Privacy Policy
Data controller
The controller of the personal data collected through this website is:
M. Rashed Reformas Integrales SL (Grupo M. Rashed), Tax ID (NIF) B75868414, with registered office at Avinguda Sants de la Pedra 43, Bajo, 46500 Sagunto (Valencia), Spain. Contact email: [email protected]. Telephone: +34 960 192 441.
The processing is carried out in accordance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
Data we process and its origin
Through the contact form we process the following data that the user voluntarily provides: name, telephone, email, postal code and the description of the project.
The origin of the data is always the data subject, who provides it by completing and submitting the form. No special categories of data are collected. The user warrants that the data provided is truthful and undertakes to communicate any change to it.
Purpose of the processing
The data is processed for the purpose of handling the enquiries and requests for information or quotations submitted through the form, contacting the user by the means provided and managing the relationship arising from that request.
No automated decisions are made and no profiling of any kind is carried out with the data provided. The data will not be used for purposes other than those described here without first obtaining the data subject's consent.
Legal basis
The legal basis legitimising the processing of the data is the data subject's consent, given freely, specifically, in an informed and unambiguous manner when completing and submitting the contact form after accepting this Privacy Policy (Art. 6(1)(a) GDPR).
Likewise, where the request concerns the engagement of services, the processing may be based on the implementation of pre-contractual measures taken at the data subject's request (Art. 6(1)(b) GDPR). The user may withdraw their consent at any time, without this affecting the lawfulness of the processing carried out prior to its withdrawal.
Retention period
Personal data will be kept for the time necessary to handle the user's request and, where applicable, for as long as the relationship arising from it is maintained.
Once the enquiry has been handled or the relationship has ended, the data will be duly blocked for the periods legally required to address potential liabilities, after which it will be securely deleted.
Recipients and data processors
The data will not be disclosed to third parties except where required by law. However, to manage the contact form we use the HighLevel (GoHighLevel) platform, which acts as a data processor and to which the data submitted through the form is sent and on which it is stored, and with which the corresponding data processing agreement has been signed in accordance with Article 28 of the GDPR.
The use of this provider may involve international transfers of data to countries located outside the European Economic Area (EEA). In such cases, these transfers are carried out with the appropriate safeguards provided for in the GDPR, such as the Standard Contractual Clauses approved by the European Commission or other legally admissible mechanisms.
Data subject rights
The user may exercise their rights of access, rectification, erasure, objection, restriction of processing and data portability, as well as withdraw the consent given, by sending a request to the email [email protected] or in writing to the controller's registered office, indicating the right they wish to exercise and enclosing a copy of a document proving their identity.
The data subject is also entitled to lodge a complaint with the competent supervisory authority, the Spanish Data Protection Agency (AEPD), through its electronic headquarters at www.aepd.es, particularly where they consider that they have not obtained satisfaction in the exercise of their rights.
Security measures
The controller has adopted the technical and organisational measures necessary to guarantee the security, confidentiality and integrity of personal data and to prevent its alteration, loss, or unauthorised processing or access, taking into account the state of the art, the nature of the data and the risks to which it is exposed.
The controller likewise requires data processors to apply equivalent security measures aligned with the data protection legislation in force.