1) Introduction and Controller.
The right to privacy, and specifically the right to the protection of personal data, is one of the values of ISDIN, S.A. (hereinafter, “ISDIN”), which is set out in our Code of Ethics.
The purpose of this policy is to explain how ISDIN will process, as controller, personal data that may be collected through the various forms and activities that may be found on the ISDIN website: https://www.isdin.com/ and other forms for collecting personal data, where applicable. Your personal data will be processed confidentially and only for the purposes explained below in this policy.
2) Commitment to privacy.
ISDIN is fully committed to complying with applicable data protection regulations, being this is a priority goal for ISDIN.
ISDIN has therefore determined to implement the following principles; being privacy the basis on which all processing is configured:
3) Purposes and lawful bases for processing. The main purposes for the processing of your personal data and applicable lawful bases are:
The lawful basis for this processing will be your express consent derived from the clear affirmative action of participating in the initiative.
We will also send you by email your personalized beauty routine or products selected on the basis of the needs detected. These communications are essential for the proper use, exploitation and correct functionality of the platform.
The lawful basis for this processing will be your express consent derived from the clear affirmative action of participating in the activities.
In addition and as further explained below, if you give your express consent, we will send you personalized commercial communications via our newsletter according to your profile based on the information you provide during the activities in which you participate, as well as according to your browsing habits and preferences with respect to ISDIN products (in accordance with our Cookie Policy).
The lawful basis for this processing is the performance of the (pre)contractual relationship with you or, where applicable (e.g. in very early stages of our relationship), our legitimate interest in developing a commercial relationship with you.
The lawful basis for this processing is the legitimate interest of the controller in the best performance of our business activity and provision of products and services, or consent, as appropriate.
The lawful basis for this processing is your consent; which you may withdraw at any time, by means of the link or button for this purpose in each of the communications, or by communicating your wish to withdraw your consent via the email indicated below in the section on “Exercise of rights and complaints”.
The lawful basis for this processing is your consent derived from the clear affirmative action implied by the use of the contact form and voluntarily providing certain information (which may include special categories of personal data) for such purposes.
The lawful basis for this processing is compliance with the legal obligations established in the legislation in force on pharmacovigilance. Likewise, in relation to the special categories, and in particular, the health data that the processing may entail, the circumstances that enable the processing thereof relates to the public interest in the area of public health, as well as those aimed at ensuring high standards of quality and safety of health care and of medicinal products and medical devices.
The lawful basis for this processing is the consent of the data subject derived from the clear affirmative action involved in sending his or her curriculum vitae.
Where we process your personal data in fulfillment of our own legitimate interests, we carry out a balancing test (available upon request) to verify that said legitimate interests are not overridden by your interests or rights.
4) Sharing of data.
Your data may be disclosed / made available to:
5) International transfers of personal data.
Some of the data recipients mentioned in section above may be located in countries that do not have an adequate level of protection (such as the United States, China or LATAM countries including Mexico and Colombia). For example, it may be necessary to provide such data to international service providers, either as necessary to provide you with the requested service or in order to provide you with the highest quality standards.
In any event, ISDIN will ensure that appropriate safeguards are put in place in accordance with applicable legal requirements to ensure that your data is adequately protected, such as:
6) Duration of the processing and retention period.
ISDIN is committed to processing personal data for as long as it is really useful to us and we can provide you with a quality service through its use. We will therefore make all appropriate and reasonable efforts to minimise the processing and retention period of personal data. In this regard, on each data collection form we will inform you of the expected period of processing and/or retention of your personal data. In relation to the processing activities described under this policy, ISDIN will retain your personal data in accordance with the following criteria:
In any case, and even if you request us to delete your data, we may retain and keep them, under appropriate blocking, for the period necessary to comply with our legal obligations and to make them available to the Authorities with competence in the different applicable matters.
7) Exercise of rights and complaints.
As a result of ISDIN’s processing of your personal data, you have a number of rights under applicable law. Below is a summary explanation of each right, in order to make it easier for you to exercise them:
Insofar as we process your data on the basis of your consent, you may also withdraw your consent at any time.
You may exercise your rights by contacting ISDIN at the e-mail address privacy@isdin.com with proper identification.
Please note that you can always, in any case, lodge a complaint with the competent data protection authority if you believe that we have not processed your data lawfully or that we have not complied with your requests or rights.
8) Confidentiality and Security in data processing.
Your personal data is very important to us, and we undertake to process the same with the utmost confidentiality and discretion and to implement all security measures that we deem appropriate and reasonable. In this regard, ISDIN declares and guarantees that it has established all the technical means at its disposal to prevent the loss, misuse, alteration, unauthorized access and theft of the data provided by users.
9) Social networking.
Social Networks are part of the daily lives of many Internet users, and we have created different ISDIN profiles for them.
All users have the opportunity to join ISDIN’s pages or groups on different social networks.
However, you should bear in mind that, unless we request your data directly (for example, through marketing actions, competitions, promotions, or any other valid way), your data will belong to the corresponding Social Network, so we recommend that you carefully read its terms of use and privacy policies, as well as make sure to configure your preferences regarding the processing of data.
10) Contact ISDIN.
If you have any queries or concerns about the processing of your personal data please contact us through: