Personal data protection policy
This Policy outlines how we manage the personal data we hold in compliance with the Personal Data Protection Act in Spain (the “Act”). This policy applies to Medcare Group S.L. & its subsidiaries (collectively, “we”, “us” or “our”).
What types of personal data do we collect?
We may collect and hold personal data of persons/entities including but not limited to:
- Job applicants and employees;
- Service providers; and
- Other people who we may come into contact.
Examples of such personal data include biodata, contact details, account information and your preferences, queries, requests and feedback.
How do we collect your personal data?
The ways in which we may collect your personal data include (but are not limited to) collecting directly or indirectly from you or your authorized representatives in the course of:
- You signing up for alerts or newsletters;
- You visiting our websites, showflats, etc;
- You purchasing or leasing a property from us;
- You making a reservation or staying in properties which we own or operate;
- You applying for a job with us;
- You participating in our marketing or promotional events;
- You using our products or services;
- You contacting us with your queries, requests or feedback;
- Our conducting or completing of transactions;
- Our conducting market research or surveys; and
- Our conducting interviews.
What kind of purposes do we collect your personal data for?
In general, we may use your personal data for the following purposes:
- Conducting and completing transactions (e.g. processing orders and payments; providing products or services that have been requested);
- Providing customer service (e.g. responding to queries and requests; informing you about service status and product updates; sending you alerts and newsletters);
- Conducting market research and improving customer service (e.g. conducting market research or surveys; performing market analysis; managing and enhancing our products and services; developing new products);
- Conducting marketing promotions (e.g. sending of alerts, newsletters, marketing materials and invitations from us wholly or through affiliation with third parties; offering promotions and loyalty programs);
- Complying with applicable laws, regulations and other requirements (e.g. providing assistance to law enforcement agencies, regulatory authorities and other governmental agencies; performing internal audits);
- Maintaining investor relations (e.g. sending of alerts, newsletters, publications, marketing materials and invitations from us wholly or through affiliation with third parties); and
- Performing evaluations (e.g. assessing suitability of employees).
We may decide to buy or sell assets which form part of or relate to a business or a division or organization within us. In any such transaction, personal data will usually be one of the transferred assets and will be disclosed to the purchaser.
In most cases, if you do not provide information about yourself which we have requested, we may not be able to provide you with the relevant product or service.
How do we use and/or disclose your personal data?
We will only use, disclose and/or transfer your personal data for the purposes you have been notified of and consented to or which are permitted under applicable laws and regulations. We will not sell, rent or give away personal data to third parties for commercial purposes without your consent.
Who do we share your personal data with?
Depending on the product or service concerned, personal data may be disclosed or transferred to:
- Other divisions or organizations within our group of companies;
- Our joint venture/ alliance partners;
- Our service providers and specialist advisers/institutions who have been contracted to provide administrative, financial, legal, accounting, information technology, marketing, research or other services;
- Other insurers, credit providers, courts, tribunals, law enforcement agencies, regulatory authorities and other governmental agencies as agreed or authorized by law;
- Credit reporting or reference agencies or insurance investigators; and
- Anyone authorized by an individual, as specified by that individual or the contract,
in the countries we/they operate in.
How do we manage, protect and store your personal data?
We regard breaches of your privacy very seriously and we have implemented reasonable measures to protect your personal data from unauthorised or accidental access, processing or loss by implementing appropriate physical, electronic and supervisory controls. However, you will appreciate that it is not for us to perfectly secure your personal data from cyber attacks, such as hacking, spyware and viruses. Accordingly, you will not hold us liable for any unauthorised disclosure, loss or destruction of your personal data arising from such risks.
The Act also requires us not to store personal data longer than necessary. We will cease to retain your personal data when we no longer require such personal data for the purposes we originally notified you of or for any business or legal needs.
How do we keep personal data accurate and up-to-date and how to exercise your right to correct the personal data we hold of you?
We endeavour to ensure that the personal data we hold about you is accurate and up-to-date. We realize that such personal data changes frequently with changes of address and other personal circumstances. We encourage you to write to us at email@example.com as soon as possible in order to update any personal data it holds about you.
How to exercise your right to access the personal data we hold of you?
You may contact us at firstname.lastname@example.org to make a request to access the personal data we hold about you. We will require you to verify your identity and to specify what data you require. We may charge a fee to cover the cost of verifying the application and locating, retrieving, reviewing and copying any material requested. If the data sought is extensive, we will advise the likely cost in advance and can help to refine your request if required.
How to exercise your right to withdraw your consent?
Please write to us at email@example.com to make a request to withdraw your consent.
What if you have a complaint?
If you consider that any action by us has breached the Act or this Policy, you can make a complaint by writing to firstname.lastname@example.org.
Our Data Protection Officer (DPO) is Dr. Manuel Salinas, Chief of Risk and Compliance Officer, Medcare Group S.L. If you have any questions about this policy or you wish to contact us in relation to your personal data, please contact:
Data Protection Officer
Dr. Manuel Salinas
Updates to this Policy
This Policy will be reviewed from time to time to take account of new laws and technology, changes to our operations and practices and the changing business environment. If you are unsure whether you are reading the most current version, please contact us at email@example.com.