Privacy Policy

PRIVACY POLICY AND DATA PROTECTION

Respecting the provisions of current legislation, Sunmarket (hereinafter, also referred to as the Website) is committed to adopting the necessary technical and organizational measures, according to the appropriate level of security based on the risk of the collected data.

Laws incorporated in this privacy policy

This privacy policy is adapted to the current Spanish and European regulations on the protection of personal data on the internet. Specifically, it complies with the following rules:

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR). Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights (LOPD-GDD). Royal Decree 1720/2007 of 21 December, approving the implementing regulation of Organic Law 15/1999 of 13 December on the Protection of Personal Data (RDLOPD). Law 34/2002 of 11 July, on Information Society Services and Electronic Commerce (LSSI-CE). Identity of the data controller

The data controller for the personal data collected on Sunmarket is: SUNMARKET WELLNESS SL, with tax ID number: B97238372, registered in the Commercial Register of Valencia with the following registration data, whose representative is: José Manuel Romero García (hereinafter, the Data Controller). The contact details are as follows:

Address: Av. Maestro Rodrigo 99 46015 - Valencia - Spain Contact telephone number: 961040660 Contact email: [email protected]

Personal Data Registry

In compliance with the GDPR and the LOPD-GDD, we inform you that the personal data collected by Sunmarket through the forms extended on its pages will be incorporated and processed in our files in order to facilitate, streamline, and fulfill the commitments established between Sunmarket and the User, or to maintain the relationship established in the forms they fill out, or to respond to a request or query from the User. Likewise, in accordance with the provisions of the GDPR and the LOPD-GDD, unless the exception provided in Article 30.5 of the GDPR applies, a record of processing activities is kept, specifying, according to their purposes, the processing activities carried out and the other circumstances established in the GDPR.

Principles applicable to the processing of personal data

The processing of the User's personal data will be subject to the following principles set forth in Article 5 of the GDPR and in Article 4 and subsequent articles of Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights:

Lawfulness, fairness, and transparency: The User's consent will be required at all times, after providing complete information on the purposes for which the personal data are collected. Purpose limitation: Personal data will be collected for specified, explicit, and legitimate purposes. Data minimization: The personal data collected will be adequate, relevant, and limited to what is necessary for the purposes for which they are processed. Accuracy: The personal data must be accurate and kept up to date. Storage limitation: Personal data will be kept for no longer than necessary for the purposes of the processing. Integrity and confidentiality: Personal data will be processed in a manner that ensures its security and confidentiality. Accountability: The Data Controller is responsible for ensuring compliance with the above principles. Categories of personal data

The categories of data processed in Sunmarket are only identifying data. Under no circumstances are special categories of personal data processed within the meaning of Article 9 of the GDPR.

Legal basis for the processing of personal data

The legal basis for the processing of personal data is consent. Sunmarket is committed to obtaining the express and verifiable consent of the User for the processing of their personal data for one or more specific purposes.

The User will have the right to withdraw their consent at any time. Withdrawing consent will be as easy as giving it. As a general rule, the withdrawal of consent will not condition the use of the Website.

In cases where the User is required or has the option to provide their data through forms to make inquiries, request information, or for reasons related to the content of the Website, they will be informed if the completion of any of the fields is mandatory because they are essential for the proper development of the operation carried out.

Purposes of the processing to which the personal data are destined

The personal data collected and managed by Sunmarket are intended to facilitate, streamline, and fulfill the commitments established between the Website and the User, or to maintain the relationship established in the forms filled out by the latter, or to respond to a request or inquiry.

Likewise, the data may be used for commercial purposes such as personalization, operation, and statistics, as well as activities related to the corporate purpose of Sunmarket, and for the extraction, storage of data, and marketing studies to tailor the Content offered to the User and improve the quality, functioning, and navigation of the Website.

At the time the personal data is obtained, the User will be informed of the specific purpose(s) of the processing to which the personal data will be destined, i.e., the use(s) that will be made of the collected information.

Retention periods of personal data

Personal data will only be retained for the minimum period necessary for the purposes of their processing and, in any case, only for the following period: 5 years, or until the User requests their deletion.

At the time the personal data is obtained, the User will be informed of the retention period for the personal data, or if that is not possible, the criteria used to determine this period.

Recipients of personal data

The User's personal data will not be shared with third parties, except in cases where it is necessary to fulfill the specific purposes of the processing and always with the prior consent of the User.

In the case of evaluating services and products through Trustpilot, the name, email, and order number will be transferred to this platform in order to collect and display user reviews. No other personal data will be transferred.

In addition, personal data may be provided to the company responsible for the delivery of products in order to manage and carry out their delivery.

Personal data of minors

Respecting the provisions of Articles 8 of the GDPR and 7 of Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights, only individuals over 14 years of age may lawfully consent to the processing of their personal data by Sunmarket. If the individual is under 14 years of age, the consent of their parents or guardians will be necessary for the processing, and it will only be considered lawful to the extent that they have authorized it.

Secrecy and security of personal data

Sunmarket is committed to adopting the necessary technical and organizational measures, according to the appropriate level of security based on the risk of the collected data, in order to ensure the security of personal data and prevent their destruction, loss, or alteration, whether accidental or unlawful, or unauthorized communication or access to such data.

The Website has an SSL certificate (Secure Socket Layer), which ensures that personal data is transmitted securely and confidentially, as the transmission of data between the server and the User, and vice versa, is fully encrypted.

However, since Sunmarket cannot guarantee the impregnability of the internet or the total absence of hackers or others who fraudulently access personal data, the Data Controller undertakes to notify the User without undue delay in the event of a breach of the security of personal data that is likely to result in a high risk to the rights and freedoms of individuals. In accordance with Article 4 of the GDPR, a security breach of personal data is understood as any breach of security that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed.