PRIVACY POLICY

Basic information

Data controller

PERSÁN, S.A.

Purpose

To manage queries or requests made by users and any issues arising from them.

Legitimacy

Execution of the legal relationship that arises when you fill out the contact form and send your query or request.

Recipients

We will mainly share your data with companies in the Persán Group and with service providers who help or support us, whether they are companies in the Persán Group itself or external collaborators with whom we have reached an agreement, and whether they are located inside or outside the European Union.

Rights

Access, rectify, and delete your data, as well as other rights that you can consult in this document.

Additional

You can find all the additional information about the processing of your personal data below.

Who is responsible for processing users’ personal data?

The entity responsible for processing personal information is PERSÁN, S.A. (“PERSÁN”), the Spanish parent company of the Persán Group (hereinafter, “Persán Group” and/or the “Organization”), with the following contact details:

  • Tax ID number: A-91380014.
  • Postal address: Calle Pino Albar, nº 2 – C.P. 41016 Seville.
  • Telephone: (+34) 954 99 83 50.
  • Email: info@persan.es.
  • Data Protection Officer: Yes, a DPO has been appointed within the organization.
  • DPO contact: gdpr@persan.es.

How did we obtain your personal data?

The personal data we process has been collected from the various forms available or via the email address provided for contacting us. All personal data marked with an asterisk on each of the forms is necessary for processing your queries or requests and is therefore mandatory. If you do not provide this data, we will not be able to respond to your queries or requests.

The categories of data processed are:

–                Identification data (first and last name, language, contact details, etc.).

–                Transactional information (for example, information you provide us about the service provided by PERSÁN).

We inform you that we do not process data that the General Data Protection Regulation classifies as “special categories of data” (health data, religion, ideology, trade union membership, etc.).

For what purpose do we process your personal data?

We process your personal data with the utmost respect and compliance with the applicable regulations on personal data protection.

We process your data for the following purposes:

  • To manage queries and requests made to us by interested parties and any issues arising from them.

We inform you that we will only process your personal data for the aforementioned purposes and that, under no circumstances, will automated decisions be made based on your profile.

What is the legal basis for processing your data?

With regard to queries and requests made through the contact form, the legal basis that legitimizes the processing of the personal data of interested parties is its necessity for the execution of the legal relationship that arises when filling out the form and sending the query or request. In other words, it is necessary to manage the queries or requests you make.

When your query is related to the exercise of the rights we inform you about below, or to complaints related to the products or services of the Persán Group, what legitimizes us to process your data is the fulfillment of legal obligations on our part.

How long will we keep your personal data?

With regard to the queries and requests we receive through the contact form, we will process your personal data for as long as necessary to resolve and respond to them and, subsequently, for as long as necessary to comply with legal obligations. Once the possible actions in each case have expired, we will proceed to delete your personal data.

What obligations do we comply with regarding the personal data we process?

PERSÁN complies with each and every one of the principles required by both the General Data Protection Regulation and the LOPDGDD. Below is a brief summary of all of them so that you can understand exactly what they entail. However, we will be happy to answer any questions you may have in this regard atgdpr@persan.es . In this regard, we will take these principles into account during all phases, processing, and actions to which the personal data for which we are responsible is subjected.

These principles are:  

  • Principle of lawfulness, fairness, and transparency, which implies, as its name suggests, that we will only have the right to process data in a “lawful, fair, and transparent manner in relation to the data subject.”
  • Principle of purpose limitation. This principle requires that data collected will only be processed for “specific, explicit, and legitimate purposes.” This principle also implies that such data may not be further processed “in a manner incompatible with those purposes.”

The prohibition on processing for incompatible purposes does not apply to the processing of such data for “archiving purposes in the public interest, scientific and historical research purposes or statistical purposes.”

  • Principle of data minimization. This obligation entails the duty of the Data Controller and all personnel working for them to process only data that is “adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.”
  • Principle of accuracy. This principle is reflected in the need to process personal data that is accurate and, therefore, up to date. We therefore ask that, if any of the personal data you provided us with when we began our relationship has changed, you please let us know as soon as possible so that we can process only personal data that is up to date and current.

You can access your Workday profile at any time to review or update your personal information.

  • Principle of storage limitation. This principle requires that personal data processed—in such a way as to allow the identification of data subjects—be kept only for as long as necessary for the purposes of processing personal data.
  • Principle of integrity and confidentiality. This obligation involves the adoption of all measures—technical, organizational, or otherwise—necessary to ensure “adequate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.”
  • Principle of Accountability. Compliance, in practice, with this duty of Accountability (also known as active responsibility or accountability) means that we must have an active and preventive—rather than reactive—attitude towards possible risks, threats, and/or inadequate processing of personal data from the outset in all phases of processing.

For this reason, all our staff are aware of the importance of this principle of accountability, which involves the adoption of preventive measures, proactive attitudes and actions, and, at all times, the utmost respect for the fundamental right to the protection of personal data of the data subject.

This principle of accountability involves extensive documentation work that allows for the traceability of all actions taken to fulfill this active responsibility by all PERSÁN staff.

  • Principle of lawfulness of processing. All processing of personal data must be lawful and, in this regard, includes six legal bases that make the processing of personal data lawful.

These bases are made up of the following factual assumptions:

  1. You gave your consent to the processing of your personal data for one or more specific purposes;
  2. the processing is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract;
  3. processing is necessary for compliance with a legal obligation to which the controller is subject;
  4. processing is necessary to protect your vital interests or those of another natural person;
  5. processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  6. processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.

You can also consult the full text of the General Data Protection Regulation and the LOPDGDD.

To whom will users’ personal data be disclosed?

In order to fulfill the purposes indicated in this Privacy Policy, we need to give access to your personal data to entities of the Persán Group (for example, to the Persán Group entity or entities located in the market you have referred to in your query) and to third parties who provide us with support in the services we offer you.

For service efficiency, some of the aforementioned providers are located in territories outside the European Economic Area that do not provide a level of data protection comparable to that of the European Union, such as the United States. In such cases, we inform you that we transfer your data with adequate safeguards and always ensuring the security of your data. We establish contractual agreements and security mechanisms that comply with our data protection, confidentiality, and security standards and applicable laws and regulations.

We may also disclose personal information to third parties for regulatory compliance purposes and/or as set forth in this Policy. We may also disclose your personal information to law enforcement, regulatory, and other government agencies, as well as professional bodies and other third parties, as required and/or in accordance with applicable laws or regulations. This includes disclosures outside the country or region where you are located. PERSÁN may also review and use your personal information to determine whether its disclosure is necessary or permitted.

What security measures has PERSÁN taken to protect your data?

At PERSÁN, we take all measures within our power to ensure the security and confidentiality of all personal data we process. These measures are both physical and logical, technical and organizational in nature, and necessary depending on the data we process. Of course, the measures are adopted with the aim of guaranteeing the security, confidentiality, and integrity of all the personal data we process to prevent its alteration, loss, unauthorized processing, and/or access, taking into account the state of technology, the nature of the data stored, and the risks to which it is exposed, whether from human action or from the physical or natural environment.

Among the security measures (by way of summary) that we adopt are: ongoing training of all our employees, use of secure passwords and frequent password changes, backups, encrypted transmission of personal data, control of access to personal data based on needs, security audits, hiring of data processors who offer the necessary security and strict compliance with data protection regulations, physical security measures for access control (keys, locks, etc.), certified destruction of confidential information, use of official programs that guarantee security in the processing of personal data, and, of course, all those offered by technology that are consistent with the risks identified for the processing of personal data carried out by PERSÁN.

In this regard, we ask that you do everything in your power to prevent yourself from becoming a victim of any of the attacks that, unfortunately, take place on the Internet. To this end, we remind you not to click on any links whose origin you are unsure of, not to provide bank details or passwords electronically or by telephone, to use a secure password (combining letters, numbers, and special characters), and to change it frequently (at least once a year). Likewise, if you have any doubts about PERSÁN requesting data and/or any other type of action, please consult us first at gdpr@persan.es before taking any action.

What rights do users have as data subjects?

As the owner of your personal data, either on your own behalf or through a legal or voluntary representative, you may exercise certain rights in relation to the personal information we hold about you. Specifically, you may have the right of access, rectification, restriction of processing, erasure, objection, and the right to data portability.

We briefly explain what each of these rights consists of:

  • Right of access: You have the right to know what personal data about you is being processed.
  • Right of rectification: You have the right to rectify any personal data about you that is incorrect or out of date (for example: change of web r email address, error in contact telephone number, change of postal address or account number).
  • Right to erasure: You have the right to request that personal data relating to you be However, if there is a reason that prevents this (contractual relationship, legal requirements, etc.), upon receiving your request, you will be informed whether your right to erasure can be granted or not.
  • Right to restriction of processing: You have the right to request that we cease certain processing of your personal data. However, as with the right to erasure, if there is a justified reason for not being able to comply with your request, we will inform you in a clear, simple, and transparent manner.
  • Right to data portability: You have the right to request a copy of the personal data being processed about you, provided that you have provided it and that it is in a structured, commonly used, and machine-readable format. You may also choose whether you want this data to be provided to you or to another data controller.
  • Right to object: You may exercise this right to object to certain processing of personal data that is being carried out. However, as with the right to erasure and restriction, if there are legitimate reasons that require the processing and/or legal obligations, you will be informed of this in a simple and transparent manner.
  • Right not to be subject to automated decisions: you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

To exercise these rights, you must contact us by email at gdpr@persan.es, indicating “Data Protection Rights” in the subject line, or, if you prefer, by post to our registered office, specifying which right you wish to exercise. We may ask you for a copy of your passport or identity document if it is necessary to verify your identity.

We will process requests in accordance with applicable law and within a reasonable time frame. We recommend that you include a clear and precise description of your request.

However, prior to submitting such a complaint, you may (and we ask you to do so) forward your complaint to our DPO, who will be happy to resolve your problem as soon as possible. You can contact our DPO at the following email address: gdpr@persan.es .

Finally, we inform you of your right to lodge a complaint with the relevant data protection supervisory authority, in particular, the Spanish Data Protection Agency (https://www.agpd.es/portalwebAGPD/index-ides-idphp.php).

Which body can you file a data protection complaint with?

Finally, we inform you of your right to file a complaint with the relevant data protection supervisory authority, in particular, the Spanish Data Protection Agency (https://www.agpd.es/portalwebAGPD/index-ides-idphp.php).

Changes to the Privacy Policy

This Privacy Policy was approved on February 16th of 2026. We may update its content at any time by publishing an updated version here. The new modified Privacy Policy will apply from the date of revision. Therefore, we recommend that you review this Policy periodically to stay informed about how we protect your information.

Persán