Privacy policy
Privacy Policy
JRJ GESTION SL makes this Privacy Policy available to you through the website www.godrevel.com in order to inform you in detail about how we process your personal data and protect your privacy and the information you provide to us. Should we introduce changes to this Policy in the future, we will notify you through the website or by other means so that you may be aware of the new privacy conditions introduced.
In compliance with Regulation (EU) 2016/679, the General Data Protection Regulation, and Organic Law 3/2018, of 5 December, on Personal Data Protection and the guarantee of digital rights, we inform you as follows:
Data Controller
Company name: JRJ GESTION SL
Tax ID (NIF): B44853646
Registered office: Gran Capitán, 46, 2-4, 14006, Córdoba, Spain
Telephone: 957080733
Email: atencioncliente@godrevel.com
Website: www.godrevel.com
For what purpose do we process your personal data?
We collect and process your personal information generally in order to manage the relationship we maintain with you. The main purposes we have identified are as follows:
- Management and contracting of the products offered by our company.
- Handling requests for information, suggestions and complaints that you may send us.
- Keeping you informed about events, offers and products that may be of interest to you through different communication channels, provided that you have given your consent.
- Management of the commercial relationship maintained with our suppliers.
How do we collect your information?
We collect your personal information through different means, but you will always be informed at the time of collection through information clauses regarding the data controller, the purpose and legal basis of the processing, the recipients of the data and the retention period of your information, as well as how you may exercise your data protection rights.
In general, the personal information we process is limited to identification data (name and surname, date of birth, address, ID number, telephone number and email address), orders placed, and payment and billing data.
We use social media, and this is another way of reaching you. The information collected through the messages and communications that you publish may contain personal information that is available online and accessible to the public. These social media platforms have their own privacy policies explaining how they use and share your information, so we recommend that you consult them before using such platforms to confirm that you agree with the way your information is collected, processed and shared.
Through our website we collect personal information related to your browsing activity by means of cookies. To learn clearly and precisely which cookies we use, what their purposes are, and how you may configure or disable them, please consult our Cookies Policy.
User responsibility
By providing us with your data through electronic channels, the user guarantees that they are over 14 years of age and that the data provided are true, accurate, complete and up to date. For these purposes, the user confirms that they are responsible for the truthfulness of the data communicated and that they will keep such information suitably updated so that it reflects their real situation, being responsible for any false or inaccurate data that they may provide, as well as for any direct or indirect damages that may arise.
How long do we keep your information?
We only retain your information for the period necessary to fulfil the purpose for which it was collected, to comply with the legal obligations applicable to us, and to deal with any liabilities that may arise from the fulfilment of the purpose for which the data were collected.
In any case, and as a general rule, we will keep your personal information for as long as there is a contractual relationship binding us or until you exercise your right to erasure and/or restriction of processing. In such case, the information will be blocked without being used beyond its storage, while it may be necessary for the exercise or defence of claims or if any kind of liability may arise that must be addressed.
To whom do we disclose your data?
In general, we do not share your personal information, except for disclosures that we are required to make based on legal obligations.
Although this does not constitute a disclosure of data, in order to provide you with the requested service it may be necessary for third-party companies acting as our service providers to access your information in order to carry out the service we have contracted them to perform. These processors access your data following our instructions, may not use them for any different purpose, and must maintain the strictest confidentiality.
Likewise, your personal information may be made available to Public Administrations, Judges and Courts in order to deal with any liabilities arising from the processing.
International data transfers
There are no international transfers of your data to countries outside the European Economic Area (EEA).
We have agreed with our providers that, for the provision of the contracted service, they will use servers located within the EEA and, if in the future we need to use servers located outside the territory of the European Union, appropriate measures will be adopted and incorporated into this Privacy Policy, guaranteeing that such providers are subject to adequate safeguards.
What are your rights in relation to the processing of your data and how can you exercise them?
Data protection regulations allow you to exercise your rights of access, rectification, erasure and data portability, as well as your rights to object to and restrict processing, and not to be subject, where applicable, to decisions based solely on the automated processing of your data.
These rights are characterised as follows:
- Their exercise is free of charge, unless the requests are manifestly unfounded or excessive, in which case we may charge a fee proportionate to the administrative costs incurred or refuse to act.
- You may exercise the rights directly or through your legal or voluntary representative.
- We must respond to your request within one month, although, taking into account the complexity and number of requests, this period may be extended by a further two months.
- We are obliged to inform you about the means of exercising these rights, which must be accessible, and we may not refuse you the exercise of the right solely because you choose another means. If the request is submitted electronically, the information will be provided by such means where possible, unless you ask us otherwise.
- If we do not act on the request, we will inform you, no later than within one month, of the reasons for not acting and of the possibility of lodging a complaint with a Supervisory Authority.
In order to facilitate the exercise of your rights, we provide the following request forms:
- Access right request form
- Rectification right request form
- Objection right request form
- Erasure right request form (“right to be forgotten”)
- Restriction of processing request form
- Data portability request form
- Request form not to be subject to automated individual decisions
To exercise your rights, we provide the following means:
- By written and signed request addressed to the company, Ref. Exercise of Data Protection Rights.
- By sending the scanned and signed form to the email address indicated above, stating in the subject line: Exercise of Data Protection Rights.
In both cases, you must prove your identity by attaching a photocopy or, where appropriate, a scanned copy of your ID card or equivalent document, so that we can verify that we only respond to the data subject or their legal representative, in which case proof of representation must also be provided.
Likewise, and especially if you consider that you have not obtained full satisfaction in the exercise of your rights, we inform you that you may lodge a complaint with the national supervisory authority by contacting the Spanish Data Protection Agency (Agencia Española de Protección de Datos), C/ Jorge Juan, 6, 28001 Madrid, Spain.
How do we protect your information?
We are committed to protecting your personal information.
We use reasonably reliable and effective physical, organisational and technological measures, controls and procedures aimed at preserving the integrity and security of your data and guaranteeing your privacy.
In addition, all personnel with access to personal data have been trained and are aware of their obligations in relation to the processing of your personal data.
In the contracts we sign with our providers, we include clauses requiring them to maintain the duty of confidentiality regarding the personal data to which they have had access by virtue of the service entrusted, as well as to implement the technical and organisational security measures necessary to guarantee the ongoing confidentiality, integrity, availability and resilience of the systems and services used to process personal data.
All these security measures are reviewed periodically in order to guarantee their adequacy and effectiveness.
However, absolute security cannot be guaranteed and no security system is impenetrable. Therefore, if any information under processing and under our control is compromised as a result of a security breach, we will take the appropriate measures to investigate the incident, notify the Supervisory Authority and, where appropriate, those users who may have been affected so that they can take the appropriate measures.