Privacy policy
Information in compliance with personal data protection regulations
In Europe and Spain, there are data protection regulations designed to protect your personal information, which our company is required to comply with.
Therefore, it is very important for us that you fully understand what we are going to do with the personal data we request from you.
We will therefore be transparent and give you control over your data, using clear language and straightforward options that will allow you to decide what we do with your personal information.
If, after reading this information, you have any questions, please do not hesitate to contact us.
Thank you very much for your cooperation.
Who are we?
- Our company name: Randal Europea, S.A.
- Our CIF / NIF: A98238967
- Our main activity: Design, manufacture and commercialisation of furniture.
- Our address: C/ Ciudad de Liria, 120, Postal Code 46988, Paterna (Valencia) and C/ Gremis, 12, Postal Code 46290, Alcácer (Valencia)
- Our contact telephone number: 961539000
- Our contact email address: natalia.gutierrez@randal.group
- Our website: www.randal.group
For your confidence and security, we inform you that we are a company registered in the following Commercial Registry / Public Registry: Valencia Commercial Registry, volume 9,593, book 6,875, folio 6, section 8, sheet V-152.694.
We remain at your disposal, please do not hesitate to contact us.
What will we use your data for?
In general, your personal data will be used to communicate with you and provide you with our services.
It may also be used for other activities, such as sending you advertising communications or promoting our activities.
Why do we need to use your data?
Your personal data is necessary in order for us to communicate with you and provide you with our services. In this regard, we will provide you with a series of checkboxes that will allow you to decide clearly and easily how your personal information is used.
Who will have access to the information we request from you?
In general, only duly authorised staff of our company will have access to the information we request from you.
Likewise, those entities that need access to your personal information in order for us to provide our services may also have access to it. For example, our bank will have access to your data if payment for our services is made by credit card or bank transfer.
Additionally, public or private entities to which we are legally required to provide your personal data may have access to your information. For example, tax legislation requires us to provide the Tax Agency with certain information regarding financial transactions exceeding a specific amount.
If, outside the situations mentioned above, we need to disclose your personal information to other entities, we will request your prior consent through clear options that will allow you to make a decision in this regard.
How will we protect your data?
We will protect your data using effective security measures according to the risks involved in the use of your information.
To this end, our company has approved a Data Protection Policy and carries out annual checks and audits to verify that your personal data remains secure at all times.
Will we transfer your data to other countries?
There are countries around the world that are safe for your data and others that are not as safe. For example, the European Union is a secure environment for your data. Our policy is not to transfer your personal information to any country that is not considered secure from a data protection perspective.
If, in order to provide you with the service, it becomes essential to transfer your data to a country that is not as secure as Spain, we will always request your prior consent and apply effective security measures to reduce the risks associated with transferring your personal information to another country.
How long will we keep your data?
We will keep your data throughout our relationship and for as long as required by law. Once the applicable legal periods have expired, we will securely delete your data in an environmentally responsible manner.
What are your data protection rights?
You may contact us at any time to find out what information we hold about you, correct it if it is inaccurate, and request its deletion once our relationship has ended, where legally possible.
You also have the right to request the transfer of your information to another organisation. This right is called “portability” and may be useful in certain situations.
To exercise any of these rights, you must submit a written request to our address, together with a photocopy of your ID document, so that we can identify you.
Our company offices provide specific forms to exercise these rights, and we offer our assistance in completing them.
To find out more about your data protection rights, you can consult the website of the Spanish Data Protection Agency (www.agpd.es).
Can you withdraw your consent if you change your mind at a later date?
You may withdraw your consent at any time if you change your mind regarding the use of your data.
For example, if you were previously interested in receiving advertising about our products or services but no longer wish to receive such communications, you can inform us using the objection to processing form available at our company offices.
Where can you file a complaint if you believe your rights have not been properly addressed?
If you believe that your rights have not been properly addressed by our company, you may file a complaint with the Spanish Data Protection Agency through any of the following means:
- Electronic office: www.agpd.es
- Postal address:
- Spanish Data Protection Agency
- C/ Jorge Juan, 6
- 28001 Madrid
- By telephone:
- Tel. 901 100 099
- Tel. 91 266 35 17
Filing a complaint with the Spanish Data Protection Agency is free of charge and does not require the assistance of a lawyer or legal representative.
Will we create profiles about you?
Our policy is not to create profiles about the users of our services.
However, there may be situations in which, for service provision, commercial or other purposes, we need to create information profiles about you. An example could be the use of your purchase or service history in order to offer you products or services adapted to your preferences or needs.
In such cases, we will apply effective security measures to protect your information at all times against unauthorised persons who may attempt to use it for their own benefit.
Will we use your data for other purposes?
Our policy is not to use your data for purposes other than those we have explained to you.
However, if we need to use your data for different activities, we will always request your prior consent through clear options that will allow you to make a decision in this regard.
COMMITMENT TO PERSONAL DATA PROTECTION
OUR COMMITMENT TO PERSONAL DATA PROTECTION: “INFORMED PEOPLE AND PROTECTED DATA”
The Management of Randal Europea, S.A. (hereinafter, the data controller) assumes the highest level of responsibility and commitment regarding the establishment, implementation and maintenance of this Data Protection Policy, ensuring the continuous improvement of the data controller with the aim of achieving excellence in compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, concerning the protection of natural persons with regard to the processing of personal data and the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119/1, 04-05-2016), as well as Spanish regulations concerning personal data protection (Organic Law, specific sector regulations and their implementing provisions).
The Data Protection Policy of Randal Europea, S.A. is based on the principle of proactive responsibility, according to which the data controller is responsible for complying with the regulatory and legal framework governing this Policy and is able to demonstrate such compliance before the competent supervisory authorities.
In this regard, the data controller shall be governed by the following principles, which must serve as a guide and reference framework for all its staff when processing personal data:
- Data protection by design: the data controller shall apply, both when determining the means of processing and during the processing itself, appropriate technical and organisational measures, such as pseudonymisation, designed to effectively implement data protection principles, such as data minimisation, and integrate the necessary safeguards into the processing.
- Data protection by default: the data controller shall apply appropriate technical and organisational measures to ensure that, by default, only the personal data necessary for each specific purpose of the processing is processed.
- Data protection throughout the information lifecycle: measures guaranteeing the protection of personal data shall apply throughout the entire lifecycle of the information.
- Lawfulness, fairness and transparency: personal data shall be processed lawfully, fairly and transparently in relation to the data subject.
- Purpose limitation: personal data shall be collected for specified, explicit and legitimate purposes and shall not be further processed in a manner incompatible with those purposes.
- Data minimisation: personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.
- Accuracy: personal data shall be accurate and, where necessary, kept up to date; every reasonable measure shall be taken to ensure that inaccurate personal data, in relation to the purposes for which it is processed, is erased or rectified without delay.
- Storage limitation: personal data shall be kept in a form that allows the identification of data subjects for no longer than necessary for the purposes of processing the personal data.
- Integrity and confidentiality: personal data shall be processed in such a way as to ensure appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, through the application of appropriate technical or organisational measures.
- Information and training: one of the key factors in guaranteeing the protection of personal data is the training and information provided to staff involved in its processing. Throughout the information lifecycle, all staff with access to data shall receive appropriate training and information regarding their obligations in relation to compliance with data protection regulations.
The Data Protection Policy of Randal Europea, S.A. is communicated to all staff of the data controller and made available to all interested parties.
Consequently, this Data Protection Policy involves all staff of the data controller, who must be aware of it and assume it as their own, with each member being responsible for applying it, verifying the data protection rules applicable to their activity, and identifying and contributing any improvement opportunities they consider appropriate with the aim of achieving excellence in compliance.
This Policy shall be reviewed by the Management of Randal Europea, S.A. as often as deemed necessary, in order to ensure its continuous adaptation to current regulations regarding personal data protection.