Privacy Policy

WEBSITE PRIVACY POLICY

https://daliaglobal.com/

I. PRIVACY AND DATA PROTECTION POLICY

In accordance with applicable legislation, Dalia Global (hereinafter also the “Website”) undertakes to adopt the technical and organisational measures required, commensurate with the level of security appropriate to the risk posed by the collected data.

Laws incorporated into this privacy policy

This privacy policy is aligned with current Spanish and European regulations on the protection of personal data on the Internet. In particular, it complies with the following rules:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR).
  • Organic Law 3/2018 of 5 December on Personal Data Protection and the guarantee of digital rights (LOPD‑GDD).
  • Royal Decree 1720/2007 of 21 December approving the implementing regulation of Organic Law 15/1999 of 13 December on the Protection of Personal Data (RDLOPD).
  • Law 34/2002 of 11 July on Information Society Services and Electronic Commerce (LSSI‑CE).

Identity of the data controller

The controller of the personal data collected on Dalia Global is: DALIA GLOBAL SERVICES, SL, with Tax ID (NIF): B8803800, registered with the Madrid Commercial Registry under the following registration details: Volume 39726, Page 96, Section 8, Sheet M‑705867, Entry 1, whose representative is Dalia Global (hereinafter, the “Controller”). The Controller’s contact details are as follows:

Address: CR FUENCARRAL, KM 22, NET PHARMA BUILDING, ALCOBENDAS, MADRID, 28108

Contact telephone: 910 88 41 88

Contact email: info@daliaglobal.com

Personal Data Register

In compliance with the GDPR and the LOPD‑GDD, we inform you that the personal data collected by Dalia Global through the forms made available on its pages will be incorporated and processed in our records in order to facilitate, streamline and fulfil the commitments established between Dalia Global and the User, to maintain the relationship established through the forms completed by the User, or to respond to a request or enquiry.
Likewise, in accordance with the GDPR and the LOPD‑GDD, and unless the exception provided in Article 30.5 of the GDPR applies, a record of processing activities is maintained, specifying (by purpose) the processing activities carried out and the other circumstances established in the GDPR.

Principles applicable to the processing of personal data

The processing of the User’s personal data shall be subject to the following principles set out in Article 5 of the GDPR and Article 4 et seq. of Organic Law 3/2018 of 5 December on Personal Data Protection and the guarantee of digital rights:

  • Principle of lawfulness, fairness and transparency: the User’s consent will be required at all times, following fully transparent information regarding the purposes for which personal data are collected.
  • Principle of purpose limitation: personal data will be collected for specified, explicit and legitimate purposes.
  • Principle of data minimisation: the personal data collected will be only those strictly necessary for the purposes for which they are processed.
  • Principle of accuracy: personal data must be accurate and kept up to date.
  • Principle of storage limitation: personal data will be kept in a form that permits identification of the User only for as long as necessary for the purposes of processing.
  • Principle of integrity and confidentiality: personal data will be processed in a manner that ensures their security and confidentiality.
  • Principle of accountability: the Controller shall be responsible for ensuring compliance with the foregoing principles.

Categories of personal data

The categories of data processed on Dalia Global are limited to identification data. Under no circumstances are special categories of personal data processed within the meaning of Article 9 of the GDPR.

Legal basis for processing personal data

The legal basis for processing personal data is consent. Dalia Global undertakes to obtain the User’s express and verifiable consent for the processing of their personal data for one or more specific purposes.

The User has the right to withdraw consent at any time. Withdrawing consent will be as easy as giving it. As a general rule, withdrawal of consent will not affect use of the Website.

Where the User must or may provide data through forms to submit enquiries, request information, or for reasons related to the Website content, the User will be informed if completion of any field is mandatory because it is essential for the proper performance of the relevant operation.

Purposes of the processing for which personal data are intended

Personal data is collected and managed by Dalia Global for the purpose of facilitating, expediting and fulfilling the commitments established between the Website and the User or maintaining the relationship established in the forms filled out by the latter or to respond to a request or query.

Similarly, the data may be used for commercial purposes of personalisation, operations and statistics, and activities related to the corporate purpose of Dalia Global, as well as for data extraction, storage and marketing studies to tailor the Content offered to the User, and to improve the quality, functioning and navigation of the Website.

At the time the personal data is obtained, the User will be informed of the specific purpose or purposes for which the personal data will be processed; that is, the use or uses that will be made of the information collected.

Retention periods for personal data

Personal data will be retained only for the minimum time necessary for the purposes of processing and, in any event, only for the following period: 24 months, or until the User requests deletion.

At the time personal data are obtained, the User will be informed of the period for which personal data will be stored or, where this is not possible, the criteria used to determine that period.

Recipients of personal data

The User’s personal data will be shared with the following recipients or categories of recipients:

Google, Google Analytics

If the Controller intends to transfer personal data to a third country or an international organisation, the User will be informed, at the time the personal data are obtained, of the third country or international organisation to which the data are intended to be transferred, as well as the existence or absence of an adequacy decision by the Commission.

Personal data of minors

In accordance with Articles 8 of the GDPR and 7 of Organic Law 3/2018 of 5 December on Personal Data Protection and the guarantee of digital rights, only persons over 14 years of age may lawfully consent to the processing of their personal data by Dalia Global. If the User is under 14 years of age, parental or guardian consent will be required for processing, and processing will be lawful only insofar as such consent has been granted.

Confidentiality and security of personal data

Dalia Global undertakes to adopt the technical and organisational measures required, commensurate with the level of security appropriate to the risk posed by the collected data, so as to ensure the security of personal data and prevent accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed, as well as unauthorised disclosure of or access to such data.

The Website has an SSL (Secure Socket Layer) certificate, ensuring that personal data are transmitted securely and confidentially, as the data transmission between the server and the User (and back) is fully encrypted.

However, since Dalia Global cannot guarantee the impregnability of the Internet or the total absence of hackers or others who may fraudulently access personal data, the Controller undertakes to inform the User without undue delay when a personal data security breach occurs that is likely to pose a high risk to the rights and freedoms of natural persons. In accordance with Article 4 of the GDPR, a personal data security breach means any breach of security leading to the accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed, or to the unauthorised disclosure of or access to such data.

Personal data will be treated as confidential by the Controller, who undertakes to inform and ensure, through a legal or contractual obligation, that such confidentiality is respected by its employees, associates and any person to whom it makes the information accessible.

Rights arising from the processing of personal data

The User has the following rights with respect to Dalia Global and may therefore exercise them before the Controller, as recognised in the GDPR and Organic Law 3/2018 of 5 December on Personal Data Protection and the guarantee of digital rights:

  • Right of access: This is the User’s right to obtain confirmation as to whether or not Dalia Global is processing their personal data and, if so, to obtain information about their specific personal data and the processing that Dalia Global has carried out or is carrying out, as well as, among other things, the information available about the origin of such data and the recipients of the communications made or planned.
  • Right to rectification: the User’s right to have personal data corrected where they are inaccurate or, taking into account the purposes of processing, incomplete.
  • Right to erasure (“right to be forgotten”): the User’s right—unless current legislation provides otherwise—to obtain the erasure of personal data when they are no longer necessary for the purposes for which they were collected or processed; the User has withdrawn consent and there is no other legal basis; the User objects to processing and there are no overriding legitimate grounds; the personal data have been unlawfully processed; the data must be erased to comply with a legal obligation; or the data were obtained in connection with a direct offer of information society services to a child under 14 years of age.
    In addition to erasing the data, the Controller, taking into account available technology and the cost of implementation, must take reasonable steps to inform controllers processing the personal data of the data subject’s request for erasure of any links to those personal data.
  • Right to restriction of processing: the User’s right to restrict the processing of their personal data. The User has the right to obtain restriction when they contest the accuracy of their personal data; processing is unlawful; the Controller no longer needs the personal data but the User needs them for claims; or the User has objected to processing.
  • Right to data portability: where processing is carried out by automated means, the User has the right to receive their personal data from the Controller in a structured, commonly used and machine‑readable format, and to transmit them to another controller. Where technically feasible, the Controller will transmit the data directly to that other controller.
  • Right to object: the User’s right to object to the processing of their personal data or to request that Dalia Global cease processing.
  • Right not to be subject to a decision based solely on automated processing, including profiling: the User’s right not to be subject to an individual decision based solely on automated processing of their personal data, including profiling, unless current legislation provides otherwise.

Accordingly, the User may exercise their rights by written communication addressed to the Controller, referencing “RGPD‑https://daliaglobal.com/”, specifying:

  • The User’s name and surname(s), and a copy of their ID. Where representation is permitted, identification of the representative by the same means will also be required, as well as proof of representation. A photocopy of the ID may be replaced by any other legally valid means proving identity.
  • A request stating the specific reasons for the application or the information to be accessed.
  • Address for notifications.
  • Date and signature of the applicant.
  • Any document supporting the request.

This request and any supporting documents may be sent to the following address and/or email:

Postal address: CR FUENCARRAL, KM 22, NET PHARMA BUILDING, ALCOBENDAS, MADRID, 28108

Email: info@daliaglobal.com

Links to third‑party websites

The Website may include hyperlinks or links allowing access to third‑party webpages other than Dalia Global, and therefore not operated by Dalia Global. The owners of such websites will have their own data‑protection policies and will, in each case, be responsible for their own files and privacy practices.

Complaints to the supervisory authority

If the User considers that there is a problem or infringement of current regulations in the way their personal data are being processed, they have the right to effective judicial protection and to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement. In Spain, the supervisory authority is the Spanish Data Protection Agency (AEPD).

II. ACCEPTANCE AND CHANGES TO THIS PRIVACY POLICY

The User must have read and agree with the personal data protection conditions contained in this Privacy Policy, and accept the processing of their personal data so that the Controller may process them in the manner, for the periods and for the purposes indicated. Use of the Website implies acceptance of this Privacy Policy.

Dalia Global reserves the right to amend its Privacy Policy at its discretion or as a result of legislative, case‑law or doctrinal changes from the Spanish Data Protection Agency. Changes or updates to this Privacy Policy will not be explicitly notified to the User. Users are advised to consult this page periodically to stay informed of the latest changes or updates.

This Privacy Policy was updated to comply with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and Organic Law 3/2018 of 5 December on Personal Data Protection and the guarantee of digital rights.