Privacy Policy

Data Controller: MABS Cancer Support Fundación.

 

C.I.F. / N.I.F. –  G54982681.

Registered address: C/ Caravaggio, 1, 03730 Jávea (Alicante).

Telephone: 686305006.

E-MAIL: [email protected]

Data Protection Officer (Procoden SL): [email protected]

 

MABS Cancer Support Fundación is a not-for-profit organisation based and operating in the Costa Blanca and Costa Cálida areas of Southern Spain, whose sole objective is ‘to care for, comfort and counsel people affected by cancer.’ This privacy policy explains how the MABS Fundación uses and protects the personal data collected from you in order to achieve our shared objectives, either when using this website, communicating via telephone or email, face to face in our support centres and charity shops, or upon delivery of loan equipment to a specified address.

The topics covered by the MABS Fundación privacy policy are as follows:

  • What data do we collect?
  • How do we collect your data?
  • How will we use your data?
  • How do we store your data?
  • What are your data protection rights?
  • What are cookies?
  • How do we use cookies?
  • How to manage your
  • Data breach reporting.
  • Changes to our privacy
  • How to contact
  • How to contact the Data Protection Authority in Spain.

 

What data do we collect?

The nature of the information collected from you depends on the specific nature of your interaction with MABS Fundación and may be divided into the following discrete activities:

  • A monetary donation to MABS Fundación.
  • A donation of saleable goods to MABS Fundación.
  • A purchase of goods at a MABS Fundación charity shop, which require delivery to a home or specified address.
  • Enrolment as a MABS Fundación volunteer.
  • Employment as a MABS Fundación employee.
  • Loan of diverse mobility and medical support equipment.
  • Provision of post-diagnosis, recuperative and palliative care.

 

A monetary donation to MABS Fundación

When kindly making a monetary donation to MABS Fundación, the following personal information is required:

  • Full name.
  • Email address.
  • Telephone number.
  • Home address.
  • NIE number.

The legal basis for holding and processing the above personal information under GDPR is consent/contract and legal obligation.

 

A donation of saleable goods to MABS Fundación

When kindly making a donation of saleable goods to MABS Fundación, the following personal information is required:

·        Full name.

·        Email address.

·        Telephone number.

·        Home address.

·        NIE number.

The legal basis for holding and processing the above personal information under GDPR is consent/contract and legal obligation.

 

The purchase of goods at a MABS Fundación charity shop, which require delivery to a home or specified address

When kindly purchasing goods at a MABS Fundación charity shop, the following personal information is required:

·        Full name.

·        Email address.

·        Telephone number.

·        Home address.

The legal basis for holding and processing the above personal information under GDPR is consent/contract.

Enrolment as a MABS Fundación volunteer

When kindly enrolling as a MABS Fundación volunteer, the following personal information is required:

·        Full name.

·        Email address.

·        Telephone number.

·        Home address.

·        NIE number.

·        Driving licence details (if providing transport services).

·        Vehicle registration number (if providing transport services using your own vehicle).

·        Vehicle insurance details (if providing transport services using your own vehicle).

·        Vehicle MOT expiry date (if providing transport services using your own vehicle).

The legal basis for holding and processing the above personal information under GDPR is consent/contract and legal obligation.

Employment as a MABS Fundación employee

When employed as a paid MABS Fundación employee, the following personal information is required:

·        Full name.

·        Email address.

·        Telephone number.

·        Home address.

·        NIE number.

·        Driving licence details (if providing transport services).

·        Vehicle registration number (if providing transport services using your own vehicle).

·        Vehicle insurance details (if providing transport services using your own vehicle).

·        Vehicle MOT expiry date (if providing transport services using your own vehicle).

The legal basis for holding and processing the above personal information under GDPR is consent/contract and legal obligation.

 

Loan of diverse mobility and medical support equipment

When availing oneself of the loan of diverse mobility and medical support equipment, the following personal information is required:

·        Full name.

·        Email address.

·        Telephone number.

·        Home address.

·        NIE number.

Please note that in such instances, special category health data may be supplied to the MABS Fundación by the local health authorities, private healthcare providers, carers, relatives and friends.

The legal basis for holding and processing the above personal information under GDPR is consent/contract, legitimate interest and, potentially, vital interest.

 

Provision of post-diagnosis, recuperative and palliative care

When receiving post-diagnosis, recuperative or palliative care via the MABS Fundación, the following personal information is required of/collected from the relevant parties:

·        Full name.

·        Email address.

·        Telephone number.

·        Home address.

·        NIE number.

·        Special category health data.

·        Next of kin details.

·        Details of any health insurance policies.

Please note that in such instances, special category health data may be supplied to the MABS Fundación by the local health authorities, private healthcare providers, carers, relatives and friends.

The legal basis for holding and processing the above personal information under GDPR is consent, legitimate interest and, potentially, vital interest.

 

How do we collect your data?

Your personal data may be collected as follows by MABS Fundación:

·        When making a monetary donation to MABS Fundación either online, by telephone, face to face in a MABS Fundación support office or charity shop.

·        When making a donation of saleable goods to MABS Fundación by telephone, face to face in a MABS Fundación support office or charity shop (also to potentially arrange collection).

·        When purchasing goods at a MABS Fundación charity shop, which require delivery to a home or specified address, by face to face interaction.

·        When enrolling as a MABS Fundación volunteer online, via email , or by face to face interaction at a MABS Fundación support office or charity shop.

·        When employed as a MABS Fundación staff member via email and/or face to face interaction at a MABS Fundación support office or charity shop.

·        When availing oneself of the loan of diverse mobility and medical support equipment, by telephone, via email, face to face, or from local health authorities and/or private healthcare providers.

·        When in need of the provision of post-diagnosis, recuperative and palliative care, by telephone, via email, face to face, or from local health authorities and/or private healthcare providers, carers, relatives and friends.

 

The personal information collected by MABS Fundación is therefore a combination of both digital and analogue information, provided directly by your good self in the main, but also from trusted third party partners and official state bodies. All personal information collected and held by MABS Fundación is subject to the most rigorous data protection policies and procedures, which are hardwired into daily operations and subject to frequent audit and review.

 

How MABS Fundación will use your personal data

MABS Fundación collects your personal data as described above in order to achieve its core objectives of caring for, comforting and counselling people affected by cancer. The necessary personal data is also collected to enable its supporting monetary and goods donation processing, and fundraising operations via sales at its charity shops, charity stalls and charity events etc.

Personal data is collected and processed by MABS Fundación in line with the six overall principles of GDPR:

1.   Fairness, lawfulness and transparency

That personal data is processed lawfully, fairly and in a transparent manner in relation to individuals

2.   Purpose Limitation

That personal data is collected for specified explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.

3.   Data Minimisation

That personal data is adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.

4.   Accuracy

That personal data is accurate, and where necessary, kept up to date. Every reasonable step must be taken to ensure that personal data that is inaccurate, having regard to the purposes for which it is processed, is erased or rectified without delay.

5.   Storage Limitation / Retention

That personal data must be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.

6.   Confidentiality and integrity / security

That your data is processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.

MABS Fundación is also responsible for, and must be able to demonstrate, compliance with GDPR legislation, which is achieved via regular reviews and updates of data protection policies, procedures, the security document, annual staff member and volunteer training and annual audits.

 

Data Protection Officer

MABS Fundación secures the services of the entity described below to fulfil the role of Data Protection Officer and to conduct ongoing monitoring and annual data protection audits to ensure compliance:

 

Procoden Consulting, S.L.

C.I.F / N.I.F.: B-54566971

Avda. Arquitecte Antoni Gilabert, 58-2, 03750 Pedreguer (Alicante) Telephone: 966 455 643 E-Mail: [email protected]

 

General liaison and interpreting services between MABS Fundación employees and volunteers are provided by:

 

Julian Parkes

Telephone: +34 660 91 76 38 E-Mail: [email protected]

 

A data protection risk assessment (DPIA) is conducted by Procoden SL at regular intervals to ensure the security, integrity and confidentiality of special category health data.

 

How and where do we store your data?

MABS Fundación store personal data as:

  • Paper records.
  • Local, fixed, digital assets (personal computers).
  • External digital assets, private server (third party).
  • External digital assets, public cloud (Microsoft email accounts).

Paper records are stored in secure, locked cabinets at the following secure building locations:

MABS Fundación

C/ Caravaggio, 1, Jávea, 03730 (Alicante)

MABS Fundación Support Centre

Avenida de París, 6, Playa del Arenal, Jávea, 03738 (Alicante)

 

MABS Fundación Respite Home

Avenida de Los Covachos, 278, Camposol Sector B4, 30875 (Murcia)

 

The above locations are provided with secure, lockable units for the safe storage of analogue data and a shredder to destroy confidential waste prior to disposal.

Digital personal data and special category health data is stored on a secure server managed on behalf of MABS Fundación by:

 

BluePrint Informática SL

Urbanización Bello Horizonte, 6 Bajo, La Nucia (Alicante)

Telephone: 965 87 10 34 Email: [email protected]

Secure Microsoft email accounts are managed on behalf of MABS Fundación by:

 

Lasertech CB

Camino Les Barranqueres, 2, Jávea, 03730 (Alicante)

Telephone: 620 29 84 18 E-Mail: [email protected]

Microsoft’s privacy statement may be viewed via the following link:

https://privacy.microsoft.com/en-us/privacystatement

 

A copy of the latest Microsoft Products and Services Data Protection Addendum (DPA) is held by the Data Protection Lead.

Security measures employed by the MABS Fundación and the above cited entities are as follows, but not limited to:

  • Professional, business-standard antivirus.
  • Patch management.
  • Email filtering.
  • Web filtering.
  • Admin privilege management.
  • Access control.
  • Two factor authentication.
  • Daily backups.
  • Employee and volunteer training and awareness sessions.

 

The MABS Fundación website is hosted, developed and maintained by the following entity:

Medianic

Jávea, 03730 (Alicante)

Telephone: +34 610 15 13 06 E-mail: [email protected]

 

Data Sharing

MABS Fundación share personal data and special category health data with the following three care agencies:

3C’s Care Agency

Sue Reula

Villa Valencia, 03509, Finestrat (Alicante)

Telephone: 664 613 912 E-mail: [email protected]

 

Premier Health Care

Heather Spence

Camposol, Mazarrón, 30875 (Murcia)

Telephone: 603 12 57 82 E-mail: [email protected]

 

Andalusia Care (Angels)

Nicki Wakeman

Los Carasoles, 04661 Zurgena (Almería)

Telephone: 711 080 462 E-mail: mailto:[email protected]

 

MABS Fundación provide personal data of employees and donors, as appropriate, to the following tax consultants and accountants for the purposes of payroll and general accounting activities for presentation to the Spanish Tax Department (Hacienda):

 

347 Asesores SL

Edificio La Ribera, Plaza de la Puerta del Mar, S/N, 30720, San Javier (Murcia)

Telephone: 968 57 35 85 E-Mail: [email protected]

 

All third party data processors are subject to a legally binding data sharing contract, which details the nature, purpose and duration of the data sharing, plus the type and category of data to be shared.

 

Storage Limitation / Data Retention

In accordance with the fifth GDPR principle, the data retention periods implemented by MABS Fundación are as follows:

  • Personal data held on volunteers – two years from the date of ceasing volunteering activities.
  • Employees – five years from the date of ceasing employment.
  • Patients – five years from the date of the last interaction with MABS Fundación or the date of passing.
  • Customer purchase and delivery invoices – five years from the date of purchase.

 

Communication

Telephone calls, be they external or internal, are not recorded by MABS Fundación as part of their daily operations and video communication platforms such as Microsoft Teams or Zoom are not used currently.

A secure, encrypted WhatsApp group is used by the MABS Fundación Management Team for daily, operational communication. Personal data, which may identify a data subject, is strictly prohibited and stringently avoided, thereby rendering the said communication non-confidential in terms of personal information.

 

Marketing

MABS Fundación does not engage in marketing activities and personal data and contact information will never be used, or shared, to such ends.

 

What are your data protection rights?

MABS Fundación fully respect and abide by a data subject’s eight rights with regard to their personal data, which are enshrined in GDPR legislation as follows:

  1. The right to be informed

You have the right to be provided with clear and concise information about what MABS Fundación does with your personal data.

  1. The right to access

You have the right to request copies of your personal data. This information is normally provided free, but MABS Fundación charge you a small fee for this service if requests may be deemed excessive or manifestly unfounded.

  1. The right to rectification

You have the right to request that MABS Fundación correct any information that you believe to be inaccurate. You also have the right to request MABS Fundación to complete any information you believe to incomplete.

  1. The right to erasure (the right to be forgotten)

You have the right to request that MABS Fundación erase your personal data. Although this is a fundamental right, such a request may also be subject to other legal considerations, which would need to be analysed on a case by case basis.

  1. The right to restrict processing

You have the right to request that MABS Fundación restrict the processing of your personal data. This is a fundamental right, but certain considerations may need to be taken into account on a case by case basis.

  1. The right to object to processing

You have the right to object to MABS Fundación’s processing of your personal data. Once again, this is a fundamental right, but certain considerations may need to be taken into account on a case by case basis.

  1. The right to data portability

You have the right to request that MABS Fundación transfer the personal data that we have collected to another organisation, or directly to you, in a user friendly format.

Should you wish to exercise one or more of your rights with regard to your personal data, please contact MABS Fundación by either of the following means:

 

Telephone: +34 660 91 76 38

Email: [email protected]

In writing: MABS Cancer Support Fundación, Calle Carvaggio, 1, Jávea, 03730 (Alicante)

 

MABS Fundación have one calendar month to respond from receipt of the written or verbal request.

 

What are cookies?

Cookies are text files placed on your computer to collect standard internet log and visitor behaviour information. When you visit the MABS Fundación website, we may collect information from you automatically through cookies or similar technology.

For further information on cookies may be obtained via the web on such sites as www.allaboutcookies.org.

 

How do we use cookies?

MABS Fundación uses cookies in a limited way to improve your experience on our website, including:

  • Recognising you on our website and remembering your previously selected These could include what language you prefer and the location you are in. A combination of first-party and third-party cookies are used.
  • Collecting information about your visit to our website, the content you viewed, the links you followed and information about your browser, device, and your IP

The above information helps MABS Fundación to understand how you use our website, thereby enabling us to improve your browsing visit experience in future.

Please note that MABS Fundación never shares cookie information with third parties for any purpose, and categorically not for advertising, automated decision-making and profiling.

 

How to manage cookies

You can set your browser not to accept cookies and instructions on how to do this may be found at www.allaboutcookies.org and other such sites. Disabling cookies, however, in a limited number of cases, may mean that some of our website features do not function as a result.

 

Data breach reporting

All MABS Fundación’s employees, volunteers and 3rd party collaborators receive awareness training on how to recognise and report a data breach, to ensure that the Data Protection Lead, Procoden SL and, as a appropriate, the Spanish Data Protection Agency are informed within 72 hours of first knowledge of the breach.

A data breach log is held by Procoden SL for the recording and subsequent analysis of all data breaches.

 

Changes to MABS Fundación Privacy Policy

MABS Fundación keeps its privacy policy under constant review and any amendments are immediately uploaded to this web page link. This privacy policy was last updated on the 29th of November 2022.

 

How to contact us

Should you have any queries with regard to MABS Fundación privacy policy, the personal data we hold on you, or you would like to exercise one of your data protection rights, please do not hesitate to contact us.

 

Telephone: +34 660 91 76 38

Email: [email protected]

In writing: MABS Cancer Support Fundación, Calle Carvaggio, 1, Jávea, 03730 (Alicante)

 

How to contact the Data Protection Authority in Spain

Data protection in Spain is regulated by the Spanish Data Protection Agency (AEPD – Agencia Española de Protección de Datos).

As MABS Cancer Support Fundación is registered, based and operates on Spanish territory, it is subject to regulation by the AEPD, irrespective of the origin or nationality of its employees, volunteers and patients.

Should you wish to report a complaint with regards to MABS Fundación and its data protection obligations, or if you feel that MABS Fundación has not addressed your concern in a satisfactory manner, you may contact the AEPD as follows:

Telephone: 900 293 183

WhatsApp: +34 616 17 22 04

Web: www.aepd.es

Address: AEPD, Calle Jorge Juan 6, 28001 (Madrid)

—————————————————

POLÍTICA DE PRIVACIDAD

La presente política de privacidad es conforme al Reglamento (UE) 2016/679 del Parlamento Europeo y del Consejo, de 27 de abril de 2016, relativo a la protección de las personas físicas en lo que respecta al tratamiento de datos personales y a la libre circulación de estos datos (RGPD), a Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD), así como en lo que no resulte contrario a la normativa indicada, a la Ley Orgánica 15/1999, de Protección de Datos de Carácter Personal (LOPD) y su normativa de desarrollo, y/o aquellas que las pudieran sustituir o actualizar en el futuro.

Nuestra organización está comprometida con la privacidad de sus datos personales. Los datos personales facilitados son necesarios para prestar nuestros servicios y son tratados de manera lícita, leal y transparente, garantizando una seguridad adecuada de los mismos, incluida la protección contra el tratamiento no autorizado o ilícito y contra su pérdida, destrucción o daño accidental mediante la aplicación de medidas técnicas y organizativas.

A través del presente documento queremos ofrecerle de forma transparente y leal toda la información necesaria relativa al tratamiento de sus datos personales que realiza esta organización.

 

I.- RESPONSABLE DEL TRATAMIENTO.

IDENTIDAD: M.A.B.S. CANCER SUPPORT

C.I.F. / N.I.F.: G54982681

DOMICILIO: C/ CARAVAGGIO, 1, 03730 JAVEA (ALICANTE)

TELÉFONO: 686305006

E-MAIL: [email protected]

DELEGADO PROTECCIÓN DATOS: [email protected]

 

II.- DESTINATARIOS DE LOS DATOS PERSONALES.

1.- Los datos personales facilitados no serán objeto de cesión alguna salvo que así se disponga en los tratamientos específicos.

2.- Opcionalmente, para la contratación de servicios de computación en la nube y/o servicios para el envío de e-mails, de comunicación, así como otros servicios informáticos relacionados, los datos personales podrán ser:

– Cedidos a empresas de servicios informáticos ubicadas dentro del Espacio Económico Europeo (EEE) o,

– Transferidos a empresas de servicios informáticos ubicadas fuera del EEE acogidos al escudo de protección Privacy Shield por lo que cuentan con medidas de protección adecuadas para garantizar la seguridad de los datos personales. Puede obtener más información visitando este enlace: https://www.privacyshield.gov/welcome

3.- Opcionalmente, a administraciones y demás organismos cuando sean requeridos en cumplimiento de obligaciones legales.

 

III.- BASE LEGAL QUE LEGITIMA EL TRATAMIENTO DE LOS DATOS PERSONALES.

En cada tratamiento específico de datos personales le informaremos de la base legal que lo legitima.

 

IV.- DERECHOS.

4.1.- DERECHO DE ACCESO.

Es el derecho a obtener del responsable del tratamiento confirmación de si están tratando o no datos personales que conciernen al interesado y, en tal caso, derecho de acceso a los datos personales y a la siguiente información: los fines del tratamiento, las categorías de datos personales de que se trate, los destinatarios o las categorías de destinatarios a los que se comunicaron o serán comunicados los datos personales, plazo de conservación o los criterios utilizados para determinar este plazo, la existencia del derecho a solicitar del responsable la rectificación o supresión de datos personales o la limitación del tratamiento de datos personales relativos al interesado o a oponerse a dicho tratamiento, derecho a presentar una reclamación ante la Agencia Española de Protección de Datos (AEPD), la existencia, en su caso, de decisiones automatizadas, incluida la elaboración de perfiles, cuando se transfieran datos a terceros países el derecho a ser informado de las garantías adecuadas aplicadas.

4.2.- DERECHO DE RECTIFICACIÓN.

Es el derecho a solicitar la rectificación de sus datos personales si son inexactos, incluyendo el derecho a completar datos que figuren incompletos. Hay que tener en cuenta que al facilitarnos los datos personales por cualquier vía, garantiza que son ciertos y exactos y se compromete a notificarnos cualquier cambio o modificación de los mismos. Por lo tanto cualquier daño causado por motivo de una comunicación de información errónea, inexacta o incompleta en los formularios de la web, será responsabilidad exclusiva del interesado.

4.3.- DERECHO DE SUPRESIÓN.

Es el derecho a solicitar la supresión de sus datos personales cuando, entre otros supuestos, ya no son necesarios para la finalidad por la cual fueron recabados, o están siendo tratados de otro modo o retire el consentimiento. Hay que tener en cuenta que no procederá la supresión cuando el tratamiento de los datos personales sea necesario, entre otros supuestos, para el cumplimiento de obligaciones legales o para la formulación, el ejercicio o la defensa de reclamaciones.

4.4.- DERECHO A LA LIMITACIÓN.

Es el derecho a solicitar la limitación del tratamiento de sus datos personales, lo que supone que en determinados casos pueda solicitarnos que suspendamos temporalmente los tratamientos de sus datos personales o que los conservemos más allá del tiempo necesario cuando pueda necesitarlo.

4.5.- DERECHO A RETIRAR EL CONSENTIMIENTO.

Es el derecho a retirar el consentimiento que ha proporcionado al firmar de forma manuscrita o digital en cualquier momento y según se especifica en el apartado correspondiente “Ejercicio de derechos” o en el tratamiento específico de comunicaciones comerciales o Newsletter. Hay que tener en cuenta que este derecho no surtirá efectos si, entre otros casos, el tratamiento de los datos personales es necesario para el cumplimiento de una obligación legal, la ejecución y el mantenimiento de una relación contractual, o para la formulación, ejercicio o la defensa de reclamaciones. Asimismo la retirada del consentimiento no tendrá efectos retroactivos, es decir, no afectará a la licitud del tratamiento basado en el consentimiento previo a su retirada.

4.6.- DERECHO A LA PORTABILIDAD.

Es el derecho a recibir los datos personales que le incumban y que nos haya facilitado, en un formato estructurado, de uso común y lectura mecánica, y a trasmitirlos a otro responsable, siempre y cuando: el tratamiento se base en su consentimiento y se efectúe por medios automatizados o informáticos.

4.7.- DERECHO DE OPOSICIÓN.

Es el derecho a oponerse al tratamiento de sus datos personales en base al interés legítimo nuestro. No seguiremos tratando sus datos personales a menos que podamos acreditar motivos legítimos imperiosos para el tratamiento que prevalezcan sobre sus intereses, derechos y libertades, o bien para la formulación, el ejercicio o la defensa de reclamaciones.

4.8.- DERECHO A PRESENTAR UNA RECLAMACIÓN ANTE UNA AUTORIDAD DE CONTROL.

Si considera que tratamos sus datos personales de un modo incorrecto, puede contactar con nosotros o también tiene derecho a presentar una reclamación ante la Agencia Española de Protección de Datos (AEPD):

https://www.agpd.es/portalwebAGPD/index-ides-idphp.php

4.9.- EJERCICIO DE DERECHOS.

Puede ejercer los derechos que le asisten a través de carta a la dirección postal arriba indicada o a través del e-mail [email protected], adjuntando en ambos casos copia de su NIF/NIE/Pasaporte o documento análogo.

 

V.- TRATAMIENTOS DE DATOS PERSONALES.

5.1.- DISPOSICIONES GENÉRICAS.

Los datos personales solicitados en cada uno de los tratamientos específicos son adecuados, pertinentes y limitados a lo necesario en relación con los fines para los que son tratados por lo que se cumple con el principio de minimización de datos.

Los datos personales solicitados en cada uno de los tratamientos específicos son los estrictamente necesarios, la negativa a facilitarlos implicaría no poder prestar el servicio solicitado.

Las comunicaciones de los datos personales previstas en cada uno de los tratamientos específicos en algunos casos son necesarias para la ejecución y el mantenimiento de un contrato y en otros casos para el cumplimiento de una obligación legal aplicable al responsable del tratamiento.

5.2.- TRATAMIENTOS BÁSICOS.

Pedido.

Los datos personales serán tratados para la confección del pedido y para aquellas otras finalidades necesarias para poder prestar el servicio contratado.

La base legal que legitima el tratamiento de los datos personales es que son necesarios para la ejecución de un contrato y para la aplicación de medidas precontractuales.

Los datos personales recabados podrán ser cedidos a colaboradores externos, así como a cualquier tercero, con la única finalidad de  poder prestar el servicio contratado.

Los datos personales se conservarán mientras se mantenga la relación entre las partes o durante los años necesarios para el cumplimiento de obligaciones legales.

Facturación.

Los datos personales serán tratados para la emisión de la correspondiente factura por los servicios prestados.

La base legal que legitima el tratamiento de los datos personales es el cumplimiento de una obligación legal aplicable al responsable.

En cumplimiento de obligaciones legales aplicables al responsable, los datos personales serán cedidos a la Administración Tributaria y demás organismos oficiales necesarios, y como requisito contractual necesario, a terceras empresas para la prestación de servicios al responsable de asesoría/gestoría, así como y en su caso, para la reclamación de garantías respecto a los productos y/o servicios contratados.

Los datos personales se conservarán mientras se mantenga la relación entre las partes o durante los años necesarios para el cumplimiento de obligaciones legales.

E-mail.

Los datos personales serán tratados para canalizar las solicitudes de información, sugerencias y reclamaciones de clientes o usuarios para su gestión y resolución.

La base legal que legitima el tratamiento de los datos personales es el interés legítimo del responsable.

Los datos personales se conservarán por un período de dos años desde el momento en que dejen de tratarse, sin perjuicio del ejercicio de los derechos que le asisten como interesado.

Alta Voluntarios.

Los datos personales serán tratados para gestionar el alta como voluntario en la Fundación, para gestiones administrativas, así como para cualquier otra finalidad legítima y necesaria en base a la relación que une a las partes.

La base legal que legitima el tratamiento de los datos personales es el consentimiento expreso prestado al firmar la correspondiente autorización para el tratamiento de los datos personales.

Como requisito contractual necesario, los datos personales podrán ser cedidos a colaboradores externos y a organismos, funcionarios públicos, registros públicos, demás terceros en general para el buen fin del encargo.

Los datos personales se conservarán mientras no retire el consentimiento, salvo que deban conservarse para el mantenimiento de la relación entre las partes o durante los años necesarios para el cumplimiento de obligaciones legales.

Alta pacientes.

Los datos personales serán tratados para gestionar el alta como paciente de  la fundación, para gestiones administrativas, para la ejecución y mantenimiento de la prestación de servicios, así como para cualquier otra finalidad legítima y necesaria en base a la relación que une a las partes.

La base legal que legitima el tratamiento de los datos personales es el consentimiento expreso prestado al firmar la correspondiente autorización para el tratamiento de los datos personales.

Como requisito contractual necesario, los datos personales podrán ser cedidos a colaboradores externos, y en cumplimiento de obligaciones legales, a organismos, funcionarios públicos, registros públicos, así como cualquier tercero, en general, necesario para el buen fin del encargo.

Los datos personales se conservarán mientras no retire el consentimiento, salvo que deban conservarse para el mantenimiento de la relación entre las partes o durante los años necesarios para el cumplimiento de obligaciones legales.

Entrevista Inicial.

Los datos personales serán tratados para prestar el servicio solicitado, así como para cualquier otra finalidad legítima y necesaria en base a la relación que une a las partes.

La base legal que legitima el tratamiento de los datos personales es el consentimiento expreso prestado por el representante legal del menor al firmar la correspondiente autorización para el tratamiento de los datos personales.

 

Los datos personales se conservarán mientras no retire el consentimiento, salvo que deban conservarse para el mantenimiento de la relación entre las partes o durante los años necesarios para el cumplimiento de obligaciones legales.

Hoja Encargo Profesional.

Los datos personales serán tratados para gestionar la ejecución y mantenimiento del encargo profesional contratado.

La base legal que legitima el tratamiento de los datos personales es el consentimiento expreso prestado al firmar la correspondiente hoja de encargo profesional.

Como requisito contractual necesario, los datos personales serán cedidos a colaboradores externos y a organismos, funcionarios públicos, registros públicos, demás terceros en general para el buen fin del encargo.

Los datos personales se conservarán mientras no retire el consentimiento, salvo que deban conservarse para el mantenimiento de la relación entre las partes o durante los años necesarios para el cumplimiento de obligaciones legales.

Currículum E-mail Voluntarios.

Los datos personales serán tratados para gestionar el proceso selectivo de Voluntarios en la Fundación y para permitir la comunicación entre las partes.

La base legal que legitima el tratamiento de los datos personales es el interés legítimo del responsable.

Como requisito contractual necesario, los datos personales podrán ser cedidos a terceras empresas/organismos que formen parte o colaboren con la Fundación con la misma finalidad indicada para este tipo de tratamiento.

Los datos personales se conservarán por un período de dos años desde el momento en que dejen de tratarse, sin perjuicio del ejercicio de los derechos que le asisten como interesado.

Eventos.

Los datos personales serán tratados para gestionar los servicios contratados, para gestiones administrativas, así como para cualquier otra finalidad legítima y necesaria en base a la relación que une a las partes.

La base legal que legitima el tratamiento de los datos personales es el consentimiento expreso prestado al firmar la correspondiente autorización para el tratamiento de los datos personales.

En cumplimiento de obligaciones legales aplicables al responsable, los datos personales podrás ser cedidos a colaboradores externos y a terceros, en general, necesarios para el buen fin del encargo.

Los datos personales se conservarán mientras no retire el consentimiento, salvo que deban conservarse para el mantenimiento de la relación entre las partes o durante los años necesarios para el cumplimiento de obligaciones legales.

Donaciones.

Los datos personales serán tratados para canalizar las donaciones económicas.

La base legal que legitima el tratamiento de los datos personales es el consentimiento expreso prestado al firmar la correspondiente autorización para el tratamiento de los datos personales.

Los datos personales se conservarán por un período de dos años desde el momento en que dejen de tratarse, sin perjuicio del ejercicio de los derechos que le asisten como interesado.

Currículum Papel.

Los datos personales serán tratados para gestionar el proceso selectivo de Voluntarios en la Fundación  y para permitir la comunicación entre las partes.

La base legal que legitima el tratamiento de los datos personales es el consentimiento expreso prestado al firmar la correspondiente autorización para el tratamiento de los datos personales.

Como requisito contractual necesario, los datos personales podrán ser cedidos a terceras empresas/organismos que formen parte o colaboren con la Fundación con la misma finalidad indicada para este tipo de tratamiento.

Los datos personales se conservarán por un período de dos años desde el momento en que dejen de tratarse, sin perjuicio del ejercicio de los derechos que le asisten como interesado.

PRIVACY POLICY

 

This privacy policy is in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council, of the 27th of April 2016, concerning the protection of natural persons with regard to the processing of personal data and free movement of these data (RGPD), to Organic Law 3/2018, of the 5th of December, Protection of Personal Data and Digital Rights Guarantee (LOPDGDD), as well as in what is not contrary to the regulations indicated, to the Law Organic 15/1999, Protection of Personal Data (LOPD) and its development regulations, and/or those that could replace or update in the future.

Our organisation is committed to the privacy of your personal data. The personal data provided are necessary to delivery of our services and are processed in a lawful, fair and transparent manner, ensuring adequate security of them, including protection against unauthorised or illegal processing and against loss, destruction or accidental damage through the application of technical and organizational measures.

Through this document we want to offer you in a transparent and loyal way all the necessary information related to the processing of your personal data that this organization makes

 

I.- RESPONSIBLE FOR PROCESSING.

IDENTITY: M.A.B.S. CANCER SUPPORT

C.I.F.: G54982681

ADDRESS: C/ CARAVAGGIO, 1, 03730 JAVEA (ALICANTE)

TELEPHONE: 686305006

E-MAIL: [email protected]

DATA PROTECTION OFFICER: [email protected]

 

II.- RECIPIENTS OF THE PERSONAL DATA.

1.- The personal data provided shall not be subject to any transfer unless it is stated specifically in the specific processes.

2.- Optionally, for the contracting of computing cloud services and/or services for the sending of emails, as well as related services, the personal data can be:

– Transferred to businesses for digital services located within the European Economic Area (EEA) or,

– Transferred to businesses for digital services located outside the EEA under the protection of the Privacy Shield as they count on means of protection sufficient to guarantee the security of personal data. More information available following this link: https://www.privacyshield.gov/welcome

3.- Optionally, to administrations and other organisations when they are required in compliance with legal obligations.

 

III.- LEGAL BASIS FOR PROCESSING YOUR PERSONAL DATA.

In each case of processing of personal data collected concerning yourself, we will inform you of the legal basis that legitimises the processing of your personal data.

 

IV.- RIGHTS.

4.1.- RIGHT OF ACCESS.

It is the right to obtain, from the responsible, the confirmation of whether or not we are processing personal data concerning you and, in such case, the right of access to personal data and the following information: the purposes of the processing, the categories of personal data in question, the recipients or their categories to whom the personal data, the storage period or the criteria used to determine this period, have been communicated or will be communicated, the existence of the right to request rectification or suppression of data, from the responsible, personal data or the limitation of the processing of personal data concerning the interested party or to oppose such processing, the right to file a claim with the Spanish Data Protection Agency (AEPD), the existence, where appropriate, of automated decisions, including the preparation of profiles, when data is transferred to third countries, the right to be informed of the appropriate guarantees applied.

4.2.- RIGHT TO RECTIFICATION.

It is the right to request the rectification of your personal data if they are inaccurate, including the right to fill out incomplete data. We must bear in mind that by providing personal data by any means, guarantees they are true and accurate and agrees to notify us of any change or modification thereof. Therefore, any damage caused due to a communication of erroneous, inaccurate or incomplete information in the forms of the web, will be the exclusive responsibility of the interested party.

4.3.- RIGHT OF SUPPRESSION.

It is the right to request the suppression of your personal data when, among other assumptions, they are no longer necessary for the purpose for which they were collected, or are being processed differently or withdraw the consent. It must be borne in mind that the suppression will not proceed when the processing of personal data is necessary, among other assumptions, for compliance with legal obligations or for the formulation, exercise or defence of claims.

4.4.- RIGHT TO LIMITATION.

It is the right to request the limitation of the processing of your personal data, which means that, in certain cases, you may ask us to temporarily suspend the processing of your personal data or that we keep them beyond the necessary time when you may need it.

4.5.- RIGHT TO WITHDRAW CONSENT.

It is the right to withdraw the consent you have provided when signing, in a handwritten or digital form, at any time and as specified in the corresponding section “Exercise of rights” or in the specific processing of commercial communications or Newsletter. It must be borne in mind that this right will not be effective if, among other cases, the processing of personal data is necessary for the fulfilment of a legal obligation, the performance and maintenance of a contractual relationship, or for the formulation, exercise or the defence of claims. Likewise, the withdrawal of consent will not have retroactive effects, that is, it will not affect the legality of the processing based on the consent prior to its withdrawal.

4.6.- RIGHT TO PORTABILITY.

It is the right to receive the personal data that concern you and that you have given us, in a structured format, of common use and mechanical reading, and to transmit them to another person responsible, as long as: the processing is based on your consent and is carried out by automated or computerized media.

4.7.- RIGHT TO OPPOSITION.

It is the right to oppose the processing of your personal data based on our legitimate interest. We will not continue to process your personal data unless we can demonstrate compelling legitimate reasons for the processing, that prevail over your interests, rights and freedoms, or for the formulation, exercise or defence of claims.

4.8.- RIGHT TO FILE A CLAIM WITH A CONTROL AUTHORITY.

If you consider that we process your personal data in an incorrect way, you can contact us or you have the right to file a claim with the Spanish Agency for Data Protection (AEPD):

https://www.agpd.es/portalwebAGPD/index-ides-idphp.php

4.9.- EXERCISING OF THESE RIGHTS.

You can exercise your rights by letter to the postal address indicated above or by e-mail [email protected], attaching in both cases a copy of your NIF/NIE/Passport or similar document.

 

V.- PERSONAL DATA PROCESSING.

5.1.- GENERAL PROVISIONS.

The personal data requested in each of the specific processings are adequate, pertinent and limited to what is necessary in relation to the purposes for which they are processed, thus complying with the principle of data minimization.

The personal data requested in each of the specific processings are strictly necessary, the refusal to provide them would imply not being able to provide the requested service.

The communications of the personal data provided in each of the specific processings, in some cases, are necessary for the execution and maintenance of a contract and in other cases for compliance with a legal obligation applicable to the processing responsible.

5.2.- BASIC PROCESSING.

Order.

Personal data will be processed for the purpose of placing the order and for other purposes necessary for the provision of the contracted service.

The legal basis that legitimises the personal data processing is that it is necessary for the execution of a contract and for the application of pre-contractual measures.

Personal data collected may be transferred to external collaborators, as well as to any third party, for the sole purpose of providing the contracted service.

Personal data will be kept for as long as the relationship between the parties is maintained or for the years necessary to comply with legal obligations.

Invoicing.

Personal data will be processed for the issuance of the corresponding invoice for the services rendered.

The legal basis that legitimises the personal data processing is the fulfilment of a legal obligation applicable to the person responsible.

In compliance with legal obligations applicable to the person responsible, the personal data will be transferred to the Tax Administration and other necessary official bodies, and as a necessary contractual requirement, to third party companies for the provision of services to the person responsible for consultancy/management, as well as and where appropriate, for the claiming of guarantees regarding the products and/or services contracted.

Personal data will be kept as long as the relationship between the parties is maintained or for the years necessary to comply with legal obligations.

E-mail.

Personal data will be processed to channel requests for information, suggestions and complaints from customers or users for management and resolution.

The legal basis that legitimises the personal data processing is the legitimate interest of the person responsible.

Personal data will be kept for a period of two years from the time they are no longer processed, without prejudice to the exercise of the rights of the data subject.

Volunteers Registration.

Personal data will be processed to manage the registration as a volunteer in the Foundation, for administrative procedures, as well as for any other legitimate and necessary purpose based on the relationship between the parties.

The legal basis that legitimises the personal data processing is the express consent given when signing the corresponding authorisation for the personal data processing.

As a necessary contractual requirement, the personal data may be transferred to external collaborators, and in compliance with legal obligations, to bodies, public officials, public registers, as well as any third party, in general, necessary for the successful completion of the assignment.

Personal data will be kept for as long as you do not withdraw your consent, unless it must be kept for the maintenance of the relationship between the parties or for the years necessary for the fulfilment of legal obligations.

Patients Registration.

Personal data will be processed to manage the registration as a patient of the foundation, for administrative procedures, for the execution and maintenance of the provision of services, as well as for any other legitimate and necessary purpose based on the relationship that binds the parties.

The legal basis that legitimises the processing of personal data is the express consent given by signing the corresponding authorisation for the persona data processing.

As a necessary contractual requirement, personal data may be disclosed to external partners, and in compliance with legal obligations, to agencies, public officials, public registers, as well as any third party, in general, necessary for the proper performance of the assignment.

Personal data will be retained for as long as you do not withdraw your consent, unless it must be retained for the maintenance of the relationship between the parties or for the years necessary for the fulfilment of legal obligations.

Initial Interview.

Personal data will be processed in order to provide the requested service, as well as for any other legitimate and necessary purpose based on the relationship between the parties.

The legal basis that legitimises the personal data processing is the express consent given by the legal representative of the minor by signing the corresponding authorisation for the processing of personal data.

Personal data will be kept for as long as you do not withdraw your consent, unless they must be kept for the maintenance of the relationship between the parties or for the years necessary for the fulfilment of legal obligations.

Professional Order Form.

Personal data will be processed to manage the execution and maintenance of the professional order.

The legal basis that legitimates the personal data processing is the express consent given when signing the corresponding professional order form.

As a necessary contractual requirement, the personal data will be transferred to external partners and organisations, public officials, public registers, other third parties in general for the purpose of the successful completion of the assignment, as well as to third companies for the provision of services to the responsible consultant/manager.

Personal data will be kept for as long as you do not withdraw your consent, unless it must be kept for the maintenance of the relationship between the parties or for the years necessary for the fulfilment of legal obligations..

Curriculum E-mail Volunteers.

Personal data will be processed in order to manage the selection process of Volunteers in the Foundation and to allow communication between the parties

The legal basis that legitimates the personal data processing is the legitimate interest of the person in charge.

As a necessary contractual requirement, personal data may be transferred to third party companies that are part of the group with the same purpose indicated for this type of processing.

Personal data will be kept for a period of two years from the time they are no longer processed, without prejudice to the exercise of the rights to which you are entitled as a data subject..

Events.

Personal data will be processed to manage the contracted services, for administrative purposes, as well as for any other legitimate and necessary purpose based on the relationship between the parties.

The legal basis that legitimises the personal data processing is the express consent given by signing the authorisation for the personal data processing.

In compliance with legal obligations applicable to the data responsible, personal data may be disclosed to external collaborators and third parties, in general, necessary for the proper performance of the assignment.

Personal data will be kept for as long as you do not withdraw your consent, unless they must be kept for the maintenance of the relationship between the parties or for the years necessary for the fulfilment of legal obligations.

Donations.

Personal data will be processed for the purpose of channelling financial donations.

The legal basis that legitimises the personal data processing is the express consent given by signing the corresponding authorisation for the processing of personal data.

Personal data will be kept for a period of two years from the time they are no longer processed, without prejudice to the exercise of the rights to which you are entitled as a data subject.

Curriculum Paper.

Personal data will be processed to manage the selection process of Volunteers in the Foundation and to allow communication between the parties.

The legal basis that legitimises the personal data processing is the express consent given when signing the corresponding authorisation for the personal data processing.

As a necessary contractual requirement, personal data may be transferred to third party companies that are part of the group with the same purpose indicated for this type of processing.

Personal data will be kept for a period of two years from the time they are no longer processed, without prejudice to the exercise of the rights to which you are entitled as a data subject.

—————————————————