PERSONAL DATA PROTECTION POLICY

HIBLAB SOLUTIONS S.A. is an organization that collects personal data through the different means at its disposal, which gives it significant responsibility in the design and organization of procedures so that they are aligned with legal compliance in Data Protection. Therefore, HIBLAB SOLUTIONS S.A. will adopt all necessary security measures to ensure the protection of the data collected.

In the exercise of these responsibilities, and with the aim of establishing the general principles that must govern the processing of personal data within the organization, HIBLAB SOLUTIONS S.A. approves this Personal Data Protection Policy, which it notifies and makes available to all its stakeholders, while also complying with the following rules:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR).
  • Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights (LOPD-GDD).
  • Law 34/2002, of 11 July, on Information Society Services and Electronic Commerce (LSSI-CE).

1.SCOPE OF APPLICATION

This Personal Data Protection Policy shall apply to HIBLAB SOLUTIONS S.A., its governing bodies, management, and staff, as well as to all individuals who interact with the Organization, including explicitly service providers with access to data (“Data Processors”).

The entity responsible for processing the personal data collected within the Organization is HIBLAB SOLUTIONS S.A., with Tax ID (NIF) A16385643, represented by ROLAND KORKOVIC (hereinafter, the “Data Controller”). Its contact details are as follows:

Address: ARTABIDE, 42-44, ONDARROA, BIZKAIA, 48700

Contact phone: 846610848

Contact email: [email protected]

2. INFORMATION ABOUT THE DATA CONTROLLER AND PERSONAL DATA PROCESSING AT HIBLAB SOLUTIONS S.A.

Additional information on data processing consists of more specific and detailed information that organizations must provide to data subjects regarding how their personal data is managed. This concept stems from the transparency principle of the General Data Protection Regulation (GDPR) and complements the basic information initially provided, offering a higher level of detail about the processing activities.

Below, HIBLAB SOLUTIONS S.A. provides additional information regarding the data processing it carries out:

  • Additional Information on Data Protection
    • DATA REGARDING THE DATA CONTROLLER
      • Identity : HIBLAB SOLUTIONS S.A.
      • Adress : ARTABIDE, 42-44, ONDARROA, BIZKAIA, 48700
      • Contact phone: 846610848, 621493284
      • E-mail: [email protected]
    • PURPOSES OF PERSONAL DATA PROCESSING
DATA PROCESSINGPURPOSE OF PROCESSINGRETENTION PERIOD
CLIENTS (COMPANIES)GMANAGEMENT OF CLIENTS, ACCOUNTING, TAX, AND ADMINISTRATIVE PURPOSESData for the purpose of client management, accounting, tax, and administrative tasks must be retained for four years.
SUPPLIERSMANAGEMENT OF CLIENTS, ACCOUNTING, TAX, AND ADMINISTRATIVE PURPOSES
Client management: 5 years.
Accounting, tax, and administrative purposes: 6 years.
VIDEO SURVEILLANCESECURITY AND ACCESS CONTROL TO BUILDINGS, VIDEO MONITORINGVideo surveillance: Images will be retained for a maximum period of one month from their capture.
WEB FORMMANAGEMENT OF CLIENTS, ACCOUNTING, TAX, AND ADMINISTRATIVE PURPOSESClient management: 6 years
Accounting, tax, and administrative purposes: 5 years
NEWSLETTERADVERTISING AND COMMERCIAL PROSPECTING5 YEARS
HUMAN RESOURCESMANAGEMENT OF CLIENTS, ACCOUNTING, TAX, AND ADMINISTRATIVE PURPOSES, PAYROLL MANAGEMENT, OCCUPATIONAL RISK PREVENTION, HUMAN RESOURCESClient management: 6 years
Accounting, tax, and administrative purposes: 6 years
Payroll management: 4 years
Occupational risk prevention: 5 years
Human resources: 4 years
CURRICULUMSMANAGEMENT OF CLIENTS, ACCOUNTING, TAX, AND ADMINISTRATIVE PURPOSESClient management: 5 years, for tax and accounting purposes.
Accounting and tax: 5 years, in accordance with the statute of limitations for tax obligations.
Administrative: 6 years, as established in Article 30 of the Commercial Code for commercial documents.

LEGAL BASES FOR PERSONAL DATA PROCESSING

DATA PROCESSINGLEGAL BASIS
CLIENTS (COMPANIES)Performance of a service contract
SUPPLIERSPerformance of a service contract
VIDEO SURVEILLANCEPublic interest for video monitoring
WEB FORMLegitimate interest / Consent
NEWSLETTERLegitimate interest / Consent
HUMAN RESOURCESPerformance of an employment contract
CURRICULUMLegitimate interest / Consent

RECIPIENTS OF YOUR PERSONAL DATA

DATA PROCESSINGPOTENTIAL DISCLOSURESINTERNATIONAL TRANSFERS
CLIENTS (COMPANIES)COMPETENT PUBLIC ADMINISTRATIONNO
SUPPLIERSCOMPETENT PUBLIC ADMINISTRATION, BANKING OR FINANCIAL INSTITUTIONSNO
VIDEO SURVEILLANCECOMPETENT PUBLIC ADMINISTRATIONNO
WEB FORMNO DISCLOSURES ANTICIPATEDNO
NEWSLETTERNO DISCLOSURES ANTICIPATEDNO
HUMAN RESOURCESCOMPETENT PUBLIC ADMINISTRATION, BANKING OR FINANCIAL INSTITUTIONSNO
CURRICULUMSNO DISCLOSURES ANTICIPATEDNO

RIGHTS ENTITLED TO YOU AND MEANS AVAILABLE TO EXERCISE THEM

Any person has the right to obtain confirmation as to whether HIBLAB SOLUTIONS S.A. is processing personal data concerning them. Data subjects have the right to access their personal data, as well as to request the correction of inaccurate data or, where applicable, request its deletion when, among other reasons, the data is no longer necessary for the purposes for which it was collected. Under certain circumstances, data subjects may request the limitation of the processing of their data, in which case we will only retain it for the exercise or defense of claims, as well as to comply with legally established retention periods. In addition, data subjects may object to the processing of their personal data. Therefore, HIBLAB SOLUTIONS S.A. will cease processing their data, except for legitimate and compelling reasons or for the exercise of possible claims. In the same way, when certain circumstances apply and it is technically possible, data subjects have the right to have their personal data transmitted directly to another controller or data processor, upon request. To exercise the rights mentioned above, you must contact us by sending a written request to:

  • HIBLAB SOLUTIONS S.A., ARTABIDE, 42-44, ONDARROA, BIZKAIA, 48700, or by email at [email protected]. We recommend including a copy of your ID with your request.

3. PRINCIPLES APPLICABLE TO THE PROCESSING OF PERSONAL DATA

The Personal Data Protection Policy is a proactive responsibility measure aimed at ensuring compliance with the applicable legislation in this area and, in relation to it, respecting the right to honor and privacy in the processing of personal data of all individuals who interact with HIBLAB SOLUTIONS S.A.

In line with this Policy, the Principles governing data processing within the organization are established, and consequently, the procedures and organizational and security measures that individuals affected by this Policy are committed to implementing within their scope of responsibility.

In this regard, HIBLAB SOLUTIONS S.A. will ensure compliance with the following principles:

  • LAWFULNESS, FAIRNESS, TRANSPARENCY, AND PURPOSE LIMITATION: Data processing must always be communicated to the data subject through established clauses and procedures and will only be considered lawful if consent has been given for the processing of data (with special attention to consent provided by minors), or there is another valid legal basis, and the purpose of the processing aligns with applicable regulations.
  • DATA MINIMIZATION: The data processed must be adequate, relevant, and limited to what is necessary in relation to the purposes of the processing.
  • ACCURACY: Data must be accurate and, where necessary, kept up to date. Appropriate measures must be taken to promptly delete or correct personal data that is inaccurate in relation to the purposes of processing.
  • LIMITATION OF RETENTION PERIOD: Data will be kept in a form that permits identification of the data subjects for no longer than necessary for the purpose for which the data is processed.
  • INTEGRITY AND CONFIDENTIALITY: Personal data must be processed in a manner that ensures adequate security, including protection against unauthorized or unlawful processing, accidental loss, destruction, or damage, through the application of appropriate technical and organizational measures.
  • DATA DISCLOSURE: The purchase or acquisition of personal data from illegitimate sources is prohibited, as well as any data collected or disclosed in violation of the law, or where the lawful origin of the data cannot be sufficiently guaranteed.
  • HIRING OF PROVIDERS WITH DATA ACCESS: Only providers that offer sufficient guarantees to implement appropriate technical and security measures for data processing will be selected. A formal contract will be documented with these providers regarding data protection obligations.
  • INTERNATIONAL DATA TRANSFERS: Any processing of personal data subject to European Union regulations that involves transferring data outside the European Economic Area must comply strictly with the requirements established by applicable law.
  • DATA SUBJECT RIGHTS: The Organization will facilitate the exercise of the rights of access, rectification, deletion, restriction of processing, objection, and data portability, establishing internal procedures, including forms and mechanisms necessary and appropriate for exercising these rights, which must at least meet the legal requirements applicable in each case.
    HIBLAB SOLUTIONS S.A. will promote the application of the principles set out in this Personal Data Protection Policy:
    • In the design and implementation of all work procedures
    • In the products and services offered
    • In all contracts and obligations formalized or assumed
    • In the deployment of all systems and platforms that allow access for its employees or third parties and/or the collection or processing of personal data

4. PERSONAL DATA OF MINORS

In accordance with the provisions of Articles 8 of the GDPR and 7 of Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights, only individuals over 14 years of age may lawfully give their consent for the processing of their personal data by HIBLAB SOLUTIONS S.A. In the case of a minor under 14 years of age, the consent of the parents or legal guardians is required for the processing, and such processing will only be considered lawful to the extent that it has been authorized by them.

5. CONFIDENTIALITY AND SECURITY OF PERSONAL DATA

HIBLAB SOLUTIONS S.A. undertakes to inform the user without undue delay in the event of a personal data security breach that is likely to pose a high risk to their rights and freedoms. In accordance with Article 4 of the GDPR, a personal data security breach is understood as any security breach that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to personal data that has been transmitted, stored, or otherwise processed.

Personal data will be treated as confidential by the Data Controller, who undertakes to inform and ensure, through a legal or contractual obligation, that such confidentiality is respected by its employees, associates, and any other persons to whom the information is made accessible.

6. COMMITMENT OF HIBLAB SOLUTIONS S.A. PERSONNEL

Accordingly, we state that the employees of HIBLAB SOLUTIONS S.A. have been informed of this Policy and acknowledge that personal data is an asset of HIBLAB SOLUTIONS S.A. In this regard, they adhere to it and commit to the following:

  • Complete the data protection awareness training provided by HIBLAB SOLUTIONS S.A.
  • Apply user-level security measures relevant to their job position, without prejudice to any responsibilities for their design and implementation that may be assigned based on their role within HIBLAB SOLUTIONS S.A.
  • Use the established formats for exercising rights by affected users and promptly inform HIBLAB SOLUTIONS S.A. so that an effective response can be provided.
  • Notify HIBLAB SOLUTIONS S.A. as soon as they become aware of any deviations from this Policy, particularly “personal data security breaches,” using the designated reporting format.

7. EVALUATION AND MONITORING

HIBLAB SOLUTIONS S.A. will conduct an annual verification, evaluation, and assessment, as well as whenever there are significant changes in data processing activities, of the effectiveness of the technical and organizational measures in place to ensure the security of data processing.