Kit Surprise is fully committed to complying with Spanish and European personal data protection regulations and ensuring full compliance with the obligations set forth, as well as implementing the security measures detailed in the General Data Protection Regulation (GDPR) (EU) 2016/679 and Law 3/2018, of 5th December, on Data Protection and Digital Rights (LOPD and GDD, hereinafter LOPD).
Pursuant to these regulations, you are hereby informed that use of our website may require that certain personal data be collected through contact forms, or by sending emails, that will be processed by Kit Surprise, the Data Controller, whose information is as follows:
- Company Name: Kit Surprise SLU
- Trade Name: Kit Surprise
- Tax ID Number: B67968768
- Registered Office: C/ Anselmo Lorenzo 26, 4º Izq. – 28044, Madrid, España
- Telephone: 659 093 837
- Email: firstname.lastname@example.org
Collection and processing of personal data
Personal data is any information concerning a person: name, email address, postal address, telephone number, tax ID number, etc. Additionally, when the User visits our website, certain information is automatically stored for technical reasons, such as the IP address assigned by the User’s internet service provider.
Kit Surprise, as the Data Controller, must suitably inform Users of this website about the collection of personal data that may be carried out, either by sending an email or by filling in the forms included on the site.
Only the data necessary to perform the hired service, or to be able to respond appropriately to the request for information made by the User, will be obtained. The data collected are identification data and they correspond to a reasonable minimum required to carry out the activity requested. Specifically, no specially protected data is collected at any time. Under no circumstances will Kit Surprise use the data obtained for purposes different to the purpose agreed with the User.
Contact form/email address.
Purpose: To respond to the User’s request for information made through our contact form/s.
Legitimation: The legal basis that legitimises this form of processing is the User’s consent, which may be withdrawn at any time.
Data transfer: Siteground it will do so as the Data Processor.
Registration/customer registration forms
- To manage your user registration on our website.
- To manage the purchases made.
- To provide information on the processing and status of purchases.
- To maintain a historic record of the purchases made on our website.
- To manage comments and contents.
- To send correspondence via email and/or communicate by telephone in order to inform the User of possible incidents, errors, issues and/or the status of orders.
Legitimation: The legal basis that legitimises this form of processing is execution of a contract.
Data transfer: Kit Surprise will not transfer or communicate your data to any third parties unless legally obliged to do so or when provision of a service involves the need for a contractual relationship with a Data Processor.
Specifically, the data may be transferred to:
– Technology service providers
– Payment service providers
– Courier and parcel companies
– Third parties or intermediaries, as service providers, operating on our own behalf.
Data transfers will occur in compliance with the strictest confidentiality, using the necessary measures, such as the signing of confidentiality contracts, or adherence to their privacy policies established on their respective websites. The User may refuse to transfer their data to the Processors, by written request, by any of the means previously referenced.
Furthermore, in some cases when necessary, customers’ data may be transferred to certain bodies in compliance with a legal obligation: Spanish Tax Administration Agency, banking entities, Labour Inspectorate, etc.
Purpose: Post your comment or review on the website.
Legitimation: The legal basis that legitimizes this processing is the consent of the User, which may revoke at any time.
Transfer of data: Personal data will be processed through the servers of this website, managed by Siteground, which will be considered as Data Processor.
Minimum age restriction
Only persons over 14 years of age may use this website. As required by the LOPD and GDD, in the case of children under 14 years of age, the consent of their parents or guardians will be mandatory for us to process their data.
On the other hand, only people over the age of 18 can hire our services. In case of children under 18 years of age, the consent of their parents or legal guardians will be mandatory so that we can provide the services offered, unless the minor is emancipated.
Registration of users
When the User registers using the corresponding form, the information we gather includes the following:
- Name and surname/s
- Email address and/or telephone number
- Postal addresses
- IP address
The User must provide a password, which must meet certain security requirements. They don’t expire. To recover the password the User must go to the specific recovery form and enter his/her email to continue the process and be able to modify it, by clicking on the link that will be sent to the email address entered. The User is responsible for maintaining the confidentiality of their password, as well as for all uses the User makes of it. You must inform “Kit Surprise” of any unauthorized use of your account or password as soon as possible.
Once registered, the User will have access to a private panel on which they may view certain content, a record of purchases made, etc. They may also manage account options, such as their password or data.
The User may receive the following notifications:
- When registering on the platform (account validation email).
- When making purchases. These include purchase confirmation, incidents, delivery sent, etc.
- By comments made, and responses to them.
- To recover their password (specified in the previous section).
- When unsubscribing or deleting the account.
Kit Surprise hereby informs Users that the necessary technical, organisational and security measures available to us have been taken to prevent the loss, misuse, alteration, unauthorised access or theft of data, and thus guarantee the confidentiality, integrity, and quality of the information contained therein, in accordance with data protection regulations in force. The personal data collected using forms are processed only by the staff of Kit Surprise or designated processors.
The Kit Surprise website also has SSL encryption, which allows Users to safely send their data using the website’s contact forms.
Veracity of data
The User states that all data they provide are true and correct, and they agree to keep them up to date. The User will be responsible for the truthfulness of their data and will be solely liable for any conflicts or disputes that may result from their falsification. It is essential that, for us to keep personal data up to date, the User informs Kit Surprise whenever there has been any modification to their data.
“Kit Surprise” will not transfer or communicate to any third party your data, except in the cases legally provided or where the provision of a service implies the need for a contractual relationship with a Processor. The User accepts that some of the personal data collected will be provided to these Data Processors (payment platforms, processing agencies, intermediaries, etc.), when it’ll be necessary for the effective performance of a contracted service or product acquired. The User also agrees that, in the event of the provision of services, these may be, in whole or in part, subcontracted to other persons or companies, which will be considered as Data Processors, with which the corresponding contract of confidentiality, or adhered to their privacy policies, set out on their respective websites. The User may refuse the transfer of his/her data to the Data Processors, by written request, by any of the means mentioned above.
In addition, where necessary, the data of Clients may be transferred to certain agencies, in compliance with a legal obligation: Spanish Tax Agency, banks, Labour Inspectorate, etc.
How a User can exercise their rights
The LOPD and the GDPR grant interested parties the option of exercising several rights related to processing of their data. To do so, the User must contact us, providing a copy of documentation proving their identity (ID card or passport), by email sent to email@example.com, or by written communication sent to the address provided in our Legal Notice. This request should also include the following information: The User’s name and surname, request, address, and supporting data.
The User must exercise these rights himself/herself. However, they may also be exercised by a person authorised as the User’s legal representative, when documentation attesting to such representation is provided.
The User may exercise the following rights:
- The right to access personal data, which is the right to obtain information on whether their data is being processed, the purpose of any processing that is being developed, as well as the information available on the origin of such data and the communications made or planned thereof.
- The right to rectification, where personal data are incorrect or inaccurate. The User may also request that data found to be inadequate or excessive be erased.
- The right to request a restriction of processing their data, in which case said data will only be retained by Kit Surprise to exercise or defend claims.
- The right to object: The User has the right to request that their data not be processed or that processing be ceased in cases where their consent is not necessary for processing. Users may oppose commercial prospecting files or decisions related to the person concerned that are based solely on automatic processing of their data, unless further processing is required for legitimate reasons or to exercise or defend potential claims.
- The right to data portability: if the User would like their data to be processed by another company, Kit Surprise will provide the User with a portable copy of their data in an exportable format.
If the User grants consent for a specific purpose, they have the right to withdraw this consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
We are committed to enforcing all these rights within the maximum legal deadline of 1 month.
If the User believes there is an issue with how Kit Surprise processes their data, they can contact our data protection officer or the appropriate data protection authority. The Spanish Data Protection Agency (AEPD) is the supervisory authority in Spain.
Requested information of Users’ personal data collected by contact form or by email will only be used strictly during the time necessary to fulfil the request for information, or until consent is withdrawn. The data of Users who subscribe to our newsletter will be kept indefinitely until the consent granted is withdrawn.
Customers’ personal data will be processed until the end of the contractual relationship. The particular data retention period shall be the minimum necessary, and it may be maintained for:
- Four years: Law on Social Infringements and Sanctions, related to obligations in matters of affiliation, contributions, payment of wages; Arts. 66 et seq. General Tax Act (accounting).
- Five years: Art. 1964 of the Civil Code (personal actions without special deadline).
- Six years: Art. 30 of the Commercial Code, related to accounting records and invoices.
- Ten years: Art. 25 of the Law on the Prevention of Money Laundering and Financing of Terrorism.
- No term: disaggregated and anonymised data.
Kit Surprise has profiles on some of the world’s major social networks (Facebook, Instagram), identifying itself in all cases as Data Controller processing the data of its followers, fans, subscribers, commentators and other user profiles (hereinafter, followers) published by Kit Surprise.
The purpose of data processing by Kit Surprise, when not prohibited by law, will be to inform its followers of its activities and offers, in any way that the social network allows, as well as providing a personalised user care service. The legal basis for such processing shall be the consent of the person concerned, which may be withdrawn at any time.
Under no circumstances will Kit Surprise obtain data from social networks, unless the User grants their consent in this regard (for example, to hold a contest).
The information supplied by the User shall, in any case, be regarded as confidential and may not be used for purposes other than those described herein. Kit Surprise is obliged to refrain from disclosing information about the User’s claims, the reasons for the information requested, or the duration of its relationship with the User.
Term of validity
This privacy and data protection policy has been drafted by EXPERTOSLOPD®, a data protection company, on March 11, 2022. It may vary depending on changes in regulations and jurisprudence. It is the responsibility of the data holder to read the updated document in order to understand their rights and obligations in this regard at any time.