Sonpetit Barcelona
PRIVACY AND PERSONAL DATA PROTECTION POLICY
1. IDENTITY OF THE DATA CONTROLLER
In compliance with Regulation (EU) 2016/679, General Data Protection Regulation ("GDPR"), Organic Law 3/2018 of 5 December on Personal Data Protection and guarantee of digital rights ("LOPDGDD"), Law 34/2002 of 11 July on information society services and electronic commerce ("LSSI-CE"), and any other applicable provisions, users are informed that the controller of personal data collected through Sonpetit's website and services is:
Tax ID: B65259988
Contact email: info@sonpetit.com Hereinafter, "SONPETIT", "Sonpetit", "we", "the company" or "the Controller".
2. SCOPE
This Privacy Policy governs the processing of personal data carried out by Sonpetit through its website, online store, user accounts, forms, customer service, electronic communications, purchasing processes, payment systems, after-sales services, returns, claims, commercial activities and other functionalities associated with Sonpetit's services. This Policy applies to website visitors, customers, registered users, prospective customers, order recipients, people who contact Sonpetit and, where appropriate, representatives of companies, establishments or professionals.
3. PRINCIPLES APPLIED TO PROCESSING
Sonpetit will process personal data in accordance with the principles laid down in data-protection legislation and, in particular, according to the principles of:
- lawfulness, fairness and transparency;
- purpose limitation;
- data minimisation;
- accuracy;
- storage limitation;
- integrity and confidentiality;
- appropriate security;
- accountability.
Sonpetit will request only data that is reasonably necessary for each purpose.
4. PERSONAL DATA WE MAY PROCESS
Depending on the relationship maintained with Sonpetit, the following categories of information may be processed:
4.1. Identification data
Name, surname, username, account identifiers and, where necessary, identification document.
4.2. Contact data
Postal address, delivery address, billing address, email address, telephone number and other data necessary to manage a communication or delivery.
4.3. Purchase and order data
Products purchased, order number, amount, discounts, promotions, returns, exchanges, incidents, shipping status, purchase history and documentation relating to the transaction.
4.4. Financial and billing data
Data necessary to issue invoices, manage payments, refunds, taxes and accounting obligations. Where payment is processed by a specialised provider, Sonpetit will seek not to store full bank-card data where this is not necessary. Payment providers may process the necessary information in accordance with their own legal and security obligations.
4.5. Account data
Encrypted or protected credentials, preferences, saved addresses, orders, wish lists and other information linked to the customer's account. Sonpetit has no legitimate need to know the user's password in readable plain text.
4.6. Technical and security data
IP address, technical identifiers, browser and device information, date and time of access, activity logs, security events, errors, authentication attempts and other data necessary to maintain the security and proper operation of the service.
4.7. Browsing data and preferences
Where there is a valid legal basis, pages visited, product interactions, preferences and other data relating to the browsing experience may be processed. Where the law requires consent for tracking technologies, such processing will take place only after valid consent has been obtained.
4.8. Communications with Sonpetit
Enquiries, requests, emails, forms, complaints and communications with customer service.
4.9. Data voluntarily provided
The user may include additional information when contacting Sonpetit. Please do not provide specially protected data or sensitive information that is not necessary to manage the request.
5. PURPOSES AND LEGAL BASES OF PROCESSING
User-account management Sonpetit may process the data necessary to create, maintain, authenticate, administer and protect a customer account. Legal basis: performance of a contract or steps taken at the request of the data subject prior to entering into a contract.
Purchase management Data will be processed to:
- process orders;
- confirm purchases;
- collect the corresponding amounts;
- prepare products;
- manage deliveries;
- send communications relating to the order;
- manage exchanges and returns;
- make refunds;
- handle guarantees;
- resolve incidents.
Legal basis: performance of the sales contract and compliance with legal obligations.
Billing, accounting and taxation Sonpetit may process and retain information necessary to issue invoices and comply with tax, accounting, commercial and administrative obligations. Legal basis: compliance with legal obligations.
Customer service Sonpetit will process the data necessary to respond to requests, enquiries, complaints, incidents, return requests and other communications. Legal basis: performance of the contract, pre-contractual measures, compliance with legal obligations and, where appropriate, legitimate interest in providing an adequate service and retaining evidence of communications.
Logistics management Strictly necessary data may be communicated to carriers, logistics operators and other providers necessary to deliver the order. Legal basis: performance of the contract.
Fraud prevention and protection of Sonpetit Sonpetit may process information in order to:
- detect potentially fraudulent transactions;
- prevent purchases made with unlawful payment methods;
- detect identity impersonation;
- prevent unauthorised access;
- detect abuse of promotions;
- identify malicious automated behaviour;
- prevent attacks against the platform;
- detect fraudulent accounts;
- protect customers, employees, suppliers and Sonpetit;
- investigate security incidents;
- retain evidence where necessary to establish, exercise or defend claims.
Legal basis: the legitimate interests of Sonpetit and users in preventing fraud, abuse, security incidents and unlawful activity, without prejudice to any applicable legal obligations. Sonpetit may temporarily suspend certain transactions or request additional verification where there are reasonable indications of fraud, manipulation, impersonation, misuse or security risk. Such measures must be applied proportionately and with respect for data subjects' rights.
Information security Sonpetit may process technical data, access logs and security events to protect its systems, detect vulnerabilities, prevent attacks, manage incidents and ensure the availability and integrity of the platform. Legal basis: legitimate interest and compliance with legal security obligations.
Commercial communications Sonpetit may send commercial information: a) where the user has given consent; or b) where there is a prior contractual relationship and the law permits information to be sent about Sonpetit's own products or services similar to those previously purchased. The recipient may object or unsubscribe easily and free of charge at any time. Objecting to promotional communications does not affect messages that are strictly necessary to manage orders, payments, security, returns, accounts or any contractual relationship.
Analytics, personalisation and measurement Sonpetit may use statistical information and measurement technologies to understand how the website operates and improve its services. Where these technologies require consent under applicable law, they will not be activated until the user has given that consent.
Legal compliance and legal defence Data may be processed where necessary to:
- comply with legal obligations;
- respond to requests from authorities;
- cooperate with judicial or administrative bodies;
- manage audits;
- prevent unlawful activities;
- establish, exercise or defend rights and claims.
Legal basis: legal obligation and legitimate interest in Sonpetit's legal defence.
6. MANDATORY NATURE OF CERTAIN DATA
Data marked as mandatory is necessary to provide the requested service. Refusal to provide information essential to process an order, make a delivery, verify a payment or comply with a legal obligation may prevent Sonpetit from providing the relevant service. Sonpetit will not request consent for processing strictly necessary to perform a contract where another appropriate legal basis exists.
7. ACCURACY OF DATA
The user guarantees that the data provided is accurate, complete and up to date and undertakes to communicate any relevant change. Sonpetit may take reasonable measures to correct or update information where it detects manifestly incorrect data. The deliberate use of false information, third-party data without authorisation, fictitious identities or fraudulent payment methods may result in suspension of the transaction and appropriate legal action.
8. DATA RELATING TO THIRD PARTIES
Where a customer provides information about another person, for example to send a gift or deliver to a different address, Sonpetit will use that data exclusively for purposes necessary in connection with that transaction, unless another valid legal basis exists. The person providing third-party data must ensure that the information is correct and that they have sufficient authority to disclose it.
9. RECIPIENTS OF THE DATA
Sonpetit does not sell personal data. Data may be communicated or made available, where necessary, to:
- transport and courier companies;
- logistics operators;
- payment-service providers;
- banks;
- hosting and technology infrastructure providers;
- email and communications providers;
- IT maintenance companies;
- security and fraud-prevention services;
- support providers;
- analytics and marketing services where there is a legal basis;
- tax, accounting or legal advisers;
- auditors;
- insurance companies where appropriate;
- public administrations;
- the Tax Agency;
- courts and tribunals;
- law-enforcement bodies;
- data-protection authorities;
- other competent bodies where there is a legal obligation.
Where a provider acts as a processor, Sonpetit will put in place the contractual safeguards required by law.
10. PAYMENT PROVIDERS
Payments may be managed through specialised providers. Depending on the method selected, certain data may be processed directly by the payment provider to:
- authorise transactions;
- verify identity;
- prevent fraud;
- comply with financial regulation;
- manage refunds;
- handle disputes.
Sonpetit will receive only the information necessary to know the status of the transaction and manage the order, unless other information is legally necessary.
11. TRANSPORT COMPANIES
To perform delivery, Sonpetit may communicate to the carrier data such as:
- name and surname;
- delivery address;
- telephone number;
- email address;
- order reference;
- instructions strictly necessary for delivery.
The carrier may use this information to locate the recipient, make the delivery and manage logistics incidents.
12. INTERNATIONAL DATA TRANSFERS
Some technology providers used by Sonpetit may be located outside the European Economic Area or provide services through international infrastructure. Where an international data transfer takes place, Sonpetit will seek to ensure that a mechanism recognised by the GDPR is in place, such as:
- an adequacy decision by the European Commission;
- standard contractual clauses;
- binding corporate rules;
- additional safeguards where necessary;
- any other legally permitted mechanism.
Where appropriate, the circumstances of the transfer may be assessed and supplementary measures applied to protect the information.
13. RETENTION PERIODS
Sonpetit will retain data only for as long as necessary to fulfil the purpose for which it was obtained and, thereafter, for the periods necessary to comply with legal obligations or potential liabilities. As a general criterion:
User account While the account remains active and afterwards for the time necessary to meet legal obligations or claims.
Orders, billing and commercial documentation For the periods required by tax, commercial and accounting legislation. Business documentation whose retention is legally required may be kept for six years, without prejudice to other applicable statutory periods.
Customer service and complaints For the time necessary to manage the request and thereafter for the periods during which liabilities may arise.
Commercial communications Until the data subject withdraws consent or exercises the right to object. Sonpetit may retain a minimum amount of information on a suppression list solely to ensure that no further commercial communications are sent to a person who has unsubscribed.
Security and fraud prevention For the period reasonably necessary to investigate the incident, prevent further abuse and, where appropriate, address legal liabilities. Where deletion is appropriate, data may remain blocked for statutory liability periods.
14. RIGHTS OF THE DATA SUBJECT
Persons whose data is processed by Sonpetit may exercise, where applicable, the following rights:
Right of access To know whether Sonpetit processes their data and obtain information about that processing.
Right to rectification To request correction of inaccurate or incomplete information.
Right to erasure To request deletion of data where the circumstances provided by law exist. This right does not mean that Sonpetit must delete information whose retention is necessary to comply with legal obligations or to establish, exercise or defend claims.
Right to restriction of processing To request that certain data be restricted in the cases provided by law.
Right to object To object, on grounds relating to their particular situation, to processing based on legitimate interests. The user may object at any time to the processing of personal data for direct marketing.
Right to data portability To receive certain data provided to Sonpetit in a structured, commonly used and machine-readable format where the legal requirements are met.
Right to withdraw consent Where processing is based on consent, the data subject may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out previously.
Automated decisions The data subject is entitled to the safeguards laid down by law where a decision based solely on automated processing produces legal effects or similarly significantly affects the person.
15. HOW TO EXERCISE RIGHTS
Rights may be exercised by a communication addressed to: SONPETIT BARCELONA S.L. Carrer del Pi Gros, 10 08349 Cabrera de Mar, Barcelona Spain or by email to: info@sonpetit.com The request must allow the applicant to be reasonably identified and specify the right they wish to exercise. Where there are reasonable doubts about the identity of the applicant, Sonpetit may request additional information strictly necessary to verify identity and prevent fraudulent access to personal data.
16. COMPLAINTS TO THE SUPERVISORY AUTHORITY
If a person considers that Sonpetit has processed their data in breach of the law, they may lodge a complaint with the Spanish Data Protection Agency (AEPD), without prejudice to any other administrative or judicial remedy available. Sonpetit recommends contacting the company first in an attempt to resolve any privacy-related incident.
17. MINORS
The Sonpetit store sells children's products, but the e-commerce service is mainly intended for adults making purchases. Sonpetit does not intend knowingly to obtain personal data from minors where this is not necessary. Where processing based on consent relates to a person under fourteen years of age, consent from the holder of parental responsibility or guardianship will be required on the terms established by Spanish law. If Sonpetit detects that it has improperly received information relating to a minor, it may take reasonable measures to delete the information or regularise the processing.
18. SPECIAL CATEGORIES OF DATA
As a general rule, Sonpetit does not need to process information relating to:
- health;
- racial or ethnic origin;
- political opinions;
- religion;
- trade-union membership;
- genetics;
- biometrics;
- sexual orientation or sex life.
The user should refrain from providing this type of information unless there is a specific need and a valid legal basis. The commercial characteristics of certain products, including their suitability or comfort for certain skin types, do not mean that Sonpetit needs to know medical information about the customer or the child who will use the product.
19. DATA SECURITY
Sonpetit will adopt technical and organisational measures appropriate to the risk to protect data against:
- accidental or unlawful destruction;
- loss;
- alteration;
- unauthorised disclosure;
- unauthorised access;
- theft of credentials;
- account abuse;
- cyberattacks.
Measures may include, where appropriate:
- encryption;
- access controls;
- authentication systems;
- backups;
- security logs;
- system updates;
- segregation of permissions;
- monitoring;
- recovery measures;
- incident-management procedures.
Nevertheless, no system connected to the Internet can be considered absolutely invulnerable. The user is also responsible for maintaining the confidentiality of credentials and must inform Sonpetit if they suspect an account has been used without authorisation.
20. SECURITY INCIDENTS AND DATA BREACHES
Where Sonpetit detects a security breach affecting personal data, it will act in accordance with obligations laid down by law. Where legally required, the incident will be notified to the supervisory authority and, in the cases required by law, to affected data subjects.
21. COOKIES AND SIMILAR TECHNOLOGIES
Sonpetit may use cookies and similar technologies necessary to:
- maintain sessions;
- remember the basket;
- manage the purchase process;
- ensure security;
- retain technical preferences;
- prevent fraud.
Technologies not strictly necessary to provide the service, including certain analytics, advertising or tracking tools, are governed by the Cookie Policy and by the choices made by the user in the consent-management system. The user must have appropriate mechanisms to accept or reject non-essential cookie categories and subsequently modify preferences.
22. MARKETING AND UNSUBSCRIBING FROM COMMUNICATIONS
Promotional communications must clearly identify Sonpetit as the sender. Recipients will have a simple and free mechanism to object or unsubscribe. Once an unsubscribe request has been made, Sonpetit will take reasonable measures to ensure that the relevant address is no longer used in new commercial campaigns, without prejudice to keeping it in limited form on a suppression list. Transactional messages about purchases, returns, security, payments or accounts are not considered optional commercial communications where necessary to provide the service.
23. SOCIAL NETWORKS
Where a person interacts with Sonpetit's official social-media profiles, their data may be processed both by Sonpetit and by the relevant platform operator, in accordance with the terms and policies applicable to that service. Sonpetit recommends reviewing the privacy policies of each social network used. Public interaction with Sonpetit should not be used to disclose bank details, identity documents or other sensitive information.
24. THIRD-PARTY LINKS
The website may contain links to third-party services or pages. Sonpetit does not generally control the privacy practices of independent external pages and recommends reviewing their respective policies before providing personal information.
25. PREVENTION OF ABUSE AND UNLAWFUL ACTIVITIES
Sonpetit reserves the right to adopt proportionate measures to protect the platform, customers and the company against fraudulent or abusive conduct. Among other circumstances, a transaction may be analysed where there are objective indications of:
- payment fraud;
- account takeover;
- impersonation;
- multiple anomalous payment attempts;
- systematic abuse of promotions;
- malicious automated activity;
- manipulation of the store's operation;
- attacks on systems;
- use of data obtained unlawfully.
Where necessary, Sonpetit may retain technical evidence and communicate information to payment providers, financial institutions, authorities or other legally authorised recipients. This provision does not limit the rights granted to the data subject by data-protection legislation.
26. BLOCKING AND RETENTION FOR THE DEFENCE OF CLAIMS
Exercising the right to erasure does not require Sonpetit immediately to delete information that must be retained by law. Where appropriate, data will cease to be used for ordinary purposes and may be retained in duly blocked form exclusively to:
- address liabilities;
- evidence transactions;
- respond to claims;
- comply with legal obligations;
- establish, exercise or defend rights.
Once the applicable periods have expired, data will be securely deleted or anonymised.
27. CHANGES TO THE PRIVACY POLICY
Sonpetit may amend this Policy where necessary to adapt it to:
- legislative changes;
- criteria of authorities;
- developments in case law;
- new services;
- technological changes;
- changes in providers;
- significant changes in processing activities.
The current version will be permanently available on the website. Where a change substantially affects processing based on consent, Sonpetit will request consent again where legally necessary.
28. INTERPRETATION
This Policy must be interpreted in accordance with applicable Spanish and European Union legislation on data protection and information society services. No provision of this Policy should be interpreted as a waiver or limitation of the rights granted to data subjects by law. Likewise, no provision prevents Sonpetit from complying with legal obligations, taking proportionate security measures, preventing fraud or retaining information where there is a lawful basis to do so.
29. CONTACT
For any matter relating to privacy, data protection or the exercise of rights: SONPETIT BARCELONA S.L. Tax ID: B65259988 Carrer del Pi Gros, 10 08349 Cabrera de Mar, Barcelona, Spain