Privacy Policy

General

This Privacy Policy details how your personal data is dealt with by Xoople S.L. and its wholly owned corporate affiliates (collectively “Xoople”, “we”, “us” or “our”) in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable data protection legislation (“Data Protection Laws”).

 

This Privacy Policy applies to all individuals that are visitors to our website, our suppliers, job applicants, or any other person (“you” or “your”) who provide us with personal data through various “Channels” (being the various services or means we make available to you to interact with us such as websites, platforms, applications, forms, mailboxes, telephone numbers, addresses, or social media profiles).

 

Data Controller contact

The Data Controller in charge of processing is:

Name: Xoople S.L.

Address: Calle San German 13-1-lz Madrid, 28020, Spain

Spanish Tax ID: B-88282090

Email: legal@xoople.com

Telephone +34 913 441 744

 

What data do we process and what is the legitimate purpose?

When you interact with the Channels we receive or collect and store certain types of information from you including the following:

To manage the relationship established with us: For our services provided through applications or online platforms we process the data provided by you in order to manage access credentials, provide assistance, answer queries, distribute our products and services, and manage the quality of same.  In these instances, we collect your data to enable us to implement the pre-contractual or contractual relationship that will allow us to provide you with our products and services efficiently.  We will also process your data whenever you subscribe to any of our social media accounts, newsletters, marketing materials or you ask us to send you commercial communications and the data you provide us with through the cookies collected when browsing online. Your informed and specific consent shall form the legal basis for such processing.

To manage staff selection: We process candidate data submitted to us in order to perform selection processes for roles at Xoople.  The legal basis for processing is the implementation of pre-contractual measures, and your informed and specific consent.

To manage contact details within the scope of contractual or commercial relationships: We process contact details of potential customers, legal representatives of legal entities and organisations, whether public or private, analysts and investors or other concerned parties who provide us with their details, this in order to send them information of interest, to manage the commercial relationship that binds us.  The basis for the legitimacy of such purposes is maintaining the pre-contractual, contractual and/or commercial relationship that binds us.

To comply with our legal obligations: We process personal data as required to discharge our commercial, fiscal, accounting or administrative legal obligations.  The legal basis authorizing us to carry out such processing is compliance with legal obligations.

To manage fraud: Some of our services require us to check on identities of people or entities to support protection, detection and prevention of fraud or other unlawful activities, unauthorised transactions, and to manage quality and business-associated risks, and to investigate, where necessary, illegal activities and potential breaches of our policies and/or the terms and conditions of our services. The legal basis for such processing is compliance with the legal obligations that apply in each case; including for example, Law 10/2010 of 28 April on the Prevention of Money Laundering and the Financing of Terrorism.

Data obtained from our services or products: We may process data obtained from your use of our contracted products or services in order to adapt and improve our products or services or more generally our business activities including through basic analysis which will be specified in the data protection clauses of the specific contract for a particular product or service. The legitimate basis for the processing is our legitimate interest in analysing or predicting in a very basic way aspects of our products and services in order to improve the administration and provision of those products and services. The right to object to such processing may be exercised in accordance with the provisions of the section on the rights of data subjects contained in this Privacy Policy.

Security and surveillance of facilities: Our facilities may be equipped with cameras and video surveillance systems that attempt to safeguard such facilities. The legitimate basis for such processing is our legitimate interest in ensuring the security of our facilities.

Visitor and third-party management: To control the access of visitors, collaborators or other third parties to facilities, it is possible that, at some of our facilities, identification data may be collected.

The legitimate basis is in this case consent, as well as our legitimate interest in ensuring the security of goods and people at its facilities.

To manage whistleblowing:  Xoople has a Whistleblower Policy in which employees, suppliers and others can report concerns.  The legal basis for the processing of the data in this case is compliance with legal obligations for the investigation of suspected criminal offences.

Direct marketing: In general, unless prior consent has been obtained, we do not use your personal data for direct marketing purposes. You may at any time unsubscribe from direct marketing campaigns and object to the future processing of your personal data for such purposes by sending us an e-mail to the address of the Data Controller or by using the relevant “unsubscribe” option included in e-mails.

Automated Decisions: Xoople does not carry out automated decision-making, including profiling, except in those cases in which you are expressly informed of this and your express consent is requested.

 

How long do we keep data?

Typically data will be kept for the shorter of:  (1) for as long as is necessary for the purpose for which the data was collected; (2) for the applicable limitation periods, if liabilities might be incurred as the result of the processing; (3) for data collected with your consent, only as long as such consent is not withdrawn; and (4) the explicit retention period we set for particular data processing operations.

In specific instances on a special basis, such as data collected for the purpose of responding to requests or enquiries will be kept for the time necessary to be able to attend to the same, but never for longer than twelve months.

 

Permitted sharing of data

Xoople undertakes not to transfer or disclose your personal data except as described in this Privacy Policy or, where applicable, as might be indicated at the time of collection of the data.   For example:

  • We may exchange personal information with service providers, who are third parties and are in some cases contracted to perform services on our behalf. In these cases, the corresponding data processor agreements are signed whenever necessary, as established by the regulations on matters relating to data protection.
  • We may disclose your personal information (1) if we are permitted or required to do so by law or by a process of law (such as a court order or subpoena); (2) to law enforcement agencies or other public officials to comply with a lawful and legitimate request; (3) whenever we consider this necessary to prevent physical harm or financial loss; (4) to establish, exercise or defend our legal rights; (5) in connection with an investigation of suspected or actual fraud or illegal activity; or (6) with your express and informed consent.
  • We reserve the right to transfer to a third party any information we hold about you in the event of any actual or potential transfer or sale of all or part of our business or assets (including in the event of any merger, acquisition, joint venture, restructuring, assignment, dissolution or liquidation) or other structural or business operation. In this case, such third parties will be required to ensure levels of protection comparable to those provided by Xoople with respect to the information to be shared.
  • Xoople is a global and interconnected company, hence we may exchange personal information within companies of the corporate group in the context of the centralisation of certain activities carried out by them as a corporate group. For certainty, any such internal transfer, assignment or processing of personal data will be carried out under the data protection laws in force and through the adoption and application of adequate guarantees designed to ensure the protection of your privacy and fundamental rights and freedoms. In the event of such a transfer, this will be indicated for the specific processing operation and will require your consent.

Likewise, we inform you that some of our service providers, third parties or Xoople companies may be located in territories outside the European Economic Area that do not provide a level of data protection comparable to that of the European Union. In such cases we transfer your data with appropriate safeguards, maintaining at all times the security of such data; these may include the formulation of Standard Contractual Clauses approved by the Commission, the content of which may be examined by clicking on the following link: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_es

Your rights

Under Data Protection Laws you have certain rights including the following:

  • Right of Information: You have the right to be informed and to obtain confirmation on whether we are processing your personal data.
  • Right of Access, Rectification and Erasure: You have the right to request access your personal data (unless your request is unfounded or unreasonable), as well as to request the rectification of inaccurate or incomplete personal data (where appropriate) and, in certain cases, to request its deletion when, among other reasons, the personal data is no longer necessary for the purposes for which it was collected.
  • Right to restrict the processing of your Personal Data: In certain circumstances, you may request that we restrict the processing of your data, in which case we will only continue to process personal information where an applicable exemption applies.
  • Right to object: You may object to the use of personal data that we are processing in accordance with the legitimate interests set out in this Privacy Policy.
  • Right to data portability: If it is technically feasible, you may request that we transmit your personal data from our systems to a third party’s system in a safe and secure way provided that the personal data has been used and/or processed with your consent or under the existence of an agreement.

You can exercise all of your rights, including rights of access, rectification, erasure and portability of data and objection to and restriction of the processing by using the contact information above and by attaching a copy of your ID or equivalent document.

In any case, you have the right to withdraw your consent, at any time, where we have relied on it. If you withdraw your consent, we may not be able to provide you with certain benefits or services. It will not affect our lawful basis for processing by consent before your withdrawal. You also have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) (or such other local data protection entity applicable to you) if you feel your data has or is being used in a way that you believe does not comply with data protection laws.

We may amend this Privacy Policy from time to time. We may also notify you of material changes to this Privacy Policy, before the effective date of the changes, by sending an email or otherwise.

 

Last update 26 September, 2023