Data Processing Agreement
Última actualización:
Data Processing Agreement (DPA)
Introduction
This Data Processing Agreement (“Agreement”) outlines the terms and responsibilities related to the processing of personal data by PIEDRA NATURAL RUBIO, S.L. in accordance with the requirements of data protection laws applicable to the processing of personal data.
Definitions
- Personal Data: Any information relating to an identified or identifiable natural person.
- Processing: Any operation or set of operations which is performed on personal data or on sets of personal data.
- Data Subject: An identified or identifiable natural person whose personal data is processed.
- Controller: PIEDRA NATURAL RUBIO, S.L., which determines the purposes and means of the processing of personal data.
- Processor: Any natural or legal person who processes personal data on behalf of the Controller.
Scope and Purpose
The purpose of this Agreement is to ensure the lawful and compliant processing of Personal Data, define the rights and obligations of all parties, and establish the framework for data protection in accordance with the GDPR and applicable Spanish data protection legislation.
Data Processing Terms
-
Processing Instructions: Data shall be processed only for the purposes of providing services related to natural stone products, customer relationship management, order fulfillment, and marketing communications (where consent has been given).
-
Security of Processing: PIEDRA NATURAL RUBIO, S.L. implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- SSL encryption for all data transmissions
- Secure data storage with access controls
- Regular security assessments and updates
- Staff training on data protection
-
Subprocessing: We may engage trusted third-party processors for specific services (hosting, email marketing, analytics, payment processing). All subprocessors are bound by contractual obligations that ensure equivalent data protection standards.
-
Data Subject Rights: We are committed to assisting data subjects in exercising their rights under applicable data protection laws, including access, rectification, erasure, restriction, portability, and objection.
-
Data Breach Notification: In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, we will notify the relevant supervisory authority without undue delay and, where required, notify affected individuals.
Data Transfers
Any transfer of personal data to countries outside the European Economic Area (EEA) will only occur where appropriate safeguards are in place, such as:
- Standard Contractual Clauses approved by the European Commission
- Binding Corporate Rules
- An adequacy decision by the European Commission
Duration and Termination
This Agreement shall remain in effect as long as personal data is processed. Upon termination of the relationship with a data subject, personal data will be retained only for the period required by applicable laws or until the data subject requests deletion, whichever is longer.
Governing Law
This Agreement shall be governed by the laws of Spain and the European Union, particularly Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD).
Contact
For any questions regarding this Data Processing Agreement:
- Email: info@rubiostone.com
- Phone: (+34) 973 140 532
- Address: Pol. Ind. Les Verdunes, Parc. 3-6, 25400 Les Borges Blanques, Lleida, Spain
Last updated: January 19, 2025
