Privacy policy
This policy explains personal data processing associated with the institutional website and enquiries to Taviel. It distinguishes that processing from activities carried out on behalf of customers using the service.
Last updated:
Controller and scope
Questions about this policy and data rights requests can be sent to info@taviel.es. Taviel is the brand used on this website; information about the operator is provided in the legal notice.
This policy covers visitors, people requesting information and professional contacts involved in a business relationship. Document processing through the service follows each party’s actual role and the applicable data processing agreement. The controller is responsible for informing the individuals concerned; Taviel provides the assistance required of it.
Data categories and sources
Providing data for an enquiry is voluntary. Without a reply address and enough information to understand the enquiry, we may be unable to answer it. Order documents, sensitive data and third-party information are not needed for an initial information request.
- Information you provide: name, email, company, role, phone number if supplied, and the content of enquiries or subsequent correspondence.
- Professional relationship information: stated requirements, proposals, management correspondence and, if a relationship is established, necessary administrative and billing information.
- Technical access data: IP address, date and time, requested resource, browser information, and error or security logs generated by the infrastructure serving the website.
- Contact information normally comes from the individual. If someone at your organisation provides your details to coordinate a request, they will be used for that purpose and you will be informed at the first contact or within the applicable legal period.
Purposes and lawful bases
An enquiry does not subscribe you to advertising. Browsing is not treated as consent. Where consent is needed for a particular purpose, it must be requested separately and may be withdrawn without affecting the lawfulness of earlier processing.
- Answering enquiries and preparing precontractual steps requested by the individual: steps before entering a contract or performance of a contract where that individual is a party (GDPR Article 6(1)(b)).
- Communicating with representatives, employees and organisational contacts: legitimate interest in maintaining the professional relationship and responding to the organisation’s request (GDPR Article 6(1)(f)). Processing is limited to necessary data and weighed against individuals’ rights.
- Protecting the website, investigating incidents and preventing abusive access: legitimate interest in system security and continuity (GDPR Article 6(1)(f)), with processing proportionate to that purpose.
- Meeting tax, accounting, data protection or other legally enforceable requirements: compliance with a legal obligation (GDPR Article 6(1)(c)).
- Sending electronic marketing: consent (GDPR Article 6(1)(a)) where necessary. For similar services of our own contracted previously, legitimate interest (GDPR Article 6(1)(f)), only where the requirements of Article 21(2) of the Spanish LSSI are met and the relevant balancing assessment has been completed. Each message will include an easy, free means to object or unsubscribe.
Retention
Enquiry data are retained until the enquiry is resolved and the resulting requested activities are closed. If a contractual relationship begins, necessary information is managed within that relationship.
Once the purpose ends, data are deleted or, where required, blocked for the periods during which liabilities or legal obligations may be enforced. Those periods depend on the document type, applicable tax and commercial duties and limitation periods for potential claims. Blocking prevents ordinary use.
Technical logs are retained for the time needed for the operation and security purposes that justified collection. Information connected with an incident or claim may be retained until resolution and for the relevant legal periods. Objection records are limited to what is needed to respect a decision not to receive communications.
Retention, return and deletion of orders and documents processed on customers’ behalf are governed by the relevant data processing agreement, including backup conditions. Their retention periods are not inferred from those of a commercial enquiry.
Recipients and providers
Data may be processed by providers needed to host and maintain the website, manage email and provide IT support. Where they act on Taviel’s behalf, access must be governed by instructions, confidentiality and the safeguards required by the GDPR.
Necessary information may also be disclosed to professional advisers for managing or defending a relationship, and to public bodies, authorities or courts where there is a legal obligation or other lawful authorisation. A website visit does not authorise disclosure to third parties for their own advertising.
Providers involved in service document processing and their access conditions must be specified in contractual subprocessor information. This website policy is not a general authorisation to add service subprocessors.
International transfers
Technology providers may involve processing or access from countries outside the European Economic Area. A server’s location does not, by itself, determine all places from which access may occur.
Where processing involves an international transfer, a valid mechanism under Chapter V of the GDPR is required, such as an applicable adequacy decision or standard contractual clauses, together with any necessary assessment and supplementary measures. A provider is not assumed to fall under an adequacy decision simply because of its country or brand.
You can request information about the recipients, countries and safeguards applicable to your processing, and a copy of safeguards where appropriate, at info@taviel.es. Transfers involving documents processed on customers’ behalf are also governed by the data processing agreement.
AI and customer documents
The institutional website does not offer an AI chat or analyse orders while you browse. Contact links open your email application; they do not upload documents to the product.
The Taviel service uses AI to extract and organise order information. Where documents contain personal data, processing by Taviel and authorised providers must follow the controller’s authorised instructions, the contracted purpose and the data processing agreement. Supplied data must be limited to what is necessary and the controller must inform the individuals concerned.
Sending an enquiry does not authorise the use of its content to train AI models. Any purpose other than the management requested requires its own assessment of lawfulness, transparency and compatibility; this policy does not provide general authorisation.
The website does not make solely automated decisions with legal or similarly significant effects on visitors or create profiles for that purpose. The order workflow described on the website includes review and approval by the customer’s authorised team.
Your rights
You may request access to your data, correction of inaccurate information, erasure where applicable, restriction of processing and portability in the circumstances provided by law. You may also object to processing based on legitimate interest for reasons relating to your particular situation and, in all cases, to direct marketing. Consent may be withdrawn at any time where processing relies on it.
Send your request to info@taviel.es, specifying the right you wish to exercise and a reply address. Additional identity information will only be requested where there are reasonable doubts and will be limited to what is necessary. Do not send a copy of an identity document in advance.
A response will be provided without undue delay and generally within one month of receipt. The period may be extended by two further months because of complexity or the number of requests, with the extension and reasons explained within the first month. Requests are free except in the exceptional circumstances provided by the GDPR.
You may complain to the Spanish Data Protection Agency or the competent supervisory authority, particularly where you habitually reside, work or where the alleged infringement occurred. You do not have to complain to Taviel first.
If a request concerns data Taviel processes on an organisation’s behalf, the controller for that processing must decide on the exercise of the right. Taviel will provide the assistance required of a processor and route the request in accordance with applicable instructions and obligations.
Security and careful communications
Protecting personal data requires technical and organisational measures appropriate to the risk and restricting access to those who need it for the relevant purpose. No system can guarantee absolute security.
Avoid attaching complete orders or confidential information to an initial enquiry. If documents are needed to provide the service, the exchange channel, authorised people and applicable safeguards will be agreed. Privacy questions and suspected incidents can be reported to info@taviel.es.
Policy changes
The policy will be updated when processing or legal requirements change. Significant changes will be communicated through appropriate means and new consent requested where necessary. Publishing a new version does not retroactively legitimise different processing.
Need more information?
Read the frequently asked questions