MANUFACTURAS HEPYC, S.A. (the “Company”) is an Organization in which personal data processing activities take place, which gives it an important responsibility in the design and organization of procedures so that they are aligned with legal compliance in this matter.
In the exercise of these responsibilities and in order to establish the general principles that should govern the processing of personal data in the Company, it approves this Policy for the protection of personal data, which notifies its Employees and makes available of all your interest groups.
The Personal Data Protection Policy is a measure of proactive Responsibility that aims to ensure compliance with the applicable legislation on this matter and in relation to it, respect for the right to honor and privacy in the processing of data. of a personal nature of all the people who are related to The Company.
In development of the provisions of this Personal Data Protection Policy, the Principles that govern the processing of data in the organization are established and, consequently, the procedures, and the organizational and security measures that the people affected by They undertake to implement this Policy in their area of responsibility.
To this end, the Management will assign responsibilities to the personnel who participate in data processing operations.
2. Scope of application
This Personal Data Protection Policy will be applicable to the Company, its administrators, managers and employees, as well as all the people who are related to it, expressly including the service providers with access to data (“Responsible for the treatment”)
3. Principles of the processing of personal data
As a general principle, The Company will scrupulously comply with the legislation on the protection of personal data and must be able to demonstrate it (Principle of "Proactive responsibility"), paying special attention to those treatments that may pose a greater risk to the rights of those affected (Principle of "risk approach").
In relation to the above, MANUFACTURAS HEPYC, S.A. will ensure compliance with the following Principles:
Legality, loyalty, transparency and limitation of the purpose. The data processing must always be informed to the affected party, through clauses and other procedures; and it will only be considered legitimate if there is consent for the processing of data (with special attention to that provided by minors), or it has another valid legitimacy and the purpose thereof is in accordance with the Regulations.
Minimization of data. The data processed must be adequate, pertinent and limited to what is necessary in relation to the purposes of the treatment.
Accuracy. The data must be exact and, if necessary, updated. In this regard, the necessary measures will be adopted so that personal data that are inaccurate with respect to the purposes of the treatment are deleted or rectified without delay.
Limitation of the conservation period. The data will be kept in a way that allows the identification of the interested parties for no longer than necessary for the purposes of the treatment.
Integrity and Confidentiality. The data will be treated in such a way as to guarantee adequate security of personal data, including protection against unauthorized or illegal treatment and against its loss, destruction or accidental damage, through the application of appropriate technical or organizational measures.
Data transfers. The purchase or obtaining of personal data from illegitimate sources or in those cases in which said data has been collected or transferred in contravention of the law or its legitimate origin is not sufficiently guaranteed.
Hiring of providers with access to data. Only suppliers that offer enough guarantees to apply appropriate technical and security measures in data processing will be chosen for their contracting. Due Agreement in this regard will be documented with these third parties.
International data transfers. All processing of personal data subject to European Union regulations that involves a transfer of data outside the European Economic Area must be carried out in strict compliance with the requirements established in the applicable law.
Rights of those affected. The Company will facilitate to those affected the exercise of the rights of access, rectification, deletion, limitation of treatment, opposition and portability, establishing for this purpose the internal procedures, and in particular the models for their exercise that are necessary and timely, which shall satisfy, at least, the legal requirements applicable in each case.
The Company will promote that the principles contained in this Policy for the protection of personal data are taken into account (i) in the design and implementation of all work procedures, (ii) in the products and services offered (iii) in all the contracts and obligations that they formalize or assume and (ii) in the implementation of any systems and platforms that allow the access of employees or third parties and / or the collection or processing of personal data.
4. Commitment of workers
Workers are informed of this Policy and declare that they are aware that personal information is an asset of the Company, and in this regard, they adhere to it, committing to the following:
Carry out the awareness training on Data Protection that the Company makes available to them.
Apply the security measures at the user level that apply to their job position, without prejudice to the responsibilities in their design and implementation that may be attributed to them based on their role within MANUFACTURAS HEPYC, S.A. .
Use the formats established for the exercise of Rights by those affected and inform the Company immediately so that the response can be made effective.
Inform the Company, as soon as it becomes aware, of deviations from what is established in this Policy, in particular "Violations of personal data security", using the format established for this purpose.
5. Control and evaluation
An annual verification, evaluation and assessment will be carried out, or each time there are significant changes in the data processing, of the effectiveness of the technical and organizational measures to guarantee the security of the processing.
For what purposes is my information used and who uses it?
This Website uses its own cookies and those of other entities, in order to access and use your information for the purposes indicated below. If you do not agree with any of these purposes, you can customize your options through this screen.
Store user information about their choices when using the web.
In order to maintain session data throughout the duration of the visit, the website uses session cookies that store the status of the user's session, as well as information necessary to display alert messages. It is necessary for the proper functioning of the web.
Store web usage statistics.