In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), and Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE), users of this website are informed of the following:
Data Controller:
• Company Name: Heart Of Lofoten Andrea Selva
• Tax Identification Number (CIF): 928687708MVA
• Telephone: +47 46227853
• Email: heartoflofoten@gmail.com
• Website: heartoflofoten.org
PURPOSE OF DATA PROCESSING
The personal data collected through the website will be used to:
• Manage user registration and access to restricted areas.
• Respond to information or contact requests.
• Formalize the contracting of products or services.
• Send newsletters and promotions, if consent has been given.
• Manage recruitment processes in the event of receiving a CV.
LEGAL BASIS FOR PROCESSING
Data processing is based on:
• The user’s consent.
• The performance of a contract.
• Compliance with legal obligations.
• The legitimate interest of the controller.
DATA RETENTION
Personal data will be retained as long as the commercial relationship is maintained or until the user requests its deletion, and for the periods required by applicable law.
DATA DISCLOSURE
Data will not be disclosed to third parties except under legal obligation or when necessary for the provision of the service. In such cases, the appropriate data processing agreements will be signed.
USER RIGHTS
Users may exercise the following rights:
• Access to their personal data.
• Rectification of inaccurate or incomplete data.
• Erasure (“right to be forgotten”).
• Restriction of processing.
• Data portability.
• Objection to processing.
• Withdrawal of consent.
To exercise these rights, a written request must be submitted to the controller’s address, accompanied by a copy of the user’s ID card or equivalent document.
SECURITY MEASURES
The controller will apply appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR.
DATA ON MINORS
No data will be collected from minors under 14 years of age without the prior consent of their parents or legal guardians. If it is detected that data has been collected without authorization, it will be immediately deleted.
CHANGES TO THE PRIVACY POLICY
The controller reserves the right to modify this policy to adapt it to legislative or jurisprudential developments. In such cases, changes will be announced on this page with reasonable notice before taking effect.
APPLICABLE LAW AND JURISDICTION
This policy is governed by Spanish and European data protection legislation. Any dispute will be resolved before the courts of the controller’s registered address.