Privacy Policy
1. Purpose
This Privacy Policy is intended to comply with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter, GDPR), and Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter, LOPDGDD).
This policy also aims to inform people (hereinafter, users or data subjects) who visit our website (hereinafter, the website or site) about how we collect, process and protect the personal data they may provide to us through any means (forms, emails, telephone calls, contracts or other channels), as well as the purposes of processing, the legal bases that justify it and their data protection rights. It also serves as an expanded version of the information previously provided to data subjects in the information notices used when collecting their personal data.
2. Who Is the Controller of Your Personal Data?
- Entity: HERRAJES NESU, S.L.
- Tax identification number (CIF/NIF): B96693031
- Postal address: C/ Islas Canarias 13, CP 46988, Paterna (Valencia)
- Telephone: 961340064
- Email: info@herrajesnesu.com
- Corporate purpose: Manufacture and distribution of furniture fittings
- Website: https://www.herrajesnesu.com/
- Registration details: Registered in the Commercial Registry of Valencia, Volume 5915, Book 3221, Folio 13, Section 8, Sheet 56939
3. What Data Will We Process and How Do We Obtain Them?
To carry out our activities and provide our services, we need to process certain personal data relating to the people with whom we interact, in the following categories:
- Identification data: first and last names, national identity document or equivalent, image, and handwritten or electronic signature.
- Contact data: telephone number, email and postal address.
- Commercial data: terms, prices, management of communications and dealings with customers, suppliers or prospective customers.
- Economic and financial data: monitoring of income and expenditure, billing data, bank details, bank transfers and direct debits.
- CV data: educational background, qualifications, professional experience and other data included in an application.
- Technical and browsing data: IP address, technical identifiers, device type, browser used, time spent on the website, pages visited and approximate geolocation data derived from the IP address.
The categories of data processed for the different groups with which we have a relationship are detailed below:
3.1. Customers
We will process identification data (relating to contact persons and legal representatives), contact data, and commercial, economic and financial data.
These data may be processed only if customers provide them when purchasing goods or contracting services, when requesting pre-contractual measures or during the relationship between the parties.
Data may be collected in person, by telephone, by email or through the forms on our website, online chat, instant messaging, etc.
3.2. Suppliers
We will process identification, contact, commercial, economic and financial data.
These data will be processed when a pre-contractual or contractual relationship begins and throughout all stages of the commercial relationship.
Data will be collected in person, by telephone, by email, through website forms, online chat, instant messaging, etc.
3.3. People Requesting Information
Whether information is requested in person, by telephone or in writing (e.g. by email or through website forms), we will request identification, contact and commercial data.
3.4. Job Applicants
We will process CV, identification and contact data supplied by applicants themselves when submitting their application.
Data may be collected through documents delivered in person, emails or website forms, during recruitment interviews (in person or remotely), or through a partner to whom we have delegated certain functions.
3.5. Social Media Users
We are present on various social networks and may process identification, contact and commercial data, as well as other data users make available for viewing or sharing with other users of the social network, including CV data (e.g. LinkedIn). For further information, please consult our Social Media Policy.
3.6. Complainants
We will process identification and contact data, as well as personal information concerning the complainant or third parties that the complainant sends to us.
Data may be collected in person, by telephone, by email, through website forms, online chat, instant messaging, etc.
3.7. Visitors
We will process identification and contact data, the company for which the visitor works and the reason for the visit. These data are collected when visitors provide them while requesting access to our premises or when their contact person within our entity provides them to allow access.
3.8. Website Users
We will process technical data necessary for the website to function and, where users voluntarily request the installation of non-technical or non-essential cookies, browsing data.
For further information, please consult our Cookie Policy.
3.9. Further Information for Data Subjects
The information required by law will be made available to data subjects in the relevant information notices included in the different data collection channels, together with details of how to access the expanded information in this policy.
The personal data processing carried out by the entity is duly documented in its Record of Processing Activities, in accordance with Article 30 of the GDPR.
4. For What Purposes and on What Legal Basis Will Your Data Be Processed?
The purposes and legal bases on which we will process the personal data of the different groups with which we interact are detailed below:
4.1. Customers
- To fulfil and maintain the pre-contractual or contractual relationship. Article 6(1)(b) GDPR (performance of a contract).
- Invoicing and compliance with tax and other legal obligations to which we are subject. Article 6(1)(c) GDPR (legal obligation).
- Management of collections and payments. Article 6(1)(b) GDPR (performance of a contract).
- Internal administrative management. Article 6(1)(f) GDPR (legitimate interests).
- Legal defence or defence against claims. Article 6(1)(f) GDPR (legitimate interests).
- Satisfaction surveys and commercial analysis. Article 6(1)(f) GDPR (legitimate interests).
- Sending electronic commercial communications. Article 6(1)(a) GDPR (consent). Article 21.2 LSSI (existing customer).
4.2. Suppliers
- To fulfil and maintain the pre-contractual or contractual relationship. Article 6(1)(b) GDPR (performance of a contract).
- Administrative, accounting and financial management. Article 6(1)(b) GDPR (performance of a contract).
- Invoicing and compliance with tax and other legal obligations. Article 6(1)(c) GDPR (legal obligation).
- Management of payments and bank transfers. Article 6(1)(b) GDPR (performance of a contract).
- Assessment of supplier quality. Article 6(1)(f) GDPR (legitimate interests).
- Internal administrative management and organisational control. Article 6(1)(f) GDPR (legitimate interests).
- Legal defence and management of claims. Article 6(1)(f) GDPR (legitimate interests).
4.3. People Requesting Information
- To handle, record, manage and respond to enquiries or requests. Article 6(1)(f) GDPR (legitimate interests).
- To take, where appropriate, pre-contractual steps requested by the data subject. Article 6(1)(b) GDPR (pre-contractual measures).
- Internal administrative management arising from handling the enquiry. Article 6(1)(f) GDPR (legitimate interests).
- Legal defence against claims. Article 6(1)(f) GDPR (legitimate interests).
4.4. Job Applicants
- Management of participation in ongoing recruitment processes. Article 6(1)(b) GDPR (taking pre-contractual steps).
- Assessment of the applicant’s professional profile and suitability for the position offered. Article 6(1)(b) GDPR (pre-contractual measures).
- Conducting in-person or remote interviews and selection tests. Article 6(1)(b) GDPR (pre-contractual measures).
- Management and documentation of the recruitment process. Article 6(1)(b) GDPR (pre-contractual measures).
- Communications with the applicant. Article 6(1)(b) GDPR (pre-contractual measures).
- Legal defence against claims. Article 6(1)(f) GDPR (legitimate interests).
- Retention of job applications for future recruitment processes. Article 6(1)(a) GDPR (the data subject’s consent).
4.5. Social Media Users
- Management of our corporate presence on social media. Article 6(1)(f) GDPR (legitimate interests).
- Handling enquiries, requests or messages received through the social network. Article 6(1)(f) GDPR (legitimate interests).
- Interaction with users through comments, posts or replies. Article 6(1)(f) GDPR (legitimate interests).
- Analysis of statistics on user interactions with our profile. Article 6(1)(f) GDPR (legitimate interests).
- Sending direct commercial communications through the social network, where applicable. Article 6(1)(a) GDPR (the user’s consent).
Data processing carried out by the social network is governed by its own privacy policy.
For further information, please consult our Social Media Policy.
4.6. Complainants
- Management, handling and resolution of claims, complaints or incidents. Article 6(1)(f) GDPR (legitimate interests).
- Compliance with legal obligations regarding consumer assistance or applicable sector-specific regulations. Article 6(1)(c) GDPR (legal obligation).
- Conducting investigations relating to the complaint. Article 6(1)(f) GDPR (legitimate interests).
- Communications with the complainant. Article 6(1)(f) GDPR (legitimate interests).
- Establishment, exercise or defence of administrative or judicial claims. Article 6(1)(f) GDPR (legitimate interests).
- Where the processing of special categories of data is necessary, Article 9(2)(f) GDPR (establishment, exercise or defence of legal claims).
- Retention of supporting documentation for the periods required by law. Articles 6(1)(c) and 6(1)(f) GDPR, as applicable.
4.7. Visitors
- Management and control of access to our premises. Article 6(1)(f) GDPR (legitimate interests).
- Ensuring the safety and security of people, property and premises. Article 6(1)(f) GDPR (legitimate interests).
- Verification of visitors’ identity and recording their entry and exit. Article 6(1)(f) GDPR (legitimate interests).
- Compliance with occupational risk prevention rules. Article 6(1)(c) GDPR (legal obligation).
- Establishment, exercise or defence of claims. Article 6(1)(f) GDPR (legitimate interests).
4.8. Website Users
- Enabling browsing and the proper functioning of the website. Article 6(1)(f) GDPR (legitimate interests).
- Ensuring website security. Article 6(1)(f) GDPR (legitimate interests).
- Ensuring network security and preventing unauthorised access or cyberattacks. Article 6(1)(f) GDPR (legitimate interests).
- Analysis of website usage and performance through analytics cookies. Article 6(1)(a) GDPR (consent).
- Displaying personalised advertising or carrying out advertising profiling, where applicable. Article 6(1)(a) GDPR (consent).
For further information, please consult our Cookie Policy.
4.9. Further Information for Data Subjects
The information legally required in relation to data protection will be provided to data subjects in the relevant information notices included in the various data collection channels (forms, contracts, electronic communications, telephone announcements or other channels), in accordance with Articles 13 and 14 of the GDPR.
Where processing is based on consent, such consent will be requested in a freely given, specific, informed and unambiguous manner and may be withdrawn at any time.
If data subjects do not provide the necessary data or provide incomplete or inaccurate information, we may be unable to handle their request or formalise the relevant relationship.
Personal data will be processed exclusively for the purposes previously communicated and specified, without prejudice to any subsequent processing that is compatible in accordance with Article 6(4) of the GDPR.
The purposes and characteristics of each processing activity are duly identified in the Record of Processing Activities held by our entity.
5. Data Retention
The personal data provided will be retained for as long as a contractual, pre-contractual, commercial, employment or other relationship exists with the data subject and for as long as necessary to fulfil the purpose for which the data were collected. Thereafter, they will be retained for the periods legally required or permitted to address any liabilities arising from the processing, in accordance with the GDPR’s storage limitation principle.
Once the relationship has ended, data may remain duly blocked in accordance with Article 32 of the LOPDGDD where retention is necessary, either until the expiry of limitation periods for liabilities, solely for the purposes of claims or legal actions, or to comply with our legal obligations.
The periods indicated below may vary depending on the specific applicable regulations, the existence of legal or contractual liabilities, and administrative, judicial or police requirements:
| Data subjects | Activity / area | Legal basis | Retention period |
|---|---|---|---|
| Customers and suppliers | Accounting and commercial matters | Article 30 of the Spanish Commercial Code | 6 years from the last accounting entry. |
| Customers and suppliers | Tax matters | Articles 66 et seq. of Spanish Law 58/2003, General Tax Law | General period: 4 years. If losses occur during the financial year: 10 years. Invoices: 5 years. |
| Any individual | General | Article 1964.2 of the Spanish Civil Code | 5 years for personal actions without a specific limitation period. |
| Job applicants | Employment | AEPD Guide to Data Protection in Employment Relations | 1 year, unless express consent allows retention for a longer period. |
| Visitors | Access control to premises | AEPD Instruction 1/1996 | 1 month. |
| Website users | Use of cookies | AEPD Guide on the Use of Cookies | Maximum 24 months. |
| Customers, suppliers, visitors, job applicants and employees | Video surveillance | Article 22.3 LOPDGDD – personal data protection | 1 month. |
When data are no longer necessary, our entity will erase, anonymise or securely destroy them.
6. Profiling
As a general rule, our entity does not carry out profiling or make automated decisions that produce legal effects concerning data subjects or similarly significantly affect them.
If processing involving profiling or automated decision-making is undertaken in the future, data subjects will be informed in advance in accordance with Article 22 of the GDPR.
Where processing is based on legitimate interests, data subjects may exercise their right to object at any time.
Likewise, where processing is based on consent, that consent may be withdrawn at any time.
7. Recipients
As a general rule, personal data will not be disclosed to third parties unless disclosure is necessary to perform the contractual relationship, there is a legal obligation or another valid legal basis applies under Article 6 of the GDPR.
In particular, data may be disclosed or made available to the following recipients:
- Transport companies, courier services and logistics operators, where necessary to manage the shipment, tracking and delivery of orders. Only data necessary for delivery will be provided, such as the recipient’s first and last names, delivery address, telephone number and shipment identification details. The legal basis for this disclosure is performance of the sales contract, in accordance with Article 6(1)(b) of the GDPR.
- Banks, payment service providers and payment platforms, to process collections, payments and refunds and, where applicable, prevent fraudulent transactions.
- Public administrations and competent bodies, including the Spanish Tax Agency, Social Security or other authorities, where disclosure is necessary to comply with a legal obligation applicable to the controller.
- Judges, courts, the Public Prosecutor’s Office, law enforcement agencies or other competent authorities, where disclosure is necessary to comply with a legal obligation or for the establishment, exercise or defence of legal claims.
- Service providers acting on behalf of the controller as processors, including providers of technology, web hosting, IT maintenance, administrative management, customer service or logistics services. These providers may process data only on the controller’s instructions and after the relevant data processing agreement has been concluded, in accordance with Article 28 of the GDPR.
Personal data will not be disclosed to other third parties unless the data subject is informed in advance and a legal basis exists to justify that disclosure.
8. International Data Transfers
If it becomes necessary to transfer personal data internationally to countries outside the European Economic Area, such transfers will take place only where there is an adequacy decision by the European Commission or the appropriate safeguards under Articles 45 and 46 of the GDPR have been adopted.
In the absence of such safeguards, transfers will take place only where one of the derogations provided for in Article 49 of the GDPR applies.
9. Security Measures
Our entity has adopted appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of Regulation (EU) 2016/679.
These measures are intended to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
The measures implemented are determined taking into account the nature of the data processed, the purposes of processing, the state of the art, implementation costs and the risks to the rights and freedoms of data subjects.
Our entity also periodically reviews and updates these measures as part of its internal data protection compliance procedures.
10. Your Rights
You may exercise the following rights in relation to your personal data at any time:
Right of Access
To obtain confirmation of whether we are processing your personal data and, if so, to access those data and the information provided for in Article 15 of the GDPR.
Right to Rectification
To ask us to rectify your personal data where they are inaccurate and to complete them where they are incomplete.
Right to Object
To object to the processing of your data where it is based on legitimate interests or the public interest, on grounds relating to your particular situation, unless there are overriding compelling legitimate grounds.
Right to Erasure
To request the erasure of your data where any of the circumstances provided for in Article 17 of the GDPR apply, including where the data are no longer necessary for the purposes for which they were collected or where you withdraw your consent if that was the basis for processing.
Right to Restriction of Processing
You may ask to exercise this right where one or more of the following circumstances apply:
- You contest the accuracy of your data, for a period enabling the controller to verify their accuracy.
- Processing is unlawful and you oppose the erasure of your data and request the restriction of their use instead.
- The data are no longer needed for the purposes of processing, but you require them for the establishment, exercise or defence of legal claims.
- You have objected to processing under Article 21(1), pending verification of whether the controller’s legitimate grounds override yours.
Right to Data Portability
To receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and to transmit those data to another controller where processing is based on consent or a contract and is carried out by automated means.
Right Not to Be Subject to Automated Decision-Making
Not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or significantly affects you, except in the cases provided for in Article 22(2) of the GDPR.
How to Exercise Your Rights
To exercise any of your rights, you must write to HERRAJES NESU, S.L., either by post to C/ Islas Canarias 13, CP 46988, Paterna (Valencia), or by email to info@herrajesnesu.com, specifying the rights you wish to exercise.
If you act on behalf of another person, you must provide evidence of your authority to represent them. If there are reasonable doubts about the identity of the person making the request, we may ask for the additional information necessary to confirm their identity.
The request will be handled within a maximum of one month from receipt, which may be extended in complex cases in accordance with Article 12 of the GDPR. Exercising your rights is free of charge, unless requests are manifestly unfounded or excessive.
You have the right to lodge a complaint with the Spanish Data Protection Agency at C/ Jorge Juan, 6, 28001 Madrid, or at https://www.aepd.es/.
If you wish to make a suggestion or enquiry regarding the processing of your personal data, you may contact our data protection consultants:
BUSINESS ADAPTER, S.L.
Ronda Guglielmo Marconi, 11, 26, (Parque Tecnológico) 46980 Paterna (Valencia).
Data Subject Enquiry Form
11. Commitment to Personal Data Protection
Our entity expresses its firm commitment to compliance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD), ensuring that personal data are processed in accordance with the principles of lawfulness, fairness, transparency, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability.
This commitment applies to all employees and collaborators involved in processing personal data, as well as third parties acting on behalf of our entity.
Governance and Compliance
Our entity keeps its Record of Processing Activities up to date in accordance with Article 30 of the GDPR.
Where processing is likely to result in a high risk to the rights and freedoms of data subjects, the corresponding Data Protection Impact Assessment is carried out in accordance with Article 35 of the GDPR.
Security and Incident Management
Appropriate technical and organisational measures are adopted to ensure a level of security appropriate to the risk. In the event of a personal data breach, the internal incident management protocol will be activated in accordance with Articles 33 and 34 of the GDPR.
Rights of Data Subjects
Our entity guarantees diligent handling of requests to exercise the rights recognised by data protection legislation.
Digital Rights in the Workplace
In the workplace, the digital rights recognised in the LOPDGDD are respected, ensuring a balance between the employer’s management powers and employees’ rights to privacy, digital disconnection and data protection.
Training and Supervision
Our entity promotes training in data protection and digital rights and has specialised external advice to ensure regulatory compliance.
12. Updates to this Policy
This Policy may be updated to reflect changes in legislation or case law. If substantial changes affect data subjects, appropriate steps will be taken to communicate them.
Last updated: 22 September 2026.