PRIVACY POLICY
PRIVACY POLICY OF https://ruthcepedano.com/
This Privacy Policy has been developed taking into account the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter, the GDPR), as well as Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter, LOPDGDD) and other applicable regulations.
This Privacy Policy aims to inform individuals who provide their personal data, and/or the data of the person they represent, about the specific aspects related to the processing of their data, the purposes of the processing, contact information for exercising their rights, data retention periods, and security measures, among other things.
WHO IS THE DATA CONTROLLER?
In terms of data protection, RUTH CEPEDANO GARCÍA is considered the Data Controller in relation to the processing of personal data carried out by this entity.
The Data Controller’s contact information is provided below:
• Identity of the Data Controller: RUTH CEPEDANO GARCÍA
• Tax ID Number: 46572231Z
• Physical Address: Av. de la Riera de Cassoles, 9, Local 5, 08012 Barcelona, Spain.
• Email: info@ruthcepedano.com
• Phone: +34 655 10 96 51
WHAT PERSONAL DATA DO WE PROCESS?
All information collected by RUTH CEPEDANO GARCÍA will be processed fairly, lawfully, and transparently.
Likewise, the data requested in each processing activity will consist solely of that which is strictly necessary to achieve the intended and informed purpose in each case.
In this way, your collected data will be adequate, relevant, and not excessive in relation to the purposes for which it is processed in each case. Furthermore, your personal data will be collected for specific, explicit, and legitimate purposes and will not be further processed in a manner incompatible with those purposes. In addition, it will be updated whenever necessary.
In general terms, within the framework of the various processing activities carried out in the organization, the following types of data are collected:
• Identifying data.
• Transactions of goods and services.
WHERE DOES THE PERSONAL DATA COME FROM?
As a general rule, personal data is always collected directly from the data subject. However, in certain exceptional cases, data may be collected through third parties, entities, or services other than the data subject.
In this regard, the data subject will be informed of this through the information clauses contained in the different data collection channels and within a reasonable timeframe or in the first communication made to the data subject.
WHAT IS THE PURPOSE OF PROCESSING PERSONAL DATA?
In general terms, personal data is processed for the following purposes:
• Contact: To respond to requests for information received about the products and services we offer, as well as to answer any other type of question submitted by users.
• Blog: Any personal data that may be processed through the blog will be used to manage the publication of informative and educational content related to the data controller’s activities.
The blog may also include features that allow content to be shared on third-party platforms, which may involve access to these external environments under their respective terms and privacy policies.
This data processing does not create profiles of website visitors, nor does it involve automated decision-making based on this data.
WHAT IS THE LEGAL BASIS FOR PROCESSING DATA?
As a general rule, the data subject’s consent is the legal basis for processing data for the purposes described above. This consent is given through a statement or a clear affirmative action, such as checking a box provided for this purpose, voluntary subscription, or by submitting data through forms. This consent can be withdrawn at any time by contacting the company through its contact channels. Generally, we will request your consent for uses other than those for which you initially provided it.
HOW LONG DO WE RETAIN PERSONAL DATA?
Generally, personal data is processed for the time necessary to fulfill the purpose for which it was collected, while the service or contractual relationship is maintained, while there is a mutual interest, and/or for the period stipulated in the applicable regulations.
Once the established retention periods have been met, the data will be deleted. This cancellation will result in the blocking of the data, which will be retained solely for the use of Public Administrations, Judges, and Courts to address any potential liabilities arising from the processing, for the duration of the applicable statute of limitations. Once this period has expired, the information will be destroyed.
WHO DO WE SHARE YOUR PERSONAL DATA WITH?
As a general rule, your data is not transferred or disclosed to third parties, except as legally required.
WHAT RIGHTS CAN YOU EXERCISE?
According to European regulations, you have the following rights:
• Right of Access: the right to request information from the data controller regarding whether your personal data is being processed.
• Right to Rectification: the right that allows the data subject to request the modification of inaccurate or incomplete data.
• Right to Object: the right of a person to object to the processing of their personal data or to request its cessation. • Right to Automated Individual Decisions: the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
• Right to Restriction of Processing: the right to suspend the processing of your personal data in certain circumstances.
• Right to Erasure (Right to be Forgotten): the right to have your personal data erased.
• Right to Data Portability: the right to request that the data controller provide your personal data in a structured, commonly used, and machine-readable format to another controller.
• Right to lodge a complaint with the competent supervisory authority if you believe that the processing does not comply with current regulations.
HOW TO EXERCISE YOUR RIGHTS?
You can exercise your rights through the following means:
• Email to info@ruthcepedano.com.
• Mail to Av. de la Riera de Cassoles, 9 local 5, 08012 Barcelona, Spain.
In both cases, documentation verifying the applicant’s identity may be required if necessary.
In any case, you may request the protection of the Spanish Data Protection Agency through its website https://www.aepd.es/.
In this regard, your request will be processed as soon as possible, taking into account the timeframes stipulated in data protection regulations.
WHAT COULD BE THE CONSEQUENCES OF NOT PROVIDING THE INFORMATION?
The data requested in the fields marked with an asterisk, or identified as mandatory, or those provided through the channels where the information is provided, are strictly necessary in relation to the purpose for which they are collected, or for providing optimal service to the interested party, or due to a legal obligation imposed on the data controller, or a requirement necessary to enter into a contract. Providing data in the remaining fields is voluntary.
If all the data is not provided, we cannot guarantee that the information and services provided will be fully tailored to your needs.
Therefore, if the required data is not provided, or is provided incorrectly or incompletely, we will be unable to process your request, making it impossible to provide you with the requested information or to contract the services.
Similarly, the user guarantees that the information transmitted in any of the forms is truthful, accurate, and corresponds to their own data.
Our platform services are not intended for minors; therefore, only individuals over 18 years of age are permitted to register. Otherwise, please note that any liabilities that may arise as a result of using our platforms will be the responsibility of the minor’s parents or guardians. To prevent the use of our services by minors, we attempt to verify the age of our users when they register by requesting their date of birth.
WHAT SECURITY MEASURES DO WE HAVE IMPLEMENTED?
The security measures adopted by RUTH CEPEDANO GARCÍA are those required in accordance with Article 32 of the GDPR. In this regard, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, appropriate technical and organizational measures have been established to ensure a level of security appropriate to the existing risk.
In any case, RUTH CEPEDANO GARCÍA has implemented sufficient mechanisms to:
• Guarantee the ongoing confidentiality, integrity, availability, and resilience of processing systems and services.
• Restore the availability of and access to personal data quickly in the event of a physical or technical incident.
• Regularly verify, assess, and evaluate the effectiveness of the technical and organizational measures implemented to ensure the security of the processing.
• Enable the encryption of data and communications.
CHANGES TO THIS PRIVACY POLICY
This Privacy Policy may be revised from time to time to reflect changes in applicable law, updates to procedures for collecting and using personal information, the introduction of new services, or the discontinuation of existing ones. These changes will be effective upon publication on the website, so it is important that you review this Privacy Policy regularly to stay informed of any updates.

