Loading...

CUSTOMER DATA PROCESSING

At MONTIGON SERVICES SL we treat the information you provide us with in order to provide the requested service and carry out your billing. The data provided will be kept as long as the commercial relationship is maintained or for the time necessary to comply with legal obligations and meet the possible responsibilities that may arise from the fulfillment of the purpose for which the data was collected. The data will not be transferred to third parties except in cases where there is a legal obligation. You have the right to obtain information about whether MONTIGON SERVICES SL is treating your personal data, so you can exercise your rights of access, rectification, deletion and portability of data and opposition and limitation to its treatment before MONTIGON SERVICES SL, CALLE ARGENTEA, 62, privacypolicy@helloresidency.com , attaching a copy of your ID or equivalent document. Likewise, and especially if you consider that you have not obtained full satisfaction in the exercise of your rights, you may file a claim with the national control authority by addressing this purpose to the Spanish Data Protection Agency, C / Jorge Juan, 6 – 28001 Madrid.
Likewise, we request your authorization to offer you products and services related to those contracted and to retain you as a customer.

DATA PROCESSING OF POTENTIAL CUSTOMERS

At MONTIGON SERVICES SL we treat the information you provide us with in order to provide the requested service or send the required information. The data provided will be kept as long as you do not request the cessation of the activity. The data will not be transferred to third parties except in cases where there is a legal obligation. You have the right to obtain information about whether MONTIGON SERVICES SL is treating your personal data, so you can exercise your rights of access, rectification, deletion and portability of data and opposition and limitation to its treatment before MONTIGON SERVICES SL, CALLE ARGENTEA, 62, 5º A 29010 (MALAGA) or at the email address privacypolicy@helloresidency.com, attaching a copy of your ID or equivalent document. Likewise, and especially if you consider that you have not obtained full satisfaction in the exercise of your rights, you may file a claim with the national control authority by addressing this purpose to the Spanish Data Protection Agency, C / Jorge Juan, 6 – 28001 Madrid.

Likewise, we request your authorization to send you advertising related to our products and services by any means (postal, email or telephone) and to invite you to events organized by the company.

DATA PROCESSING OF EMPLOYEES

At MONTIGON SERVICES SL we treat the information you provide us with in order to maintain the employment relationship. The data provided will be kept as long as the employment relationship is maintained or for the time necessary to comply with legal obligations and meet the possible responsibilities that may arise from the fulfillment of the purpose for which the data was collected. The data will not be transferred to third parties except in cases where there is a legal obligation. You have the right to obtain information about whether MONTIGON SERVICES SL is treating your personal data, so you can exercise your rights of access, rectification, deletion and portability of data and opposition and limitation to its treatment before MONTIGON SERVICES SL, CALLE ARGENTEA, 62, 5º A 29010 (MALAGA) or at the email addressprivacypolicy@helloresidency.com , attaching a copy of your ID or equivalent document. Likewise, and especially if you consider that you have not obtained full satisfaction in the exercise of your rights, you may file a claim with the national control authority by addressing this purpose to the Spanish Data Protection Agency, C / Jorge Juan, 6 – 28001 Madrid.

Contract with the Agency in charge of managing the employees:

1. Purpose of the processing order
Through these clauses, Francisco Javier Rosa Bernal, with address at Calle Salitre, number 11, 1º Office 10. CP 29002 Malaga and NIF 33370039Y, is empowered as the person in charge of the treatment to deal on behalf of MONTIGON SERVICES SL, as the person responsible for the treatment, the personal data necessary to provide the service specified hereinafter.
The treatment will consist of accounting, billing and preparation of payroll, taxation and taxes inherent to the activity.
2. Identification of the affected information
For the execution of the benefits derived from the fulfillment of the object of this assignment, the entity MONTIGON SERVICES SL as the data controller, makes the identification and banking data of its employees available to the entity Francisco Javier Rosa Bernal.
3. Duration
This agreement has a duration of, being automatically renewed unless otherwise decided by one of the parties.
Once this contract ends, the person in charge of the treatment must return to the person in charge, or transmit to another person in charge designated by the person in charge, the personal data processed and delete any copy that is in their possession. However, you may keep the data blocked for the minimum time necessary to attend to possible responsibilities that may arise from your relationship with MONTIGON SERVICES SL, destroying them safely and definitively at the end of said period.
4. Obligations of the person in charge of the treatment
The person in charge of the treatment and all his personnel are obliged to:
Use the personal data that is the object of treatment, or those collected for inclusion, only for the purpose of this order. In no case may you use the data for your own purposes.
Treat the data in accordance with the documented instructions of the controller. If the person in charge of the treatment considers that any of the instructions provided violates the General Data Protection Regulation or any other provision on data protection, the person in charge will immediately inform the person in charge.
* Keep, in writing, a record of all categories of treatment activities carried out on behalf of the person in charge, containing:
  • The name and contact details of the person in charge or managers and of each manager on behalf of whom the manager acts and, where appropriate, the representative of the manager or manager and the data protection officer.
  • The categories of processing carried out on behalf of each person in charge.
  • An overview of the appropriate technical and organizational security measures you are applying.

* Do not communicate or disseminate the data to third parties, unless you have the express authorization of the person responsible for the treatment or in the legally admissible cases. If the person in charge wants to subcontract, totally or partially, the services that are the object of this contract, he must inform the person in charge and request their prior authorization.
* Maintain the duty of secrecy regarding the personal data to which you have had access by virtue of this order, even after the contract ends.
* Guarantee that the persons authorized to process personal data undertake, expressly and in writing, to respect confidentiality and to comply with the corresponding security measures, of which the person in charge must inform them appropriately.
* Maintain at the disposal of the person in charge the supporting documentation of the fulfillment of the obligation established in the previous section.

* Guarantee the necessary training in the protection of personal data of the persons authorized to process personal data.

* When the affected persons exercise the rights of access, rectification, deletion and portability of data and opposition and limitation of the treatment before the person in charge of the treatment, this must communicate it by email to the address indicated by the person in charge as soon as possible. The communication must be made immediately and in no case beyond the working day following the receipt of the request, together, where appropriate, with other information that may be relevant to resolve it. It will assist the person in charge, whenever possible, so that he or she can comply with and respond to requests for the exercise of rights.
* Notification of data security breaches:
The person in charge of the treatment will notify the person in charge of the treatment, without undue delay and through the email address indicated by the person in charge, of the violations of the security of the personal data in his charge of which he has knowledge, together with all the information relevant for the documentation and communication of the incident. Likewise, it will notify any failure that it has suffered in its information treatment and management systems and that may endanger the security of the personal data processed, its integrity or availability, as well as any possible violation of confidentiality as a result of the placing In the knowledge of third parties of the data and information accessed during the execution of the contract. At least the following information will be provided:

A. Description of the nature of the personal data security breach, including, where possible, the categories and approximate number of affected interested parties, and the categories and approximate number of affected personal data records.
B. Contact person details for more information.
C. Description of the possible consequences of the violation of the security of personal data.
D. Description of the measures adopted or proposed to remedy the violation of the security of personal data, including, if applicable, the measures adopted to mitigate the possible negative effects.

If it is not possible to provide the information simultaneously, and to the extent that it is not, the information will be provided gradually without undue delay.
Francisco Javier Rosa Bernal, at the request of the person in charge, will communicate these data security violations to the interested parties as soon as possible, when the violation is likely to pose a high risk to the rights and freedoms of individuals.
The communication must be carried out in clear and simple language and must include the elements indicated by the person in charge in each case, at least:

A. The nature of the data breach.
B. Data of the contact point of the person in charge or the person in charge where more information can be obtained.
C. Describe the possible consequences of the violation of the security of personal data.
D. Describe the measures adopted or proposed by the person responsible for the treatment to remedy the violation of the security of personal data, including, if applicable, the measures adopted to mitigate the possible negative effects.

* Make available to the person in charge all the information necessary to demonstrate compliance with their obligations, as well as to allow and contribute to the performance of the audits or inspections carried out by the person in charge or another auditor authorized by him.
* Implement the technical and organizational security measures necessary to guarantee the confidentiality, integrity, availability and permanent resilience of the systems and services for the treatment of personal data.
* Data destination:
Delete, return to the person in charge or deliver, where appropriate, to a new manager as determined by MONTIGON SERVICES SL, all personal data once the provision of the treatment service in charge has been completed.
The destruction of the data does not proceed when there is a legal provision that requires its conservation, in which case it must be returned to the person in charge who will guarantee its conservation, duly blocked, as long as such obligation persists.
The return must entail the total erasure of the existing data in the computer equipment used by the person in charge. However, the person in charge may keep a copy of the data, duly blocked, while responsibilities may arise from the execution of the services provided to the person responsible for the treatment.

5. Obligations of the data controller

Corresponds to the person responsible for the treatment:

  1. Give the person in charge the necessary data so that he can provide the service.
  2. Ensure, previously and throughout the treatment, compliance with the current provisions on data protection by the person in charge of the treatment.
  3. Supervise the treatment, including the possibility of requesting information to verify compliance with the obligations established in this contract.

PROCESSING OF SUPPLIER DATA

At MONTIGON SERVICES SL we treat the information you provide us with in order to place orders and manage the billing of the contracted products and services. The data provided will be kept as long as the commercial relationship is maintained or for the time necessary to comply with legal obligations and meet the possible responsibilities that may arise from the fulfillment of the purpose for which the data was collected. The data will not be transferred to third parties except in cases where there is a legal obligation. You have the right to obtain information about whether MONTIGON SERVICES SL is treating your personal data, so you can exercise your rights of access, rectification, deletion and portability of data and opposition and limitation to its treatment before MONTIGON SERVICES SL, CALLE ARGENTEA, 62, privacypolicy@helloresidency.com, attaching a copy of your ID or equivalent document. Likewise, and especially if you consider that you have not obtained full satisfaction in the exercise of your rights, you may file a claim with the national control authority by addressing this purpose to the Spanish Data Protection Agency, C / Jorge Juan, 6 – 28001 Madrid.

RECORD OF TREATMENT ACTIVITIES

 

Treatment:  Clients

a) Responsible for the treatment

Identity: MONTIGON SERVICES SL – NIF: B55427488

Postal address: Calle GAD, 12, 2b, Esc. 8, 29620, Torremolinos, Málaga

Email: privacidad@montigon.com

Phone: 677 045 618

b) Purpose of the treatment

Management of the relationship with potential clients

c) Categories of interested parties

Potential customers: People with whom you want to maintain a business relationship as customers

d) Data categories

Those necessary for the commercial promotion of the company

Identification: name and surname and postal address, telephone numbers, e-mail

e) Categories of recipients

It is not contemplated

f) International transfers

International transfers are not planned

g) Period of deletion

One year from the first contact

h) Security measures

Those reflected in the ANNEX SECURITY MEASURES

Treatment:  Potential Clients

a) Responsible for the treatment

Identity: MONTIGON SERVICES SL – NIF: B55427488

Postal address: Calle GAD, 12, 2b, Esc. 8, 29620, Torremolinos, Málaga

Email: privacidad@montigon.com

Phone: 677 045 618

b) Purpose of the treatment

Management of the relationship with potential clients

c) Categories of interested parties

Potential customers: People with whom you want to maintain a business relationship as customers

d) Data categories

Those necessary for the commercial promotion of the company

Identification: name and surname and postal address, telephone numbers, e-mail

e) Categories of recipients

It is not contemplated

f) International transfers

International transfers are not planned

g) Period of deletion

One year from the first contact

h) Security measures

Those reflected in the ANNEX SECURITY MEASURES

Treatment:  Employees

a) Responsible for the treatment

Identity: MONTIGON SERVICES SL – NIF: B55427488

Postal address: Calle GAD, 12, 2b, Esc. 8, 29620, Torremolinos, Málaga

Email: privacidad@montigon.com

Phone: 677 045 618

b) Purpose of the treatment

Management of the employment relationship with employees

c) Categories of interested parties

Employees: People who work for the data controller

d) Data categories

Those necessary for the maintenance of the commercial relationship. Manage payroll

Identification: name, surname, Social Security number, postal address, telephone numbers, e-mail

Professional data

Bank details, for direct debit of payroll payment

e) Categories of recipients

State Tax Administration Agency

National Institute of Social Security

Banks and financial entities

[Other possible recipients]

f) International transfers

International transfers are not planned

g) Period of deletion

Those provided for by tax and labor legislation regarding the prescription of responsibilities

h) Security measures

Those reflected in the ANNEX SECURITY MEASURES

Treatment:  Providers

a) Responsible for the treatment

Identity: MONTIGON SERVICES SL – NIF: B55427488

Postal address: Calle GAD, 12, 2b, Esc. 8, 29620, Torremolinos, Málaga

Email: privacidad@montigon.com

Phone: 677 045 618

b) Purpose of the treatment

Management of the relationship with suppliers

c) Categories of interested parties

Suppliers: People with whom a commercial relationship is maintained as suppliers of products and / or services

d) Data categories

Those necessary for the maintenance of the employment relationship

Identification: name, NIF, postal address, telephone numbers, e-mail

Bank details: for direct debit of payments

e) Categories of recipients

State Tax Administration Agency

Banks and financial entities

[Other possible recipients]

f) International transfers

International transfers are not planned

g) Period of deletion

Those provided for by tax legislation regarding the prescription of responsibilities

h) Security measures

Those reflected in the ANNEX SECURITY MEASURES

ANNEXED

INFORMATION OF GENERAL INTEREST
This document has been designed for low-risk personal data processing from which it is deduced that it cannot be used for personal data processing that includes personal data related to ethnic or racial origin, religious or philosophical political ideology, union affiliation, data genetic and biometric data, health data, and data on people’s sexual orientation, as well as any other data processing that involves high risk for people’s rights and freedoms.
Article 5.1.f of the General Data Protection Regulation (hereinafter, RGPD) determines the need to establish adequate security guarantees against unauthorized or illegal treatment, against the loss of personal data, destruction or accidental damage. This implies the establishment of technical and organizational measures aimed at ensuring the integrity and confidentiality of personal data and the possibility of demonstrating, as established in article 5.2, that these measures have been carried out (proactive responsibility).
In addition, it must establish visible, accessible and simple mechanisms for the exercise of rights and have defined internal procedures to guarantee the effective attention of the requests received.

ATTENTION OF THE EXERCISE OF RIGHTS
The person responsible for the treatment will inform all workers about the procedure to address the rights of the interested parties, clearly defining the mechanisms by which the rights can be exercised (electronic means, reference to the Data Protection Delegate, if any, postal address , etc.) and taking into account the following:
Upon presentation of their national identity document or passport, the holders of personal data (interested parties) may exercise their rights of access, rectification, deletion, opposition, portability and limitation of treatment. The exercise of rights is free.
The person in charge of the treatment must respond to the interested parties without undue delay and in a concise, transparent, intelligible way, with a clear and simple language and retain the proof of compliance with the duty to respond to the requests for the exercise of rights made.
If the request is submitted by electronic means, the information will be provided by these means whenever possible, unless the interested party requests otherwise.
Requests must be responded to within 1 month of receipt, and may be extended by another two months taking into account the complexity or number of requests, but in that case the interested party must be informed of the extension within a month from of receipt of the request, indicating the reasons for the delay.

RIGHT OF ACCESS: In the right of access, the interested parties will be provided with a copy of the personal data that is available together with the purpose for which they have been collected, the identity of the recipients of the data, the expected retention periods or the criteria used to determine it, the existence of the right to request the rectification or deletion of personal data as well as the limitation or opposition to its treatment, the right to file a claim with the Spanish Data Protection Agency and if the data has not been obtained from the interested party, any available information about its origin. The right to obtain a copy of the data cannot adversely affect the rights and freedoms of other interested parties.

Form for the exercise of the right of access.

 

RIGHT OF RECTIFICATION: In the right of rectification, the data of the interested parties that are inaccurate or incomplete will be modified according to the purposes of the treatment. The interested party must indicate in the request what data they refer to and the correction to be made, providing, when necessary, supporting documentation of the inaccuracy or incompleteness of the data being processed. If the data has been communicated by the person in charge to other managers, they must notify them of the rectification of these unless it is impossible or requires a disproportionate effort, providing the interested party with information about said recipients, if requested.

 

RIGHT OF WITHDRAWAL:In the right of deletion, the data of the interested parties will be deleted when they express their refusal to treatment and there is no legal basis that prevents it, they are not necessary in relation to the purposes for which they were collected, they withdraw the consent given and there is no another legal basis that legitimizes the treatment or it is illegal. If the deletion derives from the exercise of the interested party’s right of opposition to the processing of their data for marketing purposes, the identification data of the interested party may be kept in order to prevent future processing. If the data has been communicated by the person in charge to other managers, they must notify them of the deletion of these unless it is impossible or requires a disproportionate effort, providing the interested party with information about said recipients, if requested.

Form for the exercise of the right of deletion.

 

RIGHT OF OBJECTION: In the right of opposition, when the interested parties express their refusal to the processing of their personal data before the person in charge, this will stop processing them as long as there is no legal obligation that prevents it. When the treatment is based on a mission of public interest or the legitimate interest of the person in charge, upon a request to exercise the right of opposition, the person in charge will stop processing the data unless compelling reasons are proven that prevail over the interests, rights and freedoms of the interested party or are necessary for the formulation, exercise or defense of claims. If the interested party opposes the treatment for direct marketing purposes, the personal data will no longer be processed for these purposes.

Form for the exercise of the right of opposition.

 

PORTABILITY RIGHT: In the portability right, if the treatment is carried out by automated means and is based on consent or is carried out within the framework of a contract, the interested parties may request to receive a copy of their personal data in a structured format, for common use and reading. mechanics. Likewise, they have the right to request that they be transmitted directly to a new person in charge, whose identity must be communicated, when technically possible.

Form for the exercise of data portability.

 

RIGHT OF LIMITATION TO TREATMENT: In the right to limit the treatment, the interested parties may request the suspension of the treatment of their data to challenge its accuracy while the person in charge carries out the necessary verifications or in the event that the treatment is carried out based on the legitimate interest of the person in charge or in compliance of a mission of public interest, while verifying if these reasons prevail over the interests, rights and freedoms of the interested party. The interested party can also request the conservation of the data if he considers that the treatment is illegal and, instead of the deletion, requests the limitation of the treatment, or if the person responsible for the purposes for which they were collected is no longer needed, the interested party You need them for the formulation, exercise or defense of claims. The circumstance that the processing of the data of the interested party is limited must be clearly stated in the systems of the person in charge. If the data has been communicated by the person in charge to other controllers, they must notify them of the limitation of the treatment of these unless it is impossible or requires a disproportionate effort, providing the interested party with information about said recipients, if requested.

 

If the interested party’s request is not acted upon, the data controller will inform them, without delay and at the latest after one month from receiving the request, of the reasons for their non-action and the possibility of filing a claim with the Agency. Spanish Data Protection and to exercise legal actions.

 

SECURITY MEASURES

Based on the type of treatment that you have revealed when you have completed this form, the minimum security measures that you should take into account are the following:

 ORGANIZATIONAL MEASURES

INFORMATION THAT SHOULD BE KNOWN BY ALL PERSONNEL WITH ACCESS TO PERSONAL DATA

All personnel with access to personal data must be aware of their obligations in relation to the processing of personal data and will be informed about said obligations. The minimum information that will be known by all personnel will be the following:

  • DUTY OF CONFIDENTIALITY AND SECRET
  • Access by unauthorized persons to personal data should be avoided. To this end, leaving personal data exposed to third parties will be avoided (unattended electronic screens, paper documents in public access areas, supports with personal data, etc.). This consideration includes the screens used to display images from the video surveillance system. When you are absent from your job, the screen will be locked or the session will be closed.
  • Paper documents and electronic media will be stored in a safe place (cabinets or restricted access rooms) 24 hours a day. 
  • Documents or electronic media (CDs, pen drives, hard drives, etc.) with personal data will not be discarded without guaranteeing their effective destruction. 
  • Personal data or any other information of a personal nature will not be communicated to third parties, paying special attention not to disclose protected personal data during telephone consultations, emails, etc.
  • The duty of secrecy and confidentiality persists even when the worker’s employment relationship with the company ends.
  • PERSONAL DATA SECURITY VIOLATIONS
  • When personal data security violations occur, such as theft or improper access to personal data, the Spanish Data Protection Agency will be notified within 72 hours of said security violations, including all the information necessary for the clarification of the facts that would have given rise to improper access to personal data. The notification will be made by electronic means through the electronic headquarters of the Spanish Agency for Data Protection at the address https://sedeagpd.gob.es/sede-electronica-web/.

 

TECHNICAL MEASURES

ID

  • When the same computer or device is used for the processing of personal data and personal use purposes, it is recommended to have several different profiles or users for each of the purposes. Professional and personal use of the computer should be kept separate.
  • It is recommended to have profiles with administration rights for the installation and configuration of the system and users without privileges or administration rights for access to personal data. This measure will prevent access privileges from being obtained or modifying the operating system in the event of a cybersecurity attack.
  • The existence of passwords for access to personal data stored in electronic systems will be guaranteed. The password will have at least 8 characters, a mixture of numbers and letters.
  • When personal data are accessed by different people, for each person with access to personal data, there will be a specific username and password (unequivocal identification).
  • The confidentiality of passwords must be guaranteed, preventing them from being exposed to third parties. For the management of passwords you can consult the internet privacy and security guide of the Spanish Agency for Data Protection and the National Institute of Cybersecurity. In no case will passwords be shared or recorded in a common place and the access of people other than the user.

DUTY OF SAFEGUARD 

Below are the minimum technical measures to guarantee the safeguarding of personal data: 

  • COMPUTER AND DEVICE UPDATE: The devices and computers used for the storage and processing of personal data must be kept up to date as much as possible. 
  • MALWARE: In the computers and devices where the automated processing of personal data is carried out, an antivirus system will be available to guarantee as far as possible the theft and destruction of personal information and data. The antivirus system must be updated periodically.
  • FIREWALL OR FIREWALL: To prevent improper remote access to personal data, it will be ensured that there is an activated and correctly configured firewall on those computers and devices on which personal data is stored and / or processed.
  • DATA ENCRYPTION When it is necessary to extract personal data outside the premises where its treatment is carried out, either by physical means or by electronic means, the possibility of using an encryption method should be evaluated to guarantee the confidentiality of personal data in case of improper access to information.
  • BACKUP COPY: Periodically a backup will be made on a second medium other than the one used for daily work. The copy will be stored in a safe place, different from the one where the computer with the original files is located, in order to allow the recovery of personal data in case of loss of information.

 

The security measures will be reviewed periodically, the review may be carried out by automatic mechanisms (software or computer programs) or manually. Consider that any computer security incident that has happened to anyone you know can happen to you, and guard against it.

If you want more information or technical guidance to guarantee the security of personal data and the information that your company deals with, the National Institute of Cybersecurity (INCIBE) on its website www.incibe.es, puts at your disposal tools with a business approach in its section «Protect your business» Where, among other services, it has:

 

In addition, INCIBE, through the Internet User Security Office, also puts at your disposal tools Free computing and additional information can be useful for your company or your professional activity. 

 

CAPTURING IMAGES WITH CAMERAS AND SECURITY PURPOSE 

(VIDEO SURVEILLANCE)

 

The image of a person, to the extent that it identifies or can identify it, constitutes a personal data that can be processed for various purposes. Although the most common is to use the cameras to ensure the safety of people, goods and facilities, they can also be used for other purposes such as controlling the labor benefits of workers. Below are the basic guidelines to respect so that the treatment of images obtained from video surveillance cameras is in accordance with data protection regulations. However, it is recommended to consult theGuide on Using Video Cameras for Security and Other Purposes for a more exhaustive knowledge of the obligations that this type of treatment entails.


  • LOCATION OF THE CAMERAS: The capture of images in areas intended for the rest of the workers will be avoided, as well as the capture of the public road if exterior cameras are used, being only allowed the capture of the minimum essential extension to preserve the safety of people, goods and installations.


  • MONITOR LOCATION: The monitors where the images from the cameras are displayed will be located in a restricted access space so that they are not accessible to third parties. Recorded images will only be accessed by authorized personnel.


  • IMAGE PRESERVATION: The images will be stored for a maximum period of one month, with the exception of images that prove the commission of acts that violate the integrity of people, property and facilities. In that case, the images must be made available to the competent authority within 72 hours from when the recording was made known.


  • DUTY OF INFORMATION: The existence of the cameras and the recording of images will be reported by means of an informational badge placed in a sufficiently visible place where at least the identity of the person in charge and the possibility of the interested parties to exercise their rights regarding the protection of data. The pictogram itself may also include a connection code or internet address in which this information is displayed. Models, both the pictogram and the text, are available on the Agency’s website.


  • LABOR CONTROLWhen the cameras are to be used for the purpose of labor control as provided in article 20.3 of the Workers’ Statute, the worker and their union representatives will be informed by any means that guarantees the receipt of information about the measures of control established by the employer with express indication of the purpose of labor control of the images captured by the cameras.


  • RIGHT OF ACCESS TO IMAGES: To comply with the right of access of the interested parties to the recordings of the video surveillance system, a recent photograph and the National Identity Document of the interested party will be requested to verify their identity, as well as the detail of the date and time to which it refers the right of access. The interested party will not be given direct access to the images of the cameras in which images of third parties are shown. If it is not possible to view the images by the interested party without showing images of third parties, a document will be provided confirming or denying the existence of images of the interested party.

For more information, you can consult the guides and video surveillance files and the legal reports published by the Spanish Data Protection Agency in the section on Video surveillance.