1.- PURPOSE OF THE PRIVACY POLICY
The purpose of this “Privacy and Data Protection Policy” is to explain the conditions governing the collection and processing of personal data by DUNE CERÁMICA S.L., which makes every effort to safeguard the fundamental rights, dignity and freedoms of the individuals whose personal data are processed, in compliance with the applicable rules and legislation governing the protection of personal data in the European Union and Spain and, in particular, those referred to in the “Data Processing Activities” section of this Privacy Policy.
Accordingly, this Privacy and Data Protection Policy provides users of the Website http://www.duneceramics.com with all relevant information regarding how these processes are carried out, the purposes for which personal data are processed, which other entities may have access to their data and what rights users have in relation to such processing.
2.- DEFINITIONS
“Personal data”: Any information relating to an identified or identifiable natural person (“the Website user”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“Processing”: Any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making data available, alignment or combination, restriction, erasure or destruction.
“Restriction of processing”: The marking of stored personal data with the aim of limiting their processing in the future.
“Profiling”: Any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
“Pseudonymisation”: The processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures designed to ensure that the personal data are not attributed to an identified or identifiable natural person.
"Filing system”: Any structured set of personal data which is accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis.
“Controller” or “Data Controller”: The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data. Where the purposes and means of such processing are determined by European Union or Member State law, the controller or the specific criteria for its nomination may be provided for by European Union or Member State law.
“Processor” or “Data Processor”: A natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
“Recipient”: A natural or legal person, public authority, agency or another body to which personal data are disclosed, whether or not a third party. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with European Union or Member State law shall not be regarded as recipients. The processing of such data by those public authorities shall comply with the applicable data protection rules according to the purposes of the processing.
“Third party”: A natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons authorised to process personal data under the direct authority of the controller or processor.
“Consent of the data subject”: Any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they, through a statement or a clear affirmative action, signify agreement to the processing of personal data relating to them.
“Personal data breach”: A breach of security leading to the accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed, or to the unauthorised disclosure of or access to such data.
“Genetic data”: Personal data relating to the inherited or acquired genetic characteristics of a natural person which provide unique information about the physiology or health of that natural person and which result, in particular, from an analysis of a biological sample from that natural person.
“Biometric data”: Personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person which allow or confirm the unique identification of that natural person, such as facial images or fingerprint data.
“Data concerning health”: Personal data relating to the physical or mental health of a natural person, including the provision of healthcare services, which reveal information about their health status.
“Main establishment”:
a) As regards a controller with establishments in more than one Member State, the place of its central administration in the European Union, unless decisions concerning the purposes and means of processing personal data are taken in another establishment of the controller in the European Union and that other establishment has the power to have such decisions implemented, in which case the establishment that took such decisions shall be considered the main establishment;
b) As regards a processor with establishments in more than one Member State, the place of its central administration in the European Union or, if the processor has no central administration in the European Union, the establishment of the processor in the European Union where the main processing activities in the context of the activities of an establishment of the processor take place, to the extent that the processor is subject to specific obligations under the GDPR.
“Representative”: A natural or legal person established in the European Union who, designated by the controller or processor in writing pursuant to Article 27 of the GDPR, represents the controller or processor with regard to their respective obligations under the GDPR.
“Enterprise”: A natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity.
“Supervisory authority”: An independent public authority established by a Member State pursuant to Article 51 of the GDPR. In Spain, this is the Spanish Data Protection Agency (Agencia Española de Protección de Datos).
“Cross-border processing”:
a) Processing of personal data which takes place in the context of the activities of establishments in more than one Member State of a controller or processor in the European Union where the controller or processor is established in more than one Member State; or
b) Processing of personal data which takes place in the context of the activities of a single establishment of a controller or processor in the European Union but which substantially affects or is likely to substantially affect data subjects in more than one Member State.
“Information society service”: Any information society service, namely any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient of services.
3.- IDENTITY OF THE DATA CONTROLLER
The Data Controller is the natural or legal person, whether public or private, or administrative body which, alone or jointly with others, determines the purposes and means of the processing of personal data, unless such purposes and means are determined by European Union or Spanish Member State law.
For the purposes set out in this Privacy and Data Protection Policy, the identity and contact details of the Data Controllers are:
• Dune Cerámica S.L (B12333324)
• Estudio Cerámico S.L (B12049466)
• Vilarroig Gestión S.L (B12467270)
Registered address: Partida Rachina S/N. 12130, Sant Juan de Moró (Castellón), Spain
Each of the above entities acts as a Joint Controller of the processing.
4.- APPLICABLE LAWS AND REGULATIONS
This Privacy and Data Protection Policy has been drawn up on the basis of the following data protection laws and regulations:
• Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. Hereinafter, the GDPR.
• Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights. Hereinafter, LOPD/GDD.
• Spanish Law 34/2002 of 11 July on Information Society Services and Electronic Commerce. Hereinafter, LSSICE.
5.- PRINCIPLES APPLICABLE TO THE PROCESSING OF PERSONAL DATA
Personal data collected and processed through this Website shall be processed in accordance with the following principles:
• Principle of lawfulness, fairness and transparency: All processing of personal data carried out through this Website shall be lawful and fair, and it shall be entirely clear to the user when personal data concerning them are being collected, used, consulted or otherwise processed. Information concerning the processing activities carried out shall be provided in advance, in an easily accessible and understandable form, using clear and plain language.
• Purpose limitation principle: All data shall be collected for specified, explicit and legitimate purposes and shall not subsequently be processed in a manner incompatible with the purposes for which they were collected.
• Data minimisation principle: The data collected shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
• Accuracy principle: Personal data shall be accurate and, where necessary, kept up to date. All reasonable measures shall be taken to ensure that personal data that are inaccurate with regard to the purposes for which they are processed are erased or rectified without delay.
• Storage limitation principle: Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
• Integrity and confidentiality principle: Personal data shall be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, through the implementation of appropriate technical and organisational measures.
• Accountability principle: The entity that owns the Website shall be responsible for compliance with the principles set out in this section and shall be able to demonstrate such compliance.
6.- DATA PROCESSING ACTIVITIES
The data processing activities carried out through the Website are detailed below, specifying each of the following elements:
• Activity: Name of the data processing activity.
• Purposes: Each of the uses and processing operations carried out with the data collected.
• Legal basis: The legal basis that legitimises the processing of the data.
• Data processed: Types of data processed.
• Source: Where the data are obtained from.
• Retention: Period for which the data are retained.
• Recipients: Third parties or entities to whom the data are disclosed.
• International transfers: Cross-border transfers of data outside the European Union.
6.1 MAIN PROCESSING ACTIVITIES
These are data processing activities whose purposes are necessary and essential for the provision of the services.
6.2 OPTIONAL PROCESSING ACTIVITIES (if the user has indicated their consent)
These are personal data processing activities whose purposes are not essential for the provision of the service and which are carried out only if the user has selected YES when providing consent for such activities.
Website enquiries
Legal basis – Explicit consent of the data subject.
Purposes – Responding to enquiries received through the Website’s electronic form.
Categories of data and data subjects – Website contacts (identification data).
Source of data – The data subject or their legal representative.
Categories of recipients – None envisaged.
International transfers – None envisaged.
Retention period – For a period of 1 year from the last confirmation of interest.
WhatsApp communications from the Website
Legal basis – (Art. 6(1)(a) GDPR) Consent of the data subject; (Art. 6(1)(b) GDPR) Existence of a contractual relationship with the data subject through a contract or pre-contractual measures; (Art. 6(1)(f) GDPR) Legitimate interests pursued by the Data Controller or third parties.
Purposes – Handling enquiries, requests for information and commercial communications via WhatsApp Web.
Categories of data and data subjects – Website contacts (identification data).
Source of data – The data subject or their legal representative.
Categories of recipients – Telecommunications service providers; entities that own instant messaging applications.
International transfers – None envisaged.
Retention period – For as long as no objection to the processing is expressed and/or legal liabilities may arise.
Security measures
• Restricted access to communications for authorised personnel only.
• Systems protected by secure authentication.
• Control of devices with access to WhatsApp.
• Confidentiality obligations for personnel.
• Secure management of conversations and shared documentation.
Job applications
Legal basis – Explicit consent of the data subject.
Purposes – Recruitment and personnel selection.
Categories of data and data subjects – Job applicants (identification data; academic and professional data; personal characteristics; social circumstances; employment details).
Source of data – The data subject or their legal representative.
Categories of recipients – None envisaged.
International transfers – None envisaged.
Retention period – For a period of 1 year from the last confirmation of interest.
User management
Legal basis – Explicit consent of the data subject.
Purposes – E-commerce.
Categories of data and data subjects – Registered users (identification data).
Source of data – The data subject or their legal representative.
Categories of recipients – None envisaged.
International transfers – None envisaged.
Retention period – For a period of 5 years from the last confirmation of interest.
Subscriber management
Legal basis – Explicit consent of the data subject.
Purposes – Marketing, advertising and commercial prospecting.
Categories of data and data subjects – Subscribers (identification data).
Source of data – The data subject or their legal representative.
Categories of recipients – None envisaged.
International transfers – None envisaged.
Retention period – Until the data subject requests the erasure of their data.
Use of cookies and tracking technologies on the Website
Legal basis – (Art. 6(1)(a) GDPR) Consent of the data subject.
Purposes – Analysing user browsing behaviour, measuring Website audiences and providing personalised content or advertising based on users’ browsing habits.
Categories of data and data subjects – Website users (technical data, browsing data and online identifiers).
Source of data – The data subject or their legal representative.
Categories of recipients – Organisations or individuals directly related to the Data Controller; analytics and advertising service providers.
International transfers – None envisaged.
Retention period – According to the lifespan of the cookies (see Cookie Policy).
Security measures
• Automatic blocking of non-essential cookies until consent has been obtained (with the banner configured accordingly).
• Configuration of the cookie management tool to allow users to accept or reject categories of cookies.
• Access controls for the Website administration panel and analytics data (authorised users only).
• Annual review and update of the Cookie Policy and consent banner.
• Recording of the processing activity in the Record of Processing Activities (ROPA).
• Limited retention of data in accordance with the lifespan of the cookies.
• Monitoring of external service providers.
7.- NECESSARY AND UP-TO-DATE INFORMATION
All fields marked with an asterisk (*) in the Website forms are mandatory. Failure to complete any of these fields may result in the requested services or information being unavailable.
You must provide accurate and truthful information. To ensure that the information provided remains up to date and free from errors, you must inform the Data Controller as soon as possible of any changes or corrections to your personal data by sending an email to: rrhh@estudioceramico.es.
Likewise, by clicking the “I Accept” button (or equivalent) included in the aforementioned forms, you declare that the information and data provided therein are accurate and truthful and that you understand and accept this Privacy Policy.
8.- DATA RELATING TO MINORS
In accordance with Article 8 of the GDPR and Article 7 of the LOPD/GDD, only persons over 14 years of age may lawfully provide their consent to the processing of their personal data by ESTUDIO CERÁMICO S.L.
Accordingly, children under 14 years of age may not use the services available through the Website without the prior authorisation of their parents, guardians or legal representatives, who shall be solely responsible for all actions carried out through the Website by minors under their responsibility, including the completion of online forms using the personal data of such minors and, where applicable, the selection of the corresponding checkboxes.
9.- TECHNICAL AND ORGANISATIONAL SECURITY MEASURES
The Data Controller adopts the organisational and technical measures necessary to guarantee the security and privacy of personal data and to prevent their alteration, loss, unauthorised processing or access, taking into account the state of the art, the nature of the data stored and the risks to which they are exposed.
These measures include, among others:
• Ensuring the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
• Restoring the availability of and access to personal data promptly in the event of a physical or technical incident.
• Regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures implemented to ensure the security of processing.
• Pseudonymising and encrypting personal data where sensitive data are involved.
Furthermore, the Data Controller has decided to manage its information systems in accordance with the following principles:
• Regulatory compliance principle: All information systems shall comply with applicable legal, regulatory and sector-specific requirements affecting information security, particularly those relating to the protection of personal data, system security, data, communications and electronic services.
• Risk management principle: Risks shall be reduced to acceptable levels, seeking an appropriate balance between security controls and the nature of the information. Security objectives shall be established and reviewed and shall be consistent with information security requirements.
• Awareness and training principle: Training programmes, awareness initiatives and awareness-raising campaigns shall be implemented for all users with access to information in relation to information security.
• Proportionality principle: Controls aimed at mitigating security risks affecting assets shall be implemented while seeking an appropriate balance between security measures, the nature of the information and the level of risk.
• Responsibility principle: All members of the Data Controller’s organisation shall be responsible for their conduct in relation to information security and shall comply with the established rules and controls.
• Continuous improvement principle: The effectiveness of the security controls implemented within the organisation shall be reviewed on a recurring basis in order to improve the organisation’s ability to adapt to the constant evolution of risks and the technological environment.
10.- RIGHTS OF DATA SUBJECTS
Applicable data protection legislation grants users a number of rights in relation to the use of their personal data. Each of these rights is personal and non-transferable and may therefore only be exercised by the data subject after their identity has been verified.
The rights of Website users are detailed below:
• Right of access: The Website user has the right to obtain confirmation as to whether or not the Data Controller is processing their personal data and, where that is the case, to obtain information about the specific personal data concerned and the processing that the Data Controller has carried out or is carrying out, including, among other information, the available information concerning the source of such data and the recipients of any disclosures made or envisaged.
• Right to rectification: The Website user has the right to have inaccurate personal data corrected or, taking into account the purposes of the processing, incomplete personal data completed.
• Right to erasure: Commonly known as the “right to be forgotten”, this is the Website user’s right, unless otherwise provided by applicable law, to obtain the erasure of their personal data where the data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; the user has withdrawn their consent and there is no other legal ground for the processing; the user objects to the processing and there are no overriding legitimate grounds for continuing the processing; the personal data have been unlawfully processed; or the personal data were collected in relation to the direct offering of information society services to a child under 14 years of age. In addition to erasing the data, the Data Controller, taking into account the available technology and the cost of implementation, shall take reasonable steps to inform other controllers processing the personal data that the data subject has requested the erasure of any links to such personal data.
• Right to restriction of processing: The Website user has the right to restrict the processing of their personal data. The Website user has the right to obtain restriction of processing where they contest the accuracy of their personal data; the processing is unlawful; the Data Controller no longer needs the personal data, but the user requires them for the establishment, exercise or defence of legal claims; or the Website user has objected to the processing.
• Right to data portability: Where processing is carried out by automated means, the Website user has the right to receive from the Data Controller the personal data concerning them in a structured, commonly used and machine-readable format and to transmit those data to another controller. Where technically feasible, the Data Controller shall transmit the data directly to that other controller.
• Right to object: The user has the right to object to the processing of their personal data or to request that the Data Controller cease processing such data.
• Right not to be subject to automated decision-making and/or profiling: The Website user has the right not to be subject to an individual decision based solely on automated processing of their personal data, including profiling, unless otherwise provided by applicable law.
• Right to withdraw consent: The Website user has the right to withdraw, at any time, the consent previously given for the processing of their personal data.
The Website user may exercise any of the aforementioned rights by contacting the Data Controller, subject to verification of the user’s identity, using the following contact details:
• Controller: DUNE CERÁMICA S.L
• Address: Partida Rachina S/N. 12130, San Juan de Moró (Castellón), Spain
• Telephone: 964 328 187
• Email: rrhh@estudioceramico.es
• Website: http://www.duneceramics.com
11.- RIGHT TO LODGE A COMPLAINT WITH THE SUPERVISORY AUTHORITY
The user is informed of their right to lodge a complaint with the Spanish Data Protection Agency if they consider that data protection legislation has been infringed in connection with the processing of their personal data.
Contact details of the supervisory authority:
Spanish Data Protection Agency
(Agencia Española de Protección de Datos)
Email: info@aepd.es
Telephone: 900293183
Website: https://www.aepd.es
Address: C/. Jorge Juan, 6. 28001, Madrid (Madrid), Spain
12.- ACCEPTANCE OF AND CHANGES TO THE PRIVACY POLICY
The Website user must have read and agreed to the data protection conditions contained in this Privacy Policy and must consent to the processing of their personal data so that the Data Controller may process them in accordance with the manner, retention periods and purposes specified herein.
The Data Controller reserves the right to amend this Privacy Policy at its own discretion or as a result of legislative or regulatory changes, case law or guidance issued by the Spanish Data Protection Agency. Any changes or updates to this Privacy Policy affecting the purposes of processing, retention periods, disclosure of data to third parties, international data transfers or any rights of the Website user shall be expressly communicated to the user.
Version dated 20 July 2026