Privacy Policy
At Agencia Prodereg we are committed to protecting your privacy. This policy explains what data we collect, how we use it and what your rights are under the General Data Protection Regulation (GDPR) of the European Union and the Spanish Organic Law on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).
1. Data controller
2. Data we collect
We collect personal data in the following contexts:
Contact form
- First and last name
- Email address
- Phone number (optional)
- Company name (optional)
- Message or enquiry
Job application form ("Work with us")
- First and last name
- Phone number
- Date of birth
- City and province of residence
- Email address
- Photograph (optional)
- Curriculum Vitae
We do not collect sensitive data (racial origin, health, political or religious beliefs, etc.) unless it is provided voluntarily by the user in the body of a message.
3. Purpose and legal basis for processing
| Purpose | Legal basis |
|---|---|
| Responding to enquiries submitted through the contact form | Legitimate interest of the controller / Performance of a contract |
| Managing job applications | Consent of the data subject |
| Sharing data with third-party organisations interested in certain professional profiles | Explicit consent of the data subject |
| Sending commercial communications about our services | Consent of the data subject |
4. Recipients of the data
Your personal data will not be shared with third parties except in the following cases:
- When the data subject has given explicit consent for the sharing of data with organisations seeking specific professional profiles (job application form).
- When the disclosure is necessary to comply with a legal obligation.
- Technology service providers acting as data processors under a contract and with appropriate data protection guarantees.
We do not carry out international data transfers outside the European Economic Area without appropriate safeguards.
5. Data retention period
- Contact form: Data will be retained for as long as necessary to handle the enquiry and, thereafter, for the limitation period of any legal actions that may arise (maximum 5 years).
- Job applications: CVs and candidate data will be retained for a maximum of 2 years from receipt. After this period, they will be securely deleted unless the data subject renews their application.
- Commercial communications: Until the data subject withdraws their consent.
6. Your rights
As a data subject, you have the right to:
- Access: Obtain confirmation of whether we process your personal data and, where applicable, access it.
- Rectification: Request the correction of inaccurate or incomplete data.
- Erasure ("right to be forgotten"): Request the deletion of your data when it is no longer necessary for the purpose for which it was collected, among other cases.
- Restriction of processing: Request that the processing of your data be restricted in certain circumstances.
- Portability: Receive your data in a structured, commonly used and machine-readable format.
- Objection: Object to the processing of your data, in particular for direct marketing purposes.
- Withdraw consent: At any time, without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, you can contact us by sending an email to [email protected], indicating your first and last name and the right you wish to exercise, attaching a copy of your identity document.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) if you consider that the processing of your data does not comply with current regulations. You can do so via www.aepd.es.
7. Minors
Our services are aimed at people over 16 years of age. We do not knowingly collect data from minors under that age. If you become aware that a minor has provided us with personal data without the consent of their parents or guardians, please let us know so that we can delete it.
8. Security measures
We have adopted appropriate technical and organisational measures to guarantee a level of security appropriate to the risk of processing, in accordance with Article 32 of the GDPR. These measures include access controls, encrypted data transmission (HTTPS) and incident management procedures.
9. Changes to the privacy policy
We reserve the right to modify this Privacy Policy to adapt it to legislative or case-law developments, as well as to changes in our services. We will notify you of relevant changes through the website or, where possible, by email.
Last updated: