Privacy Policy

1. Introduction

CYP BRANDS EVOLUTION, S.L. is committed to protecting the privacy and rights of its users and customers, and to complying with current data protection regulations, including the Organic Law on Data Protection and Guarantee of Digital Rights (LOPDGDD) and the National Security Scheme (ENS).

2. Data Controller

The data controller at CYP BRANDS EVOLUTION, S.L. is a key figure in compliance with data protection and privacy regulations. In our case, the data controller is [name of controller], who acts on behalf of the company and is responsible for ensuring that personal data is processed appropriately and in compliance with the law.

The data controller’s responsibilities include:

Implementing policies and procedures:

  • The data controller is responsible for developing, implementing, and maintaining internal policies and procedures to ensure compliance with data protection and privacy regulations.
  • Monitoring compliance: It is the controller’s responsibility to monitor compliance with established policies and procedures, as well as with legal data protection obligations by the company and its employees.
  • Responding to inquiries and complaints: The data controller is the point of contact for users and supervisory authorities regarding inquiries, complaints, and claims related to data protection and privacy.
  • Ensure data security: It is the data controller’s responsibility to ensure the security, confidentiality, and integrity of the personal data processed by the company, implementing appropriate technical and organizational measures to protect them against unauthorized access, disclosure, and alteration.
  • Facilitate the exercise of user rights: The data controller must facilitate the exercise of users’ rights regarding their personal data, such as the right to access, rectification, erasure, and portability, as well as the right to object and withdraw consent.

It is important to emphasize that the data controller acts as the internal and external point of reference for all matters related to data protection and privacy. At CYP BRANDS EVOLUTION, S.L., we are committed to designating a qualified and competent person as the data controller and providing them with the necessary resources and support to perform their duties effectively.

3. Data Collected and Purposes of Processing

At CYP BRANDS EVOLUTION, S.L., we collect a variety of personal data from our users and customers for various purposes, all in compliance with data protection and privacy regulations. Below, we detail the types of data we collect and the purposes for which it is processed:

  • Identification Data: We collect data such as first names, last names, date of birth, identification numbers (DNI, NIF, etc.), and other similar data that allow us to uniquely identify our users and customers. This data is collected for registration purposes, creating user accounts, and personalizing the user experience on our website.
  • Contact Data: We collect contact data such as email addresses, phone numbers, postal addresses, and other similar data that allow us to communicate with our users and customers. This data is used to send communications related to contracted services, important notifications, and to respond to user inquiries and requests.
  • Payment and Billing Data: If users make financial transactions on our website, we collect payment data such as credit card numbers, banking information, and billing details. This data is used to process payments, issue invoices, and manage the contractual relationship with our customers.
  • Usage and Navigation Data: We collect data about user activity on our website, such as pages visited, actions performed, browsing preferences, and other similar data. This data is collected to improve the user experience, personalize the content and services offered, and conduct statistical analysis and market research.
  • Sensitive Data: In exceptional cases and when strictly necessary, we may collect sensitive data such as health information, religious beliefs, union membership, and other sensitive data in compliance with applicable regulations and with the user’s explicit consent. This data is treated with special care and is only used for the specific purposes for which it is collected.

It is important to emphasize that we collect and process this data only with the user’s explicit consent or when necessary to comply with our legal obligations or for the company’s legitimate interests. Furthermore, we guarantee the confidentiality, integrity, and security of personal data at all times, and we adopt appropriate technical and organizational measures to protect it against unauthorized access, disclosure, and alteration.

4. Data Protection Principles

The principle of accountability, or proactive responsibility, is a fundamental concept in data protection that is emphasized in the Organic Law on Data Protection and Guarantee of Digital Rights (LOPDGDD). This principle establishes that those responsible for the processing of personal data must be able to demonstrate compliance with data protection regulations by implementing appropriate and effective measures.

The principle of accountability establishes that the data controller (whether a natural or legal person, public entity, or agency) is responsible for complying with the obligations established in the LOPDGDD and other data protection regulations.

The data controller must adopt appropriate organizational and technical measures to ensure and demonstrate that the processing of personal data is carried out in compliance with the law.

  • Implementation of Data Protection Measures:

The data controller must implement appropriate measures to ensure the protection of personal data and the rights of data subjects.

This includes adopting internal policies and procedures, appointing a Data Protection Officer (DPO) in certain cases, conducting privacy impact assessments, and implementing appropriate technical and organizational security measures.

The principle of accountability requires the data controller to maintain a record of all personal data processing activities carried out under its responsibility.

This record, known as the Processing Activities Register, must contain detailed information on the processing operations carried out, including the purposes of the processing, the categories of personal data processed, the categories of data recipients, international data transfers, and retention periods, among other aspects.

  • Demonstration of Compliance:

The data controller must be able to demonstrate compliance with data protection regulations to data protection supervisory authorities and data subjects.

This involves having documentation and evidence supporting compliance with legal obligations, such as internal policies and procedures, privacy impact assessments, data processing agreements with third parties, and records of processing activities.

In addition to data controllers, data processors are also subject to the principle of accountability.

Data processors must ensure that the processing activities they carry out on behalf of the data controller are carried out in compliance with the law and that they can demonstrate such compliance.

In short, the principle of accountability establishes the obligation of data controllers and processors to implement appropriate measures to protect the privacy of personal data and demonstrate their compliance with data protection regulations through documentation and transparency in their processing operations.

We further commit to complying with the following principles in all our data processing activities:

  • Transparency: We will inform users about how their personal data is collected, used, protected, and shared.
  • Legality: We will only process personal data legally and ethically, complying with all applicable laws and regulations.
  • Purpose Limitation: We will use personal data only for the specific purposes for which it was collected, and will not process it in a manner incompatible with these purposes.
  • Data Minimization: We will collect and store only the minimum amount of personal data necessary to fulfill our business purposes.
  • Accuracy: We will keep personal data accurate and up-to-date, taking reasonable steps to correct or delete any inaccurate information.
  • Security: We will implement appropriate technical and organizational measures to protect personal data against unauthorized access, disclosure, and alteration.
  • Data Subject Rights: We will respect and facilitate the exercise of data subject rights, including the right to access, rectification, erasure, and data portability.

5. Legal Basis of Treatment

The processing of personal data at CYP BRANDS EVOLUTION, S.L. is carried out on the basis of one or more of the following legal bases, in compliance with data protection and privacy regulations:

  • User consent: When necessary, we obtain the user’s explicit consent to process their personal data for specific purposes. This consent is requested in a clear and transparent manner, and the user has the right to withdraw it at any time.
  • Performance of a contract: In some cases, data processing is necessary for the performance of a contract with the user, such as the provision of services or the delivery of products requested by the user. Data processing in this context is necessary to fulfill our contractual obligations.
  • Compliance with legal obligations: In certain circumstances, we are required by law to process personal data, such as to comply with tax, accounting, or regulatory obligations. In these cases, data processing is necessary to comply with our legal obligations.
  • Legitimate business interest: In some cases, data processing may be necessary for the legitimate interests of the business, provided that these interests do not override the fundamental rights and freedoms of the user. Before processing based on this legal basis, we conduct an impact assessment on the user’s rights and freedoms.

It is important to note that we choose the legal basis for data processing carefully and based on the specific purpose for which the data is collected. Furthermore, we ensure that data processing is carried out transparently and in accordance with the data protection principles established by applicable regulations. 5. Security measures.

6. Recommendations for implementing Organizational Measures in the company:

  • Development of Policies and Procedures: We will develop and document clear and transparent internal policies and procedures for the processing of personal data within our company. These policies will include security measures, incident management procedures, data retention policies, and other aspects related to privacy protection.
  • Staff Training: We will provide regular training on data protection and information security to all company employees. This training will include topics such as the importance of privacy, best practices for handling personal data, and how to identify and respond to security incidents.
  • Assignment of Responsibilities: We will clearly clarify and assign responsibilities related to data protection within the organization. This will include designating specific people responsible for managing security incidents, monitoring regulatory compliance, and coordinating training and awareness activities.
  • Privacy Impact Assessment (PIDA): We will conduct privacy impact assessments before undertaking any project or activity that poses a high risk to the rights and freedoms of individuals. These assessments will help us identify and mitigate potential privacy risks from the outset.
  • Supplier and Contractor Management: We will establish processes to assess and monitor our suppliers and contractors regarding the processing of personal data on our behalf. We will ensure that all third parties comply with the same data protection standards as we do.

Support Management Protocol:

This protocol establishes the guidelines and procedures that CYP BRANDS EVOLUTION, S.L. must follow for the proper management of media containing personal data, in order to guarantee the security and confidentiality of the information, in compliance with the LOPDGDD and other applicable regulations.

Media Classification

Media containing personal data will be classified according to their level of sensitivity and privacy risk, dividing them into the following categories:

  • Physical Media: Printed documents, paper files, physical storage devices (USB drives, external hard drives, etc.).
  • Digital Media: Electronic files, databases, information systems, digital storage devices (servers, computers, laptops, etc.).

Storage and Custody

  • Physical Media: Printed documents and other physical media containing personal data will be stored in secure locations and accessible only to authorized personnel. Physical access control measures, such as locks and security systems, will be implemented.
  • Digital Media: Electronic files and other digital media containing personal data will be stored on computer systems protected by passwords and additional security measures, such as data encryption and firewalls. Access to these systems will be restricted to authorized personnel with unique access credentials.

Access and Control

Specific managers will be designated to manage access to media containing personal data and to control their use and manipulation.

Policies and procedures for access management will be established, which will include the assignment of role-based access permissions and regular review of access privileges.

All activities related to access and use of media containing personal data, including queries, modifications, and deletions, will be logged and audited.

Secure Transfer and Deletion

Security measures will be implemented to ensure the secure transfer of media containing personal data, both in physical and digital formats.

When physical or digital media containing personal data are no longer needed or relevant, they will be securely disposed of in accordance with established policies and procedures. This may include the physical destruction of documents or the secure deletion of electronic files.

Staff Training and Awareness

All CYP BRANDS EVOLUTION, S.L. staff will receive training and awareness-raising on the media management protocol and its importance in protecting personal data.

Specific training will be provided on how to properly handle media containing personal data, including identifying security risks and implementing appropriate security measures.

Review and Update of the Protocol

This protocol will be reviewed periodically to ensure its effectiveness and continued compliance with legal requirements and best practices in data protection. Updates will be made as necessary to reflect changes in legislation, technology, or CYP BRANDS EVOLUTION, S.L.’s internal procedures.

  • Internal Audits and Compliance Reviews: We will conduct periodic internal audits and compliance reviews to ensure that our data protection policies and procedures are being properly followed throughout the organization.
  • Processing Activity Log: We will maintain an up-to-date log of all personal data processing activities carried out by the company, as required by the LOPDGDD (Spanish Data Protection Act). This log will help us demonstrate our compliance with data protection regulations in the event of an audit or investigation.

These organizational measures will help ensure that the company complies with the provisions of the LOPDGDD (Spanish Data Protection Act) and adequately protects the personal data of its customers, employees, and other stakeholders. It is important to adapt these measures to the company’s specific needs and circumstances, as well as to stay up-to-date on changes in legislation and best practices in data protection.

  • If necessary or required by law: We will appoint a Data Protection Officer (DPO) responsible for overseeing compliance with the LOPDGDD and other data protection regulations, as well as serving as a point of contact for queries related to privacy and information security.

7. Recommendation of security measures to be implemented in the company

We implement appropriate technical measures to protect personal data against loss, unauthorized access, disclosure, and alteration. These measures include:

  • Data Encryption: We use encryption techniques to protect the confidentiality of data during storage and transmission, ensuring that only authorized individuals can access it.
  • Access Controls: We limit access to personal data to only those employees and contractors who need to access it to fulfill their job responsibilities. In addition, we use strong authentication systems to verify user identity and control access.
  • Activity Tracking and Logging: We implement activity tracking and logging systems to record and monitor access to personal data, detect suspicious activity, and respond to security incidents in a timely manner.
  • Staff Training: We provide regular information security and data protection training to all our staff to raise awareness of security best practices and reduce the risk of incidents caused by human error.
  • Periodic Risk Assessments: We conduct periodic information security risk assessments to identify potential vulnerabilities and threats, and take proactive measures to mitigate identified risks.
  • Malware and Virus Protection: We implement IT security solutions, such as firewalls, antivirus, and antispyware, to protect our systems against malware and cyber threats.
  • Data Backup and Recovery: We perform regular backups of personal data and maintain disaster recovery procedures to ensure data availability and integrity in the event of system failures or security incidents.

These additional measures will help strengthen the security of your personal data and more effectively protect it against security threats and risks. Remember that the implementation of security measures should be tailored to your organization’s specific needs and circumstances.

7.1. Security Measures for Company Software

  • Restricted Access: We will implement an access control system that limits access to the software to authorized users only. This will include assigning specific roles and permissions to each user, ensuring they only have access to the functions and data necessary to perform their job duties.

  • Multi-Factor Authentication: We will use multi-factor authentication to strengthen the security of user accounts. This will require users to provide more than one form of authentication (e.g., password and verification code sent to their mobile phone) to access the software.

  • Data Encryption: We will implement end-to-end encryption to protect the confidentiality of data while it is transmitted over networks and while it is stored in the software. This will ensure that even if the data is intercepted, it cannot be read without the corresponding encryption key.

  • Access Audits: We will conduct periodic access audits to monitor and record user activities within the software. This will allow us to detect and respond to any suspicious or unauthorized activity and maintain detailed records of who accesses what data and when.

  • Updates and Patches: We will keep the software up-to-date with the latest versions and security patches. This will allow us to address any known vulnerabilities and ensure the software is protected against the latest security threats.

  • Regular Data Backup: We will perform regular backups of the data stored in the software to protect it against loss, theft, or corruption. These backups will be stored in secure locations and regularly tested to ensure their integrity and availability.

  • Staff Training: We will provide regular training on information security and best practices for using the software to all staff. This will include raising awareness about the importance of protecting sensitive data and identifying potential security threats and risks.

These software security measures will help protect personal data and ensure compliance with the LOPDGDD (Spanish Data Protection Act). It’s important to tailor these measures to your company’s specific needs and circumstances, as well as seek specialized legal and technical advice to ensure effective data protection.

7.2. Security Measures for the Company's Hardware

  • Physical Access Control: We will implement physical access control measures to ensure that only authorized personnel can access the premises where hardware devices that process personal data are located. This may include the use of locks, key cards, and biometric access control systems.
  • Device Security: All hardware devices used for the processing of personal data will be physically protected against unauthorized access. This may include the use of security cables, safes, or locked cabinets to protect servers, computers, and other critical devices.
  • Firmware Updates and Patches: We will keep the firmware on all hardware devices up to date to address potential security vulnerabilities and ensure they are protected against the latest threats. A patch management process will be implemented to ensure all critical updates are applied in a timely manner.
  • Protection Against Theft and Loss: All hardware devices containing personal data will be protected against theft and loss. This may include the installation of security systems such as alarms, surveillance cameras, and GPS tracking systems on mobile devices.
  • Secure Disposal: When hardware devices reach the end of their useful life, ensure that the data stored on them is securely deleted before disposal. Best practices for secure data erasure, such as secure formatting or physical destruction of the devices, will be followed.
  • Monitoring and Logging: A monitoring and logging system will be implemented to oversee access to and use of hardware devices that process personal data. This will help detect any suspicious or unauthorized activity and maintain an audit trail for compliance purposes.
  • Staff Training: All staff will receive regular training on information security and best practices in the use and maintenance of hardware devices. This will include awareness of the importance of protecting sensitive data and the identification of potential security threats and risks.

7.3. Password Policy

  • Introduction: At CYP BRANDS EVOLUTION, S.L., we recognize the importance of protecting the security of our systems and data through strong passwords and password management practices. This policy establishes the requirements and best practices for creating, using, and managing passwords within our company.
  • Password Creation: Passwords must be at least 12 characters long.

They must include a combination of uppercase and lowercase letters, numbers, and special characters.

Common passwords, such as “123456” or “password,” are not allowed.

It is recommended to use phrases or acronyms that are easy to remember but difficult to guess.

Passwords must be unique and should not be used across multiple accounts.

  • Password Change: Users will be required to change their passwords every 90 days. It is recommended that passwords be changed immediately if there is any suspicion of a security compromise or unauthorized access.

 

  • Password Storage and Management: Passwords must be stored securely using strong encryption methods. Sharing passwords with others, whether via email, text messages, or other insecure means of communication, will not be permitted. Writing passwords in visible or accessible locations, such as post-it notes on the desktop, is prohibited.

 

  • Password Access by Authorized Personnel: Only authorized personnel will have access to passwords, and this access will be limited to those necessary for legitimate work purposes. Access to passwords will be logged and regularly audited to ensure traceability and accountability.

 

  • Use of Password Managers: The use of secure and reliable password management tools is recommended to centrally store and manage passwords. These tools must be protected with a strong master password and use strong encryption methods to protect data.

 

  • Awareness and Training: Regular training on good practices in password use and management will be provided to all staff. Staff will be made aware of the importance of protecting password security and will be taught how to create and manage strong passwords.

 

  • Enforcement and Sanctions: Failure to comply with this policy may result in disciplinary action, which may include suspension of access to systems or data, or termination of employment.

Periodic audits will be conducted to ensure compliance with the password policy, and corrective action will be taken if necessary.

7.4. Protocol for the Backup Procedure

  • Objective: The objective of this protocol is to establish the guidelines and procedures for performing data backups at CYP BRANDS EVOLUTION, S.L., in order to guarantee the availability, integrity, and confidentiality of the information, as well as to comply with the requirements established in the LOPDGDD (Spanish Data Protection Act).
  • Responsibilities: The Data Controller will be responsible for overseeing the implementation and compliance with this protocol.
IT Team: Will be responsible for configuring, scheduling, and maintaining backups.
  • Backup Frequency: Regular backups will be performed according to the following schedule:
    • Daily backups of critical data.
    • Weekly backups of non-critical data.
    • Monthly backups of all data.
  • Backup Methods: An automated backup method will be used to ensure backup consistency and reliability. Incremental backup technology will be used to minimize the time and resources required to perform daily backups.
  • Backup Storage: Backups will be stored in a secure, off-site location to protect them from physical damage, theft, or loss. Encrypted cloud storage will be used to store backups, with access restricted to authorized personnel.
  • Recovery Testing: Regular data recovery testing will be performed to ensure the integrity and availability of backups. Testing will be conducted using a separate test environment to minimize the risk of disruption to business operations.
  • Data Retention: Data retention periods will be established to determine how long backups will be retained. Data retention will be based on legal, operational, and business requirements, as well as privacy and security considerations.
  • Logging and Documentation: A detailed record will be maintained of all backups performed, including the date, time, type of backup, data backed up, and any relevant observations. Documentation will be kept in a secure location and available for review by authorized personnel.
  • Review and Update: This protocol will be reviewed periodically to ensure its effectiveness and continued compliance with legal requirements and information security best practices.
  Updates will be made as needed to reflect changes in technology, infrastructure, or regulatory requirements.

7.5. Security protocol for company domains

  • Staff Training: Provide regular cybersecurity and phishing awareness training to all company employees. Teach them to recognize signs of phishing, such as requests for personal information or login credentials via suspicious emails.
  • Anti-Spam Filters: Implement robust anti-spam filters on the company email server to detect and block malicious emails before they reach employees’ inboxes. Configure filters to flag suspicious emails and send them to spam or automatically delete them.
  • Email Authentication: Configure email authentication systems, such as SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance), to prevent phishing and ensure that emails originate from legitimate sources.
  • Domain Monitoring: Actively monitor the company’s domain registry for potentially malicious or company-like registrations that could be used in phishing attacks. Register domain variants to prevent cybercriminals from using them to deceive employees or customers.
  • Software Updates: Keep the company’s email software and server operating systems up to date to address potential vulnerabilities that could be exploited by phishing attackers. Configure automatic updates to ensure the software is always protected against the latest threats.
  • Secure Login Page: Use a secure login page for company online services, such as email and internal systems. Implement SSL/TLS encryption to protect communications between the user’s web browser and the company server, thus preventing login credentials from being stolen through phishing attacks. Request
  • Verification Policy: Establish a clear policy requiring employees to personally verify all requests for confidential information or transfers of funds received via email, especially if they appear unusual or come from unknown sources.

8. Protocol for Action in Case of Security Breach

  • Security Breach Detection: Any employee who detects or suspects a security breach must immediately inform the Data Controller or their direct supervisor.
  • Preliminary Assessment: The Data Controller or designated supervisor will conduct a preliminary assessment of the security breach to determine its nature, scope, and potential impacts.
  • Containment and Mitigation: Immediate measures will be taken to contain and mitigate the security breach and reduce any potential damage, such as suspending access to compromised systems, restoring backups, or implementing corrective measures.
  • Internal Notification: All relevant parties, including IT, legal, and communications departments, will be notified internally of the security breach and the measures taken to address it.
  • Risk Assessment: A detailed assessment of the risks associated with the security breach will be conducted, including the impact on personal data and data subject rights, and the actions necessary to mitigate these risks will be determined.
  • Notification to the Supervisory Authority: If the security breach represents a risk to the rights and freedoms of data subjects, the Spanish Data Protection Agency (AEPD) will be notified within a maximum of 72 hours of its detection, in accordance with the provisions of Article 33 of the LOPDGDD.
  • Communication to Data Subjects: If the security breach may have a significant impact on the rights and freedoms of data subjects, they will be informed in a timely and transparent manner about the nature of the breach, the measures taken to mitigate it, and any actions they can take to protect themselves.
  • Investigation and Documentation: A thorough investigation into the security breach will be conducted to identify the underlying causes and take corrective measures to prevent future incidents. All stages of the process and the measures taken will be documented.
  • Review and Continuous Improvement: Information security procedures will be periodically reviewed, and improvements will be implemented as necessary to prevent and more effectively manage future security breaches.
  • Logging and Documentation: A detailed record will be kept of all security breaches, including the date of detection, the nature of the breach, the actions taken, notifications made, and any subsequent follow-up.

9. Security Measures to Implement on the Web

Measures based on the principles established in the Organic Law on Data Protection and Guarantee of Digital Rights (LOPDGDD):

SSL/TLS Certificate: We will implement an SSL/TLS certificate on our website to ensure that all communications between the user’s browser and our web server are encrypted and protected against malicious interception.

  • Software Updates: We will keep all software components of our website up to date, including the operating system, web server, content management system, and any plugins or extensions used, to address potential security vulnerabilities and ensure a secure web environment.
  • Firewalls and Security Filters: We will implement firewalls and security filters on our web server to protect against distributed denial of service (DDoS) attacks, SQL injection, cross-site scripting (XSS) attacks, and other types of cyberattacks.
  • User Authentication: We will use strong authentication methods, such as strong passwords, two-factor authentication (2FA), and biometrics, to ensure that only authorized users can access restricted areas of our website and sensitive information.
  • Session Management: We will implement secure session management mechanisms to protect the integrity of user sessions and prevent session hijacking and session fixation attacks.
  • Data Injection Protection: We will validate and escape all input data to prevent code injection attacks, such as SQL injection, script injection, and other types of malicious data injection.
  • Security Audits: We will conduct periodic security audits on our website to identify potential vulnerabilities and ensure compliance with established security policies.
  • Privacy Policy and Legal Notice: We will publish a privacy policy and legal notice on our website to inform users about how their personal data is collected, used, and protected, in compliance with the transparency requirements established in the LOPDGDD (Spanish Data Protection Act).
  • Cookie Consent: We will implement a cookie consent mechanism that complies with the requirements of the LOPDGDD (Spanish Data Protection Act) and the GDPR, informing users about the use of cookies on our website and obtaining their consent before using non-essential cookies.
  • Staff Training: We will provide regular training on information security and good practices in the use and maintenance of our website to all staff involved in its development, management and maintenance.

Web Security Measures according to the LSSICE:

  • Legal Notice and Privacy Policy: We will publish a legal notice and privacy policy on our website, complying with the requirements established in the LSSICE (Spanish Law on the Use of Personal Data). These documents will inform users about the company’s identity, the website’s conditions of use, and the processing of personal data collected.
  • Cookie Consent: We will implement a cookie banner that complies with the requirements of the LSSICE (Spanish Law on the Use of Personal Data) and the GDPR. This banner will inform users about the use of cookies on our website and obtain their consent before using non-essential cookies.
  • Personal Data Protection: We will implement appropriate technical and organizational security measures to protect personal data collected through the website, in compliance with the LSSICE (Spanish Law on the Use of Personal Data) and applicable data protection regulations.
  • Electronic Commercial Communications: We will obtain users’ prior and express consent before sending them commercial communications by email, in compliance with the requirements established in the LSSICE (Spanish Law on the Use of Personal Data).
  • Protection against Cyberattacks: We will implement technical security measures to protect our website against cyberattacks, such as distributed denial-of-service (DDoS) attacks, malicious code injection, and unauthorized access.
  • Record Keeping: We will maintain records of all commercial transactions carried out through the website, in compliance with the data retention requirements of the LSSICE (Spanish Law on Information Society Services).
  • Information about Services: We will provide clear and accessible information about the services offered on our website, including prices, terms and conditions, and contact information.
  • Web Accessibility: We will ensure that our website complies with the accessibility requirements established in the LSSICE (Spanish Law on Information Society Services), ensuring that everyone can access and use our online services.

10. International data transfers

We will only transfer personal data outside the European Economic Area (EEA) where there is a valid legal mechanism to do so, such as approval of standard contractual clauses by the European Commission.

11. User rights

Stakeholder Rights Protocol for CYP BRANDS EVOLUTION, S.L.:

11.1. Introduction

This protocol establishes the guidelines and procedures that CYP BRANDS EVOLUTION, S.L. must follow to guarantee the effective exercise of the rights of data subjects regarding the protection of personal data, in accordance with the provisions of the Organic Law on Data Protection and Guarantee of Digital Rights (LOPDGDD) and other applicable regulations.

11.2. Rights of Interested Parties:

  • Right of Access: The right of data subjects to obtain confirmation as to whether their personal data is being processed and, if so, to access that data and obtain information regarding the processing.
  • Right to Rectification: The right of data subjects to rectify inaccurate or incomplete personal data.
  • Right to Deletion: The right of data subjects to request the deletion of their personal data when it is no longer necessary for the purposes for which it was collected, among other circumstances.
  • Right to Object: The right of data subjects to object to the processing of their personal data in certain circumstances, such as processing for direct marketing purposes.
  • Right to Restriction of Processing: The right of data subjects to request the restriction of the processing of their personal data in certain cases, such as where the data is accurate or where the processing is unlawful.
  • Right to Data Portability: The right of data subjects to receive the personal data concerning them, which they have provided to a data controller, in a structured, commonly used, and machine-readable format.
  • Right not to be subject to automated individual decisions: The right of data subjects not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.

11.3. Procedure for the Exercise of Rights:

  • Receiving Requests: Requests to exercise data subject rights may be submitted in writing or electronically through the means provided by CYP BRANDS EVOLUTION, S.L., such as the contact form on our website or the email address designated for this purpose.
  • Identity Verification: To ensure the security and privacy of personal data, applicants will be required to verify their identity before proceeding with the request. This verification may be accomplished by presenting a valid document or other appropriate method of verification.
  • Response Time: CYP BRANDS EVOLUTION, S.L. will respond to requests to exercise data subject rights within the period established by the LOPDGDD (Spanish Data Protection Act), which is one month from receipt of the request. This period may be extended for another two months in the case of complex or numerous requests, in which case the applicant will be informed of the extension and the reasons for it.
  • Response to Requests: In the event of a request for access, rectification, deletion, objection, restriction of processing, or data portability, CYP BRANDS EVOLUTION, S.L. will take the necessary measures to address the request within the established period. If the request cannot be addressed, the interested party will be informed of the reasons for the denial and of their right to file a complaint with the Spanish Data Protection Agency (AEPD) or another competent authority.

11.4. Request and Response Log:

CYP BRANDS EVOLUTION, S.L. will keep a record of all requests received from data subjects to exercise their rights, as well as the responses provided to them. This record will include information on the nature of the request, the date it was received, verification of the requester’s identity, the actions taken to address the request, and any other relevant information.

11.5. Staff Training and Awareness:

All CYP BRANDS EVOLUTION, S.L. staff will receive training and awareness-raising on the data subject rights protocol and its importance in compliance with the LOPDGDD (General Data Protection Act). Specific training will be provided on how to recognize and appropriately respond to data subject requests to exercise their rights.

11.6. Review and Update of the Protocol:

This protocol will be reviewed periodically to ensure its effectiveness and continued compliance with legal requirements and best practices in data protection. Updates will be made as necessary to reflect changes in legislation, technology, or CYP BRANDS EVOLUTION, S.L.’s internal procedures.

12. Policy Update

This data protection policy is reviewed and updated periodically to ensure compliance with current regulations and best privacy practices.

Shopping Basket
Scroll to Top