Data Protection Policy
How we process your personal data
This policy explains how we process your personal data when you interact with our websites www.emedec.com and www.panelate.com, write to us by email or register through forms (online or offline). By using our services you accept this policy and we invite you to review it periodically.
1. Who we are
Emedec, S.L. (hereinafter, “Emedec” or “we”) is the data controller. Registered office: Avinguda Miguel Hernández, 27, 46960 Aldaia, València, España. Contact email: emedec@emedec.com.
2. Privacy principles
- Lawfulness, fairness and transparency.
- Data minimisation and purpose limitation.
- Accuracy, security and confidentiality.
- We do not sell your data to third parties.
- We respect your choices and your rights.
3. What data we process
Depending on your interaction, we may process: identification and contact data (name, email, telephone, addresses), account and activity data (username/password, order history, preferences), purchase and payment data (products, amounts; the payment gateway handles sensitive data), browsing/technology data (IP, device, pages viewed, cookies – see the Cookie Policy) and communications/content (messages, reviews, surveys, promotions). If you use social login, the social network may share certain data according to your settings.
4. Purposes and legal basis
- Contract management: creating an account, processing orders, shipping, after-sales service, invoicing. Legal basis: performance of a contract and legal obligations.
- Service and support: responding to enquiries (forms, email, chat). Legal basis: legitimate interest and/or pre-contractual measures.
- Marketing: newsletters, offers and events only if you subscribe/consent. Legal basis: consent (revocable at any time).
- Analysis and improvement: aggregated metrics, usability and statistics. Legal basis: legitimate interest and, where applicable, consent (analytics cookies).
- Advertising and personalisation: remarketing, audiences and saved carts, only if you consent (marketing cookies). Legal basis: consent.
- Security and compliance: fraud prevention, security and regulatory compliance. Legal basis: legitimate interest and/or legal obligation.
- Profiling: we may create basic segments or profiles (for example, by purchased categories) for recommendations and campaign measurement. We do not make automated decisions with legal effects, or that significantly affect you, without human intervention.
5. Origin of the data
- Directly from you (forms, orders, emails, chat).
- From your browsing (cookies/SDKs according to your preferences).
- From third parties when you authorise it (e.g. social login).
6. Who we share your data with
Only with trusted providers acting as data processors under contract: technology and infrastructure (hosting, maintenance, analytics, CRM, transactional email), logistics/courier services (order delivery), payment and anti-fraud gateways, and agencies/media (when you consent to marketing cookies). We do not transfer data to third parties for their own commercial purposes.
7. International transfers
In principle, we do not carry out international transfers. Should it be necessary to use providers located outside the EEA, we will apply appropriate safeguards (Standard Contractual Clauses and supplementary measures) and will state this in this policy.
8. Retention periods
- Contracts/orders: for the duration of the relationship and the legal retention periods (e.g. 6 years for commercial/accounting purposes).
- Enquiries/support: the time strictly necessary to handle them.
- Consent-based marketing: until you withdraw it or after prolonged inactivity (max. 3 years).
- Cookies: according to purpose and lifetime (see the Cookie Policy; in general, up to 365 days for preferences).
Once these periods have elapsed, we block or anonymise the data.
9. Security
We apply technical and organisational measures to protect your data (access control, encryption in transit, backups, internal policies and provider selection). Although we work to prevent unauthorised access, no transmission over the Internet is 100% secure.
10. Minors
Our sites and services are not directed at minors. If we detect the processing of minors' data without the proper authorisation, we will delete it diligently.
11. Links and social login
Our sites may link to third-party websites with their own policies. Review them before providing data. If you use social login, the social network shares certain data with us according to your settings.
12. Cookies and Consent Mode
We use essential, analytics and marketing cookies. Non-essential cookies are only activated if you consent through the banner/settings panel. You can manage or withdraw your preferences at any time from the Cookie settings link in the footer. More details in the Cookie Policy. If we use Google Analytics / Consent Mode, we configure anonymize_ip and the consent mode in accordance with your choices.
13. Your rights
You may exercise your rights of access, rectification, erasure, objection (including to marketing and to profiling for marketing purposes), restriction, portability and withdrawal of consent. To exercise them, write to emedec@emedec.com indicating “Protección de Datos” and, where appropriate, a document proving your identity. You may also lodge a complaint with the AEPD. We encourage you to contact us first in order to resolve any issue.
14. Changes to this policy
We may update this policy to reflect legal, technical or business changes. We will publish the new version with its update date and, if the changes are substantial, we may communicate this through additional channels (banner, email).
Last updated:
