Secrecy and security of personal data
Unlimited Sheets undertakes to adopt the necessary technical and organizational measures, according to the level of security appropriate to the risk of the data collected, so as to ensure the security of personal data and prevent accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed, or unauthorized communication or access to such data.
The Web Site is SSL (Secure Socket Layer) certified, which ensures that personal data is transmitted securely and confidentially, as the transmission of data between the server and the User, and in return, is fully encrypted or encoded.
However, because Unlimited Sheets can not guarantee the impregnability of the Internet or the total absence of hackers or others who fraudulently access personal data, the Data Controller undertakes to notify the User without undue delay when there is a breach of security of personal data that is likely to pose a high risk to the rights and freedoms of natural persons. In accordance with Article 4 of the GDPR, a breach of security of personal data means any breach of security resulting in the accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed, or the unauthorised disclosure of or access to such data.
Personal data shall be treated as confidential by the Controller, who undertakes to inform and to ensure by means of a legal or contractual obligation that such confidentiality is respected by its employees, partners, and any person to whom it makes the information accessible.
Rights arising from the processing of personal data
The User has over Unlimited Sheets and may, therefore, exercise against the Controller the following rights recognized in the RGPD and the Organic Law 3/2018 of 5 December on the Protection of Personal Data and guarantee of digital rights:
- Right of access: it is the right of the User to obtain confirmation of whether or not Unlimited Sheets is processing their personal data and, if so, obtain information about their specific personal data and the treatment that Unlimited Sheets has made or makes, as well as, among others, the information available on the origin of such data and the recipients of the communications made or planned thereof.
- Right of rectification: This is the User’s right to have his/her personal data amended if it proves to be inaccurate or, having regard to the purposes of the processing, incomplete.
- Right of erasure («the right to be forgotten»): This is the User’s right, unless otherwise provided for by law, to obtain the erasure of his or her personal data when it is no longer necessary for the purposes for which it was collected or processed; the User has withdrawn his or her consent to the processing and the processing has no other legal basis; the User objects to the processing and there is no other legitimate reason to continue the processing; the personal data have been processed unlawfully; the personal data must be erased in compliance with a legal obligation; or the personal data have been obtained as a result of a direct offer of information society services to a child under the age of 14. In addition to erasure, the Controller shall, taking into account the technology available and the cost of its implementation, take reasonable steps to inform controllers who are processing the personal data of the data subject’s request for erasure of any link to those personal data.
- Right to restriction of processing: This is the User’s right to restrict the processing of his or her personal data. The User has the right to obtain the restriction of processing where the User contests the accuracy of his or her personal data; the processing is unlawful; the Controller no longer needs the personal data, but the User needs it to make claims; and where the User has objected to the processing.
- Right to data portability: Where processing is carried out by automated means, the User shall have the right to receive from the Controller his or her personal data in a structured, commonly used and machine-readable format and to transmit it to another controller. Where technically feasible, the Controller shall transmit the data directly to that other controller.
- Right of opposition: It is the right of the User not to carry out the processing of their personal data or cease the processing of personal data by Unlimited Sheets.
- Right not to be subject to a decision based solely on automated processing, including profiling: It is the right of the user not to be subject to an individualized decision based solely on automated processing of personal data, including profiling, existing unless otherwise provided by law.
Therefore, the User may exercise his/her rights by means of a written communication addressed to the Data Controller with the reference «RGPD-https://unlimitedsheets.com/», specifying:
Name, surname(s) of the User and a copy of the User’s National Identity Document. In cases where representation is permitted, it will also be necessary to identify the person representing the User by the same means, as well as the document accrediting the representation. The photocopy of the document may be substituted by any other legally valid means that accredits identity.
Request with the specific reasons for the request or information to which access is sought.
Address for notification purposes.
Date and signature of the applicant.
Any document that accredits the request being made.
This request and any other attached documents may be sent to the following address and/or e-mail address:
Postal address: Avinguda Roma 112 6º 1º 08015 Barcelona
Links to third party websites
The Web Site may include hyperlinks or links that allow access to third party websites other than Unlimited Sheets, and therefore are not operated by Unlimited Sheets. The owners of such websites will have their own data protection policies, being themselves, in each case, responsible for their own files and their own privacy practices.
Complaints to the supervisory authority
In the event that the User considers that there is a problem or infringement of the regulations in force in the way in which his or her personal data is being processed, he or she shall have the right to effective judicial protection and to lodge a complaint with a supervisory authority, in particular, in the State in which he or she has his or her habitual residence, place of work or place of the alleged infringement. In the case of Spain, the supervisory authority is the Spanish Data Protection Agency (https://www.aepd.es/).