COMMITMENT TO THE PROTECTION OF PERSONAL DATA – ENGLISH
This information, addressed to all individuals (whether or not they are users of the website), shall be made available through a link on the website entitled “COMMITMENT TO THE PROTECTION OF PERSONAL DATA”.
This link should preferably be located at the top of the website to ensure its visibility and accessibility.
OUR COMMITMENT TO THE PROTECTION OF PERSONAL DATA: “INFORMED INDIVIDUALS, PROTECTED DATA”
The Management / Governing Body of THE ROOM STUDIO, S.L. (hereinafter, the Data Controller) assumes the highest level of responsibility and commitment with regard to the establishment, implementation, and maintenance of this Data Protection Policy, ensuring the continuous improvement of the Data Controller with the aim of achieving excellence in compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation – GDPR) (OJ L 119/1, 04-05-2016), as well as the applicable Spanish legislation on the protection of personal data (Organic Law, specific sectoral legislation, and its implementing regulations).
THE ROOM STUDIO, S.L.’s Data Protection Policy is based on the principle of accountability, whereby the Data Controller is responsible for complying with the legal and regulatory framework governing this Policy and is able to demonstrate such compliance before the competent supervisory authorities.
Accordingly, the Data Controller shall be guided by the following principles, which shall serve as guidance and a framework of reference for all personnel involved in the processing of personal data:
- Data protection by design: the Data Controller shall implement appropriate technical and organizational measures, such as pseudonymization, both when determining the means of processing and during the processing itself. These measures are designed to effectively implement data protection principles, such as data minimization, and to incorporate the necessary safeguards into the processing activities.
- Data protection by default: the Data Controller shall implement appropriate technical and organizational measures to ensure that, by default, only the personal data necessary for each specific processing purpose are processed.
- Data protection throughout the information lifecycle: measures ensuring the protection of personal data shall apply throughout the entire lifecycle of the information.
- Lawfulness, fairness, and transparency: personal data shall be processed lawfully, fairly, and transparently in relation to the data subject.
- Purpose limitation: personal data shall be collected for specified, explicit, and legitimate purposes and shall not be further processed in a manner that is incompatible with those purposes.
- Data minimization: personal data shall be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.
- Accuracy: personal data shall be accurate and, where necessary, kept up to date. Every reasonable step shall be taken to ensure that inaccurate personal data are erased or rectified without undue delay, taking into account the purposes for which they are processed.
- Storage limitation: personal data shall be retained in a form that permits the identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
- Integrity and confidentiality: personal data shall be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, through the implementation of appropriate technical and organizational measures.
- Information and training: one of the key elements in ensuring the protection of personal data is providing appropriate information and training to personnel involved in processing such data. Throughout the information lifecycle, all personnel with access to personal data shall receive appropriate training and information regarding their obligations under applicable data protection legislation.
THE ROOM STUDIO, S.L.’s Data Protection Policy is communicated to all personnel of the Data Controller and made available to all interested parties.
Accordingly, this Data Protection Policy applies to all personnel of the Data Controller, who must be familiar with it and embrace it as their own. Each member of staff is responsible for implementing it, ensuring compliance with the data protection rules applicable to their activities, and identifying and proposing any opportunities for improvement they consider appropriate, with the aim of achieving excellence in compliance.
This Policy shall be reviewed by the Management / Governing Body of THE ROOM STUDIO, S.L. as often as deemed necessary to ensure that it remains fully aligned, at all times, with the applicable legislation governing the protection of personal data.