PRIVACY POLICY

Your privacy is important to us.

This privacy statement (hereinafter, the “Privacy Policy”) explains what personal data we collect from our users and how we use it. We encourage you (hereinafter, the “User”) to read these terms carefully before providing your personal data on this website.

Those over the age of thirteen may register as users of https://www.bluemarasolutions.com without the prior consent of their parents or guardians. In the case of children under thirteen years of age, the consent of their parents or guardians is required for the processing of their personal data.

Under no circumstances will data relating to the professional or financial situation of other family members be collected from minors without their consent.
If you are under thirteen years of age and have accessed this website without notifying your parents, you should not register as a User.

On this website, the personal data of Users is respected and protected. As a User, you should know that your rights are guaranteed.

  • We have made an effort to create a safe and trustworthy space, and that is why we want to share our principles regarding your privacy:
  • We never request personal information unless it is truly necessary to provide you with the services you request.
  • We will never use your personal data for a purpose other than that expressed in this Privacy Policy.

Bluemara Solutions S.L.U has adapted this website to the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, regarding the protection of natural persons (GDPR), as well as Law 34/2002, of July 11, on Information Society Services and Electronic Commerce (LSSICE or LSSI).

1. Service Manager

This Service is the responsibility of Bluemara Solutions S.L.U (hereinafter Bluemara)

  • CIF ES:B85081305
  • Ins. Reg. Madrid: T 24294; L 0; F 34; S 8; H M436764.
  • Address: Avenida Juan Carlos I, 40. 28400. Collado Villalba.
  • Contactadmfin@k-infotec.es

2. Motivation

Bluemara respects the privacy rights of its Users and recognizes the importance of protecting the personal data that Bluemara collects about its Users.
The purpose of this document is to inform Users of the Service about the personal data processing carried out in this Service.

In the processing of your personal data, we will apply the following principles that comply with the requirements of the GDPR:

  • Principle of legality, loyalty and transparency: we will always base our processing on a legitimate basis. If this basis is consent, we will require it to process your personal data for one or more specific purposes that we will inform you about in advance with absolute transparency.
  • Principle of data minimization: we will only request the data strictly necessary in relation to the purposes for which we use them. We require.
  • Principle of limitation of the retention period: The data will be kept for no longer than necessary for the purposes of the processing, depending on the purpose. We will inform you of the corresponding retention period. In the case of subscriptions, we will periodically review our lists and delete those records that have been inactive for a considerable period.
  • Principle of integrity and confidentiality: Your data will be treated in such a way as to guarantee adequate security of personal data and ensure confidentiality. You should know that we take all necessary precautions to prevent unauthorized access or misuse of our users’ data by third parties.

3. Personal data processed by mere access to the Service

3.1. What data is processed

By mere access to the Service, Bluemara collects the IP address and other data relating to the connection and its origin.

The IP address is a code that identifies the User’s internet connection at a specific time. Only the User’s internet access provider can identify the subscriber assigned an IP address at a specific time.

Due to the very nature of the server that supports the Service, the User’s IP address is automatically logged along with the date and time of access.

In addition, Bluemara will collect merely identifying data from the User through the various contact forms. The necessary data will be marked with an asterisk (*).

3.2. What is this data used for?

This data will be used for the following purposes:

  • In the case of IP addresses, they will be used only to manage normal use of the Service and perform statistical analysis on the use of the Service.
  • The data provided through the contact form will be processed by Bluemarafor the purpose of providing the service requested by the User. This may be for explanatory purposes, but not limited to, resolving queries, handling complaints and suggestions, or responding to contact requests.
  • The data provided by the User to subscribe to our newsletter will be used solely for sending it.

3.3. Data Recipients

Bluemara does not provide this information to any third party unless required to do so by current legislation (for example, an official request in the context of a police investigation).

Furthermore, Bluemarainforms the User that the data is hosted on the servers of EMAIL MANAGER, a company located in the European Union.

3.4. Legal Basis for Processing

The legal basis for processing the IP address is the technological necessity to enable the provision of the Service.

Furthermore, the legal basis for processing the data provided by Users through the contact form or newsletter subscription will be the express consent granted by the User.

3.5. Data processing period

IP addresses will be retained for a period of 1 month.

Data provided through the contact form will be retained for a period of 1 month after the request has been resolved.

Newsletter subscription data will be retained indefinitely or until the User revokes their consent or exercises their right to cancellation and/or deletion.

3.6. What rights does the User have and how to exercise them?

Data protection regulations guarantee Users the following rights:

  • Access: Allows the User to know what information is held, where it was obtained from, to whom it was provided, and for what purposes it has been processed.
  • Rectification: Allows the User to rectify any erroneous or outdated data.
  • Deletion: Allows the User to have their data stopped being processed.
  • Objection: Allows the User to have their data stopped being used for a specific purpose.
  • Limitation: Allows the User to restrict the processing of their data, but in such a way that they are kept for a subsequent purpose.
  • Portability: Allows the User to obtain a copy of their data in electronic format and, in certain circumstances, request that they be communicated to another service provider. This only applies to computerized processing carried out with the User’s consent or for the fulfillment of a contract.

These rights require the ability to identify the User requesting them and link their identity to the data processed by Bluemara.

However, Bluemara cannot establish this link with any of the data it processes by simply accessing the Service, unless the User can provide certain documentation that allows their identification (for example, a certificate from their Internet access provider indicating the IP address assigned to the User on a specific date and time).

If you wish to exercise any of the aforementioned rights, you may do so by writing to Bluemara Solutions S.L.U. CIF ES B85081305 Ins. Reg. Madrid T 24294; L 0; F 37; S 8; H M436764.

Address: Avenida Juan Carlos I, 40. 28400. Collado Villalba, , attaching the petition in which your request is specified, dated and signed, as well as (optionally) your email or address for notification purposes if you wish. If you wish to do so by email, you can send us the request ADMFIN@K-INFOTEC.ES.

If Users require more information or believe their right to data protection has been violated, they may contact the Spanish Data Protection Agency (www.aepd.es).

3.7. Cookies and similar

Bluemara uses cookies and other similar mechanisms for storing and retrieving data on terminal equipment (hereinafter, cookies).

Cookies are files that are downloaded to the User’s browser and can subsequently be read by Bluemara. In this way, cookies enable various functionalities, such as recognizing a User who has previously accessed the Service and performing analysis on the use of the Service to improve it. However, it is not possible to determine the User’s identity from the cookies used by Bluemara, unless the User provides additional information through other means and these could be linked to the cookies downloaded.

For more information, consult the Cookie Policy

RIGHTS OF THE AFFECTED PARTIES

1. Objective

The objective of this policy is to regulate the general conditions for giving compliance with the obligation to duly respond to requests for the exercise of rights by those affected whose personal data are the responsibility of Bluemara Solutions S.L.U (hereinafter Bluemara)

2. Content

General considerations 

Current data protection regulations guarantee the following rights to those affected:

  • : Right of the affected party to know what data is being processed, the purpose of the processing, as well as the origin of said data and the communications made or planned for them.
  • : Right of the data subject to have data that is found to be inaccurate or incomplete modified.
  • : Right to have data that is found to be inadequate or excessive deleted, without prejudice to the obligation to block it.
  • : Right to have certain processing of personal data not carried out or to have it ceased.
  • Right to have all data processing restricted or blocked when any of the following conditions is met:

Challenge of the accuracy of the data by the data subject (for the period necessary to verify the accuracy of the data and, where appropriate, correct them).

Unlawful processing of data, and the data subject opposes its erasure.

The data is no longer necessary and could be deleted, but the data subject requires it to file a complaint.

The data subject requests an objection to the processing, while it is verified whether the legitimate interests of the controller prevail over those of the data subject.

  • Data portability: This right has two distinct effects:
  1. Right to obtain a copy of the data obtained from the interested party in a standard machine-readable file.
  2. Right to request that the Data Controller transmit the data to another Controller (without this implying that the data must subsequently be cancelled or deleted).

These rights are highly personal and may only be exercised by their legitimate owners or their legal or voluntary representatives, always providing documentation proving their status. Therefore, they must be denied if such documentation is not provided.

The rights are independent, so that none of them will be a prerequisite for exercising the other.

Bluemara will have a simple and free procedure for exercising rights, and it is not feasible to impose the sending of certified letters or calls to premium rate numbers. When the requests are manifestly unfounded or excessive, especially due to their repetitive nature,

  • charge a reasonable fee based on the administrative costs incurredto provide the information or communication or take the requested action, or
  • refuse to act on the request.

Bluemara will bear the burden of demonstrating that the request is manifestly unfounded or excessive.

Bluemara will comply with requests even if the established procedure has not been used, provided that the interested party has used a means that allows proof of sending and receiving the request.

Bluemara will request Correction of the application if any of the following information is missing:

  • Name and surname of the interested party.
  • Photocopy of the DNI (National Identity Document) or equivalent and, where applicable, a document proving legal or voluntary representation. The use of an electronic signature identifying the affected party will exempt the submission of another identification document.
  • Petition specifying the application.
  • Address for notifications, date, and signature of the applicant. If this information is missing, the application will be archived in accordance with the procedure established for this purpose.
  • Where applicable, documents proving the request made.

Bluemara will inform all its employees of the procedure established for the exercise of rights, so that they can inform interested parties of the procedure to follow.

3. Deadlines

Rights must be addressed and responded to as quickly as possible and within a maximum period of 1 month from the date of receipt of the request.Exceptionally, this period may be extended for another 2 months if necessary, taking into account the complexity or volume of requests.

If it is deemed that the requested right should not be addressed, the interested party must also be responded to within a maximum period of 1 month from the date of receipt of the request.

4. Procedure

1. Receipt of the request

Regardless of the medium, any employee of the company who receives a request to exercise their rights will forward it immediately and urgently to the Rights Officer..

2. Formal validation of the request

TheRights Officerwill validate the request by carrying out the following checks:

Corrective defects:

  • Failure to provide a photocopy of the DNI (National Identity Document) or equivalent document.
  • Failure to specify the right being requested.
  • Lack of sufficient information to make the requested right effective.

In any of these cases, The Rights Manager will respond to the affected party requesting correction of their request, using the corresponding model included in this Security Document.

Incorrigible defects:

  • Failure to provide contact information from the applicant.

In this case, and with respect to the rights of ACCESS and PORTABILITY, the Rights Officerwill file the request, stating the impossibility of contacting the applicant.

With respect to the rights of RECTIFICATION, DELETION, OPPOSITION, and LIMITATION, if applicable, the rights will be honored and the request will be filed, stating the impossibility of contacting the applicant.

Reasons for denial of rights:

  • In the case of RIGHT OF ACCESS and PORTABILITY: The Rights Manager will consult the register of requests to exercise rights in ANNEX VII, in order to verify that the same applicant has not requested the right of access in the last 12 months, unless a legitimate interest is proven. In such case, the exercise of the right may be denied or payment of a reasonable fee may be requested to compensate for the work time dedicated to responding to the request.
  • In the case of the RIGHT OF RECTIFICATION, DELETION, OPPOSITION or LIMITATION: The Rights Controller will check that there are no legal regulations that oblige the conservation or processing of the data.
  • In the case of the right of LIMITATION: The Rights Controller will check if any of the circumstances provided for in the GDPR apply to process this right.

In these cases of denial, the Rights Officer will respond to the affected party, communicating the reason for the denial and informing them of their right to seek the protection of the Spanish Data Protection Agency, using the corresponding model included in this Security Document.

5. Granting of the right

Once the request has been validated and any formal defects have been corrected, theRights Officer will send an urgent internal communication to the departments responsible for the processing or processing affected.Each of these departments will carry out the relevant procedures requested and will respond to the Rights Officer within the period established by the latter determine.

In the case of a RIGHT OF ACCESS or PORTABILITY, once all the necessary information has been received, the Rights Officer will contact the applicant to determine the means by which the applicant wishes to exercise his or her right, whether by regular mail, email, fax, etc. The Rights Officer will retain proof of having sent the information.

In the case of a RIGHT TO RECTIFICATION, DELETION, OPPOSITION or LIMITATION, once confirmation has been received from the departments responsible for the processing or processing affected, the Rights Manager will inform the affected party, by any means that allows proof of the sending of the communication, that their data has been rectified/cancelled or that the processing to which they had objected has ceased.

In any case, the corresponding model, included in this Security Document, will be used.

6. Possible assignees of the information

If a right of RECTIFICATION or DELETION has been requested and the information has been transferred to a third party, the Rights Manager will communicate the rectified or cancelled data to the assignees within 1 month by any means that allows the communication to be accredited.

7. Record of requests

The Rights Officer shall keep a record of the requests received from ANNEX VII and shall retain proof of the communications sent for 3 years, which is the maximum period for which liability for failure to properly address the rights requests of those affected may be subject to prescription.