allows you to oppose certain purposes and provided that there are no legitimate interests that prevail over your interests. One of the examples of this right concerns opposition to direct marketing purposes.
Right to Withdraw Consent: right that allows you to withdraw your consent, but which can only be exercised when your consent is the only condition of legitimacy.
4.2. How can you exercise your rights?
All rights described above may be exercised, subject to limitations provided for by applicable law, upon written request, to be sent through the email email@example.com.
5. Data transmission
5.1. With whom do we share your personal data?
Given ARABESCO SIDERAL's attributions, and depending on the respective purpose, your data may be shared with third parties, which include national and international public bodies and private entities for the purpose of complying with legal or regulatory, contractual obligations.
Your data may also be accessed by ARABESCO SIDERAL service providers, considered necessary for the execution of the purposes described above, namely with regard to information security and archiving services. ARABESCO SIDERAL guarantees that it only uses service providers that present the guarantees of execution of necessary and adequate technical and organizational measures to protect your personal data.
5.2. Transfers of personal data outside the EEA
ARABESCO SIDERAL may, exceptionally, transfer your personal data to third countries (outside the EEA – European Economic Area).
In such cases, ARABESCO SIDERAL will ensure that data transfers are carried out in strict compliance with applicable legal regulations.
The processing of personal data of users and customers carried out by ARABESCO SIDERAL, as well as sending of commercial communications carried out by electronic means are in accordance with national and community legislation in force, namely the General Data Protection Regulation.
Last Updated: June 30, 2022