PRIVACY AND DATA PROTECTION POLICY
1. Data Controller
This Privacy Policy governs the processing of personal data collected through this website, managed by Cristina Chiquinquirá Carrillo Bonnet, holder of Spanish ID number (DNI) 47382107Z, with registered address at Calle Santo Domingo, nº 9, 2, 15001 A Coruña, Galicia, Spain, and contact email studio@bonnetstudio.es.
2. Purpose of Data Processing
Personal data collected through this website will be processed for the following purposes:
– To manage orders placed through the online store, including payment processing, invoicing, product shipping and customer support.
– To manage user registration and the creation of a personal account, allowing access to a private area protected by a password.
– To respond to inquiries, requests or communications sent through the contact form or by email.
– To send necessary communications related to order management, incidents, returns or information required for the proper provision of the service.
– To send information related to products, brand news or marketing communications, only when the user has given their prior consent.
3. Legal Basis for Processing
The processing of personal data is carried out on the following legal grounds:
Performance of a contract: to process and deliver orders placed through the online store.
User consent: when subscribing to newsletters or voluntarily submitting inquiries.
Compliance with legal obligations: in tax, accounting, or consumer matters.
4. Data Retention
Personal data will be retained for as long as necessary to fulfill the purposes for which it was collected and for the periods during which legal liabilities may arise.
Personal data associated with the user account will be retained for as long as the user keeps their account active and thereafter for the periods required to comply with applicable legal obligations.
In the case of marketing communications, personal data will be retained until the user requests its deletion.
5. Data Disclosure
Personal data will not be disclosed to third parties, except where required by law or when necessary for the proper provision of the service.
In particular, personal data may be accessed, as data processors, by the following categories of service providers:
– Technology and web hosting service providers, necessary for the operation and maintenance of the website.
– Payment service providers and financial institutions, for processing payments.
– Shipping and logistics companies, for the management and delivery of orders.
These providers will process personal data solely in accordance with the instructions of the data controller and in compliance with applicable data protection regulations.
Where service providers are located outside the European Economic Area, international data transfers will be carried out with appropriate safeguards, including adequacy decisions issued by the European Commission.
Bonnet Studio uses web hosting and website management services provided by Wix.com Ltd. In this context, certain personal data may be subject to international data transfers.
Such transfers are carried out to a country that has been recognized by the European Commission as providing an adequate level of data protection, in accordance with the General Data Protection Regulation.
6. User Rights
Users may exercise the following rights at any time:
-
Access to their personal data.
-
Rectification of inaccurate or incomplete data.
-
Deletion of their data when no longer needed.
-
Objection to the processing of their data.
-
Restriction of processing or data portability.
To exercise these rights, users may send a request to studio@bonnetstudio.es, duly identifying themselves.
If they believe their rights have not been respected, users may file a complaint with the Spanish Data Protection Agency (www.aepd.es).
Users may also request the deletion of their user account at any time, without prejudice to the retention of data that must be kept in order to comply with legal obligations.
7. Data Security
The controller is committed to ensuring the security and confidentiality of personal data, adopting the necessary technical and organizational measures to prevent loss, alteration, or unauthorized access.
8. Links to Third-Party Sites
This website may include links to third-party websites (for example, social networks or payment platforms).
The controller is not responsible for the privacy policies or content of such external sites.
9. Changes to This Privacy Policy
The controller reserves the right to modify this Privacy Policy at any time in order to adapt it to new legislation or changes in data management practices.
Any modifications will be published on this same page.