Privacy Policy
This Privacy Policy has been developed taking into account the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter, the GDPR), as well as Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter, LOPDGDD) and other applicable regulations.
Esta Política de Privacidad tiene por objeto poner en conocimiento a las personas físicas que faciliten sus datos personales, y/o los de la persona a la que representa, respecto de los cuales se está recabando información, los aspectos específicos relativos al tratamiento de sus datos, las finalidades de los tratamientos, los datos de contacto para ejercer los derechos que le asisten, los plazos de conservación de la información y las medidas de seguridad, entre otras cosas.
Who is the Data Controller?
In terms of data protection, GANNET PARTNERS SGEIC SA must be considered the Data Controller regarding personal data processing carried out by this entity.
The contact details of the Data Controller are set out below:
- Identity of the Controller: GANNET PARTNERS SGEIC SA.
- Physical Address: C/ Orense 34, Edificio Norte, Segunda Planta, 28020, Madrid, Spain.
- Email: participes@gannetpartners.com
Who is the Data Protection Officer?
This entity includes a Data Protection Officer, who can be contacted at the following email address: participes@gannetpartners.com, or by writing to this entity's registered address for the attention of the "Data Protection Officer".
What Personal Data Do We Process?
All information collected by GANNET PARTNERS SGEIC SA will be processed fairly, lawfully, and transparently.
Furthermore, the data requested for each processing activity carried out will consist strictly of what is essential to achieve the intended purpose informed in each case.
Thus, the data collected will be adequate, relevant, and not excessive in relation to the purposes for which they are processed in each case. Therefore, your personal data will be collected for specified, explicit, and legitimate purposes, and will not be further processed in a manner incompatible with those purposes. Additionally, it will be updated whenever necessary.
Generally, within the framework of the different processing activities carried out in the organization, the following types of data are collected:
- Identification data.
- Academic, professional, and training data.
- Commercial information.
- Transactions of goods and services.
- Economic and financial data.
Data belonging to minors may be processed provided it is supplied by legal representatives, guardians, or parents, and in connection with the contracted product or service.
Where Do Personal Data Come From?
As a general rule, personal data are always collected directly from the data subject; however, in certain exceptional cases, data may be collected through third parties, entities, or services other than the data subject.
In this sense, this point will be communicated to the data subject through the informative clauses included in the different collection channels within a reasonable timeframe or in the first communication made to the data subject.
For What Purpose and Specific Cases Do We Process Personal Data?
In general terms, personal data are processed for the following purposes:
- User Registration Management: The information provided in the registration form will be processed to manage users on our platforms.
- Contracting Products and Services: To manage the contracting and execution of requested products and services; payment management for transactions; contacting you regarding any incident related to your service or product; and informing you about the availability of requested products.
- Compliance with Regulatory Obligations: For the prevention of money laundering, terrorist financing, or tax fraud, among others. For instance, requesting information to verify the origin of funds in your accounts.
- Newsletter: Sending information via the provided contact channels regarding news, updates, products, and services related to us or our sector.
- Contact: Responding to information requests received regarding the products and services offered, as well as answering any other type of inquiry sent by users.
- Surveys: Conducting customer service and/or product quality surveys. To improve these services, we will process your personal data to obtain feedback on our products or the support provided by our customer service team.
- Clients: Carrying out sales management of goods and services, invoicing, accounting, collections, non-payments, quotes, budgets, contracts, customer service, contact, and commercial relations.
- Potential Clients: Following up on sales opportunities for the organization.
- Suppliers: Managing purchases, accounting, payments, delivery notes, purchase orders, contact, and commercial relations.
- Video Surveillance: Controlling access to the organization's facilities and ensuring the security of company assets and personnel.
- Candidates: Conducting internal candidate selection processes, both current and future.
- Whistleblowing Channel: Processing personal data to manage the whistleblowing channel (or internal reporting system), investigating facts, proposing corrective measures, preventing regulatory non-compliance, rectifying detected issues, and contributing to operational efficiency through continuous improvement of internal processes for managing and controlling illegal conduct or behavior contrary to the organization's ethical culture.
No profiling or automated decision-making will be performed with the collected personal data.
However, all explicit purposes for which each processing activity is carried out are set out in the informative clauses incorporated into each data collection channel (web forms, paper forms, audio recordings/announcements, posters, informative notices, invoices, contracts, and other documents containing personal data).
What Is the Lawful Basis for Data Processing?
As a general rule, prior to processing personal data, GANNET PARTNERS SGEIC SA informs of the legal basis establishing the lawfulness of the processing in question.
However, the organization may process personal information based on:
- Compliance with Legal and Regulatory Obligations: Including, but not limited to, the General Law for the Protection of Consumers and Users, General Tax Law, Corporate Income Tax Law, Account Auditing Law, Value Added Tax Law, Civil Code, Commercial Code, as well as the existence of any specific law or rule authorizing or requiring data processing, which will be stated in the corresponding informative clause. The whistleblowing channel (or internal reporting system) is legitimized by Law 2/2023, of February 20, regulating the protection of persons who report normative infringements and the fight against corruption.
- Performance of a Contract: For the preliminary management of a contracted service or product, execution of a contract, or subsequent procedures arising from such operations.
- Consent: Processing based on obtaining express and unambiguous consent from the data subject via informed consent clauses across different collection systems. Consent is granted through a statement or clear affirmative action, such as ticking a box provided for that purpose, signing the relevant document, or sending data via specified contact methods. Additionally, we inform you that we will only use personal information pursuant to this Privacy Policy and, generally, will request your consent for uses other than those initially granted.
- Legitimate Interest: Data processing based on the controller's legitimate interest will primarily be established for sending commercial communications or events regarding products or services similar to those contracted. According to Article 21.2 of the Information Society Services Act (LSSI), this processing will only be valid when, as a client, you have not expressly objected at the time of collection or in any subsequent communications.
How Long Do We Retain Personal Data?
Personal data are processed for the time necessary to fulfill the purpose for which they were collected, for as long as the service provision or contractual/employment relationship continues, provided there is mutual interest, and/or for the period specified by applicable regulations.
Once the established time criteria are met, data will be erased. Eradication will involve blocking data, keeping them available solely to Public Administrations, Judges, and Courts to fulfill potential liabilities arising from processing, during their statutory limitation period. Upon expiration of this period, the information will be destroyed.
Regarding data processed under the whistleblowing channel: Data will be retained as long as necessary to fulfill the purpose for which they were collected. In any case, three months after data entry, they will be deleted from the reporting system, unless retention is required to demonstrate the functioning of the crime prevention model of the legal entity. After this period, data may continue to be processed by the body responsible for investigating the reported facts and will no longer be stored within the whistleblowing channel itself.
Who Do We Share Personal Data With?
To fulfill the purposes described above, personal data may be shared with entities including, but not limited to:
- Supervisory Authority for Money Laundering Prevention (SEPBLAC).
- Mercantile Registry.
- General Council of the Judiciary.
- Bank of Spain.
- National Securities Market Commission (CNMV).
- Tax Agency and General Social Security Treasury.
- Public authorities, regulatory bodies, and supervisory entities, such as central banks and other financial sector supervisors.
- Banking entities.
- Tax authorities upon request to report on assets or other personal data.
- Judicial and investigative authorities, such as Law Enforcement Agencies, Public Prosecutor's Office, courts and tribunals, mediation and arbitration bodies, following an explicit judicial request.
- Administration with competencies in money laundering and terrorist financing.
- And any other entity required in compliance with our legal duties.
Are International Data Transfers Conducted?
We inform you that, as a general rule, no international data transfers are conducted outside the European Economic Area (EEA). In the event of a data transfer outside the EEA, THE ORGANIZATION will ensure appropriate safeguards under the requirements established by the General Data Protection Regulation.
What Rights Can You Exercise?
Under European regulations, your rights consist of:
- Right of Access: The right to request information from the data controller on whether your personal data are being processed.
- Right to Rectification: The right allowing the data subject to request the modification of inaccurate or incomplete data.
- Right to Object: The right to object to the processing of your personal data or demand its cessation.
- Right regarding Automated Individual Decisions: The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you.
- Derecho de Limitación, derecho a suspender el tratamiento de los datos personales del usuario en determinados supuestos
- Right to Erasure (Right to be Forgotten): The right to request the deletion of personal data.
- Right to Data Portability: The right to request the data controller to provide personal data in a structured and clear format to another controller.
- Right to Lodge a Complaint: The right to file a complaint with the competent supervisory authority if you consider that the processing does not comply with current regulations.
How to Exercise Your Rights?
Applicants may exercise their rights by emailing: participes@gannetpartners.com.
Documentation proving the applicant's identity (copy of the front of the National Identity Document or equivalent) may be required. In any case, you may request protection from the Spanish Data Protection Agency (AEPD) through its website.
GANNET PARTNERS SGEIC SA will handle your request as promptly as possible, taking into account statutory deadlines under data protection regulations.
What Are the Consequences of Not Providing Information?
Data requested in fields marked with an asterisk (*) or provided in documents or media where notice is given are strictly necessary for the purpose collected, for providing optimal service, or due to a legal obligation or contractual requirement. Providing data in remaining fields is voluntary.
Failure to provide all requested data means we cannot guarantee that information and services will fully meet your needs.
Consequently, if required data are omitted, incorrect, or incomplete, your request cannot be processed, making it impossible to provide requested information or execute services.
Similarly, the user guarantees that information provided across any forms is true, accurate, and corresponds to their own data.
Our platform services are not intended for minors; registration is restricted to individuals over 18. Potential liabilities resulting from platform use by minors will be the responsibility of parents or guardians.
To prevent minor usage, we verify age during registration by asking for date of birth.
What Security Measures Do We Have in Place?
The security measures adopted by GANNET PARTNERS SGEIC SA comply with Article 32 of the GDPR.
Taking into account state-of-the-art technology, application costs, nature, scope, context, and purposes of processing, as well as varying risks to rights and freedoms of natural persons, GANNET PARTNERS SGEIC SA has established technical and organizational measures to ensure a level of security appropriate to the risk.
In all cases, GANNET PARTNERS SGEIC SA has implemented sufficient mechanisms to:
- Ensure ongoing confidentiality, integrity, availability, and resilience of processing systems and services.
- Restore availability and access to personal data promptly in the event of a physical or technical incident.
- Regularly test, assess, and evaluate the effectiveness of technical and organizational measures for ensuring processing security.
Changes to This Privacy Policy
This Privacy Policy may occasionally be revised to incorporate updates in applicable legislation, changes in data collection and usage procedures, new services, or the exclusion of existing ones. Changes will take effect upon publication on the website; please review this policy regularly to stay informed.

