Introduction
This Privacy Policy describes how VISUALNACERT, S.L. (hereinafter, “VISUAL”) collects, uses, processes and protects the personal data of its users and customers (hereinafter, the “User” or “Customer”) in connection with the provision of its services through the website and platform of “VISUAL” (hereinafter, the “Platform”).
At VISUAL, we are committed to protecting your privacy and processing your personal data with the utmost diligence and in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016 (General Data Protection Regulation, GDPR) and Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
By using our Platform and services, you accept the practices described in this Privacy Policy. We recommend that you read it carefully.
Definition of personal data “Personal Data” is to be understood as any information relating to an identified or identifiable natural person. This includes, among others, name, surname, postal and email address, and telephone number.
Principles of Personal Data Processing At VISUAL, the processing of personal data is governed by the following principles established in the GDPR:
Lawfulness, fairness and transparency: Data is processed lawfully, fairly and in a transparent manner in relation to the data subject.
Purpose limitation: Data is collected for specified, explicit and legitimate purposes and will not be further processed in a manner incompatible with those purposes.
Data minimization: Data is adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.
Accuracy: Data is accurate and, where necessary, kept up to date; every reasonable step is taken to ensure that personal data that is inaccurate, having regard to the purposes for which it is processed, is erased or rectified without delay.
Storage limitation: Data is kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which it is processed.
Integrity and confidentiality: Data is processed in a manner that ensures appropriate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, through the use of appropriate technical or organizational measures.
| Purpose of Processing | Legal Basis | Retention Period | Disclosures to Third Parties |
|---|---|---|---|
| A. Management of inquiries and requests for information (Contact Forms and Emails) | |||
| Responding to inquiries, questions or requests for information made by the User through the Platform’s contact forms or by email. | VISUAL’s legitimate interest in attending to the requests of its prospective customers and users. Consent of the data subject upon submitting the form or email. | For the time necessary to manage and resolve the inquiry, and thereafter blocked for the legal limitation periods applicable to possible claims. | No disclosures to third parties are envisaged, except where legally required. |
| B. Provision of the VISUAL Platform Services | |||
| Managing the User’s registration and account on the Platform. | Performance of a contract or pre-contractual measures at the request of the data subject (Subscription to the Platform). | For the duration of the contractual relationship and, once it has ended, for the applicable legal limitation periods (e.g., 6 years for commercial documentation, 10 years for anti-money laundering purposes). | Cloud infrastructure service providers (e.g., Amazon Web Services, Google Cloud Platform) for hosting the Platform and the data. Where applicable, payment service providers for managing subscriptions. |
| Enabling access to and use of the Platform’s functionalities (digital solutions for agricultural operations). | Performance of a contract. | For the duration of the contractual relationship and, once it has ended, for the applicable legal limitation periods. | Cloud infrastructure service providers. |
| Providing technical support and customer service to resolve issues and questions related to the use of the Platform. | Performance of a contract (Subscription to the Platform) and VISUAL’s legitimate interest in maintaining the operability of the service. | For the duration of the contractual relationship and, once it has ended, for the applicable legal limitation periods. | Providers of support and incident management tools. |
| C. Sending Commercial Communications and Marketing | |||
| Sending commercial communications, news, offers and promotions related to VISUAL’s services, by electronic or non-electronic means. | Consent of the data subject (when explicitly requested). VISUAL’s legitimate interest for existing customers, based on Article 21.2 of the LSSI. | Until the data subject withdraws their consent or objects to the processing. | Communication delivery platforms (e.g., email marketing services). |
| D. Improvement and Maintenance of the Platform | |||
| Carrying out statistical and usage analysis of the Platform to improve its operation, design and to offer new functionalities. | VISUAL’s legitimate interest in improving its products and services. | Anonymized or aggregated data indefinitely. Non-anonymized data for the time necessary for analysis and implementation of improvements. | Web analytics service providers (e.g., Google Analytics), with anonymization or pseudonymization safeguards. |
| E. Compliance with Legal Obligations | |||
| Responding to legal, tax, accounting and administrative requirements. | Compliance with a legal obligation applicable to VISUAL. | For the periods legally established for each type of obligation (e.g., 4 years for tax obligations, 10 years for anti-money laundering purposes). | Competent Public Administrations (Tax Authorities, Social Security, Courts and Tribunals, etc.). |
| F. Conducting training sessions and webinars | |||
| Webinars may be recorded in order to allow subsequent viewing by participants and/or for training purposes related to VISUAL’s activity as controller. | VISUAL’s legitimate interest in documenting the session and facilitating access to it for registered participants, having carried out the corresponding assessment of the risk to the rights and freedoms of data subjects. Consent of the data subject (when explicitly requested), in cases where the recording includes the voice and/or image of attendees who participate voluntarily during the session by activating their camera and/or microphone and who may be freely accessible on VISUAL’s platform or website. | For the period necessary to fulfil the purpose of the processing, and, where applicable, until the data subject withdraws their consent or objects to the processing. | The recording will not be publicly disseminated beyond the purposes indicated. |
In this case, VISUAL undertakes to:
Process the personal data only in accordance with the Customer’s documented instructions, including with regard to transfers of personal data to a third country or an international organization, unless required to do so by Union or Member State law applicable to VISUAL; in such a case, VISUAL shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
Ensure that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
Adopt all appropriate technical and organizational security measures to ensure a level of security appropriate to the risk, including, among others, the measures described in section 6 of this Policy.
Assist the Customer, taking into account the nature of the processing, by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Customer’s obligation to respond to requests for exercising data subjects’ rights.
Assist the Customer in ensuring compliance with the obligations set out in Articles 32 to 36 of the GDPR (security of processing, notification of security breaches, impact assessment, prior consultation).
At the Customer’s choice, delete or return all personal data after the end of the provision of processing services, and delete existing copies unless retention of the personal data is required under Union or Member State law.
Make available to the Customer all information necessary to demonstrate compliance with the obligations set out in Article 28 of the GDPR, and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.
4.1 Sub-processors VISUAL may engage other processors (sub-processors) to provide the services, such as cloud infrastructure providers (e.g., Amazon Web Services). VISUAL will ensure that these sub-processors assume obligations equivalent to those established in this Privacy Policy and in the data processing agreement, through contracts compliant with Article 28.4 of the GDPR.
4.2 International Data Transfers Where it is necessary to carry out international transfers of personal data to countries outside the European Economic Area (EEA), VISUAL will ensure that such transfers are carried out in accordance with the GDPR, applying appropriate safeguards, such as the Standard Contractual Clauses approved by the European Commission, and adopting supplementary measures where necessary to ensure a level of protection equivalent to that provided in Europe.
Formalized information security policies.
Logical access controls based on roles and the principle of least privilege.
Secure authentication mechanisms.
Encryption of communications and, where appropriate, of stored information.
Security incident management procedures.
Periodic backups and business continuity and disaster recovery plans.
Continuous assessment and improvement of the security level.
VISUAL periodically reviews and updates these measures to adapt to the evolution of risks, the state of the art and applicable regulatory requirements.
For detailed information about the cookies we use, their purposes, the legal basis for their use, retention periods and how to manage them, please refer to our specific Cookie Policy, available at https://visualnacert.com/politica-de-cookies/.
Right of Access: Obtain confirmation as to whether VISUAL is processing your personal data and, if so, access it.
Right to Rectification: Request the correction of inaccurate or incomplete data.
Right to Erasure (“Right to be Forgotten”): Request the deletion of your personal data when, among other reasons, it is no longer necessary for the purposes for which it was collected.
Right to Restriction of Processing: Request the restriction of the processing of your data, in which case we will only retain it for the exercise or defense of claims.
Right to Data Portability: Receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and to transmit it to another controller.
Right to Object: Object to the processing of your personal data, in which case VISUAL will cease processing it, except for compelling legitimate grounds or the exercise or defense of possible claims.
Right to Withdraw Consent: Withdraw consent given at any time, without affecting the lawfulness of processing based on consent prior to its withdrawal.
To exercise any of these rights, you may send a communication to our data protection officer at the email address privacy@visualnacert.com, attaching a copy of your ID card or equivalent identification document. You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) if you consider that your rights have not been properly addressed.
Changes to the Privacy Policy VISUAL reserves the right to modify this Privacy Policy at any time to adapt it to legislative or case-law developments or to changes in business practice. Any modification will be published on the Platform and, in the event of substantial changes, we will notify you by electronic means (e.g., email) so that you can review the changes before they take effect. Continued use of the Platform after the publication of the changes will constitute acceptance of them.
Contact If you have any questions about this Privacy Policy or about the processing of your personal data, you may contact us through the data protection officer’s email address: privacy@visualnacert.com
Support