Sonpetit Barcelona
PATAKARAN SA PRIVACY AT PROTEKSIYON NG PERSONAL NA DATOS
Mga tuntunin ng Sonpetit sa personal-data processing, rights, security at privacy
1. PAGKAKAKILANLAN NG DATA CONTROLLER
Bilang pagsunod sa Regulation (EU) 2016/679, General Data Protection Regulation (“GDPR”), Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales (“LOPDGDD”), Ley 34/2002, de 11 de julio, de servicios de la sociedad de la información y de comercio electrónico (“LSSI-CE”), at iba pang applicable rules, ipinababatid na ang controller ng personal data na kinokolekta sa website at services ng Sonpetit ay:
Contact email: info@sonpetit.com Sa ibaba, “SONPETIT”, “Sonpetit”, “kami”, “ang kumpanya” o “ang Controller”.
2. SAKLAW
Ang Privacy Policy na ito ang namamahala sa personal-data processing na ginagawa ng Sonpetit sa pamamagitan ng website, online store, user accounts, forms, customer service, electronic communications, purchase processes, payment systems, after-sales services, returns, complaints, commercial actions at iba pang functions na kaugnay ng Sonpetit services. Naaangkop ito sa website visitors, customers, registered users, potential customers, recipients ng orders, mga taong nakikipag-ugnayan sa Sonpetit at, kung nararapat, representatives ng companies, establishments o professionals.
3. MGA PRINSIPYO SA PROCESSING
Ipoproseso ng Sonpetit ang personal data ayon sa data-protection law at partikular sa mga prinsipyo ng:
- lawfulness, fairness at transparency;
- purpose limitation;
- data minimization;
- accuracy;
- storage limitation;
- integrity at confidentiality;
- appropriate security;
- accountability.
Hihingi lamang ang Sonpetit ng data na reasonably necessary sa bawat purpose.
4. PERSONAL DATA NA MAAARING IPROSESO
Depende sa relationship sa Sonpetit, maaaring iproseso ang sumusunod:
4.1. Identification data
Pangalan, apelyido, username, account identifiers at, kapag kailangan, identity document.
4.2. Contact data
Postal address, delivery address, billing address, email, phone at iba pang data na kailangan sa communication o delivery.
4.3. Purchase at order data
Products purchased, order number, amount, discounts, promotions, returns, exchanges, incidents, shipping status, purchase history at documents na kaugnay ng transaction.
4.4. Economic at billing data
Data na kailangan sa invoices, payments, refunds, taxes at accounting obligations. Kung specialized provider ang nagpo-process ng payment, sisikapin ng Sonpetit na hindi mag-store ng full bank-card details kung hindi kailangan. Maaaring iproseso ng payment providers ang necessary information ayon sa sariling legal at security obligations.
4.5. Account data
Encrypted o protected credentials, preferences, saved addresses, orders, wishlists at iba pang information na linked sa customer account. Walang legitimate need ang Sonpetit na malaman ang password ng user sa readable plain text.
4.6. Technical at security data
IP address, technical identifiers, browser at device information, date at time of access, activity logs, security events, errors, authentication attempts at iba pang data na kailangan para sa security at proper operation ng service.
4.7. Browsing at preference data
Kapag may valid legal basis, maaaring iproseso ang pages visited, interactions with products, preferences at iba pang data na kaugnay ng browsing experience. Kapag kailangan ng consent para sa tracking technologies, gagawin lamang ang processing pagkatapos makakuha ng valid consent.
4.8. Communications with Sonpetit
Queries, requests, emails, forms, complaints at communications sa customer service.
4.9. Data na kusang ibinigay
Maaaring magbigay ang user ng additional information kapag kumokontak sa Sonpetit. Huwag magbigay ng specially protected o sensitive data na hindi kailangan sa request.
5. PURPOSES AT LEGAL BASES
User-account management Maaaring iproseso ang data na kailangan upang gumawa, mag-maintain, mag-authenticate, mag-administer at mag-protect ng customer account. Legal basis: performance of a contract o pre-contractual measures.
Purchase management Ipoproseso ang data upang:
- process orders;
- confirm purchases;
- collect payments;
- prepare products;
- manage deliveries;
- send order-related communications;
- manage exchanges at returns;
- issue refunds;
- handle warranties;
- resolve incidents.
Legal basis: performance of sales contract at compliance with legal obligations.
Billing, accounting at taxation Maaaring iproseso at i-retain ang information na kailangan sa invoices at sa tax, accounting, commercial at administrative obligations. Legal basis: compliance with legal obligations.
Customer service Ipoproseso ang data na kailangan sa requests, queries, complaints, incidents, return requests at iba pang communications. Legal basis: contract performance, pre-contractual measures, legal obligations at, kung applicable, legitimate interest sa proper service at preservation of communication evidence.
Logistics management Ang strictly necessary data ay maaaring ibigay sa transport companies, logistics operators at ibang providers na kailangan sa delivery. Legal basis: performance of contract.
Fraud prevention at protection ng Sonpetit Maaaring iproseso ang information upang:
- detect potentially fraudulent transactions;
- prevent purchases gamit ang illicit payment methods;
- detect identity impersonation;
- prevent unauthorized access;
- detect promotion abuse;
- identify malicious automated behavior;
- prevent attacks against the platform;
- detect fraudulent accounts;
- protect customers, employees, providers at Sonpetit;
- investigate security incidents;
- retain evidence kung kailangan para mag-file, gumamit o mag-defend ng claims.
Legal basis: legitimate interests ng Sonpetit at users sa fraud, abuse, security incidents at unlawful activities, nang hindi naaapektuhan ang applicable legal obligations. Maaaring pansamantalang i-suspend ang operations o humiling ng additional checks kapag may reasonable indicators ng fraud, manipulation, impersonation, misuse o security risk. Dapat proporsyonal ang measures at igalang ang rights ng data subjects.
Information security Maaaring iproseso ang technical data, access logs at security events upang protektahan ang systems, detect vulnerabilities, prevent attacks, manage incidents at tiyakin ang availability at integrity ng platform. Legal basis: legitimate interest at legal security obligations.
Commercial communications Maaaring magpadala ang Sonpetit ng commercial information: a) kapag nagbigay ang user ng consent; o b) kapag may prior contractual relationship at pinapayagan ng law ang communication tungkol sa sariling similar products o services. Maaaring tumutol o mag-unsubscribe ang recipient anumang oras sa simple at free na paraan. Ang objection sa promotions ay hindi makakaapekto sa messages na strictly necessary sa orders, payments, security, returns, accounts o contractual relationship.
Analytics, personalization at measurement Maaaring gumamit ng statistical information at measurement technologies upang malaman ang website performance at mapabuti ang services. Kung kailangan ng consent, hindi ito ia-activate bago magkaroon ng consent.
Compliance at legal defense Maaaring iproseso ang data kung kailangan upang:
- comply with legal obligations;
- respond sa authorities;
- cooperate sa judicial o administrative bodies;
- manage audits;
- prevent unlawful activities;
- formulate, exercise o defend rights at claims.
Legal basis: legal obligation at legitimate interest sa legal defense ng Sonpetit.
6. MANDATORY NATURE NG ILANG DATA
Ang data na marked mandatory ay kailangan upang maibigay ang requested service. Ang hindi pagbibigay ng essential information sa order processing, delivery, payment verification o legal obligation ay maaaring pumigil sa Sonpetit na magbigay ng corresponding service. Hindi hihingi ang Sonpetit ng consent para sa processing na strictly necessary sa contract kung may ibang appropriate legal basis.
7. ACCURACY NG DATA
Ginagarantiya ng user na accurate, complete at updated ang data at ipaaalam ang relevant changes. Maaaring gumawa ang Sonpetit ng reasonable measures upang itama o i-update ang obviously incorrect data. Ang deliberate use ng false information, third-party data nang walang authorization, fictitious identities o fraudulent payment methods ay maaaring magresulta sa suspension at legal action.
8. DATA NG THIRD PERSONS
Kapag nagbigay ang customer ng data ng ibang tao, halimbawa para sa gift o different delivery address, gagamitin ito ng Sonpetit para lamang sa purposes na kailangan sa transaction maliban kung may ibang valid legal basis. Dapat tiyakin ng taong nagbigay ng third-party data na correct ang information at may sufficient legal basis para ibahagi ito.
9. RECIPIENTS NG DATA
Hindi nagbebenta ang Sonpetit ng personal data. Kapag kailangan, maaaring ibigay o gawing accessible ang data sa:
- transport at courier companies;
- logistics operators;
- payment service providers;
- banking institutions;
- hosting at technology-infrastructure providers;
- email at communications providers;
- IT maintenance companies;
- security at fraud-prevention services;
- support providers;
- analytics at marketing providers kung may legal basis;
- tax, accounting o legal advisers;
- auditors;
- insurers kung applicable;
- public administrations;
- tax authorities;
- courts;
- law-enforcement bodies;
- data-protection authorities;
- ibang competent bodies kung may legal obligation.
Kapag processor ang provider, ilalagay ng Sonpetit ang contractual safeguards na hinihingi ng law.
10. PAYMENT PROVIDERS
Maaaring professional providers ang mag-manage ng payments. Depende sa payment method, maaaring directly iproseso ng provider ang data upang:
- authorize transactions;
- verify identity;
- prevent fraud;
- comply with financial regulations;
- manage refunds;
- handle disputes.
Tatanggap lamang ang Sonpetit ng information na kailangan sa transaction status at order management maliban kung legally necessary ang iba.
11. TRANSPORT COMPANIES
Para sa delivery, maaaring ibigay sa carrier ang:
- name at surname;
- delivery address;
- phone;
- email;
- order reference;
- instructions na strictly necessary sa delivery.
Maaaring gamitin ito ng carrier para kontakin ang recipient, gawin ang delivery at manage logistics incidents.
12. INTERNATIONAL DATA TRANSFERS
Maaaring may technology providers sa labas ng EEA o gumagamit ng international infrastructure. Kung may international data transfer, sisikapin ng Sonpetit na magkaroon ng recognized GDPR mechanism, gaya ng:
- adequacy decision ng European Commission;
- standard contractual clauses;
- binding corporate rules;
- additional safeguards kung kailangan;
- iba pang legally accepted mechanisms.
Kapag applicable, maaaring i-assess ang circumstances at mag-apply ng supplementary measures.
13. RETENTION PERIODS
Pananatilihin lamang ang data habang kailangan sa purpose at pagkatapos sa periods na kailangan sa legal obligations o possible liabilities. General criteria: User account: habang active at pagkatapos sa period na kailangan sa legal obligations o claims. Orders, billing at commercial documents: ayon sa tax, commercial at accounting periods. Business documentation na legally required ay maaaring panatilihin ng anim na taon nang hindi naaapektuhan ang ibang legal periods. Customer service at complaints: habang kailangan sa request at sa period na maaaring magkaroon ng liability. Commercial communications: hanggang i-withdraw ang consent o gamitin ang right to object. Maaaring mag-retain ng minimal information sa suppression list upang hindi na padalhan ang nag-unsubscribe. Security at fraud prevention: reasonable period para investigate, prevent recurrence at, kung applicable, address legal liability. Kapag dapat nang burahin, maaaring manatiling blocked sa legal liability periods.
14. RIGHTS NG DATA SUBJECT
Kapag applicable, maaaring gamitin ang: Right of access: malaman kung nagpo-process ang Sonpetit ng data at makakuha ng information. Right of rectification: ipa-correct ang incorrect o incomplete information. Right of erasure: hilinging burahin kapag legal requirements are met. Hindi nito obligadong burahin ang data na kailangang i-retain para sa legal obligations o legal claims. Right to restriction: hilinging limitahan ang processing sa legal cases. Right to object: tumutol sa processing based on legitimate interest ayon sa personal situation. Maaaring tumutol anumang oras sa direct marketing. Right to portability: makatanggap ng certain data sa structured, commonly used at machine-readable format kung legal requirements are met. Right to withdraw consent: kapag consent ang basis, maaaring i-withdraw anumang oras. Hindi nito binabago ang lawfulness ng previous processing. Automated decisions: may safeguards ang data subject kapag solely automated decision ang may legal o similarly significant effect.
15. PAANO GAMITIN ANG RIGHTS
Maaaring magpadala ng request sa: SONPETIT BARCELONA S.L. Carrer del Pi Gros, 10 08349 Cabrera de Mar, Barcelona España O sa email: info@sonpetit.com Dapat reasonably matukoy ang requester at tukuyin ang right na gustong gamitin. Kung may reasonable doubt sa identity, maaaring humiling ang Sonpetit ng additional information na strictly necessary para verification at fraud prevention.
16. COMPLAINTS SA SUPERVISORY AUTHORITY
Kung naniniwala ang isang tao na nilabag ng Sonpetit ang data-protection law, maaari siyang magreklamo sa Agencia Española de Protección de Datos (AEPD), nang hindi naaapektuhan ang iba pang administrative o judicial remedies. Inirerekomenda ng Sonpetit na kontakin muna ang kumpanya upang subukang lutasin ang privacy issue.
17. MINORS
Nagbebenta ang Sonpetit ng products para sa bata, ngunit ang e-commerce service ay pangunahing para sa adults na bumibili. Hindi layunin ng Sonpetit na sadyang kumuha ng personal data ng minors kung hindi kailangan. Kung ang consent-based processing ay tungkol sa person below 14 years old, kailangan ang consent ng parent o guardian ayon sa Spanish law. Kung matukoy na hindi wastong nakatanggap ng information tungkol sa minor, maaaring gumawa ng reasonable steps upang burahin o gawing lawful ang processing.
18. SPECIAL CATEGORIES OF DATA
Bilang general rule, hindi kailangan ng Sonpetit ang data tungkol sa:
- health;
- racial o ethnic origin;
- political opinions;
- religion;
- trade-union membership;
- genetics;
- biometrics;
- sexual orientation o sex life.
Huwag ibigay ang ganitong information maliban kung may specific need at valid legal basis. Ang commercial features ng products, kabilang ang suitability sa certain skin types, ay hindi nangangahulugang kailangang malaman ng Sonpetit ang medical information ng customer o bata.
19. DATA SECURITY
Magpapatupad ang Sonpetit ng technical at organizational measures na naaangkop sa risk laban sa:
- accidental o unlawful destruction;
- loss;
- alteration;
- unauthorized disclosure;
- unauthorized access;
- credential theft;
- account abuse;
- cyberattacks.
Maaaring kabilang sa measures ang encryption, access controls, authentication, backups, security logs, system updates, permission segregation, monitoring, recovery measures at incident-management procedures. Gayunman, walang Internet-connected system na maaaring ituring na absolutely invulnerable.
20. SECURITY INCIDENTS AT DATA BREACHES
Kapag may security breach na nakakaapekto sa personal data, kikilos ang Sonpetit ayon sa legal obligations. Kapag required, ipo-notify ang supervisory authority at, sa mga kasong hinihingi ng law, ang affected data subjects.
21. COOKIES AT SIMILAR TECHNOLOGIES
Maaaring gumamit ang Sonpetit ng cookies at similar technologies na kailangan upang:
- maintain sessions;
- remember cart;
- manage purchase process;
- ensure security;
- retain technical preferences;
- prevent fraud.
Ang non-essential technologies gaya ng ilang analytics, advertising o tracking tools ay pamamahalaan ng Cookie Policy at ng choices sa consent-management system. Dapat may mechanism ang user upang accept o reject non-essential cookie categories at baguhin ang preferences later.
22. MARKETING AT UNSUBSCRIBE
Dapat malinaw na kilalanin ng promotional communications ang Sonpetit bilang sender. May simple at free method ang recipients para tumutol o mag-unsubscribe. Pagkatapos mag-unsubscribe, gagawa ang Sonpetit ng reasonable steps upang hindi na gamitin ang address sa new campaigns, bagaman maaaring limited itong i-retain sa suppression list. Ang transactional messages sa purchases, returns, security, payments o accounts ay hindi optional commercial communications kung kailangan sa service.
23. SOCIAL NETWORKS
Kapag nakikipag-interact ang tao sa official Sonpetit profiles sa social networks, maaaring iproseso ang data ng Sonpetit at platform operator ayon sa applicable terms at policies. Inirerekomendang basahin ang privacy policies ng bawat social network. Huwag gumamit ng public interaction para magbigay ng bank data, identity documents o ibang sensitive information.
24. THIRD-PARTY LINKS
Maaaring may links ang website sa third-party services o pages. Hindi karaniwang kontrolado ng Sonpetit ang privacy practices ng independent external pages at inirerekomendang basahin ang kanilang policies bago magbigay ng personal information.
25. PREVENTION NG ABUSE AT UNLAWFUL ACTIVITIES
Maaaring gumawa ang Sonpetit ng proportionate measures upang protektahan ang platform, customers at company laban sa fraud o abuse. Maaaring suriin ang transaction kapag may objective signs ng:
- payment fraud;
- account takeover;
- impersonation;
- multiple abnormal payment attempts;
- systematic promotion abuse;
- malicious automated activity;
- store-operation manipulation;
- system attacks;
- use of unlawfully obtained data.
Kung kailangan, maaaring mag-retain ng technical evidence at magbigay ng information sa payment providers, financial institutions, authorities o legally authorized recipients. Hindi nito nililimitahan ang data-protection rights ng data subject.
26. BLOCKING AT RETENTION PARA SA DEFENSE OF CLAIMS
Ang right to erasure ay hindi nangangahulugang kailangang agad burahin ang information na dapat i-retain dahil sa legal obligation. Kapag applicable, titigil ang ordinary use at maaaring panatilihing blocked lamang upang:
- address liabilities;
- prove transactions;
- respond to claims;
- comply with legal obligations;
- formulate, exercise o defend rights.
Pagkatapos ng applicable periods, securely buburahin o i-a-anonymize ang data.
27. MGA PAGBABAGO SA PRIVACY POLICY
Maaaring baguhin ang policy upang umangkop sa:
- legislative changes;
- authority criteria;
- case-law changes;
- new services;
- technology changes;
- provider changes;
- significant changes sa processing.
Ang current version ay laging available sa website. Kung materially naapektuhan ang consent-based processing, hihingi muli ng consent kapag legally required.
28. INTERPRETATION
Dapat i-interpret ang policy ayon sa Spanish at EU law sa data protection at information-society services. Walang provision na dapat ituring na waiver o limitation ng rights na ibinibigay ng law. Wala ring provision na pumipigil sa Sonpetit na tuparin ang legal obligations, gumawa ng proportionate security measures, prevent fraud o retain information kung may legal basis.
29. CONTACT
Para sa privacy, personal data o exercise of rights: SONPETIT BARCELONA S.L.
Carrer del Pi Gros, 10 08349 Cabrera de Mar, Barcelona, España