Privacy policy
PAYPER S.A. wishes to draw the attention of users of the website to its policy on the processing and protection of personal data concerning users and customers.
The company guarantees at all times full and complete compliance with the obligations laid down by the regulations on data protection and information society services: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the GDPR), Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), and Law 34/2002 of 11 July on Information Society Services and Electronic Commerce (LSSIce).
DATA CONTROLLER
PAYPER S.A.
Company Tax Code (CIF): A25011180
Address: POL. IND. VINYES DEL MIG, PAR. 12-14 – 25220 – BELL-LLOC D’URGELL (LLEIDA)
Listed in the LLEIDA Company Register: Sheet: L-3242 IRUS: 1000082361966 Entry: 54 E-commerce folio.
Phone: 973216040
E-mail: rgpd@payper.com
TYPES OF DATA PROCESSING, PURPOSES, LEGITIMATION AND RETENTION PERIOD
The personal data provided by the User are processed by PAYPER, S.A. for the purposes and on the legal bases indicated below:
CUSTOMERS
- Purpose of processing: To manage and execute the contractual relationship with the customer, including the provision of the contracted services or products, the fulfilment of accounting, fiscal and administrative obligations, as well as responding to queries and improving the commercial relationship.
- Legitimation of the processing: Execution of a contract and fulfilment of legal obligations. In certain cases, consent of the data subject.
- Data processed: Name and surname, ID or tax number, telephone number, postal and e-mail address, handwritten or electronic signature, image or voice, bank details, goods and services contracted, financial transactions, compensation and indemnities, IP address and other data necessary for the business relationship.
- Retention period: During the term of the contractual relationship and subsequently during the applicable statutory requirement periods.
CONTACTS / USERS
- Purpose of processing: To attend to and manage requests for information, queries or contacts made by interested parties, as well as the sending of commercial information or quotations as requested.
- Legitimation of the processing: Consent of the data subject or implementation of pre-contractual measures at the request of the data subject.
- Data processed: Name and surname, ID or tax number, telephone number, postal or e-mail address, image or voice, signature (handwritten or electronic), details of professional or business activity, newsletter subscriptions and e-mail.
- Retention period: For as long as necessary to fulfil the request and, where appropriate, for the duration of the potential business relationship.
COMMERCIAL / MARKETING COMMUNICATIONS
- Purpose of processing: Manage the sending of commercial, informative or promotional communications related to products or services similar to those contracted by the customer, as well as participation in satisfaction surveys or corporate events.
- Legitimation of the processing: Legitimate interest of the data controller (Article 21.2 LSSICE) with respect to existing customers or consent of the data subject in cases where there is no prior contractual relationship.
- Data processed: Name and surname, e-mail address, telephone number, postal address, history of business relationship, preferences or interests expressed and professional contact details.
- Retention period: Until the data subject objects to the processing or revokes the consent given.
SUPPLIERS
- Purpose of processing: Manage and execute the contractual relationship with suppliers, including compliance with accounting, tax and administrative obligations.
- Legitimation of the processing: Execution of a contract and fulfilment of legal obligations.
- Data processed: Name and surname, ID or tax number, telephone number, postal and e-mail address, signature (manual or electronic), bank details, goods supplied, economic operations and IP address.
- Retention period: During the term of the contractual relationship and subsequently during the applicable statutory requirement periods.
ADMINISTRATIVE AND ACCOUNTING MANAGEMENT
- Purpose of processing: Management of the administrative, accounting and tax obligations arising from contractual relations with customers, suppliers and employees, including the issuing of invoices, the making and collection of payments, and compliance with tax obligations.
- Legitimation of the processing: Compliance with legal obligations established in tax, commercial and accounting legislation (General Tax Law, Commercial Code, Social Security regulations).
- Data processed: Identification and contact data, bank, economic and financial data, transactions carried out, invoicing and supporting documentation.
- Retention period: During the legal periods of retention and of liability (a minimum 6 years according to the Commercial Code and up to 10 years in tax matters or prevention of money laundering).
HUMAN RESOURCE MANAGEMENT
- Purpose of processing: Management of the employment relationship with employees, including administrative, tax and risk prevention matters, and compliance with employment obligations.
- Legitimation of the processing: Execution of the employment contract, fulfilment of legal obligations and, in certain cases, the legitimate interest of the data controller.
- Data processed: Name and surname, ID or tax number, telephone number, postal and e-mail address, Social Security number, signature, image or voice, marital status, date and place of birth, nationality, education, employment history, bank details, salary, deductions, insurance, pension plans and corporate e-mail.
- Retention period: During the employment relationship and thereafter for the legal retention periods (minimum 10 years).
PERSONNEL SELECTION
- Purpose of processing: Management of the personnel selection processes, evaluate the applications received and keep the CVs for future selection processes in accordance with the profile of the interested party.
- Legitimation of the processing: Consent of the interested party when sending their CV or participating in selection processes.
- Data processed: Name, surname, telephone number, e-mail address, curriculum vitae, cover letter and any other information included in the professional profile.
- Retention period: Maximum of 2 years from receipt of the curriculum vitae, unless deletion is requested earlier.
VIDEO SURVEILLANCE
- Purpose of processing: To ensure the security of persons, property and facilities by means of access control and video surveillance.
- Legitimation of the processing: The legitimate interest of the data controller in protecting its premises, property and personnel.
- Data processed: Image, voice, name and surname, identification number and access codes to the facilities.
- Retention period: Video surveillance images: maximum 30 days, except as required by the authorities.
MANAGEMENT OF VISITS TO FACILITIES
- Purpose of processing: To monitor and record visits to PAYPER, S.A. facilities, ensuring the security of people, goods and information, and allowing the traceability of accesses.
- Legitimation of the processing: Legitimate interest of the controller in ensuring the security of its premises and compliance with internal access protocols.
- Data processed: Name and surname, identification document (ID card or similar), company of origin, person visited, date and time of entry and exit, and signature.
- Retention period: For a maximum of 30 days, unless it is retained at the request of the authorities or for security reasons.
WEB MAINTENANCE
- Purpose of processing: To monitor and ensure the technical maintenance, security and operational functioning of the website, as well as the detection and resolution of incidents.
- Legitimation of the processing: Legitimate interest of the controller in ensuring the security and continuity of the service.
- Data processed: Technical data (IP address, session identifiers, activity logs or system logs).
- Retention period: For as long as necessary to ensure the security of the website and during the applicable statutory requirement periods.
RECIPIENTS OF THE DATA
Please note that PAYPER S.A. will not communicate personal data to third parties, except in the following cases:
- Legal obligation: when necessary to comply with applicable regulations or requirements of competent authorities (e.g. Public Administrations, Judges and Courts).
- Contractual execution: when necessary for the development, fulfilment, execution and control of the contractual relationship between the Data Controller and the data subject (e.g. financial institutions for the management of collections and payments).
- Consent of the data subject: when the data subject has expressly authorised it.
- Data processors: PAYPER S.A. may allow access to personal data by suppliers that provide services necessary for the operation of the company (e.g. IT services, web maintenance, consultancy, courier and transport services). Such access does not constitute a transfer of data, but rather processing on behalf of the Data Controller, governed by contract in accordance with Article 28 of the GDPR, ensuring at all times the confidentiality, integrity and security of the information.
Likewise, PAYPER S.A. ensures that all third parties accessing the personal data comply with current data protection regulations and apply the appropriate technical and organisational measures to guarantee the security of the processing.
INTERNATIONAL DATA TRANSFERS
PAYPER S.A. may make international transfers of personal data to service providers located outside the European Economic Area (EEA), provided that such transfers are necessary for the performance of its business (for example, web hosting services, e-mail, communications management or computer support).
In such cases, PAYPER S.A. will ensure that the data is transferred to countries that offer an adequate level of protection as recognised by the European Commission or, failing that, that the Standard Contractual Clauses approved by the European Commission or other adequate protection mechanisms established in articles 46 and 49 of Regulation (EU) 2016/679 (GDPR) are applied.
COOKIES
For detailed information on the use of cookies and similar storage or tracking technologies, please refer to the Cookie Policy on this website.
The legal basis for the processing of personal data derived from the use of non-technical cookies is the consent given by the user by accepting their installation through the banner or the settings panel.
Users may modify or withdraw their consent at any time by accessing the cookie settings panel or through their browser settings.
AUTOMATED DECISIONS AND PROFILING
PAYPER S.A. does not make automated decisions, nor does it create profiles that produce legal effects or that significantly affect the data subject.
USER RIGHTS
The user has the right to:
- Request access to their personal data being processed and to receive such information in writing by the means requested.
- Request the rectification of inaccurate personal data or, where appropriate, request its deletion when, inter alia, the data is no longer necessary for the purpose for which it was collected.
- Request the restriction of the processing of their data.
- Object to the processing of their personal data where appropriate, in which case their data will no longer be processed except for legitimate reasons.
- The right to portability of personal data where the processing is based on consent and carried out by automated means. The data will be provided in a structured, commonly used and machine-readable form.
- Right to withdraw consent.
- Right to complain to the Spanish Data Protection Agency.
The User may exercise the said rights by writing to the postal or e-mail address of the Data Controller, proving their identity with a scanned copy of their ID card or equivalent document, and specifying the right they wish to exercise.
ORIGIN OF THE DATA
Personal data shall be provided by the data subject on an absolutely voluntary basis. Failure to provide certain data or questions that may be asked in the registration processes or in the various electronic forms presented to the User may result it being impossible to access certain services which require personal data, in which case the Data Controller will inform the data subject of the obligatory and/or necessary nature of the provision of personal data in order for the service to function.
The Data Controller assures you of the confidentiality of your personal data and guarantees its security, adopting the necessary measures to avoid any alteration, loss, unauthorised processing or access.
INFORMATION PROVIDED BY THE USER
Children under the age of 18 may not disclose their personal data without the prior consent of their parent and/or legal guardian.
By entering their data in the contact forms or as submitted in download forms, Users expressly, freely and unequivocally accept that their data are necessary for the Data Controller to process their request. The inclusion of data in the remaining fields is voluntary.
The User guarantees that the personal data provided are truthful and is responsible for communicating any changes to the data.
All data requested through the website are necessary for the provision of an optimal service to the User. In the event that not all the data is provided, there is no guarantee that the information and services provided by the Data Controller will be completely tailored to the User’s needs.
SECURITY MEASURES
In accordance with the provisions of the applicable regulations on the protection of personal data, the Data Controller is compliant with all the provisions of the RGPD and LOPDGDD regulations for the processing of personal data under its responsibility, which are processed lawfully, fairly and transparently in relation to the data subject and are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
The Data Controller guarantees that it has implemented appropriate technical and organisational policies to apply the security measures established by the RGPD and the LOPDGDD to protect the rights and freedoms of Users, and has provided them with the appropriate information in order for them to be exercised.
SECURITY BREACHES
The Data Controller will report any security breach affecting the database used by this website, or affecting any of our third party services, to any and all persons whose data may have been affected and to the authorities, within 72 hours of detection of the breach.
APPLICABLE LAW AND JURISDICTION
It reserves the right to bring any civil or criminal action that may be deemed necessary in cases of improper use of the Website and its Contents.
The relationship between the User and the Data Controller shall be governed by legislation in force and applicable in Spanish territory. In the event of any dispute arising in relation to interpretation and/or application, the parties shall submit their claims to the ordinary jurisdiction of the relevant courts and tribunals.