Home · Privacy policy
Privacy policy
Serglo-LCG S.L. · Last updated: January 2025
Introduction
This Privacy Policy has been developed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, hereinafter the GDPR.
The purpose of this Privacy Policy is to inform data subjects, in relation to whom information is being collected, of the specific aspects concerning the processing of their data, including, among other things, the purposes of the processing, contact details for exercising their rights, data retention periods and security measures, among other matters.
Data Controller
For data protection purposes, Serglo-LCG, S.L. must be considered the Data Controller in relation to the files/processing activities it manages.
The identifying details of the owner of this website are set out below:
Main Office
Postal address:
Avda. Primo de Rivera, 11 2º izda.
15006 – A Coruña, Spain
Email address: serglo@serglo.net
Phone: 981 902 092
Data Processing
Any personal data requested will consist solely of the data strictly necessary to identify and handle the request made by the data subject (hereinafter, the “data subject”). Such information will be processed fairly, lawfully and transparently in relation to the data subject. Furthermore, personal data will be collected for specified, explicit and legitimate purposes, and will not be further processed in a manner incompatible with those purposes.
The data collected from each data subject will be adequate, relevant and not excessive in relation to the purposes for which they are processed in each case, and will be kept up to date whenever necessary.
Prior to the collection of their data, the data subject will be informed of the general points set out in this policy so that they may give express, specific and unambiguous consent for the processing of their data, in accordance with the following aspects.
Purposes of processing
The explicit purposes for which each processing activity is carried out are set out in the information clauses included in each of the data collection channels (web forms, paper forms, spoken announcements or signage, and information notices).
Notwithstanding the above, the data subject’s personal data will be processed solely for the purpose of providing an effective response and handling the requests made by the user, as specified alongside the particular option, service, form or data collection system used by the data subject.
Legal basis
As a general rule, prior to processing personal data, Serglo-LCG, S.L. obtains the express and unambiguous consent of the data subject, through the inclusion of informed consent clauses in the various data collection systems.
However, where the data subject’s consent is not required, the legal basis relied upon by Serglo-LCG, S.L. for the processing is the existence of a specific law or regulation that authorizes or requires the processing of the data subject’s data.
Recipients
As a general rule, Serglo-LCG, S.L. does not transfer or disclose data to third parties, except where legally required. However, where such a transfer or disclosure is necessary, the data subject will be informed of this through the informed consent clauses included in the various data collection channels.
Source
As a general rule, personal data is always collected directly from the data subject. However, in certain exceptional cases, data may be collected through third parties, entities or services other than the data subject. In such cases, this fact will be communicated to the data subject through the informed consent clauses included in the various data collection channels, within a reasonable period after the data is obtained, and no later than one month thereafter.
Retention periods
Information collected from the data subject will be kept for as long as necessary to fulfil the purpose for which the personal data was collected; once that purpose has been fulfilled, the data will be deleted. Such deletion will result in the data being blocked, being retained solely for use by public authorities, judges and courts to address any liabilities that may arise from the processing, for the duration of the statute of limitations applicable to such liabilities; once that period has elapsed, the information will be destroyed.
For informational purposes, the legal retention periods for information relating to different matters are set out below:
| DOCUMENT | PERIOD | |
| Employment-related or social security documentation | 4 years | Article 21 of Royal Legislative Decree 5/2000, of 4 August, approving the consolidated text of the Law on Offences and Sanctions in the Social Order |
| Accounting and tax documentation for commercial purposes | 6 years | Art. 30 of the Commercial Code |
| Accounting and tax documentation for tax purposes | 4 years | Articles 66 to 70 of the General Tax Law |
| Building access control | 1 month | Instruction 1/1996 of the AEPD (Spanish Data Protection Agency) |
| Video surveillance | 1 month | Instruction 1/2006 of the AEPD; Organic Law 4/1997 |
Browsing Data
Regarding any browsing data that may be processed through the website, should data subject to applicable regulations be collected, please refer to the Cookie Policy published on our website.
Rights of Data Subjects
Data protection regulations grant a series of rights to data subjects or data owners, users of the website, or users of Serglo-LCG, S.L.’s social media profiles.
These rights afforded to data subjects are as follows:
- Right of access: the right to obtain information as to whether their own data is being processed, the purpose of such processing, the categories of data concerned, the recipients or categories of recipients, the retention period, and the origin of such data.
- Right of rectification: the right to obtain the rectification of inaccurate or incomplete personal data.
- Right of erasure: the right to obtain the erasure of data in the following circumstances:
- When the data is no longer necessary for the purpose for which it was collected
- When the data subject withdraws their consent
- When the data subject objects to the processing
- When the data must be erased in compliance with a legal obligation
- When the data was obtained in connection with an information society service, pursuant to Article 8(1) of the General Data Protection Regulation.
- Right to object: the right to object to specific processing based on the data subject’s consent.
- Right to restriction of processing: the right to obtain the restriction of the processing of data in any of the following circumstances:
- When the data subject contests the accuracy of the personal data, for a period enabling the company to verify its accuracy.
- When the processing is unlawful and the data subject opposes the erasure of the data.
- When the company no longer needs the data for the purposes for which it was collected, but the data subject needs it for the establishment, exercise or defence of legal claims.
- When the data subject has objected to the processing pending verification as to whether the company’s legitimate grounds override those of the data subject.
Data subjects may exercise the rights indicated above by writing to Serglo-LCG, S.L., sent to the following address: serglo@serglo.net, stating in the subject line the right they wish to exercise.
Serglo-LCG, S.L. will handle such requests as promptly as possible and in accordance with the time limits set out in applicable data protection regulations.
Furthermore, it should be noted that the data subject may lodge a complaint with the relevant supervisory authority at any time.
Security
The security measures adopted by Serglo-LCG, S.L. are those required pursuant to Article 32 of the GDPR. In this regard, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, Serglo-LCG, S.L. has established appropriate technical and organizational measures to ensure a level of security appropriate to the existing risk.
In all cases, Serglo-LCG, S.L. has implemented sufficient mechanisms to:
- Ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
- Restore the availability of and access to personal data rapidly in the event of a physical or technical incident.
- Regularly test, assess and evaluate the effectiveness of the technical and organizational measures implemented to ensure the security of the processing.
- Pseudonymize and encrypt personal data, where applicable.