Privacy Policy
This is a courtesy translation. In the event of any discrepancy, the Spanish version prevails. Read the Spanish version
Privacy policy for https://cedesa.es/ – last updated: 21 April 2026
At CEDESA DIGITAL SL (hereinafter “CEDESA”) we care about privacy and transparency.
Below we set out in detail the personal data processing activities that we carry out, together with all the information relating to them.
Personal data protection – Privacy
The service provider is deeply committed to complying with personal data protection legislation and guarantees full compliance with the obligations laid down, as well as the implementation of technical and organisational security measures, in accordance with the EU General Data Protection Regulation, Regulation (EU) 2016/679 (GDPR), and Organic Law 3/2018 of 5 December on the Protection of Personal Data and the Guarantee of Digital Rights (Ley Orgánica 3/2018, LOPDGDD).
The service provider makes its Privacy Policy available to users, informing them of the following matters:
- Details of the Data Controller.
- Purpose.
- Legal basis.
- Recipients.
- Source.
- Additional information.
Whenever we need to obtain personal information from you, you will always be asked to provide it voluntarily and expressly.
In compliance with personal data protection legislation, you explicitly consent to the personal data provided being processed under our responsibility for the following purposes:
- To manage our relationship with you and to provide you with the requested service in a personalised manner.
- To handle enquiries, requests for advice, orders, applications or any other type of request made by the User through any of the contact channels made available to the User on the CEDESA website.
- To send commercial advertising communications about our products by email, fax, SMS, MMS, social media communities or any other electronic or physical means, present or future, that makes it possible to send commercial communications.
All the data requested are mandatory; if they are not provided, it would be impossible to fulfil the purpose for which they are requested in each case.
Information on processing
In accordance with Article 13 of the General Data Protection Regulation (Regulation (EU) 2016/679) and Article 11 of Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights, the User must receive specific and precise information about the data controller and about the uses and purposes of the processing.
1. Who is the controller of your data?
CEDESA DIGITAL SL
Tax ID (NIF): B06684369
Campus Universitario, Avda. de la Investigación S/N, Edificio PCTEX Oficina 2.1 – 06006 – Badajoz (Spain)
Telephone: (+34) 924 090 608
Email: mcastano@cedesa.es
Contact details of the Data Protection Officer (DPO):
Tuidentidad y seguridad SLU
C/ Francisco Guerra 12 Portal 4 1ºC, 06011 Badajoz (Spain)
Email: privacidad@cedesa.es
2. For what purpose do we process your personal data?
At CEDESA we process the information provided to us by data subjects for the following purposes:
- CLIENT MANAGEMENT: To carry out the administrative, accounting and tax management of the services requested, and to send commercial communications about our products and services.
- IMAGE MANAGEMENT FOR MARKETING PROJECTS: to capture and disseminate personal data consisting of your image and/or video, for promotional and informational purposes, as part of the marketing projects carried out by our organisation, for publication on the internet (social networks, video platforms and websites), in the organisation's publications and in other media.
- SUPPLIER MANAGEMENT: The administrative, accounting and tax management of the services contracted, and of the contact persons.
- RECRUITMENT: To manage the curricula vitae received and to carry out recruitment processes.
- VIDEO SURVEILLANCE MANAGEMENT: To ensure the security of people, property and premises.
- MANAGEMENT OF THE DATA OF THE PARTIES INVOLVED IN THE INTERNAL WHISTLEBLOWING CHANNEL: Management of the internal whistleblowing channel for the purpose of informing the controller of acts or conduct that occur within the organisation, or are caused by third parties contracting with it, and that may be contrary to the general or sector-specific legislation applicable to it.
- MANAGEMENT OF THE DATA OF THE PARTIES INVOLVED IN THE PROTOCOL FOR THE PREVENTION OF SEXUAL HARASSMENT OR HARASSMENT ON GROUNDS OF SEX: Management of the protocol for the prevention of sexual harassment or harassment on grounds of sex; regulation of the procedure, handling of the complaint, collection of personal data and interviews with the parties affected.
- NEWSLETTER SUBSCRIPTION FORM: to send our newsletter and other promotional communications of interest to its subscribers.
- CONTACT FORMS: In relation to the contact forms on our website, to deal with your request and to send you commercial communications, including by electronic means.
3. How long will we keep your data?
The data will be kept:
- For as long as the contractual relationship is maintained or for the years necessary to comply with legal obligations.
- In the case of curricula vitae, the data will be kept for 2 years after the last interaction.
- For the management of the protocol for the prevention of sexual harassment or harassment on grounds of sex, the data will be erased after two years, unless they need to be kept in order to determine any liabilities that may arise from possible claims made by those affected.
- In the case of the internal whistleblowing channel, the data will be kept for the time strictly necessary to decide whether an investigation into the facts reported should be opened. The maximum period will be three months from their entry into the system, unless the purpose of keeping them is to serve as evidence of the operation of the prevention model, in which case the data will be kept in anonymised form. (Article 24(4) LOPDGDD).
- In the case of video surveillance, the data will be kept for a maximum of 30 days, unless they are disclosed to the law enforcement agencies (Fuerzas y Cuerpos de Seguridad) and/or the courts and tribunals.
4. What is the legal basis for processing your data?
The legal basis for processing your data is set out below:
1. CLIENT MANAGEMENT:
- Performance of a contract: Tax, accounting and administrative management of clients. (Article 6(1)(b) GDPR).
- Legitimate interest of the Data Controller: The sending of commercial communications, including by electronic means. (Recital 47 GDPR; Article 21(2) of the LSSI, Spain's e-commerce act).
2. IMAGE MANAGEMENT FOR MARKETING PROJECTS:
- Consent of the data subject: We ask for your consent to capture, disseminate and disclose data consisting of your image and/or video for promotional purposes, for publication on social networks, video platforms and websites, as well as in the organisation's publications and in other media. (Article 2 of Organic Law 1/1982 (Ley Orgánica 1/1982); Article 6(1)(a) GDPR).
3. SUPPLIER MANAGEMENT:
- Performance of a contract: To carry out the administrative, accounting and tax management of the services contracted. (Article 6(1)(b) GDPR).
- Legitimate interest of the Data Controller: Management of professional contact details. (Article 19 LOPDGDD; Article 6(1)(f) GDPR).
4. RECRUITMENT:
- Performance of a contract: Management of the curricula vitae submitted by the candidate in order to carry out recruitment processes. (Article 6(1)(b) GDPR).
5. VIDEO SURVEILLANCE:
- Task carried out in the public interest: Processing necessary for the performance of a task carried out in the public interest (Article 6(1)(e) GDPR), in line with the guide on the use of video cameras for security and other purposes (“Guía sobre el uso de videocámaras para seguridad y otras finalidades”) published by the Spanish Data Protection Agency (AEPD).
6. MANAGEMENT OF THE DATA OF THE PARTIES INVOLVED IN THE INTERNAL WHISTLEBLOWING CHANNEL:
- Task carried out in the public interest: Control of the risk of non-compliance within the organisation; (Organic Law 3/2018 [Preamble, section V]).
- Compliance with a legal obligation: Article 8 of Directive (EU) 2019/1937; Article 10 of Law 2/2023 of 20 February (Ley 2/2023).
- Consent of the data subject: For the retention and recording of reports made by telephone line and by recorded voice messaging systems, and for the recording of the in-person meeting. (Article 18(2) and (4) of Directive (EU) 2019/1937; Article 32(4) and (5) of Law 2/2023).
7. MANAGEMENT OF THE DATA OF THE PARTIES INVOLVED IN THE PROTOCOL FOR THE PREVENTION OF SEXUAL HARASSMENT OR HARASSMENT ON GROUNDS OF SEX:
- Compliance with a legal obligation: Article 48 of Organic Law 3/2007 (Ley Orgánica 3/2007); Royal Decree 901/2020 (Real Decreto 901/2020); Article 14 of Law 31/1995 (Ley 31/1995).
8. NEWSLETTER SUBSCRIPTION FORM:
- Consent of the data subject: to send our newsletter and other promotional communications of interest. (Article 6(1)(a) GDPR; Article 21 LSSI).
9. CONTACT FORMS:
- Performance of a contract: Management of potential clients who have expressed an interest in our products and/or services. (Article 6(1)(b) GDPR; Article 21 LSSI).
- Legitimate interest of the Data Controller: Management of professional contact details. (Article 19 LOPDGDD; Article 6(1)(f) GDPR).
5. To which recipients will your data be disclosed?
The data will be disclosed to the following recipients:
1. CLIENT MANAGEMENT:
- The tax authorities, for the purpose of complying with legal obligations (legal requirement).
- Banks, for the purpose of collecting the corresponding payments by direct debit (contractual requirement).
2. IMAGE MANAGEMENT FOR MARKETING PROJECTS:
- The internet (social networks, video platforms and websites), the organisation's website and other media, for the purpose of disclosing and publishing the personal data and images and/or video of employees for promotional purposes. (consent of the data subject).
3. SUPPLIER MANAGEMENT:
- The tax authorities, for the purpose of complying with legal obligations (legal requirement).
- Banks, for the purpose of making the corresponding payments (contractual requirement).
4. RECRUITMENT:
No data will be disclosed to third parties, unless there is a legal obligation to do so.
5. VIDEO SURVEILLANCE:
- Where applicable, the State law enforcement agencies and the courts and tribunals, for the purpose of providing the images if an offence has been committed (legal requirement).
6. MANAGEMENT OF THE DATA OF THE PARTIES INVOLVED IN THE INTERNAL WHISTLEBLOWING CHANNEL:
- The Independent Whistleblower Protection Authority (Autoridad Independiente de Protección del Informante), for the purpose of managing and monitoring requests and any complaints concerning whistleblower protection measures (legal requirement).
- The State law enforcement agencies; judicial bodies; the Public Prosecutor's Office (Ministerio Fiscal), for the purpose of reporting the possible commission of an offence (legal requirement).
7. MANAGEMENT OF THE DATA OF THE PARTIES INVOLVED IN THE PROTOCOL FOR THE PREVENTION OF SEXUAL HARASSMENT OR HARASSMENT ON GROUNDS OF SEX:
- The State law enforcement agencies; judicial bodies; the Public Prosecutor's Office, for the purpose of reporting the possible commission of an offence (legal requirement).
8. CONTACT AND NEWSLETTER FORMS:
No data will be disclosed to third parties, unless there is a legal obligation to do so.
6. Are data transferred to third countries?
No transfers of data to third countries are envisaged.
7. What are your rights when you provide us with your data?
Any person has the right to obtain confirmation as to whether or not CEDESA is processing personal data concerning them.
Data subjects have the right to access their personal data and to request the rectification of inaccurate data or, where applicable, to request their erasure when, among other reasons, the data are no longer necessary for the purposes for which they were collected. They also have the right to data portability.
In certain circumstances, data subjects may request the restriction of the processing of their data, in which case we will keep them only for the exercise or defence of claims.
In certain circumstances and on grounds relating to their particular situation, data subjects may object to the processing of their data. In that case, CEDESA will stop processing the data, except on compelling legitimate grounds or for the exercise or defence of possible claims.
You may exercise your rights in practice as follows: by writing to privacidad@cedesa.es or to C/ Francisco Guerra 12 Portal 4 1ºC, 06011 Badajoz (Spain).
Where commercial communications are sent on the legal basis of the controller's legitimate interest, the data subject may object to the processing of their data for that purpose.
The consent given covers all the purposes indicated whose legal basis is the consent of the data subject. You have the right to withdraw that consent at any time, without this affecting the lawfulness of processing based on consent before its withdrawal.
If you feel that your rights in relation to the protection of your personal data have been infringed, especially where you have not obtained satisfaction in exercising your rights, you may lodge a complaint with the competent data protection supervisory authority through its website: www.aepd.es.
8. How did we obtain your data?
The personal data that we process at CEDESA come from the data subject or from their legal representative.
The categories of data processed are:
- Identification data.
- Postal and email addresses.
- Commercial information.
- Bank and financial details.