Introduction

This Privacy Policy has been prepared taking into account the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, hereinafter the GDPR.

The purpose of this Privacy Policy is to inform the holders of personal data about what information is collected, the specific aspects related to the processing of their data and, among other matters, the purposes of processing, contact details for exercising their rights, information retention periods and the security measures applied.

Data controller

For data protection purposes, Data Events Services, S.L. must be considered the Data Controller in relation to the files/processing operations it manages.

The identifying details of the owner of this website are listed below:
Registered office postal address: C/ Ferrol, 2. Urb. La Barcia – 15897 Santiago de Compostela, A Coruna
Email: info@cyex.es
Telephone: +34 981 555 720

Data processing

The personal data requested, where applicable, will consist only of the data strictly necessary to identify and handle the request made by its holder, hereinafter the data subject. Such information will be processed fairly, lawfully and transparently in relation to the data subject.

In addition, personal data will be collected for specific, explicit and legitimate purposes and will not be further processed in a manner incompatible with those purposes. The data collected from each data subject will be adequate, relevant and not excessive in relation to the purposes corresponding to each case, and will be kept up to date when necessary.

The data holder will be informed, before the data are collected, of the general aspects regulated in this policy so that they may give their express, specific and unequivocal consent to the processing of their data, in accordance with the aspects set out below.

Purposes of processing

The specific purposes for which each processing operation is carried out are included in the information clauses incorporated into each data collection channel (web forms, paper forms, voice recordings or posters and information notices).

In general, the data provided by the data subject will be processed, in each case, for the following purposes:

  • Managing presentations, events or congresses promoted by the entity.
  • Sending information about activities and events promoted by the entity.
  • Managing transfers, travel and accommodation for congress or event attendees.
  • Managing accreditations, attendance certificates or suggestions related to the event.
  • Handling queries, complaints, suggestions or any other request processed through the relevant section of the website.

However, the data subject’s personal data will be processed only for the purpose of providing an effective response and handling the requests made by the user, as specified together with the option, service, form or data collection system used by the holder.

Legal basis

In general, before processing personal data, Data Events Services, S.L. obtains the express and unequivocal consent of the data holder through the inclusion of informed consent clauses in the different information collection systems.

However, in cases where the data subject’s consent is not required, the legal basis for the processing carried out by Data Events Services, S.L. will be the existence of a specific law or regulation that authorizes or requires the processing of the data subject’s data.

Recipients

In general, Data Events Services, S.L. does not transfer or disclose data to third parties, except in the cases provided for by law.

However, where necessary, such data transfers or disclosures will be communicated to the data subject through the informed consent clauses contained in the different methods used to collect personal data, such as the communication of data to the entities responsible for accommodation and transfers for attendees.

Source

In general, personal data are always collected directly from the data subject. However, in certain exceptional cases, data may be collected through third parties, entities or services other than the data subject.

In such cases, this circumstance will be communicated to the data subject through the informed consent clauses included in the different means of collecting information and within a reasonable period after obtaining the data, and in any case within a maximum period of one month.

Retention periods

The information collected from the data subject will be kept for the time necessary to fulfil the purpose for which the personal data were collected. Once that purpose has been fulfilled, the data will be cancelled.

Cancellation will result in the blocking of the data, which will be kept only at the disposal of Public Administrations, Judges and Courts in order to address any liabilities arising from the processing during the applicable limitation period. Once that period has elapsed, the information will be destroyed.

Browsing data

With regard to browsing data that may be processed through the website, if data subject to regulations are collected, we recommend consulting the Cookie Policy published on our website.

Rights of data subjects

Data protection regulations recognize a series of rights for data subjects or data holders, website users or users of the social media profiles of Data Events Services, S.L. The rights available to data subjects are the following:

  • Right of access: the right to obtain information about whether personal data concerning them are being processed, the purpose of the processing, the categories of data concerned, the recipients or categories of recipients, the retention period and the source of those data.
  • Right to rectification: the right to have inaccurate or incomplete personal data rectified.
  • Right to erasure: the right to have data erased in the following cases:
    • When the data are no longer necessary for the purpose for which they were collected.
    • When the holder withdraws consent.
    • When the data subject objects to the processing.
    • When the data must be erased in order to comply with a legal obligation.
    • When the data have been obtained by virtue of an information society service in accordance with article 8.1 of the GDPR.
  • Right to object: the right to object to a specific processing operation based on the consent of the data subject.
  • Right to restriction: the right to obtain restriction of data processing when any of the following circumstances apply:
    • When the data subject contests the accuracy of the personal data, for a period allowing the company to verify their accuracy.
    • When the processing is unlawful and the data subject objects to the erasure of the data.
    • When the company no longer needs the data for the purposes for which they were collected, but the data subject needs them for the establishment, exercise or defence of legal claims.
    • When the data subject has objected to processing, pending verification of whether the legitimate grounds of the company override those of the data subject.

Data subjects may exercise the rights indicated by contacting Data Events Services, S.L. in writing at the following email address: info@cyex.es, indicating in the subject line the right they wish to exercise.

In this regard, Data Events Services, S.L. will respond to the request as soon as possible and taking into account the deadlines established in data protection regulations. Likewise, it should be noted that the data subject or data holder may, at any time, lodge a complaint with the competent supervisory authority.

Security

The security measures adopted by Data Events Services, S.L. are those required in accordance with article 32 of the GDPR.

In this regard, Data Events Services, S.L., taking into account the state of the art, implementation costs and the nature, scope, context and purposes of processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, has established appropriate technical and organizational measures to ensure a level of security appropriate to the existing risk.

In any case, Data Events Services, S.L. has implemented sufficient mechanisms to:

  • Ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
  • Restore the availability of and access to personal data quickly in the event of a physical or technical incident.
  • Regularly verify, evaluate and assess the effectiveness of the technical and organizational measures implemented to guarantee the security of processing.
  • Pseudonymize and encrypt personal data where appropriate.