Privacy policy

In compliance with the provisions of current legislation, MaMaterno (hereinafter, also Website) undertakes to adopt the necessary technical and organizational measures, according to the level of security appropriate to the risk of the data collected.

Laws incorporated into this privacy policy

This privacy policy is adapted to current Spanish and European regulations on the protection of personal data on the internet. Specifically, it complies with the following regulations:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council, of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR).
  • Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (LOPD-GDD).
  • Royal Decree 1720/2007, of December 21, approving the regulations for the development of Organic Law 15/1999, of December 13, on the Protection of Personal Data (RDLOPD).
  • Law 34/2002, of July 11, on Information Society Services and Electronic Commerce (LSSI-CE).

1 - WHO IS RESPONSIBLE FOR THE PROCESSING OF YOUR DATA?

The owner of the website mamaterno.com responsible for the processing of your data is:

  • IDENTIFICATION DATA
    • Name: Nerea Pérez Carneiro
    • DNI (National ID): 1543190E
    • Address: Avda. Castrelos, 27, 36210, Galicia (Spain)
    • Phone: 600087760
    • Email: infomamaterno@gmail.com

This privacy policy regulates the access, browsing, and use of the website.

2 - LEGAL BASIS FOR THE PROCESSING OF PERSONAL DATA

The categories of data processed on MaMaterno are solely identification data. In no case are special categories of personal data processed within the meaning of Article 9 of the GDPR.

The legal basis for the processing of personal data is consent. MaMaterno undertakes to obtain the User's express and verifiable consent for the processing of their personal data for one or more specific purposes.

The User shall have the right to withdraw their consent at any time. It will be as easy to withdraw consent as it is to give it. As a general rule, the withdrawal of consent will not condition the use of the Website.

On occasions where the User must or may provide their data through forms to make inquiries, request information, or for reasons related to the content of the Website, they will be informed if the completion of any of them is mandatory because they are essential for the proper development of the operation carried out.

2.1 Principles applicable to the processing of personal data

The processing of the User's personal data shall be subject to the following principles set forth in Article 5 of the GDPR and in Article 4 and following of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights:

  • Principle of lawfulness, fairness, and transparency: the User's consent will be required at all times after completely transparent information regarding the purposes for which the personal data is collected.
  • Principle of purpose limitation: personal data will be collected for specified, explicit, and legitimate purposes.
  • Principle of data minimization: the personal data collected will only be that which is strictly necessary in relation to the purposes for which it is processed.
  • Principle of accuracy: personal data must be accurate and always kept up to date.
  • Principle of storage limitation: personal data will only be kept in a form which permits identification of the User for as long as necessary for the purposes of its processing.
  • Principle of integrity and confidentiality: the personal data will be processed in a manner that ensures its security and confidentiality.
  • Principle of accountability: the Controller shall be responsible for ensuring that the above principles are complied with.

3 - WHAT TYPE OF DATA DO WE MANAGE?

  • Identification information: First and last names.
  • Contact information: Email address, phone number, and postal address.
  • Data on the purchase of goods and services on the Website: Products and services in which the user has shown interest.
  • Financial information: Bank card.
  • Search information: IP address, browser type, Internet service provider, referring/exit pages, operating system, date/time stamp, and user tracking data on our website.

4- FOR WHAT PURPOSE DO WE MANAGE YOUR DATA?

Personal data is collected and managed by MaMaterno with the purpose of being able to facilitate, expedite, and fulfill the commitments established between the Website and the User, or the maintenance of the relationship established in the forms that the latter fills out, or to respond to a request or inquiry.

Likewise, the data may be used for commercial purposes of personalization, operational and statistical analysis, and activities proper to the corporate object of MaMaterno, as well as for data extraction, storage, and marketing studies to adapt the Content offered to the User, as well as to improve the quality, operation, and navigation of the Website.

At the time the personal data is obtained, the User will be informed about the specific purpose or purposes of the processing for which the personal data will be intended; that is, the use or uses that will be given to the collected information.

    5 - DATA STORAGE

    The protection of the privacy and personal data of Users is very important to MaMaterno. We do everything possible to prevent the User's data from being used inappropriately. Only authorized personnel have access to the User's data.

    MaMaterno will keep the Users' personal data only for the time necessary to carry out the purposes for which it was collected, as long as the User does not revoke their will to unsubscribe from MaMaterno's services.

    Subsequently, if necessary, MaMaterno will keep the information blocked within the legally established deadlines.

    6- USER RIGHTS

    The User has the following rights recognized under the GDPR and Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights, regarding MaMaterno, and may therefore exercise them before the Controller:

    • Right of access: It is the User's right to obtain confirmation of whether or not MaMaterno is processing their personal data and, if so, to obtain information about their specific personal data and the processing that MaMaterno has carried out or is carrying out, as well as, among others, information available about the origin of said data and the recipients of the communications made or planned to be made.
    • Right to rectification: It is the User's right to have their personal data modified if it is found to be inaccurate or, taking into account the purposes of the processing, incomplete.
    • Right to erasure ("the right to be forgotten"): It is the User's right, provided that current legislation does not establish otherwise, to obtain the erasure of their personal data when it is no longer necessary for the purposes for which it was collected or processed; the User has withdrawn their consent for the processing and there is no other legal basis for it; the User objects to the processing and there is no other legitimate reason to continue with it; the personal data has been processed unlawfully; the personal data must be erased in compliance with a legal obligation; or the personal data has been obtained as a result of a direct offer of information society services to a minor under 14 years of age. In addition to erasing the data, the Controller, taking into account available technology and the cost of implementation, must take reasonable steps to inform controllers who are processing the personal data of the data subject's request for the erasure of any links to such personal data.
    • Right to restriction of processing: It is the User's right to restrict the processing of their personal data. The User has the right to obtain the restriction of processing when they contest the accuracy of their personal data; the processing is unlawful; the Controller no longer needs the personal data, but the User needs it to make claims; and when the User has objected to the processing.
    • Right to data portability: In the event that the processing is carried out by automated means, the User shall have the right to receive their personal data from the Controller in a structured, commonly used, and machine-readable format, and to transmit it to another controller. Whenever technically possible, the Controller will transmit the data directly to that other controller.
    • Right to object: It is the User's right not to have their personal data processed or to have the processing stopped by MaMaterno.
    • Right not to be subject to a decision based solely on automated processing, including profiling: It is the User's right not to be subject to an individualized decision based solely on the automated processing of their personal data, including profiling, existing unless current legislation establishes otherwise.

    Thus, the User may exercise their rights by written communication addressed to the Controller with the reference "GDPR-mamaterno.com", specifying:

    • Name, surnames of the User, and a copy of their DNI (ID card). In cases where representation is admitted, identification by the same means of the person representing the User will also be necessary, as well as the document accrediting the representation. The photocopy of the DNI may be replaced by any other legally valid means that proves identity.
    • Petition with the specific reasons for the request or information to which access is sought.
    • Address for notification purposes.
    • Date and signature of the applicant.
    • Any document that proves the request being made.

    This request can be sent to the following email address:

    Email: infomamaterno@gmail.com

    7 - SHOPIFY

    Our store is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our products and services to you.

    Your data is stored through Shopify's data storage, databases, and the general Shopify application.

    Payments:

    If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete the purchase transaction. After it is completed, your purchase transaction information is deleted.

    All direct payment gateways adhere to the standards set by PCI-DSS as indicated by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express, and Discover.

    PCI-DSS requirements help ensure the secure handling of credit card information by stores and their service providers.

    8 - THIRD-PARTY SERVICES

    In general, the third-party services used by us will only collect, use, and disclose your information to the extent necessary to allow them to perform the services they provide to us.

    However, some third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies with respect to the information we are required to provide to them for purchase-related transactions.

    For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled.

    In particular, remember that some providers may be located in or have facilities that are located in a different jurisdiction than you or us. So if you wish to proceed with a transaction that involves the services of a third-party provider, your information may be subject to the laws of the jurisdiction(s) in which the service provider or its facilities are located.

    Once you leave our store's website or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy or our website’s Terms of Service.

    Links:

    When you click on links in our store, you may be redirected away from our site. We are not responsible for the privacy practices of other sites and we encourage you to read their privacy statements.

    9 - COOKIES

    We use cookies and similar devices to facilitate your browsing on mamaterno.com, to understand how you interact with us, and, in certain cases, to show you advertisements based on your browsing habits. Please read our Cookie Policy to learn more about the cookies and similar devices we use.

    For information about our cookie policy, you can access the following link.

    10 - SECURITY

    MaMaterno is committed to adopting the necessary technical and organizational measures, according to the security level appropriate to the risk of the collected data, in such a way as to guarantee the security of personal data and avoid the accidental or unlawful destruction, loss, or alteration of personal data transmitted, stored, or otherwise processed, or the unauthorized communication of or access to such data.

    However, because MaMaterno cannot guarantee the impregnability of the internet or the total absence of hackers or others who access personal data fraudulently, the Data Controller undertakes to notify the User without undue delay when a breach of personal data security occurs that is likely to pose a high risk to the rights and freedoms of natural persons. Following the provisions of Article 4 of the GDPR, a personal data security breach is understood to be any security breach that leads to the accidental or unlawful destruction, loss, or alteration of personal data transmitted, stored, or otherwise processed, or the unauthorized communication of or access to such data.

    11 - PERSONAL DATA OF MINORS

    Respecting the provisions of Articles 8 of the GDPR and 7 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights, only those over 14 years of age may grant their consent for the processing of their personal data lawfully by MaMaterno. If the individual is under 14 years of age, the consent of parents or guardians will be necessary for the processing, and this will only be considered lawful to the extent that they have authorized it.

    12 - CHANGES TO THIS PRIVACY POLICY

    We reserve the right to modify this privacy policy at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their posting on the website. If we make material changes to this policy, we will notify you here that it has been updated, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it.

    If our store is acquired or merged with another company, your information may be transferred to the new owners so that we can continue to sell products to you.

    13 - QUESTIONS AND CONTACT INFORMATION

    If you would like to: access, correct, amend, or delete any personal information we have about you, register a complaint, or simply want more information, contact our email address: infomamaterno@gmail.com