Privacy and data protection policy
PRIVACY AND DATA PROTECTION POLICY
Pursuant to Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter, the GDPR), and Article 11 of Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights, we hereby inform you of the following:
The User must carefully read this Privacy Policy, which has been drafted in clear and accessible language to facilitate its understanding, so that the User may freely, knowingly and voluntarily decide whether they wish to provide their own personal data or the personal data of third parties to RADIOTRANS, S.A. (hereinafter, the Entity).
Information about the Data Controller:
COMPANY NAME: RADIOTRANS, S.A.
TAX ID NUMBER: A80318389
REGISTERED OFFICE: AVENIDA JUAN CARAMUEL (LEGANES TECNOLOGICO), 17, POSTCODE 28919, LEGANÉS (MADRID).
DATA PROTECTION OFFICER EMAIL ADDRESS: cperez@radiotrans.com
DATA PROTECTION CHANNEL: https://corporate-line.com/cnormativo-radiotrans
Purpose, legal basis and retention of your personal data
The Entity will process the personal data provided by the User for the following purposes and for the retention periods indicated below:
To manage the provision and performance of the contracted services and/or products, as well as the preparation, monitoring and management of contracts, offers and service proposals, including the data of persons whose involvement is necessary for such purposes. The legal basis for this processing is the performance of a contract or the implementation of pre-contractual measures at the request of the data subject. In this case, we will retain personal data for as long as the contractual or pre-contractual relationship remains in force and, once it has ended, for the legally required periods necessary to address any liabilities arising therefrom.
To manage and respond to communications, requests of any kind, suggestions, complaints or petitions submitted by reporting persons/users through the Internal Information System, in accordance with Law 2/2023 of 20 February governing the protection of persons who report regulatory infringements and the fight against corruption. These communications may involve their management and, where appropriate, referral to the responsible department so that they can be properly addressed and handled in accordance with the applicable regulatory framework. The legal basis for this processing is compliance with legal obligations applicable to the Entity. Data relating to information received and internal investigations will be retained for the period necessary and proportionate to comply with whistleblower protection legislation and, under no circumstances, for longer than ten years. Three months after receipt, communications will be deleted unless they must be retained to demonstrate and provide evidence of the existence and operation of the System and/or pursuant to other regulatory compliance requirements connected with the information. In such cases, the reporting person's identity will be anonymised in a separate area subject to appropriate security measures.
To send informational communications concerning products or services similar to those already contracted by the Customer. The legal basis for this processing is the Entity's legitimate interest within the framework of a prior contractual relationship, provided that such communications concern the Entity's own products or services that are similar to those originally contracted, while in all cases guaranteeing the right to object in each communication. In the case of electronic communications, this processing is based on Article 21.2 of Law 34/2002 on Information Society Services and Electronic Commerce (hereinafter, the LSSI). Personal data will be retained until the right to object is exercised or the recipient requests to unsubscribe from such communications.
Within the framework of employment relationship management, the Entity may process personal data relating to employees, candidates or associated personnel for the following purposes:
To manage the employment relationship, including the formalisation, performance and termination of the employment contract, as well as administrative, accounting and payroll management.
To manage attendance monitoring, working-time records and compliance with working hours.
To organise and manage compulsory training or training required for the performance of the position.
To comply with obligations relating to occupational risk prevention, health monitoring and the management of psychosocial risks.
To exercise the employer's supervisory powers provided for under employment legislation, in accordance with Article 20.3 of the Workers' Statute.
To manage internal communications necessary for the proper conduct of work activities, including operational notices, alerts, or access to corporate tools and documentation. Such communications may be made through personal contact details provided by the data subject where necessary for the employment relationship, with corporate channels being used in preference whenever they are available.
To verify the absence of conflicts of interest or circumstances that could compromise the Entity's integrity, security or regulatory compliance.
To ensure the implementation of policies on equality, non-discrimination, harassment prevention and the protection of vulnerable groups in the workplace.
To process employees' images for corporate or publicity purposes where prior express consent has been obtained.
Depending on the specific nature of each processing activity, the legal basis for these processing operations is the performance of the employment contract, compliance with legal obligations, the Entity's legitimate interest or the data subject's consent where required. Personal data will be retained throughout the employment relationship and, once it has ended, for the legally required periods necessary to address any potential liabilities.
To send commercial communications, newsletters or mailings where such communications are not covered by a prior contractual relationship under the terms indicated above. The legal basis for this processing is the data subject's freely given, specific, informed and unambiguous consent. Personal data will be retained until the consent given is withdrawn or the recipient requests to unsubscribe from such communications.
To manage the receipt and assessment of applications, CVs and recruitment processes, including unsolicited applications submitted through the website or contact email address, and to consider them for current or future vacancies matching the candidate's profile. The legal basis for this processing is the data subject's consent, expressed through the submission of their application. Personal data will be retained until consent is withdrawn and, in all cases, for no longer than one year from receipt of the curriculum vitae.
To ensure the security of persons, property and facilities by means of video surveillance systems. The legal basis for this processing of personal data is the Entity's legitimate interest in preserving the security of its facilities, persons and property. As a general rule, images will be retained for no longer than 30 days from the date they are recorded, unless they must be retained for a longer period to provide evidence of acts affecting the integrity of persons, property or facilities, or to comply with a legal obligation.
To manage the professional relationship with suppliers, partners and third parties, including the commercial, administrative, accounting and invoicing relationship arising from services contracted by the Entity. The legal basis for this processing is the performance of the contract and compliance with the legal obligations applicable to the Entity. Personal data will be retained for the period necessary to manage the contractual relationship and subsequently for the legally required periods.
To manage and monitor internal regulatory compliance mechanisms, policies and procedures, including internal control, prevention, detection and investigation activities concerning breaches of regulations or internal policies. The legal basis for this processing is compliance with legal obligations and, where applicable, the public interest or the Entity's legitimate interest in ensuring regulatory compliance and the integrity of its organisation. Personal data will be retained for the period strictly necessary to process, investigate and close the relevant proceedings and, subsequently, for the legally required periods.
To manage requests to exercise data protection rights received through the channel established by the Entity for this purpose. The legal basis for this processing is compliance with a legal obligation applicable to the data controller. Personal data will be retained for the period necessary to process and resolve the request and, subsequently, for the legally required periods needed to demonstrate that it was properly handled.
To manage and respond to reports or communications concerning the prevention of and response to harassment, violence or particularly serious conduct, especially where such conduct affects specially protected groups, including, where applicable, transgender persons, LGBTI persons and minors, and to conduct any corresponding internal proceedings. Depending on the specific nature of the communication and the data processed, the legal basis for this processing is compliance with legal obligations, substantial public interest and, where applicable, the establishment, exercise or defence of legal claims. Personal data will be retained for the period strictly necessary to process the communication, conduct the investigation and adopt the appropriate measures and, subsequently, for the legally required periods. Where such communications are submitted through the Internal Information System, the time limits laid down in Law 2/2023 of 20 February will apply.
To comply with the legal obligations applicable to the Entity in commercial, tax, accounting, administrative, anti-money laundering, employment, data protection or any other relevant area. The legal basis for this processing is compliance with a legal obligation. Personal data will be retained for the periods established in the applicable legislation in each case.
The Entity may also process personal data for any other purposes necessary to comply with legal obligations or specific regulatory requirements applicable to its activities.
As a general rule, the personal data processed are obtained from the data subject. However, in certain cases, the data may be obtained from third parties with whom the data subject has a relationship, such as customer companies, partner entities or suppliers, as well as from publicly accessible sources where legally permitted. In such cases, the data subject will be informed in accordance with Article 14 of the GDPR.
Recipients of your personal data and international transfers
The Entity may disclose the data subject's personal data to the following recipients where necessary in view of the purpose of the processing and on the corresponding legal basis in each case:
Competent Public Administrations, such as Social Security, the Spanish Tax Agency, bodies responsible for managing grants or the Public Prosecutor's Office, where disclosure of personal data is necessary to comply with legal obligations applicable to the Entity.
Mutual insurance companies collaborating with Social Security, occupational risk prevention services or similar entities, where necessary to comply with employment, health and safety obligations or to protect employees.
Employees' legal representatives, including works councils, trade unions and health and safety representatives, in cases where employment legislation applies.
Customers or entities connected with the provision of services, solely where it is essential to identify employees for the proper performance of the contracted service. In all cases, disclosure will be limited to data that are adequate, relevant and not excessive, in accordance with the data minimisation principle.
Service providers acting as processors with whom the Entity has entered into the corresponding data processing agreement pursuant to Article 28 of the GDPR.
Where necessary, personal data may be disclosed to the competent authorities, the Public Prosecutor's Office, judicial bodies or third-party processors that provide services linked to the management of the Internal Information System, subject to the appropriate contractual and confidentiality safeguards.
Judicial authorities, the Public Prosecutor's Office and law enforcement agencies, where disclosure is necessary to comply with a legal obligation, establish, exercise or defend legal claims, or comply with requests or orders issued by such authorities.
As a general rule, no international transfers of personal data are envisaged. However, where technology service providers are used and this may involve the processing of data outside the European Economic Area, such transfers will be carried out in full compliance with Articles 44 et seq. of the GDPR through the adoption of appropriate safeguards, such as the execution of standard contractual clauses approved by the European Commission or other valid mechanisms under the legislation in force.
Personal Data Protection Rights
To ensure transparency in the processing of your personal data, we inform you of the rights granted to you by data protection legislation. Each of these rights and the way in which they may be exercised in relation to the personal data we hold are described below.
Right of access: You have the right to know whether the Entity is processing your personal data.
Right to rectification: You have the right to request the correction of inaccurate data.
Right to erasure: You have the right to request the deletion of your personal data where they are no longer necessary for the purpose for which they were collected.
Right to restriction of processing: You have the right to request that the use of your data be restricted, with the data being retained solely for the defence of legal claims.
Right to object: You have the right to object to the processing of your personal data, unless legitimate grounds exist or the data are required for the defence of legal claims.
Right to data portability: You have the right to receive the data in a structured, commonly used and machine-readable format so that they can be transferred to another controller, where technically feasible.
Right to withdraw consent: You have the right to withdraw your consent at any time, except where processing is authorised by law or necessary for a contracted service, without retroactive effect.
Right not to be subject to automated decision-making: You have the right not to be subject to automated decisions based on personal data that significantly affect you, such as profiling.
You may communicate and process the exercise of your rights and report any indication or knowledge of potential security breaches, cyberattacks and/or potential breaches or irregularities relating to data protection legislation through the channel established by the Entity for this purpose: https://corporate-line.com/cnormativo-radiotrans
In the event of disagreements with the Entity concerning the processing of your data, you have the right to lodge a complaint with the corresponding Data Protection Supervisory Authority. In Spain, this authority is the Spanish Data Protection Agency (www.aepd.es).
The Entity may request additional information to confirm the applicant's identity where there are reasonable doubts concerning it and will respond to the request within a maximum period of one month from receipt. This period may be extended in particularly complex cases.
Internal Information System
The Entity has implemented an Internal Information System (SIIF), which constitutes a fundamental tool for supervision, control and prevention in the field of regulatory compliance and reflects the highest degree of commitment, rigour and professionalism in relation to security, confidentiality, data protection, experience, independence and expertise in the handling of communications received.
The internal reporting channels integrated into the System have been implemented using technical tools that meet all the requirements necessary to uphold and guarantee the commitments described above. The SIIF also guarantees the basic principles of anonymity, proper recording, retention and non-alteration, prevention of conflicts of interest, protection of reporting persons and prevention of retaliation.
Through this System, any reporting person must report in good faith any indication, suspicion or evidence of potential regulatory breaches, offences, unethical conduct and, in general, any failure to comply with the Entity's protocols, rules and codes of conduct.
Access to the SIIF has been made available in a separate section of our website.
Processing of personal data in the Internal Information System
Within the framework of the Internal Information System (SIIF), the Entity will process personal data for the purpose of managing and handling the communications received, as well as analysing, verifying and investigating the reported facts and, where appropriate, adopting the corresponding corrective, disciplinary or legal measures.
This processing is carried out in compliance with the legal obligations established in Law 2/2023 of 20 February governing the protection of persons who report regulatory infringements and the fight against corruption and, where applicable, on the basis of the Entity's legitimate interest in preventing and detecting unlawful conduct or conduct contrary to internal regulations.
The following categories of personal data may be processed in connection with these activities:
Identification and contact details of reporting persons, affected persons and third parties involved.
Professional and employment data connected with the relationship with the Entity.
Information concerning the reported facts, including descriptions, assessments or associated documentation.
Where applicable, special categories of data pursuant to Article 9 of the GDPR, where their processing is strictly necessary for the investigation and there is a sufficient legal basis under the applicable legislation.
Personal data may be obtained from the reporting person, whether identified or anonymous, from affected persons or from third parties participating in the investigation.
Confidentiality and protection of reporting persons
The Entity guarantees the confidentiality of the reporting person's identity, as well as that of any third party mentioned in the communication and any affected person. Access to the data will be restricted exclusively to authorised personnel involved in managing and investigating the communications.
Any form of retaliation, discrimination or adverse treatment against the reporting person or persons cooperating with the investigation is expressly prohibited under the terms provided for in Law 2/2023.
The exercise of data protection rights may be restricted where necessary to preserve the confidentiality of the reporting person's identity, prevent obstruction of the investigation or ensure the proper conduct of the proceedings, under the terms established in the applicable legislation.
Security and control measures
General
The Entity will process personal data by applying appropriate technical, legal, organisational and security measures in order to guarantee the confidentiality and integrity of the information it manages, in accordance with the legislation in force.
Cybersecurity
As a specific concept complementing the foregoing, the Entity applies cybersecurity measures to prevent and manage potential attacks and fraud by cybercriminals that threaten the privacy and protection of the data processed and accessed by the Entity in the course of its activities and operations.
In this regard, we wish to warn that, in potential risk situations involving communications whose content and/or format raises doubts as to their authenticity, we recommend disregarding them and contacting the Entity through the contact details provided in this Privacy Policy.
Likewise, any request purportedly originating from the Entity concerning changes to payment methods, requests for data or contact persons, confidential information that is not publicly available, bank and/or credit card details and/or other official data should not be acted upon without direct confirmation from the Entity through an alternative means of communication.
We appreciate and require your cooperation in reporting any notification relating to this type of request and other potential cyberattack risks in which the Entity may be misused, as well as any potential security risk of which you may become aware.
Assistance and support
Data subjects may contact the Entity with any questions concerning the processing of their personal data or the interpretation of this Policy by contacting the Data Protection Officer at the email address indicated at the beginning of this Policy.
Updates and amendments
The Entity reserves the right to amend and/or update the information concerning data protection where necessary to ensure proper compliance with the relevant legislation. If any amendment is made, the new text will be published in this same section of the website.