PRIVACY POLICY
This privacy policy applies to the processing of personal data of customers and/or users of https://esenziaclub.com, hereinafter referred to as "the WEBSITE", which is owned by ESENZIA ENTERPRISE 2019, S.L., hereinafter referred to as "the DATA CONTROLLER".
Applicable Regulations
Our Privacy Policy has been designed in accordance with REGULATION (EU) 2016/679 of the EUROPEAN PARLIAMENT and of the COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter GDPR EU 2016/679, and, insofar as it does not contradict said Regulation, in accordance with Organic Law 3/2018 of 5 December on the Protection of Personal Data and the guarantee of digital rights, hereinafter LOPDGDD 3/2018.
By providing their data, the customer and/or user declares to have read and understood this Privacy Policy, giving their unambiguous and express consent to the processing of their personal data in accordance with the purposes and terms set out herein.
Basic Data Protection Information
|
|
| Controller |
ESENZIA ENTERPRISE 2019, S.L. |
| Purpose |
To respond to information requests received, answer queries raised, process newsletter subscriptions to receive the latest news, offers and special promotions on our items and/or products, process orders from customers and/or users of the online store, provide customer service, and send commercial communications about our items and/or products via post, telephone, email, SMS/MMS, WhatsApp, Telegram or other equivalent electronic communication channels, provided the data subject has consented to the processing of their personal data for this purpose. |
| Legal basis |
Performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract. Legitimate interest of the controller. Consent of the data subject. |
| Recipients |
Data will not be shared with third parties, except where required by law. |
| Rights |
You have the right to access, rectify and erase your data, as well as other rights detailed in the additional information, which you may exercise by contacting the Data Controller at atencionalcliente@esenziaclub.com
|
| Additional information |
You can consult additional and detailed information on Data Protection in the annexed clauses available at https://esenziaclub.com/politica-de-privacidad
|
Additional Data Protection Information
The Data Controller is:
Data Protection Officer
The DATA CONTROLLER does not have a Data Protection Officer.
Purposes and Legal Basis for Processing
a) General
The DATA CONTROLLER processes the personal data provided by its customers and/or users for the following purposes:
Purpose: To handle information requests received, answer queries raised, process newsletter subscriptions to receive the latest news, offers and special promotions on our items and/or products, process orders from customers and/or users of the online store, provide customer service, carry out administrative, commercial, accounting and tax management, and send commercial communications about our items and/or products via post, telephone, email, SMS/MMS, WhatsApp, Telegram or other equivalent electronic communication channels, provided the data subject has consented to the processing of their personal data for this purpose.
Legal basis: Performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract. Legitimate interest. The consent of the data subject, which may be withdrawn at any time.
b) Website Electronic Forms
The DATA CONTROLLER processes the personal data provided by customers and/or users through the electronic data collection forms on the WEBSITE for the purposes identified below:
"Contact Form" and other enquiries (including those sent to the email accounts listed on the WEBSITE):
-
Purpose: To contact the data subject, handle information requests received and respond to queries raised, provide customer service, and send commercial communications about our items and/or products via post, telephone, email, SMS/MMS, WhatsApp, Telegram or other equivalent electronic communication channels, provided the data subject has consented to the processing of their personal data for this purpose.
-
Legal basis: Performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract. The consent of the data subject, which may be withdrawn at any time.
"Newsletter Subscription Form":
-
Purpose: Allows the user to subscribe to the informational newsletter to receive the latest news, offers and special promotions on our items and/or products directly to their email inbox.
-
Legal basis: The consent of the data subject, which may be withdrawn at any time.
"Create an Account Form":
-
Purpose: Allows the user to register to access the website's online store, and to receive commercial communications about promotions on our items and/or products via post, telephone, email, SMS/MMS, WhatsApp, Telegram or other equivalent electronic communication channels, provided the data subject has consented to the processing of their personal data for this purpose.
-
Legal basis: Performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract. The consent of the data subject, which may be revoked at any time.
"Log In Form":
-
Purpose: Allows registered users to access the online store using their username and password to purchase the items and/or products available.
-
Legal basis: Performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
"Guest Checkout Form":
-
Purpose: Allows users to purchase items and/or products available in the online store without prior registration.
-
Legal basis: Performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
"Live Chat Form – WhatsApp Web Online Customer Service Platform":
-
Purpose: Enables direct communication between the user and the DATA CONTROLLER via WhatsApp Web, an instant messaging application integrated into the website.
-
Legal basis: The consent of the data subject, which may be withdrawn at any time.
Where data requested in electronic forms is mandatory, the DATA CONTROLLER will indicate this at the point of collection, and failure to provide it will mean the corresponding request cannot be processed.
What Types of Data Do We Process?
For the purposes described above, we process customer data from the following sources and categories:
a) Data provided directly by the customer and/or user: data provided directly by the customer and/or user, either when requesting a service by completing electronic data collection forms or on paper, as well as data provided throughout the contractual relationship through various means, such as complaints or information requests submitted to Customer Services. The customer and/or user is responsible for the accuracy and currency of this data.
-
Identification data (name and surname(s), national ID, NIE, passport, postal address, email address, telephone number, mobile number, manual, handwritten or digital signature, social media profiles, IP addresses, username and password)
-
Financial data (bank details)
b) Data obtained from sources other than the customer and/or user: data obtained from third-party sources, either with the data subject's consent or on another legal basis (legitimate interest, compliance with a legal obligation, etc.).
c) Data derived from the commercial relationship: data provided indirectly by the customer and/or user as a result of the contracted service and the maintenance of that activity. This includes traffic data, payment history, purchase history of items and/or products, browsing data on the public website or within the private area, and other data of a similar nature.
Records of Processing Activities
We inform you that the personal data obtained from customers and/or users as a result of completing the electronic forms on the WEBSITE forms part of the DATA CONTROLLER's Records of Processing Activities (RPA), which will be updated periodically in accordance with GDPR EU 2016/679 and LOPDGDD 3/2018.
Recipients
The personal data of data subjects will be shared with the following recipients:
a) General:
- The DATA CONTROLLER's service providers acting as data processors, within the scope of the relevant services provided (lawyers, accounting and tax advisors, consultants, transport agencies and IT service providers — website hosting and email services).
- Competent authorities and bodies, to the extent necessary to comply with legal obligations.
b) In relation to the "Contact Form" and other enquiries, the "Newsletter Subscription Form", the "Create an Account Form", the "Log In Form", the "Guest Checkout Form" and the "Live Chat Form – WhatsApp Web Online Customer Service Platform":
- Data will not be shared with third parties, except where required by law.
International Data Transfers
No transfers of personal data to third countries without an adequate level of protection are planned.
Retention Periods
Personal data will be retained as follows:
a) General: Data will be retained until the data subject requests its deletion, and in any case for as long as necessary to comply with legal obligations.
b) In relation to the "Contact Form" and other enquiries, the "Newsletter Subscription Form", the "Create an Account Form", the "Log In Form", the "Guest Checkout Form" and the "Live Chat Form – WhatsApp Web Online Customer Service Platform": Personal data will be retained until the end of the relationship between the DATA CONTROLLER and the customer and/or user, unless the data subject requests deletion beforehand, or until the data subject withdraws their consent at any time, without affecting the lawfulness of processing based on consent prior to its withdrawal.
In this regard, data subjects are reminded that they must inform the DATA CONTROLLER, as the recipient of personal data, of any rectification or deletion of data relating to their representatives, authorised persons and other contacts.
Once the relationship has ended, to the extent that the personal data of data subjects remains relevant for the purposes of the DATA CONTROLLER's liability towards customers and/or users, such data will be retained in a duly blocked state, available to the relevant judicial authorities or public administrations, for the enforcement of any liabilities arising from the processing, until the applicable limitation period expires.
Rights of Data Subjects
Customers and/or users of the WEBSITE may exercise the following rights against the DATA CONTROLLER, where applicable: right of access to personal data, rectification, erasure (right to be forgotten), restriction of processing, data portability, objection to processing and the right not to be subject to automated individual decision-making, and, where processing is based on consent, the right to withdraw it at any time.
Customers and/or users may exercise these rights by submitting a signed written request to the DATA CONTROLLER's postal address at C/ San Eloy, 25, 41001, Seville (Spain), or by email to atencionalcliente@esenziaclub.com, attaching in both cases a valid proof of identity, such as a copy of their national ID, NIE or equivalent document, and clearly stating the right they wish to exercise.
Customers and/or users also have the right to lodge a complaint with the competent supervisory authority (the Spanish Data Protection Agency — AEPD) if they consider that the processing does not comply with applicable regulations or that their data protection rights have been infringed, particularly if they have not obtained satisfaction in the exercise of their rights, via https://www.aepd.es
These rights will be addressed by the DATA CONTROLLER within 1 month, which may be extended to 2 months if the complexity or volume of requests so requires. This is without prejudice to the obligation to retain certain data within the legal timeframes and until the expiry of any possible liability arising from the processing or, where applicable, from a contractual relationship.
In addition to the above, and in relation to data protection regulations, users who so request may arrange for the management of their data after their death.
Sending Commercial Communications
In compliance with the Second Final Provision of Law 9/2014 of 9 May on Telecommunications, which amends Law 34/2002 of 11 July on Information Society Services and Electronic Commerce, commercial communications sent electronically must be clearly identifiable as such, and the natural or legal person on whose behalf they are made must also be clearly identifiable.
Customers and/or users who provide their contact details to the DATA CONTROLLER by clicking the "SUBMIT" button on the electronic data collection forms on the website and affirmatively checking both consent boxes — "I accept the processing of my data for the purposes indicated in the basic data protection information" and "I give my consent to receive commercial communications about your items and/or products" — expressly and freely grant their consent to the DATA CONTROLLER to process their personal data for the purpose of sending commercial communications about its items and/or products via post, telephone, email, SMS/MMS, WhatsApp, Telegram or other equivalent electronic communication channels.
The legal basis for this processing is the consent of the data subject, which may be revoked at any time.
In accordance with Articles 21 and 22 of Law 34/2002 of 11 July on Information Society Services and Electronic Commerce, users may object to the processing of their data for promotional purposes and withdraw their consent to receive commercial communications by email by simply notifying the DATA CONTROLLER free of charge, by sending an email to atencionalcliente@esenziaclub.com with the subject line "UNSUBSCRIBE" or "DO NOT SEND".
Data provided will be retained for as long as the commercial relationship is maintained or for as long as necessary to comply with legal obligations.
Social Media Policy
The DATA CONTROLLER has profiles on the following social media platforms:
In this context, the DATA CONTROLLER is considered responsible for the processing of data belonging to its users, including followers, subscribers, fans, or anyone who leaves comments or makes enquiries through these channels.
The DATA CONTROLLER may use these profiles to share news and information relevant to the services offered, or to share content and articles published by other social media users.
Under no circumstances will users' personal data be used without their consent for purposes beyond those expected within the relevant social media platform. Where applicable, the user's prior agreement will be sought.
Accuracy of Data Provided by Data Subjects
The customer and/or user is responsible for ensuring that the information provided through the electronic forms available on the WEBSITE, or via emails sent to any account under the domains @esenziashop.es or @esenziaclub.com, is truthful. They are responsible for the accuracy of all data submitted and must keep it up to date so that it reflects their actual situation. They are liable for any false or inaccurate information provided and for any damages, inconvenience or issues this may cause to the DATA CONTROLLER or third parties.
Security Measures
The DATA CONTROLLER guarantees that it has implemented appropriate technical and organisational policies on the WEBSITE to apply the security measures required by GDPR EU 2016/679 and LOPDGDD 3/2018, with the aim of protecting the rights and freedoms of customers and/or users, and has provided them with adequate information to enable them to exercise those rights.
In order to protect individual rights, particularly in relation to automated processing, and with a commitment to transparency towards customers and/or users, the DATA CONTROLLER has established a policy covering all such processing activities, their purposes, their legal basis, and the tools available to customers and/or users to exercise their rights.
The WEBSITE is built on the Shopify e-commerce platform and uses the following plugins: Booster: EU Cookie Bar GDPR, Loox Product Reviews & Photos, Order Deadline, Releasit Cash On Delivery Fee, Sendcloud, Sendvio: Email Marketing & SMS, Shopify Mail, SMSBump SMS Marketing by Yotpo, and WhatsApp app by SuperLemon. An SSL encryption certificate is active across the entire domain, enabling users to securely submit their personal data through the electronic forms on the website.
All information will be stored and managed in strict confidence, with the necessary IT security measures in place to prevent unauthorised access, misuse, manipulation, deterioration or loss of data.
However, customers and/or users should be aware that the security of computer systems is never absolute. When personal data is shared over the internet, such information may be collected without consent and processed by unauthorised third parties. The DATA CONTROLLER accepts no liability for the consequences of such actions on the user, where the information was voluntarily disclosed by the user.
Acceptance and Consent
The customer and/or user declares to have been informed of the conditions governing the protection of personal data, and accepts and consents to the automated processing of such data by the DATA CONTROLLER in the manner and for the purposes set out in this Privacy Policy. Certain services provided on the WEBSITE may contain specific conditions with particular provisions regarding the protection of personal data.
Changes to This Privacy Policy
The DATA CONTROLLER reserves the right to modify this Privacy Policy to reflect legislative developments, case law, guidance from the Spanish Data Protection Agency, and industry practices.
In such cases, the DATA CONTROLLER will announce any changes on the website with reasonable notice prior to their implementation.
This Privacy Policy may be supplemented by the Legal Notice, Cookie Policy and General Terms and Conditions which may, where applicable, apply to specific products or services, if such access involves any particular aspects regarding the protection of personal data.