Privacy policy

1. Record of processing activities

Treatment: clients
Responsible for the treatment
  • Company name: THE RIBAGORZA REGION
  • Tax ID: P-2200126-G.
  • Registered office: Plaza Mayor, 17. 22430, Graus (Huesca)
  • Phone: 974 540 385
  • Email: tourism@cribagorza.org
  • Data Protection Officer: THE RIBAGORZA REGION
  • DPD contact: Plaza Mayor, 17. 22430, Graus (Huesca)
  • Phone: 974 540 385
Purposes of the processing Customer relationship management
Categories of interested parties Clients: People with whom a commercial relationship is maintained as clients
Data categories The information necessary for maintaining the business relationship. Invoicing, sending advertising by mail or email, after-sales service, and customer loyalty programs. Identification details: name and surname, tax identification number (NIF), postal address, telephone numbers, email address. Bank details: for direct debit payments.
Recipient categories State Tax Administration Agency, National Social Security Institute, banks and financial entities, Security Forces and Corps.
International transfers International transfers are not planned.
Deletion period Those provided for by tax legislation regarding the statute of limitations for liabilities.
Security measures Those reflected in the SECURITY MEASURES ANNEX.
Treatment: potential clients
Responsible for the treatment
  • Company name: THE RIBAGORZA REGION
  • Tax ID: P-2200126-G.
  • Registered office: Plaza Mayor, 17. 22430, Graus (Huesca)
  • Phone: 974 540 385
  • Email: tourism@cribagorza.org
  • Data Protection Officer: THE RIBAGORZA REGION
  • DPD contact: Plaza Mayor, 17. 22430, Graus (Huesca)
  • Phone: 974 540 385
Purposes of the processing Managing relationships with potential customers
Categories of interested parties Potential customers: People with whom you want to maintain a business relationship as customers
Data categories The information necessary for the company's commercial promotion. Identification details: name and surname, postal address, telephone numbers and email.
Recipient categories Marketing agency
International transfers International transfers are not planned
Deletion period One year from the first contact
Security measures Those reflected in the ANNEX SECURITY MEASURES
Treatment: customers employees
Responsible for the treatment
  • Company name: THE RIBAGORZA REGION
  • Tax ID: P-2200126-G.
  • Registered office: Plaza Mayor, 17. 22430, Graus (Huesca)
  • Phone: 974 540 385
  • Email: tourism@cribagorza.org
  • Data Protection Officer: THE RIBAGORZA REGION
  • DPD contact: Plaza Mayor, 17. 22430, Graus (Huesca)
  • Phone: 974 540 385
Purposes of the processing Managing the employment relationship with employees
Categories of interested parties Employees: People who work for the data controller
Data categories The information necessary for maintaining the employment relationship. Payroll and training management. Identification details: name, surname, Social Security number, postal address, telephone numbers, and email address. Personal characteristics: marital status, date and place of birth, age, gender, nationality, and percentage of disability. Academic details. Professional details. Bank details for direct debit of payroll payments.
Recipient categories State Tax Administration Agency, National Social Security Institute, banks and financial entities.
International transfers International transfers are not planned
Deletion period Those provided for by tax and labor legislation regarding the statute of limitations for liabilities
Security measures Those reflected in the ANNEX SECURITY MEASURES
Treatment: Candidates
Responsible for the treatment
  • Company name: THE RIBAGORZA REGION
  • Tax ID: P-2200126-G.
  • Registered office: Plaza Mayor, 17. 22430, Graus (Huesca)
  • Phone: 974 540 385
  • Email: tourism@cribagorza.org
  • Data Protection Officer: THE RIBAGORZA REGION
  • DPD contact: Plaza Mayor, 17. 22430, Graus (Huesca)
  • Phone: 974 540 385
Purposes of the processing Managing the relationship with job applicants at the company
Categories of interested parties Candidates: People who want to work for the data controller
Data categories The information necessary to manage the resumes of potential future employees. Identification data: name, surname, postal address, telephone numbers, and email address. Personal characteristics: marital status, date and place of birth, age, gender, nationality, and other relevant information, excluding data on race, health, or union affiliation. Academic data. Professional data.
Recipient categories The sending of personal data to any recipient is not contemplated.
International transfers International transfers are not planned
Deletion period One year since the candidacy was submitted
Security measures Those reflected in the ANNEX SECURITY MEASURES
Treatment: Providers
Responsible for the treatment
  • Company name: THE RIBAGORZA REGION
  • Tax ID: P-2200126-G.
  • Registered office: Plaza Mayor, 17. 22430, Graus (Huesca)
  • Phone: 974 540 385
  • Email: tourism@cribagorza.org
  • Data Protection Officer: THE RIBAGORZA REGION
  • DPD contact: Plaza Mayor, 17. 22430, Graus (Huesca)
  • Phone: 974 540 385
Purposes of the processing Supplier relationship management
Categories of interested parties Suppliers: People with whom a commercial relationship is maintained as suppliers of products and / or services
Data categories The information necessary for maintaining the business relationship. Identification details: name, tax identification number (NIF), postal address, telephone numbers, and email address. Bank details: for direct debit payments.
Recipient categories State Tax Administration Agency, banks and financial entities.
International transfers International transfers are not planned
Deletion period Those provided by tax legislation regarding the prescription of responsibilities
Security measures Those reflected in the ANNEX SECURITY MEASURES

2. Information of general interest

This document has been designed for low-risk personal data processing from which it is deduced that it cannot be used for personal data processing that includes personal data related to ethnic or racial origin, religious or philosophical political ideology, union affiliation, data genetic and biometric data, health data, and data on people's sexual orientation, as well as any other data processing that involves high risk for people's rights and freedoms.

Article 5.1.f of the General Data Protection Regulation (hereinafter, GDPR) establishes the need to implement appropriate security measures against unauthorized or unlawful processing, loss of personal data, accidental destruction, or damage. This entails implementing technical and organizational measures to ensure the integrity and confidentiality of personal data and the ability to demonstrate, as established in Article 5.2, that these measures have been put in place (proactive accountability). Furthermore, organizations must establish visible, accessible, and user-friendly mechanisms for exercising data protection rights and have defined internal procedures to ensure the effective handling of requests received.

3. Attention to the exercise of rights

The person responsible for the treatment will inform all workers about the procedure to address the rights of the interested parties, clearly defining the mechanisms by which the rights can be exercised (electronic means, reference to the Data Protection Delegate, if any, postal address , etc.) and taking into account the following:

Upon presentation of their national identity document or passport, the holders of personal data (interested parties) may exercise their rights of access, rectification, deletion, opposition, portability and limitation of treatment. The exercise of rights is free.

The person in charge of the treatment must respond to the interested parties without undue delay and in a concise, transparent, intelligible way, with a clear and simple language and retain the proof of compliance with the duty to respond to the requests for the exercise of rights made.

If the request is submitted by electronic means, the information will be provided by these means whenever possible, unless the interested party requests otherwise.

Requests must be answered within 1 month of receipt, and may be extended for another two months taking into account the complexity or number of requests, but in that case the interested party must be informed of the extension within a month from of receipt of the request, indicating the reasons for the delay.

 

Right of access

The right of access entitles data subjects to a copy of their personal data held, along with the purpose for which it was collected, the identity of the recipients, the envisaged retention periods or the criteria used to determine them, the existence of the right to request rectification or erasure of personal data, as well as the restriction or objection to its processing, the right to lodge a complaint with the Spanish Data Protection Agency, and, if the data was not obtained from the data subject, any available information as to its source. The right to obtain a copy of the data may not adversely affect the rights and freedoms of other data subjects.

Form for exercising the right of access.

 

Right of rectification

In the right of rectification, the data of the interested parties that were inaccurate or incomplete will be modified according to the purposes of the treatment. The interested party must indicate in the request what data they refer to and the correction to be made, providing, when necessary, supporting documentation of the inaccuracy or incompleteness of the data being processed. If the data has been communicated by the person in charge to other managers, they must notify them of the rectification of these unless it is impossible or requires a disproportionate effort, providing the interested party with information about said recipients, if requested.

Form for the exercise of the right of rectification

 

Right of suppression

In the right of deletion, the data of the interested parties will be deleted when they express their refusal to treatment and there is no legal basis that prevents it, they are not necessary in relation to the purposes for which they were collected, they withdraw the consent given and there is no another legal basis that legitimizes the treatment or it is illegal. If the deletion derives from the exercise of the interested party's right of opposition to the processing of their data for marketing purposes, the identification data of the interested party may be kept in order to prevent future processing. If the data has been communicated by the person in charge to other managers, they must notify them of the deletion of these unless it is impossible or requires a disproportionate effort, providing the interested party with information about said recipients, if requested.

Form for exercising the right to erasure.

 

Right of opposition

In the right of opposition, when the interested parties express their refusal to process their personal data before the person in charge, he will stop processing them as long as there is no legal obligation that prevents it. When the treatment is based on a mission of public interest or the legitimate interest of the person in charge, upon a request to exercise the right of opposition, the person in charge will stop processing the data unless compelling reasons are proven that prevail over the interests, rights and freedoms of the interested party or are necessary for the formulation, exercise or defense of claims. If the interested party opposes the treatment for direct marketing purposes, the personal data will no longer be processed for these purposes.

Form for exercising the right to object.

 

Right of portability

In the portability right, if the treatment is carried out by automated means and is based on consent or is carried out within the framework of a contract, the interested parties may request to receive a copy of their personal data in a structured format, for common use and reading. mechanics. Likewise, they have the right to request that they be transmitted directly to a new person in charge, whose identity must be communicated, when technically possible.

Form for exercising the right to data portability.

 

Right of limitation of treatment

Under the right to restriction of processing, data subjects may request the suspension of the processing of their data to contest its accuracy while the controller carries out the necessary verifications, or if the processing is based on the controller's legitimate interests or is carried out in the public interest, while it is verified whether these grounds override the data subject's interests, rights, and freedoms. Data subjects may also request the retention of their data if they consider the processing unlawful and, instead of erasure, request restriction of processing, or if, even though the controller no longer needs the data for the purposes for which it was collected, the data subject requires it for the establishment, exercise, or defense of legal claims. The fact that the processing of the data subject's data is restricted must be clearly indicated in the controller's systems. If the data has been disclosed by the controller to other controllers, the controller must notify them of the restriction of processing unless this proves impossible or involves disproportionate effort, providing the data subject with information about those recipients upon request.

Form for the exercise of the limitation of the treatment.

 

If the interested party's request is not followed up, the data controller will inform them, without delay and no later than one month after receiving the request, of the reasons for their non-action and the possibility of filing a claim with the Agency. Spanish Data Protection and to exercise legal actions.

4 Security measures

4.1. Organizational measures

All personnel with access to personal data must be aware of their obligations regarding the processing of personal data and will be informed about these obligations.

The minimum information that will be known by all staff will be the following:

 

Duty of confidentiality and secrecy

Access by unauthorized persons to personal data should be avoided. To this end, leaving personal data exposed to third parties will be avoided (unattended electronic screens, paper documents in public access areas, media with personal data, etc.). This consideration includes the screens used to display images from the video surveillance system. When you are absent from your job, the screen will be blocked or the session will be closed.

Paper documents and electronic media will be stored in a safe place (cabinets or restricted access rooms) 24 hours a day.

Documents or electronic media (CDs, pen drives, hard drives, etc.) with personal data will not be discarded without guaranteeing their effective destruction

Personal data or any other information of a personal nature will not be communicated to third parties, paying special attention not to disclose protected personal data during telephone consultations, emails, etc.

The duty of secrecy and confidentiality persists even when the worker's employment relationship with the company ends.

 

Personal data security breaches

When personal data security breaches occur, such as theft or unauthorized access to personal data, the Spanish Data Protection Agency will be notified within 72 hours of such security breaches, including all the information necessary to clarify the facts that led to the unauthorized access to personal data.

The notification will be made electronically through the electronic headquarters of the Spanish Data Protection Agency at the following address https://sedeagpd.gob.es/sede-electronica-web/.

4.2. Technical Measures

Identification

When the same computer or device is used for the processing of personal data and personal use purposes, it is recommended to have several different profiles or users for each of the purposes. Professional and personal use of the computer should be kept separate.

It is recommended to have profiles with administration rights for the installation and configuration of the system and users without privileges or administration rights for access to personal data. This measure will prevent access privileges from being obtained or modifying the operating system in the event of a cybersecurity attack.

The existence of passwords for access to personal data stored in electronic systems will be guaranteed. The password will have at least 8 characters, a mixture of numbers and letters.

When personal data is accessed by different people, for each person with access to personal data, there will be a specific username and password (unequivocal identification).

Password confidentiality must be guaranteed, preventing them from being exposed to third parties. For password management, you can consult the online privacy and security guide from the Spanish Data Protection Agency and the National Cybersecurity Institute. Under no circumstances should passwords be shared or written down in a common place, and access should be restricted to those other than the user.

 

Duty to safeguard

Below are the minimum technical measures to guarantee the safeguarding of personal data:

  • UPDATING COMPUTERS AND DEVICES: The devices and computers used for the storage and processing of personal data must be kept up-to-date as much as possible.
  • MALWARE: Computers and devices where automated processing of personal data takes place must have an antivirus system in place to ensure, as far as possible, the prevention and destruction of personal information and data. The antivirus system must be updated regularly.
  • FIREWALL: To prevent unauthorized remote access to personal data, we will ensure that a firewall is activated and correctly configured on the computers and devices where personal data is stored and/or processed.
  • DATA ENCRYPTION: When it is necessary to extract personal data from the premises where it is processed, whether by physical or electronic means, the possibility of using an encryption method should be considered to guarantee the confidentiality of personal data in case of unauthorized access to the information.
  • BACKUP: A backup copy will be periodically made on a separate storage medium from the one used for daily work. This copy will be stored in a secure location, separate from the computer containing the original files, to allow for the recovery of personal data in case of data loss.

Security measures will be reviewed periodically; the review may be carried out by automated mechanisms (software or computer programs) or manually.