TABLE OF CONTENTS
1. Purpose of the Privacy Policy
2. Definitions
3. Identity of the Data Controller
4. Applicable laws and regulations
5. Principles applicable to the processing of personal data
6. Data processing activities carried out
7. Necessary and updated information
8. Personal data of minors
9. Technical and organisational security measures
10. Rights of data subjects
11. Complaints to the Supervisory Authority
12. Acceptance and changes to the Privacy Policy
1.- PURPOSE OF THE PRIVACY POLICY
The purpose of this ‘Privacy and Data Protection Policy’ is to disclose the conditions governing the collection and processing of personal data by SKYLINE PARTNERS S.L., making every effort to ensure the fundamental rights, honour and freedoms of persons whose personal data is processed in compliance with the regulations and laws in force governing the Protection of personal data according to the European Union and the Spanish Member State and, specifically, those expressed in the section ‘Processing Activities’ of this Privacy Policy.
Therefore, in this Privacy and Data Protection Policy, users of the Website https://www.skyline.es/es are informed of all the details of interest to them regarding how these processes are carried out, for what purposes, which other entities may have access to their data and what the rights of users are.
2.- DEFINITIONS
«Personal data»: All information relating to an identified or identifiable natural person ('the Website user'); an identifiable natural person shall be considered to be any person whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person.
«Processing»: any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, extraction, consultation, use, communication by transmission, dissemination or any other form of making available, alignment or combination, restriction, erasure or destruction.
«Restriction of processing»: the marking of personal data stored with the aim of limiting their processing in the future.
«Profiling» means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
«Pseudonymisation» means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
«File» means any structured set of personal data, accessible according to specified criteria, whether centralised, decentralised or distributed on a functional or geographical basis.
«Controller» or «controller» means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing; where the purposes and means of the processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
«Data processor» or «processor» means the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
«Recipient» means a natural or legal person, public authority, agency or other body, to which personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the data protection rules applicable to the purposes of the processing.
«Third party» means a natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and the persons who, under the direct authority of the controller or the processor, are authorised to process personal data.
«Consent of the data subject» means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, agrees to the processing of personal data relating to him or her.
«Personal data breach» means any breach of security leading to the accidental or unlawful destruction, loss, alteration of, or unauthorised disclosure of, personal data transmitted, stored or otherwise processed;
«Genetic data» means personal data relating to inherited or acquired genetic characteristics of a natural person which provide unique information about that person's physiology or health, obtained in particular from the analysis of a biological sample from that person.
«Biometric data» means personal data obtained through specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person which permit or confirm the unique identification of that natural person, such as facial images or dactyloscopic data.
«Health data» means personal data relating to the physical or mental health of a natural person, including the provision of health-care services, which reveal information about his or her state of health.
«Main establishment»: a) in respect of a controller with establishments in more than one Member State, the place of its central administration in the Union, unless decisions on the purposes and means of processing are taken at another establishment of the controller in the Union and that latter establishment has the power to enforce those decisions, in which case the establishment which has taken those decisions shall be considered to be the main establishment; b) in respect of a processor with establishments in more than one Member State, the place of its central administration in the Union or, if there is no such central administration, the establishment of the processor in the Union where the main processing activities in the context of the activities of an establishment of the processor are carried out insofar as the processor is subject to specific obligations under this Regulation.
«Representative»: a natural or legal person established in the Union who, having been designated in writing by the controller or the processor in accordance with Article 27 of the GDPR, represents the controller or the processor with regard to their respective obligations under this Regulation.
«Company»: a natural or legal person engaged in an economic activity, irrespective of its legal form, including companies or associations regularly carrying out an economic activity.
«Supervisory authority»: the independent public authority established by a Member State pursuant to Article 51 of the GDPR. In the case of Spain, this is the Spanish Data Protection Agency.
«Cross-border processing» a) the processing of personal data carried out in the context of the activities of establishments in more than one Member State of a controller or processor in the Union, if the controller or processor is established in more than one Member State, or b) the processing of personal data carried out in the context of the activities of a single establishment of a controller or processor in the Union, but which substantially affects or is likely to substantially affect data subjects in more than one Member State.
«Information society service» means any information society service, meaning any service which is normally provided for a fee, at a distance, by electronic means and at the individual request of a recipient of the services.
3.- IDENTITY OF THE DATA CONTROLLER
The Data Controller is the natural or legal person, public or private, or administrative body, which alone or jointly with others determines the purposes and means of the processing of personal data; in the event that the purposes and means of the processing are determined by the Law of the European Union or of the Spanish Member State.
In the aspects expressed in this Data Protection Policy, the identity and contact details of the Data Controller are:
SKYLINE PARTNERS S.L - CIF B64157845
Carrer del Berguedà 43 local 18. 08211, CASTELLAR DEL VALLES (Barcelona), Spain
Email: info@skyline.es
Phone: 93 519 00 00
4.- APPLICABLE LAWS AND REGULATIONS
This Privacy and Data Protection Policy is developed based on the following data protection laws and regulations:
5.- PRINCIPLES APPLICABLE TO THE PROCESSING OF PERSONAL DATA
The personal data collected and processed through this website will be processed in accordance with the following principles:
6.- DATA PROCESSING ACTIVITIES
Below, the data processing activities carried out through the Website are detailed, specifying each of the following sections:
6.1 MAIN PROCESSING ACTIVITIES
These are data processing activities whose purposes are necessary and essential for the provision of services.
CONTACT VIA WEBSITE
Legal bases (Art. 6.1.f GDPR) Legitimate interest of the Data Controller or third parties
Purposes CONTACT VIA WEBSITE
Data categories and groups CLIENTS (Identification data). POTENTIAL CLIENTS (Identification data)
Data origin The interested party or their legal representative
Category of recipients Not foreseen
International transfer Not foreseen
Conservation period Until the interested party requests its deletion
BILLING TO CLIENTS
Legal bases (Art. 6.1.b GDPR) Existence of a contractual relationship with the interested party through a contract or pre-contract; (Art. 6.1.f GDPR) Legitimate interest of the Data Controller or third parties
Purposes BILLING TO CUSTOMERS
Data categories and groups CUSTOMERS (Identification data; Economic, financial and insurance)
Data source The interested party or their legal representative
Category of recipients Not foreseen
International transfer Not foreseen
Conservation period As long as the business relationship is maintained
PROCESSING OF BUDGETS
Legal bases (Art. 6.1.f GDPR) Legitimate interest of the Data Controller or third parties
Purposes PROCESSING OF BUDGETS
Data categories and groups CUSTOMERS (Identification data). POTENTIAL CUSTOMERS (Identification data)
Data source The interested party or their legal representative
Category of recipients Not foreseen
International transfer Not foreseen
Conservation period As long as the interested party does not request its deletion
6.2 OPTIONAL PROCESSING ACTIVITIES (if the user has marked their acceptance)
These are personal data processing activities whose purposes are not essential for the provision of the service and which are only carried out if the user has marked YES in the consent for the performance of these activities.
RECEPTION OF CURRICULUMS
Legal bases (Art. 6.1.a RGPD) Consent of the interested party; (Art. 6.1.f GDPR) Legitimate interest of the Data Controller or third parties
Purposes RECEIPT OF CURRICULUMS
Data categories and groups POTENTIAL EMPLOYEES (Identification data; Academic and professional;
Personal characteristics; Employment details)
Data source The interested party or their legal representative
Category of recipients Not foreseen
International transfer Not foreseen
Conservation period Until the interested party requests its deletion
7.- NECESSARY AND UPDATED INFORMATION
All fields marked with an asterisk (*) in the forms on the Website must be completed, so that the omission of any of them could result in the impossibility of providing the requested services or information.
You must provide truthful information so that the information provided is always up-to-date and does not contain errors. You must notify the Data Controller as soon as possible of any changes or corrections to your personal data by sending an email to the following address: info@skyline.es.
Furthermore, by clicking on the “I accept” button (or equivalent) included in the aforementioned forms, you declare that the information and data you have provided in them are accurate and true, and that you understand and accept this Privacy Policy.
8.- DATA OF MINORS
In compliance with the provisions of article 8 of the GDPR and article 7 of the LOPD/GDD, only those over 14 years of age may give their consent for the processing of their personal data in a legal manner by SKYLINE PARTNERS S.L.
Therefore, minors under 14 years of age may not use the services available through the Website without the prior authorization of their parents, guardians or legal representatives, who will be solely responsible for all acts carried out through the Website by minors under their care, including the completion of electronic forms with the personal data of said minors and the marking, where appropriate, of the boxes that accompany them.
9.- TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
The Data Controller adopts the necessary organizational and technical measures to guarantee the security and privacy of your data, prevent its alteration, loss, treatment or unauthorized access, depending on the state of the technology, the nature of the data stored and the risks to which they are exposed.
Among others, the following measures stand out:
On the other hand, the Data Controller has made the decision to manage the information systems according to the following principles:
10.- RIGHTS OF INTERESTED PARTIES
The current data protection regulations protect the user with a series of rights in relation to the use given to their data.
Each and every one of these rights are personal and non-transferable, that is, they can only be exercised by the owner of the data, after verifying their identity.
The rights of the users of the Website are detailed below:
The Website user may exercise any of the aforementioned rights by contacting the Data Controller and after identifying the User using the following contact information:
11.- RIGHT TO COMPLAIN TO THE CONTROLLING AUTHORITY
The user is informed of his/her right to file a complaint with the Spanish Data Protection Agency if he/she considers that a violation of data protection legislation has been committed with respect to the processing of his/her personal data.
Contact information for the supervisory authority:
Spanish Data Protection Agency
Email: info@aepd.es
Telephone: 912663517
Website: https://www.aepd.es
Address: C/. Jorge Juan, 6. 28001, Madrid (Madrid), Spain
12.- ACCEPTANCE AND CHANGES IN THE PRIVACY POLICY
The Website user must have read and agreed to the data protection conditions contained in this Privacy Policy, as well as accept the processing of their personal data so that the Data Controller can proceed with it in the manner, timeframes and purposes indicated.
The Data Controller reserves the right to modify this Privacy Policy, at its own discretion, or motivated by a legislative, jurisprudential or doctrinal change of the Spanish Data Protection Agency. Any changes or updates made to this Privacy Policy that affect the purposes, retention periods, transfers of data to third parties, international data transfers, as well as any rights of the Website User, will be explicitly communicated to the user.
Version of March 4, 2025