Privacy Policy Information

Table of Contents

1.- Objective of the Privacy Policy

The purpose of this “Privacy and Data Protection Policy” is to outline the conditions governing the collection and processing of personal data by INCOSPEL S.L. The company makes every effort to safeguard the fundamental rights, reputation, and freedoms of the individuals whose personal data is processed, in compliance with applicable regulations and laws governing personal data protection within the European Union and Spain—specifically those detailed in the “Processing Activities” section of this Privacy Policy.

Accordingly, this Privacy and Data Protection Policy informs users of the website https://incospel.com of all relevant details regarding how these processes are carried out, the purposes involved, which other entities may have access to their data, and the rights available to users.

2.- Definitions

Personal data“: Any information relating to an identified or identifiable natural person (“the Website user”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.

Processing“: any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction. “Restriction of processing”: the marking of stored personal data with the aim of limiting their processing in the future.

Profiling“: any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

Pseudonymisation“: the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

Filing system“: any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis.

Controller“: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

Processor“: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

Recipient“: a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.

Third party“: a natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and persons who, under the direct authority of the controller or the processor, are authorised to process personal data.

Consent of the data subject“: any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

Personal data breach“: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;

Genetic data“: personal data relating to the inherited or acquired genetic characteristics of a natural person which provide unique information about the physiology or the health of that person, obtained in particular from the analysis of a biological sample from that person.

Biometric data“: personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that person, such as facial images or dactyloscopic data.

Data concerning health“: personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status.

Main establishment“: (a) as regards a controller with establishments in more than one Member State, the place of its central administration in the Union, unless the decisions on the purposes and means of the processing are taken in another establishment of the controller in the Union and the latter establishment has the power to have such decisions implemented, in which case the establishment having taken such decisions is to be considered to be the main establishment; (b) as regards a processor with establishments in more than one Member State, the place of its central administration in the Union or, if it has no such central administration, the establishment of the processor in the Union where the main processing activities take place in the context of the activities of an establishment of the processor to the extent that the processor is subject to specific obligations under this Regulation.

Representative“: a natural or legal person established in the Union who, having been designated in writing by the controller or the processor pursuant to Article 27 of the GDPR, represents the controller or processor with regard to their respective obligations under this Regulation.

Undertaking“: a natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity.

Supervisory authority“: the independent public authority established by a Member State pursuant to Article 51 of the GDPR. In the case of Spain, it is the Spanish Data Protection Agency.

Cross-border processing“: (a) processing of personal data which takes place in the context of the activities of establishments in more than one Member State of a controller or processor in the Union, where the controller or processor is established in more than one Member State, or (b) processing of personal data which takes place in the context of the activities of a single establishment of a controller or processor in the Union but which substantially affects or is likely to substantially affect data subjects in more than one Member State.

Information society service“: any information society service, that is to say, any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient of services.

3.- Identity of the Data Controller

The Data Controller is the natural or legal person, public or private entity, or administrative body that, alone or jointly with others, determines the purposes and means of personal data processing; or where the purposes and means of processing are determined by European Union law or Spanish Member State law.

Regarding the matters set out in this Data Protection Policy, the identity and contact details of the Data Controller are:

  • INCOSPEL S.L.
  • CIF B60532082
  • Ctra-A1239 Albalate de Cinca – Binéfar Km 4.6 22534 Albalate de Cinca (Huesca), España
  •  info@incospel.com
  • Tels: 974 46 93 94 / 610 243 204

4.- Applicable Laws and Regulations

This Privacy and Data Protection Policy has been developed based on the following data protection laws and regulations:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. Hereinafter, GDPR.
  • Organic Law 3/2018 of 5 December on the Protection of Personal Data and the Guarantee of Digital Rights. Hereinafter, LOPD/GDD.
  • Law 34/2002 of 11 July on Information Society Services and Electronic Commerce. Hereinafter, LSSICE.

5.- Principles Applicable to the Processing of Personal Data

Personal data collected and processed through this website will be handled in accordance with the following principles:

  • Principle of lawfulness, fairness, and transparency: All processing of personal data carried out via this website shall be lawful and fair, ensuring it is entirely clear to the user when their personal data is being collected, used, consulted, or processed. Information regarding the processing activities will be provided in advance, be easily accessible and understandable, and use clear, simple language.
  • Principle of purpose limitation: All data shall be collected for specified, explicit, and legitimate purposes and shall not be further processed in a manner incompatible with the purposes for which they were collected.
  • Principle of data minimization: The data collected shall be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.
  • Principle of accuracy: Data shall be accurate and, where necessary, kept up to date; all reasonable steps must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay.
  • Principle of storage limitation: Data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
  • Storage limitation principle: Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes of the processing of personal data.
  • Principle of integrity and confidentiality: Data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss or damage, using appropriate technical or organizational measures.
  • Principle of accountability: The entity owning the Website shall be responsible for compliance with the principles set out in this section and shall be able to demonstrate such compliance.

6.- Data Processing Activities

The data processing activities carried out via the website are detailed below, specifying each of the following sections:

  • Activity: Name of the data processing activity
  • Purposes: Each of the uses and processing operations applied to the collected data
  • Legal basis: The legal grounds legitimizing the data processing
  • Processed data: Types of data processed
  • Source: Where the data is obtained
  • Retention: Period during which the data is retained
  • Recipients: Third parties or entities to whom the data is disclosed
  • International transfers: Cross-border transfers of data outside the European Union

6.1- Main Processing Activities

These are data processing activities whose purposes are necessary and essential for the provision of the services.

Website Management (www.incospel.com)

Legal bases

(Art. 6.1.a GDPR) Consent of the data subject; (Art. 6.1.f GDPR) Legitimate interest of the Data Controller or third parties; Organic Law on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) 3/2018; Regulation (EU) 2016/679 on the protection of personal data.

Purposes

Data requested via the contact form, sent by email, or provided via the telephone number published on our website will be used to respond to your inquiry and send you information about our organization and services. The consequence of not providing this data is the inability to contact you and provide a response to your request. You have the right to receive a response to any question, inquiry, or clarification arising from this form or from the other contact channels published on the corporate website, by calling us, sending us an email, or visiting our facilities.

Data categories and groups: Website users (Identifying data) Data source: The data subject themselves or their legal representative Recipient category: We do not transfer your data to anyone, but we may allow its processing by third parties solely for technical, legal, and/or service provision reasons.

Data categories and data subjects

Web users (Identifying data)

Category of recipients

We do not transfer your data to anyone, but we may allow its processing by third parties solely for technical, legal, and/or service provision reasons.

International transfer

None planned.

Retention period

Other. We keep your data only for the time necessary to handle the request for information or if there is a legal obligation or legitimate interest regarding it.

Security measures

The security measures implemented correspond to those described in the documents comprising the organization’s Data Protection and Information Security Policy.

7.- Necessary and Up-to-Date Information

All fields marked with an asterisk (*) on the Website forms are mandatory; consequently, failure to complete any of them may make it impossible to provide the requested services or information.

You must provide truthful information. To ensure the information provided remains up-to-date and error-free, you must notify the Data Controller as soon as possible of any changes or corrections to your personal data by sending an email to: info@incospel.com.

Furthermore, by clicking the “I Accept” button (or equivalent) included in said forms, you declare that the information and data you have provided are accurate and truthful, and that you understand and accept this Privacy Policy.

8.- Data Concerning Minors

In compliance with Article 8 of the GDPR and Article 7 of the LOPD/GDD, only individuals over the age of 14 may provide consent for the lawful processing of their personal data by INCOSPEL S.L.

Consequently, minors under the age of 14 may not use the services available through the Website without the prior authorization of their parents, guardians, or legal representatives, who shall be solely responsible for all actions performed through the Website by the minors in their care, including the completion of online forms with said minors’ personal data and the checking, where applicable, of the accompanying checkboxes.

9.- Technical and Organizational Security Measures

The Data Controller adopts the necessary organizational and technical measures to guarantee the security and privacy of your data and to prevent their alteration, loss, or unauthorized processing or access, taking into account the state of the art, the nature of the stored data, and the risks to which they are exposed.

The following measures are particularly noteworthy:

  • Ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services.
  • Restore availability and access to personal data in a timely manner in the event of a physical or technical incident.
  • Regularly verify, assess, and evaluate the effectiveness of the technical and organizational measures implemented to ensurethe security of processing.
  • Pseudonymize and encrypt personal data, where such data is sensitive.

Furthermore, the Data Controller has decided to manage information systems in accordance with the following principles:

  • Principle of regulatory compliance: All information systems shall comply with applicable legal, regulatory, and sectoral standards regarding information security, particularly those concerning the protection of personal data and the security of systems, data, communications, and electronic services.
  • Principle of risk management: Risks shall be minimized to acceptable levels, seeking a balance between security controls and the nature of the information. Security objectives must be established and reviewed, and must be consistent with information security aspects.
  • Principle of awareness and training: Training programs, sensitization initiatives, and awareness campaigns regarding information security will be implemented for all users with access to information.
  • Principle of proportionality: The implementation of controls to mitigate asset security risks will be carried out by striking a balance between security measures and the nature of the information and associated risks.
  • Principle of responsibility: All members of the Data Controller organization shall be responsible for their conduct regarding information security, complying with established standards and controls.
  • Principle of continuous improvement: The effectiveness of security controls implemented within the organization will be periodically reviewed to enhance the ability to adapt to the constantly evolving risk landscape and technological environment.

10.- Rights of Data Subjects

Current data protection regulations grant the user a series of rights regarding the use of their data.

Each and every one of these rights is personal and non-transferable; that is, they may only be exercised by the data subject, subject to verification of their identity.

The rights of Website users are detailed below:

  • Right of access: This is the right of the Website user to obtain confirmation as to whether or not the Data Controller is processing their personal data and, if so, to obtain information regarding the specific personal data concerned and the processing activities carried out or being carried out by the Data Controller, as well as—among other things—information available regarding the source of said data and the recipients of any communications made or planned regarding them.
  • Right to rectification: This is the right of the Website user to have their personal data modified if it is inaccurate or—taking into account the purposes of the processing—incomplete.
  • Right to erasure: Commonly known as the “right to be forgotten,” this is the right of the Website user—provided that applicable law does not state otherwise—to have their personal data erased when: the data are no longer necessary for the purposes for which they were collected or processed; the User has withdrawn their consent to the processing and there is no other legal basis for it; the User objects to the processing and there are no overriding legitimate grounds for continuing it; the personal data have been processed unlawfully; or the personal data were obtained through a direct offer of information society services to a minor under the age of 14. In addition to erasing the data, the Data Controller—taking into account available technology and the cost of implementation—shall take reasonable steps to inform other potential controllers processing the personal data of the data subject’s request to erase any links to such personal data.
  • Right to restriction of processing: This is the Website User’s right to restrict the processing of their personal data. The website User has the right to obtain restriction of processing when they contest the accuracy of their personal data; the processing is unlawful; the Data Controller no longer needs the personal data, but the User requires it to make claims; and when the Website User has objected to the processing.
  • Right to data portability: In cases where processing is carried out by automated means, the Website User shall have the right to receive their personal data from the Data Controller in a structured, commonly used, and machine-readable format, and to transmit said data to another data controller. Provided it is technically feasible, the Data Controller shall transmit the data directly to that other Data Controller.
  • Right to object: This is the User’s right to prevent the processing of their personal data or to have the Data Controller cease such processing.
  • Right not to be subject to automated decision-making and/or profiling: The Website User’s right not to be subject to an individualized decision based solely on the automated processing of their personal data, including profiling, unless otherwise provided by applicable law.
  • Right to withdraw consent: The Website User’s right to withdraw, at any time, the consent given for the processing of their data.

Website users may exercise any of the aforementioned rights by contacting the Data Controller—subject to user identification—using the following contact details:

Controller: INCOSPEL S.L.
Address: Ctra-A1239 Albalate de Cinca – Binéfar, Km 4.6
22534, Albalate de Cinca (Huesca), España
Telephone: 974 46 93 94 / 610 243 204
Email: info@incospel.com
Website: https://incospel.com

11.- Right to Lodge a Complaint with the Supervisory Authority

The user is informed of their right to lodge a complaint with the Spanish Data Protection Agency if they consider that a breach of data protection legislation has occurred regarding the processing of their personal data.

Contact information for the supervisory authority:

Spanish Data Protection Agency
(Agencia Española de Protección de Datos)
Email: info@aepd.es
Telephone: 900 293 183
Website: https://www.aepd.es
Address: C/ Jorge Juan, 6. 28001, Madrid (Madrid), Spain

12.- Acceptance of and Changes to the Privacy Policy

Website users must read and agree to the data protection conditions contained in this Privacy Policy, and must consent to the processing of their personal data so that the Data Controller may proceed with such processing in the manner, within the timeframes, and for the purposes indicated.

The Data Controller reserves the right to modify this Privacy Policy at its own discretion or in response to changes in legislation, case law, or guidelines issued by the Spanish Data Protection Agency. Any changes or updates to this Privacy Policy affecting purposes, data retention periods, data disclosures to third parties, international data transfers, or any rights of the Website user will be explicitly communicated to the user.

Version dated July 13, 2026

Scroll to Top