Privacy policy

Privacy Policy

We are delighted that you have shown interest in our company. The protection of personal data is of paramount importance to the management of Empire Sapphire SL. Use of the Empire Sapphire SL website is possible without providing personal data; however, if an interested party wishes to use special services offered by the company through our website, the processing of personal data may be necessary. When such processing is necessary and there is no legal basis for it, we will generally obtain the consent of the interested party.

The processing of personal data, such as the name, address, email address, or telephone number of an interested party, will always be carried out in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”) and with the specific data protection regulations applicable to Empire Sapphire SL. Through this data protection statement, our company wishes to inform the general public about the nature, scope, and purpose of the personal data we collect, use, and process. This statement also informs data subjects of their rights.

As the data controller, Empire Sapphire SL has implemented numerous technical and organizational measures to ensure the most comprehensive protection possible for personal data processed through this website. However, internet-based data transmissions can, in principle, have security vulnerabilities, and therefore absolute protection cannot be guaranteed. For this reason, any data subject is free to transmit their personal data to us by alternative means, such as by telephone.

Definitions

The data protection policy of Empire Sapphire SL. is based on the terms used by the European legislator in adopting the GDPR. Our intention is for this policy to be readable and understandable for the general public, as well as for our clients and business partners. To ensure this, we explain below, among others, the terms used:

a) Personal Data
Personal data: any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

b) Data Subject
Any identified or identifiable natural person whose personal data is processed by the controller.

c) Processing
Any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

d) Restriction of processing
The marking of stored personal data for the purpose of limiting its processing in the future.

e) Profiling
Any form of automated processing of personal data consisting of using such data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements.

f) Pseudonymization
The processing of personal data in such a way that they can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

(g) Data Controller
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by Union or Member State law, the controller or the specific criteria for its designation may be provided for by Union or Member State law.

(h) Data Processor
The natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

(i) Recipient
The natural or legal person, public authority, agency or other body to whom personal data are disclosed, whether or not a third party. Public authorities which may receive personal data in the course of a specific investigation pursuant to Union or Member State law shall not be considered recipients; the processing of such data by such public authorities shall comply with the data protection rules applicable in relation to the purposes of the processing.

j) Third party
A natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and persons who, under the direct authority of the controller or the processor, are authorized to process personal data.

k) Consent
Any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

Name and address of the data controller

Data controller for the purposes of the GDPR and other applicable data protection regulations in the Member States of the European Union and other related provisions:

Empire Sapphire SL
Avenida Constitución 22, bajo 4, Boiro, A Coruña 15930

Website: https://empire-sapphire.com

Cookies

The Empire Sapphire SL website uses cookies. Cookies are text files that are stored on a computer system via a web browser.

Numerous websites and servers use cookies. Many cookies contain what is called a cookie ID, a unique identifier that allows the specific browser of the user to be distinguished from other browsers that contain different cookies. This makes it possible to recognize and identify a specific browser.

By using cookies, Empire Sapphire, S.L. can offer users of this website more user-friendly services that would not be possible without them. Among other things, cookies allow us to optimize the information and offers on our website with the user in mind. For example, visitors who use cookies do not have to enter login details each time they access the site, as these are managed by the website itself thanks to the cookie stored on the user's computer system. Another example is a shopping cart cookie in an online store.

The user can, at any time, prevent the installation of cookies by adjusting the corresponding settings in their web browser, thus permanently blocking their installation. Existing cookies can also be deleted at any time through the browser or other programs. If the user disables the installation of cookies, not all website functions may be fully available.

Collection of General Data and Information

The Empire Sapphire, S.L. website collects a range of general data and information when a user or an automated system accesses the site. This data and information is stored in the server's log files. The following may be collected, among other things: (1) browser type and version; (2) the operating system of the accessing system; (3) the website from which an accessing system reaches our site (so-called referrers); (4) the subpages visited; (5) the date and time of access to the site; (6) the Internet Protocol (IP) address; (7) the Internet service provider of the accessing system; and (8) other similar data that may be used in the event of attacks on our computer systems.

Empire Sapphire, S.L. does not draw any conclusions about the user from this data. The information is needed to (1) deliver content correctly, (2) optimize both the site's content and advertising, (3) ensure the long-term viability of our computer systems and site technology, and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyberattack. Anonymous log file data is stored separately from all personal data provided by the data subject.

Registration on our website

Users can register on the website by providing personal data. The type of data transmitted is determined by the corresponding input form. The data entered is collected and stored exclusively for the controller's internal use and purposes. The controller may transmit this data to one or more processors (e.g., a parcel service) who will also use the data for an internal purpose attributable to the controller.

Upon registration, the IP address assigned by the Internet Service Provider (ISP), as well as the date and time of registration, are also stored. This is necessary to prevent misuse of our services and, where applicable, to facilitate the investigation of crimes committed. Storing this data is necessary to protect the controller. It will not be transferred to third parties except where required by law or if such transfer is necessary for the purposes of criminal prosecution.

Registration, which is voluntary, allows users to access content or services that are only available to registered users. Registered individuals may modify their personal data at any time or request its complete deletion from the data controller's database.

The data controller will provide information at all times about what personal data is stored about the data subject and will correct or delete the data upon request, provided there are no legal obligations to retain it. All of the data controller's employees are available as contact persons.

Newsletter Subscription

On the Empire Sapphire, S.L. website, users can subscribe to our newsletter. The submission form used determines the personal data transmitted and the time of the request.

Empire Sapphire, S.L. regularly informs its customers and partners about company offers via a newsletter. The newsletter is only sent if (1) the interested party has a valid email address and (2) they register to receive it. For legal reasons, a confirmation email will be sent as part of the double opt-in process. This email allows us to verify that the address holder is authorized to receive the newsletter.

During the subscription process, we also store the IP address of the computer system assigned by the ISP, as well as the date and time of registration. The collection of this data is necessary to detect potential misuse of the email address in the future and thus serves for the legal protection of the data controller.

The personal data collected during the subscription process will be used exclusively for sending the newsletter. Subscribers may receive email communications when necessary for the operation of the service or for modifications to the offer or technical circumstances. This data will not be transferred to third parties. You can unsubscribe at any time by using the link provided in each newsletter or by contacting the email administrator.

Newsletter Tracking

The Empire Sapphire, S.L. newsletter uses tracking pixels. A tracking pixel is a tiny graphic embedded in HTML emails that allows for statistical analysis of marketing campaigns. Thanks to this pixel, we can know if and when an email was opened and which links were clicked.

The personal data collected through these pixels is analyzed to optimize newsletter delivery and tailor future content to the subscriber's interests. This data will not be shared with third parties. Subscribers can withdraw their consent at any time; after withdrawal, this data will be deleted. Unsubscribing from the newsletter is automatically interpreted as withdrawal of consent.

Contact via the Website

The Empire Sapphire, S.L. website includes information that allows for quick electronic contact with the company, as well as direct communication via a general email address. If an interested party contacts the data controller by email or form, the personal data transmitted is automatically stored to respond to the inquiry. This data will not be shared with third parties.

Routine Erasure and Blocking of Personal Data

The controller will process and store personal data only for as long as necessary for the purpose of the processing or as required by applicable law. If the purpose ceases to exist or the statutory retention period expires, the data will be blocked or erased in accordance with the law. Rights of the Data Subject

a) Right to Confirmation
The data subject has the right to obtain confirmation as to whether or not we process their personal data.

b) Right of Access
Right to obtain free information about the personal data stored, as well as:

  • purposes of processing;
  • categories of data;
  • recipients;
  • envisaged retention period;
  • existence of the rights of rectification, erasure, restriction of processing, or objection;
  • right to lodge a complaint with a supervisory authority;
  • the source of the data (if not from the data subject);
  • existence of automated decision-making, including profiling.

c) Right to rectification
Right to obtain the rectification of inaccurate data without undue delay, or to have it completed.

d) Right to erasure (“right to be forgotten”)
Right to have data erased without undue delay when one of the grounds set out in Article 17 GDPR applies. e) Right to restriction of processing
Right to obtain restriction of processing in the cases set out in Article 18 GDPR.

f) Right to data portability
Right to receive personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.

g) Right to object
Right to object, on grounds relating to your particular situation, to processing based on Article 6.1(e) or (f) GDPR, including profiling.

h) Automated individual decisions, including profiling
Right not to be subject to decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.

i) Right to withdraw consent
Right to withdraw your consent at any time.

To exercise any of these rights, you may contact any employee of Empire Sapphire SL.

Legal basis for processing

  • Art. 6.1 a) GDPR – Processing based on consent.
  • Art. 6.1 b) GDPR – Processing necessary for the performance of a contract or for taking steps prior to entering into a contract.
  • Art. 6.1 c) GDPR – Processing necessary for compliance with a legal obligation.
  • Art. 6.1 d) GDPR – Processing necessary to protect vital interests.
  • Art. 6.1 f) GDPR – Processing based on overriding legitimate interests.

Legitimate interests pursued by the controller or a third party

When processing is based on Art. 6.1 f) GDPR, our legitimate interest is to develop our business for the benefit of all our employees and shareholders.

Retention period for personal data

The criterion used to determine the retention period is the applicable statutory retention period. Once this period has expired, the data is routinely deleted, provided it is no longer necessary for the performance or initiation of a contract.

Mandatory or Optional Nature of Providing Personal Data

In some cases, the law or the contract may require the data subject to provide us with personal data. Failure to provide this data may prevent the conclusion of the contract. Before providing personal data, the data subject can contact an employee to clarify whether providing it is mandatory and the consequences of not doing so.

Existence of Automated Decision-Making

As a responsible company, we do not use automated decision-making or profiling.