Privacy policy and data protect
Bustper, S.A. is committed to exercising due diligence and ensuring full compliance with applicable data protection legislation. As part of this commitment, the company has implemented a Data Protection Channel (https://www.dataprotect-line.com/bustper), which brings together the essential elements of its data protection framework. This system is managed, supervised and certified by BONET Consulting, a specialist firm and recognised leader in Regulatory Compliance and Data Protection.
The following information sets out Bustper’s Privacy Policy and the processing of personal data in accordance with Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation – GDPR) and Article 11 of Spanish Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD).
1. Data Controller
Data Controller: Bustper
Address: Carretera Ulldecona km 14.2 · 43560 · La Sénia · Tarragona · Spain
Email: info@bustper.es
Telephone: +34 977 570 509
2. Purpose of Processing
Bustper processes the personal data provided by data subjects for the following purposes:
- To manage visits, meetings and appointments at our premises, as well as the provision and administration of the contracted products and services.
- To process and respond to requests, enquiries, suggestions or complaints relating to our professional services, including forwarding them to the relevant department where necessary to ensure an appropriate response and compliance with the applicable legal framework.
- To manage and process communications submitted through the Internal Information System, in accordance with Spanish Law 2/2023 of 20 February, on the protection of persons reporting regulatory breaches and combating corruption.
- To manage reports, communications or complaints relating to the prevention of and response to harassment or violence affecting specially protected groups, particularly transgender persons, LGTBI individuals and minors. Personal data will be processed in a manner that guarantees confidentiality, integrity and proportionality, in compliance with the applicable legislation. The legal basis for this processing is compliance with a legal obligation pursuant to Article 6(1)(c) of the GDPR.
- To promote equality, prevent discrimination, harassment and psychosocial risks in the workplace. Personal data may be processed to ensure equal treatment and equal opportunities, prevent discrimination based on sex, sexual orientation, gender identity or expression, age, disability, race, religion, beliefs or any other personal or social circumstance. Data may also be processed to prevent, detect and manage workplace harassment, sexual harassment, gender-based harassment and other psychosocial risks, as well as to comply with internal protocols and legal obligations relating to occupational health and safety and equality. The legal basis for this processing is compliance with a legal obligation (Article 6(1)(c) GDPR) and Bustper’s legitimate interests (Article 6(1)(f) GDPR) in promoting employee wellbeing, a positive working environment and a culture of equality beyond the minimum legal requirements.
3. Data Retention
- Contracted products and services
Personal data contained in contracts, quotations, service proposals, and any information relating to other individuals whose involvement is necessary for the provision of the contracted services, will be retained for as long as the contractual relationship remains in force.
Once the contractual relationship has ended, the personal data will be retained where necessary to comply with legal obligations or where liabilities may arise involving Bustper, in accordance with the applicable legislation. The data will be stored in a manner that allows the identification of data subjects and the exercise of their rights, while ensuring appropriate technical, organisational and legal measures to safeguard their confidentiality and integrity.
- Curriculum Vitae (CV)
As a general rule, Bustper retains applicants’ CVs for a maximum period of one year. Once this period has expired, the CV will be securely deleted in accordance with the principle of data minimisation and storage limitation.
- Internal Information System
Personal data submitted through the Internal Information System will be retained only for the time strictly necessary to determine whether an investigation should be initiated. If no investigation is commenced within three months, the data will be deleted from the reporting system unless they have been anonymised or their retention is necessary to demonstrate the proper functioning of the system.
Where an investigation is initiated, the data may continue to be processed until its conclusion. They will then be retained only for the period necessary to implement the relevant measures and subsequently blocked for the applicable statutory limitation periods relating to potential criminal, civil, commercial, employment or administrative liabilities. Under no circumstances will such data be retained for more than ten years.
- Other data
Any other personal data or information provided by users, regardless of the means through which it is submitted, will be retained only for as long as necessary to fulfil the purpose for which it was collected.
4. Legal Basis for Processing
The legal bases that entitle Bustper to process the personal data of users, customers and prospective customers are as follows:
- The data subject’s consent for the processing and management of requests for information, enquiries and communications relating to our products and services.
- The consent provided by job applicants for recruitment and selection purposes.
- The performance of a contract or the implementation of pre-contractual measures relating to the provision of products and services by Bustper.
- Bustper’s legitimate interests in sending informational communications, commercial information and promotional offers relating to its business activities and to the products and services contracted, whether by email or through any other communication channel.
5. Data Recipients
Personal data will not be disclosed to third parties except where required by law.
However, certain service providers may have access to personal data where this is necessary for the operation of the website or the conduct of Bustper’s business activities. Such providers will always act under a data processing agreement and in accordance with the instructions of the Data Controller.
6. Source of the Data
Personal data are obtained directly from the data subjects themselves and from our collaborators.
The categories of personal data that may be collected include:
- Identification data.
- Postal and electronic contact details.
- Information provided and/or authorised by the data subjects that is necessary for the management and provision of the requested products or services.
7. Data Subject Rights
Right of Access, Rectification and Erasure
Data subjects have the right to obtain confirmation as to whether Bustper is processing their personal data. They also have the right to access their personal data, request the rectification of inaccurate data and request the erasure of their personal data where, among other reasons, the data are no longer necessary for the purposes for which they were collected.
Right to Restriction of Processing and Right to Object
In certain circumstances, data subjects may request the restriction of the processing of their personal data. In such cases, Bustper will retain the data only for the establishment, exercise or defence of legal claims.
Data subjects may also object to the processing of their personal data on grounds relating to their particular situation. Where such an objection is valid, Bustper will cease processing the data unless there are compelling legitimate grounds to continue processing or where the processing is necessary for the establishment, exercise or defence of legal claims.
These rights may be exercised through our Data Protection Channel, as described in the following section.
Right to Withdraw Consent
Where processing is based on consent, data subjects have the right to withdraw that consent at any time. However, such withdrawal will not affect the lawfulness of any processing carried out before consent was withdrawn.
Please note that certain processing activities are carried out on the basis of legal obligations or contractual necessity and therefore do not require the data subject’s consent.
8. Data Protection Channel / DATAPROTECT-line
Bustper has implemented a Data Protection Channel, reflecting its commitment to the highest standards of security, professionalism, independence and expertise in the management of data protection matters.
The Data Protection Channel operates through a dedicated web platform developed and managed by an independent external specialist, ensuring the confidentiality and reliability of all communications received.
Through this channel, data subjects may exercise their data protection rights, as described above, and report any suspected or actual personal data breaches, as well as any potential non-compliance with data protection legislation or with this Privacy Policy.
Access details for the Data Protection Channel are provided at the beginning of this Privacy Policy.
9. Supervisory Authority
If you consider that the processing of your personal data does not comply with the applicable data protection legislation, you have the right to lodge a complaint with the competent data protection supervisory authority.
In Spain, the competent supervisory authority is the Spanish Data Protection Agency (Agencia Española de Protección de Datos – AEPD): www.aepd.es
10. Assistance and Support
Data subjects may contact Bustper at any time with any questions regarding the processing of their personal data or the interpretation of this Privacy Policy.
11. Internal Information System (SIIS)
Bustper has implemented an Internal Information System (SIIS), which serves as a key mechanism for monitoring, oversight and the prevention of regulatory breaches. The system reflects the Company’s commitment to the highest standards of security, confidentiality, data protection, independence, expertise and professionalism in the handling of all reports received.
The internal reporting channels integrated into the SIIS have been implemented using dedicated technical solutions that meet all necessary legal and organisational requirements. The system guarantees the fundamental principles of anonymity, secure record-keeping, data preservation, protection against unauthorised alteration, prevention of conflicts of interest, protection of reporting persons and safeguards against retaliation.
Through this system, any reporting person is expected to act in good faith when reporting any indication, suspicion or evidence of regulatory breaches, criminal offences, unethical conduct or any failure to comply with the Company’s internal protocols, policies or codes of conduct.
Access to the SIIS is available through a dedicated section of our website.
12. Security and Control Measures
General
In accordance with the applicable data protection legislation, Bustper processes personal data by applying the appropriate technical, organisational, legal and security measures necessary to ensure the confidentiality, integrity and protection of the information under its responsibility.
If you become aware of, or suspect, any security risk that could compromise the confidentiality or integrity of personal data or confidential information, we kindly ask you to notify the Data Controller or the Data Protection Officer through the contact details or the Data Protection Channel provided in this Privacy Policy. This will enable Bustper to take the appropriate measures to prevent unauthorised processing, loss, destruction or accidental damage.
Cybersecurity
As an additional safeguard, Bustper implements cybersecurity measures designed to prevent, detect and respond to cyberattacks and fraudulent activities that may compromise the privacy and protection of the personal data processed in the course of its business activities.
If you receive any communication whose content or format raises doubts as to its authenticity, we recommend that you do not respond to it and instead contact the Data Controller or the Data Protection Officer using the contact details provided in this Privacy Policy.
Likewise, any request appearing to originate from Bustper concerning changes to payment methods, requests for confidential information, contact details, banking information, credit card details or any other sensitive data should not be acted upon without first obtaining direct confirmation from Bustper through an alternative communication channel.
We appreciate your cooperation in reporting any such suspicious communications or any other potential cybersecurity incidents or security risks that may involve Bustper, enabling us to take the necessary preventive measures.