Blok I
Personeel
Beveiligingsbeleid voor personeel bij de verwerking van persoonsgegevens
1.- Toepassingsgebied
De Verwerkingsverantwoordelijke is ertoe verbonden een privacycultuur binnen de organisatie te implementeren en vereist daarom dat de personen die gemachtigd zijn persoonsgegevens te verwerken, geïnformeerd zijn over de verwerking van gegevens en daarvoor verantwoordelijkheid dragen.
Van elke persoon die gemachtigd is persoonsgegevens te verwerken, wordt verwacht dat hij of zij dit Beveiligingsbeleid leest, begrijpt, naleeft en handhaaft ter bescherming van persoonsgegevens, inclusief personen die hun werkzaamheden uitvoeren voor de Verwerkingsverantwoordelijke als zelfstandige of diensten verlenen via uitbestede ondernemingen.
This Security Policy sets out the obligations and procedures to be followed by the organisation's personnel, both internal and external, who process personal data in the course of their activity, and is based on the provisions of the applicable data protection regulations, Regulation (EU) 2016/679 of 27 April 2016 (GDPR) and Organic Law 3/2018, of 5 December (LOPDGDD).
In this regard, in order to oversee and enforce this Policy, the organisation has appointed a Security Officer who will be available to all personnel and will be responsible for coordinating, monitoring, developing and verifying compliance with the aforementioned regulations.
2.- Basisprincipes
De persoon die gemachtigd is persoonsgegevens te verwerken, verbindt zich ertoe de volgende basisprincipes na te leven:
Structure of the processing:
- Personal data: Information relating to a natural person by which their identity can be determined.
- Processing: Any operation performed on personal data: collection, access, intervention, transmission, storage and erasure.
- Data subject: Natural person whose personal data are subject to processing.
- Filing system: Structured set of personal data liable to be processed for a specific purpose.
- Data Controller: Organisation that determines the purposes and means of the processing.
- Authorised personnel: Person authorised by the Data Controller to carry out data processing by means of a confidentiality commitment.
Categories of data:
- Identifying: Data that do not correspond to Criminal or Special categories, for example: name, address, email, telephone, age, sex, signature, image, hobbies, assets, banking details, academic, professional, social, commercial and financial information, etc.
- Criminal: Data relating to the commission of administrative or criminal offences, or those that may offer a definition of personality characteristics, etc.
- Special: Data relating to ethnic or racial origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data allowing the unique identification of a person, data concerning health or sexual life and orientation.
3.- Verplichtingen
Van elke persoon die gemachtigd is persoonsgegevens te verwerken, wordt verwacht dat hij of zij:
- Lawfulness: fairness and transparency towards the data subject.
- Purpose limitation: processed for specified purposes.
- Data minimisation: only the data necessary to achieve the purposes should be collected.
- Accuracy: kept up to date.
- Storage limitation: kept for no longer than necessary to achieve the purposes.
- Integrity and confidentiality: application of security measures for the protection of the data in all phases of the processing.
- Accountability: compliance with all data protection principles must be demonstrable.
Consent to carry out data processing
- When the processing of personal data is based on the data subject's consent, we must obtain explicit consent to process them and keep the supporting document that proves it.
- When we obtain data from third parties, we must ensure that the communication is lawful and keep the supporting document that proves it.
- It is not necessary to obtain the data subject's consent when the processing is based on a legal obligation (for example, to issue an invoice), on a contractual relationship, or on a legitimate, public or vital interest.
Information to the data subject about the processing
We must provide the following information to the data subject:
- The identity and contact details of the Data Controller.
- The purposes of the processing.
- The legal basis for the processing.
- The storage period of the data or the criteria used to determine it.
- The rights to which the data subject is entitled.
- And if they exist:
- The recipients or categories of recipients of the data.
- The transfer of data to countries or organisations established outside the EU.
- And if the data have not been obtained from the data subject:
- Category of data.
- Sources of origin.
Responsibility for the processing
Data processing may be carried out by external organisations provided that there is express authorisation from the Data Controller and that a contract to carry out such processing has been signed in accordance with the applicable legislation. To find out which companies or third parties are authorised for the disclosure of data, please contact the Security Officer.
External organisations may be:
- Data processors: Organisation that processes personal data on behalf of the Data Controller.
- Data recipients: Organisation other than the Processor that receives a communication of personal data from the Data Controller.
Security measures
The organisation has implemented technical and organisational measures to ensure a level of security appropriate to the risks that the processing may entail as a result of the accidental or unlawful destruction of data, loss, alteration or unauthorised communication and access to the data when they are transmitted, stored or otherwise processed.
Personnel must safeguard the security of the data processed by the organisation and shall report to the Controller any processing operation that may pose a risk affecting data protection or the interests and freedoms of the data subjects.
Any design of a new processing operation or update of an existing operation must guarantee, prior to its implementation, the protection of personal data and the exercise of the data subjects' rights in all phases of the processing: collection, access, intervention, transmission, storage and erasure.
4.- Beheer van beveiligingsincidenten
Elke persoon die een mogelijke inbreuk in verband met gegevens die persoonsgegevens betreft ontdekt, of vermoedt dat een dergelijke inbreuk heeft plaatsgevonden, dient dit onmiddellijk te melden aan zijn of haar leidinggevende, die op zijn of haar beurt de compliance-verantwoordelijke informeert.
Organisation of information
Data must be classified in such a way that the rights of data subjects can be exercised: access, rectification, erasure and portability of the data and restriction of or objection to the processing.
Storage of data
Data must be stored in the furniture and department designated for this purpose. For automated processing, files shall be saved on the media, folders or network directory indicated by the Security Officer.
It is not permitted to keep data on the physical or digital desktop. Only their temporary processing on that desktop is allowed to carry out the operations that require it, and they must be kept in the appropriate place at the end of the working day.
Access to information
The restricted access mechanisms to information implemented by the organisation must be applied, safeguarding the access credentials from any disclosure or communication to other persons.
Each person is only authorised to access the resources necessary for the development and fulfilment of their functions. Access to computer equipment shall be restricted by means of procedures that can identify and authenticate the person accessing it. The username and password shall be regarded as non-transferable personal data.
Data processing
Documentary and computer media must be arranged in such a way that they are not accessible to unauthorised persons.
If a person temporarily leaves their workstation, they must hide the documents and lock the computer, so as to prevent the viewing of the information they were working with.
When printers, photocopiers or scanners are used, after processing any personal information, it must be collected immediately, ensuring that no printed documents are left in the output tray or scanned documents in the shared folder.
Transport of media
The transport of media containing personal data must be carried out only by authorised personnel or external companies hired for this purpose by the Data Controller.
Disposal of documents
Any physical document or digital medium that is to be disposed of and that includes personal data must be destroyed with the shredder or removed by an approved document destruction company.
Backup and data recovery
Personnel must store all processed information in the corresponding network directory indicated by the Security Officer, which will allow the existing security measures to be applied to this information and to be subject to the backup procedures applied by the organisation.
Data protection
The data protection measures established by the organisation regarding the security of the processing must be applied, such as the pseudonymisation or encryption of data or intrusion warnings such as antivirus, antispam, etc.
Incident management
An incident is considered to be any security breach that causes the accidental or unlawful destruction, loss, alteration, or unauthorised access to or communication of personal data.
Personnel are obliged to notify, without undue delay, any incident of which they become aware to the Security Officer for their information and the application of corrective measures to remedy and mitigate the effects it may have caused. Incidents must be documented by the person who notifies them with a detailed description of the incident and the date and time on which it occurred or became known.
The knowledge and failure to notify an incident by personnel shall be considered a breach of data security and may give rise to the initiation of legal action, as well as the claim for compensation, penalties and damages or losses that the Controller is obliged to address as a result of such non-compliance.
Other mandatory functions and obligations
Use of computer systems (IT systems)
The Computer System, and the terminals assigned to or used by each USER, are, as a general rule, the property of the CONTROLLER.
The following activities are expressly prohibited: expressly prohibited :
- The use of computer programs without the corresponding licence, as well as the use, reproduction, transfer, transformation or public communication of any type of work or invention protected by intellectual or industrial property. Failure to comply may give rise to disciplinary, administrative, civil and criminal liability.
- Destroying, altering, disabling or in any other way damaging the data, programs or electronic documents of the CONTROLLER or of third parties. These acts may constitute an offence of damage, provided for in artículo 264.2 del Código Penal.
- Voluntarily introducing programs, viruses, macros, applets, ActiveX controls or any other logical device or character sequence that causes or is liable to cause any type of alteration in the Computer Systems of the CONTROLLER or of third parties. In this regard, it should be recalled that the system itself automatically runs the antivirus programs and their updates to prevent the entry into the system of any element intended to destroy or corrupt computer data.
- Introducing, downloading from the Internet, reproducing, using or distributing computer programs not expressly authorised by the CONTROLLER. This prohibition includes any other type of work or material whose intellectual or industrial property rights belong to third parties, when authorisation for it is not available.
- Installing illegal copies of any program, including those that are standardised.
- Deleting any of the legally installed programs.
- Introducing obscene, immoral or offensive content and, in general, content lacking utility for the objectives of the CONTROLLER.
- Encrypting information without being expressly authorised to do so.
It is prohibited to use the information system resources to which one has access for private use or for any purpose other than strictly work-related ones.
Safeguarding and protection of personal passwords
In relation to the passwords of computer equipment, when the system itself does not incorporate mechanisms requiring certain requirements, the USER shall be responsible for complying with the following rules:
- The password must consist of at least 8 characters; it is recommended that it include upper- and lower-case letters, special characters (of the type @, #, +, etc.) and numeric digits.
- The access password shall expire after no more than 365 days, and must be modified at the time of the first access to the system.
- Common names, vehicle registration numbers, telephone numbers, names of relatives, friends, etc. shall be avoided, as well as derivatives of the user's name such as permutations or changing the order of the letters, transpositions, repetitions of a single character, etc.
- Users shall be responsible for their safekeeping and custody.
- The system shall not be accessed using another user's identifier and password. The responsibilities for any access carried out using a given identifier shall fall on the user to whom it has been assigned.
Information about access to corporate email
The commitment that DUKAT ORB SL has assumed to ensure the privacy of the personal information processed or disclosed is specified in that the use of email by each employee must be carried out exclusively within the scope of work activity, as it is a tool provided by the company for that purpose. exclusively, dentro del ámbito de la actividad laboral, pues se trata de una herramienta puesta por la empresa para tal fin.
Consequently, the USER shall be obliged to perform the agreed work under the direction of the employer or the person to whom they delegate, with access to the professional email being possible both by the employer and by those persons designated or entrusted by them.
Likewise, the organisation may adopt the surveillance and control measures it deems most appropriate to verify the employee's compliance with their work obligations and duties, observing in their adoption and application the consideration due to their human dignity.
The USER must be aware that, among other mechanisms, techniques may be applied for the purpose of monitoring their computer, with and without prior notice, and without prejudice to the possible application of other preventive measures, such as the exclusion of certain connections, reviews, analysis or remote monitoring, indexing of Internet browsing, review and monitoring of email and/or the use of their computer, or the consultation of those voice messages included in the voicemail of the mobile device provided by the company.
Any file introduced into the Computer Systems via email messages coming from external networks must comply with the requirements established in these rules in addition to those of the client, in particular those concerning intellectual and industrial property and virus control.
Email addresses directed at persons are considered personal data, so when emails are sent to more than one recipient, if it is not strictly necessary for the others to see everyone else's email addresses, they must be sent as a blind carbon copy «Bcc».
Likewise, the following activities are expressly prohibited: expressly prohibited :
- Attempting to read, delete, copy or modify the email messages or files of other USERS. This activity may constitute an offence of interception of telecommunications (disclosure of secrets), provided for in artículo 197 del Código Penal.
- Sending email messages on a massive scale or for commercial or advertising purposes without the recipient's consent.
- Sending or forwarding chain or pyramid-type messages.
By signing this document, the USER declares that they have been informed of the security policy applicable within the organisation.
Beleid inzake de verwerking van persoonsgegevens
CONFIDENTIALITY AND PROFESSIONAL SECRECY AGREEMENT
PERSON AUTHORISED FOR DATA PROCESSING
On the one part, Mr./Ms., in the name and on behalf of DUKAT ORB SL, with NIF B75963934 and registered office located at Passeig del Bellesguard, 12 - 08320 El Masnou (Barcelona) SPAIN, hereinafter the CONTROLLER. CONTROLLER.
And on the other part, Mr./Ms., of legal age and, in their own name and representation, hereinafter the USER. USER.
Both parties mutually recognise the legal capacity necessary to enter into this contract for the provision of services with access to personal data and
DECLARE
- That DUKAT ORB SL is the Controller of the processing of the personal data subject to this agreement in accordance with the provisions of the applicable data protection regulations, Regulation (EU) 2016/679 of 27 April 2016 (GDPR) and Organic Law 3/2018, of 5 December (LOPDGDD).
- That by virtue of the provision of employment or professional services that the USER carries out in favour of the CONTROLLER, they will have access to the processing of personal data and to confidential information.
- That the USER knows and accepts that maintaining the confidentiality of such information is essential in the sector in which they carry out their activities and that, therefore, failure to respect such confidentiality causes very serious harm to the CONTROLLER.
- That in compliance with the provisions of artículo 29 del GDPR, the USER is aware that they are bound by professional secrecy with respect to the personal data they process and by the duty to protect them, obligations that shall subsist even after the termination of their relationship with the CONTROLLER, for which reason both parties agree to enter into this agreement subject to the following
INSTRUCTIONS FOR DATA PROCESSING
1.- Confidential information
«Confidential information» shall be understood as information that is accessible only by authorised personnel, that is, information that should only be made known to the persons, entities or systems authorised to access it. This confidential information may include:
- Personal information, which is all information relating to an identified or identifiable natural person by which their identity can be determined, directly or indirectly, whether by means of an identifier, name, number, location or factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person.
- Trade secrets, business secrets, technical knowledge and any other business information, encompassing the following types of information (whether or not recorded in writing), without this enumeration excluding other classes of equally confidential information: techniques, training programmes, tests, research and development, ideas, inventions, concepts, notes, schemes, designs, drawings, organisational charts, memoranda, processes, procedures, know-how, formulas, data, computer programs and applications, improvements, discoveries, knowledge of any kind made available to the USER, reference materials, marketing materials and techniques, research and development plans, marketing, new products, customer names, marketing channels, trade secrets and any other information related to customers and suppliers, price lists, pricing policies, sales policy, financial information, budgets, templates and management and accounting methods, as well as the rights, titles and interests that may be claimed over inventions, whether patentable or not, made or obtained by the USER during the term of their contract.
Likewise, in the event of an occupational accident, and in compliance with the provisions of the Occupational Risk Prevention Law (L.P.R.L.), if the processing of this information falls within the functions of the USER, the latter undertakes to comply with the confidentiality and security measures determined by the CONTROLLER.
2.- Commitment to confidentiality and professional secrecy
The USER undertakes to comply with the instructions determined by the CONTROLLER that affect the development of their functions in order to guarantee the confidentiality and professional secrecy of all the "confidential information", and therefore expressly undertakes not to disclose, publish, transfer, sell, or otherwise, directly or indirectly, make it available to third parties, either in whole or in part, and to comply with this obligation even with their own relatives or other members of the organisation who are not authorised to access such information, whatever the medium containing it.
The USER shall access the "confidential information" only if it is necessary for the provision of the services for which they have been hired and exclusively for the purposes authorised by the CONTROLLER.
The work resources provided by the CONTROLLER (computers, internet, email, etc.) shall be used solely and exclusively for the efficient development of the work itself, and the USER is therefore informed that the CONTROLLER may carry out verification, surveillance and control tasks over such resources pursuant to artículo 20.3 del Estatuto de los Trabajadores.
3.- Ownership of the "confidential information"
The USER acknowledges the CONTROLLER's ownership of all data considered "confidential information" in section 1 of this agreement and undertakes to return all copies of such information and any physical medium under their control to the CONTROLLER if the latter so requests.
4.- Data processing
The USER declares that they are aware of the information and security policies established by the CONTROLLER to guarantee data protection and undertakes to follow the instructions reflected therein and, in the event of noticing that they are being violated, to notify it without undue delay to the CONTROLLER for their information and the application of corrective measures to remedy and mitigate the effects caused.
5.- Liability of the USER
The USER shall be liable to the CONTROLLER and third parties for any harm that may arise for either party from the breach of the commitments of this agreement, which may give rise to the initiation of legal action, as well as the claim for compensation, penalties and damages or losses that the CONTROLLER is obliged to address as a result of such non-compliance.
6.- Data protection
In accordance with the applicable data protection regulations, the CONTROLLER informs the USER that their personal data obtained at the time of hiring, those communicated throughout the duration of the contract and those communicated in the future for the fulfilment of their legal obligations, will be processed for the purpose of managing the employment or professional relationship that binds them. Likewise, in the event of an occupational accident, the CONTROLLER will not directly process health data of the USER. Such data will be processed, where applicable, exclusively by the competent healthcare personnel or prevention services, for the purpose of managing the care and investigation of the occupational accident, in accordance with the applicable regulations.
The data obtained will be processed for as long as the employment or professional relationship with the USER exists. Subsequently, they will be kept blocked in order to comply with the legally established periods, adopting the technical and organisational measures to prevent their processing, including their viewing, and being available only to judges, courts, the public prosecutor's office or public administrations, for the purpose of addressing legal liabilities. Once the required legal period has elapsed, these data will be definitively destroyed. The legal basis for the processing of the data shall be the performance of an employment or professional contract, as well as compliance with the legal obligations of the CONTROLLER.
The data will be communicated to public bodies and administrations, Social Security, the Tax Agency, the Labour Inspectorate, the health surveillance mutual insurer and the occupational risk prevention service. In the event of subcontracting of personnel, the data of the WORKER could be disclosed in order to comply with the legal obligation regarding the coordination of business activities.
Likewise, they may be communicated for the management of grants, participation in public tenders, to the works council, trade unions, banking entities, as well as to the providers linked to the CONTROLLER who act as data processors in the services related to personnel (consultancies, insurance companies, IT providers, among others).
Where applicable, they may be communicated to external training companies for the purpose of identifying and assessing participants, as well as issuing the corresponding attendance certificate, the legal basis being the legitimate interest of the CONTROLLER in improving the skills of workers.
Finally, they may be provided to those entities or clients that require identifying and employment data of personnel to carry out the contracted or subcontracted service, and that prove the relationship with the company.
The CONTROLLER informs that the USER may exercise at any time the rights of access, rectification, portability and erasure of their data and those of restriction of and objection to their processing by contacting Passeig del Bellesguard, 12 - 08320 El Masnou (Barcelona). E-mail: compliance@dukat.es. If they consider that the processing does not comply with the applicable regulations, they may lodge a complaint with the supervisory authority at www.aepd.es
7.- End of the provision of service
Compliance with the obligations contained in this agreement is of an indefinite nature and shall remain in force after the termination of the relationship between the USER and the CONTROLLER. Therefore, the USER guarantees that, after the relationship ends, they will keep the same professional secrecy with respect to the "confidential information" to which they have had access during the performance of their functions.
Blok II
Verwerking
Service provision clause
DUKAT ORB SL is the Controller of the processing of the personal data of the data subject and informs them that these will be processed in accordance with the provisions of the applicable data protection regulations, Regulation (EU) 2016/679 of 27 April 2016 (GDPR) and Organic Law 3/2018, of 5 December (LOPDGDD), and therefore the following information about the processing is provided:
Purpose of the processing: Provision of professional services.
Legal basis for the processing: The legal basis for the processing of personal data shall be the performance of the requested service.
Data retention criteria: The data will be processed for as long as the contractual or professional relationship exists. Subsequently, they will be kept blocked to comply with the legally established periods, adopting the technical and organisational measures to prevent their processing, including their viewing, and being available only to judges, courts, the public prosecutor's office or public administrations, for the purpose of addressing legal liabilities. Once the required legal period has elapsed, these data will be definitively destroyed.
Communication of the data: No data will be communicated to third parties, except by legal obligation or those providers linked to the controller who act as data processors.
Rights to which the data subject is entitled:
- Right of access, rectification, portability and erasure of their data and to the restriction of or objection to their processing.
- Right to lodge a complaint with the supervisory Authority www.aepd.es if they consider that the processing does not comply with the applicable regulations.
Contact details to exercise your rights: DUKAT ORB SL. Passeig del Bellesguard, 12 - 08320 El Masnou (Barcelona). E-mail: compliance@dukat.es
Blok III
Beelden
Beeldenbeleid
DUKAT ORB SL is the Controller of the processing of the personal data of the data subject and informs them that these will be processed in accordance with the provisions of the applicable data protection regulations, Regulation (EU) 2016/679 of 27 April 2016 (GDPR), Organic Law 3/2018, of 5 December (LOPDGDD), and Law (ES) 1/1982 on the civil protection of the right to honour, personal and family privacy and one's own image, and therefore the following information about the processing is provided:
Purpose of the processing: Capture and recording of images or videos of the data subject during the activities organised by the Data Controller in order to publicise them in the media. Under no circumstances will the name of the data subject be published.
Legal basis: The processing of your personal data, including the images, is based on the consent that the data subject must provide by signing this document. The authorisation contemplated herein is granted free of charge, without any right to receive any financial compensation for its use.
Data retention criteria: The data will be processed for the time necessary to maintain the purpose of the processing, unless the data subject has revoked their consent. Subsequently, they will be kept blocked to comply with the legally established periods.
Consent: The Data Subject may authorise or not the processing by marking with an "x" in the corresponding box YES (I give consent) or NO (I do not give consent) for the following categories of recipients:
| YES | NO | AUTHORISATION OF THE PROCESSING OF THE IMAGE |
|---|---|---|
| Publication in the Controller's own media (websites, blogs, social networks, corporate platforms, internal publications, etc.) | ||
| Publication in media external to the Controller (sector magazines or newsletters, press, etc.) |
The data subject is informed that they may exercise their right of access, rectification, portability and erasure of their data and the restriction of or objection to their processing at Passeig del Bellesguard, 12 - 08320 El Masnou (Barcelona). E-mail: compliance@dukat.es Likewise, they may lodge a complaint with the supervisory Authority www.aepd.es if they consider that the processing does not comply with the applicable regulations.
Blok IV
Contractmodellen
Contractmodellen tussen Verwerkingsverantwoordelijke en Verwerker
In compliance with the provisions of artículo 28 del GDPR, when DUKAT ORB SL (CONTROLLER) hires the services of a third party (PROCESSOR) that requires access to personal data, both parties enter into a data processing agreement subject to the following instructions for data processing.
1. Subject matter, nature and purpose of the assignment
The CONTROLLER guarantees that the data provided to the PROCESSOR have been obtained lawfully and that they are adequate, relevant and limited to the purposes of the processing. The CONTROLLER shall make available to the PROCESSOR all the information necessary to carry out the services subject to the assignment.
The CONTROLLER warns the PROCESSOR that, if it determines on its own the purposes and means of the processing, it shall be considered a data controller and shall be subject to compliance with the provisions of the applicable regulations as such.
4. Obligations and rights of the PROCESSOR
The PROCESSOR undertakes to respect all the obligations that may correspond to it as a data processor in accordance with the provisions of the applicable regulations and any other provision or regulation that is equally applicable to it.
The PROCESSOR shall not allocate, apply or use the data to which it has access for a purpose other than the assignment or that entails a breach of this contract.
The PROCESSOR shall make available to the CONTROLLER the information necessary to demonstrate compliance with the contract, allowing the inspections and audits necessary to assess the processing.
5. Personnel authorised to carry out the processing
The PROCESSOR guarantees that the personnel authorised to carry out the processing have expressly and in writing committed to respect the confidentiality of the data or are subject to a legal obligation of confidentiality of a legal nature.
The PROCESSOR shall take measures to ensure that any person acting under its authority who has access to personal data can only process them following the instructions of the CONTROLLER or is obliged to do so under the applicable legislation.
The PROCESSOR guarantees that the personnel authorised to carry out the processing have received the necessary training to ensure that the protection of personal data is not put at risk.
6. Security measures
The PROCESSOR, as a result of the risk management process it has carried out on the entrusted processing operations, has adopted technical and organisational security measures that, among others, include the requirements demanded by artículo 32 del RGPD, in order to guarantee a level of security appropriate to the risk that the processing entails. The measures implemented are the following:
Organisational security measures
- Security policy and internal protocols documented and accessible to personnel.
- Periodic training and awareness-raising in data protection and information security.
- Confidentiality commitment signed/informed by all personnel with access to data.
- Confidentiality and data processing agreements with suppliers.
- Request and assessment of compliance guarantees from suppliers.
- Confidentiality and data processing agreements with clients.
- Control of processors and sub-processors (security due diligence).
- Risk management and periodic reviews of the measures adopted.
- Documented protocol for the management of incidents and security breaches.
- Consultation of notifications and alerts from sources specialised in information security and data protection.
Technical security measures
- Logging of access and operations (auditable logs).
- Secure access management (permissions, robust passwords, MFA, credential expiry, etc.).
- Use of encryption and/or pseudonymisation of personal data when the processing allows it.
- Access privileges according to users.
- Protected systems and networks (firewalls, antivirus, IDS/IPS, etc.).
- Prohibition of installing unlicensed software.
- Prohibition of filing confidential information on paper or removable media.
- Secure data transmission channels (HTTPS, VPN, SFTP).
- Periodic, encrypted, external backups with restoration drills.
- Business continuity and disaster recovery plan.
- Secure destruction of documentation, media and devices.
- Security audits carried out by independent personnel.
- System vulnerability analysis.
7. Security breach
Security breaches of which the PROCESSOR becomes aware must be notified without undue delay to the CONTROLLER for their information and the application of measures to remedy and mitigate the effects caused. Notification will not be necessary when it is unlikely to entail a risk to the rights and freedoms of natural persons.
The notification of a security breach must contain, as a minimum, the following information:
- Description of the nature of the breach.
- Categories and the approximate number of data subjects affected.
- Categories and the approximate number of data records affected.
- Possible consequences.
- Measures adopted or proposed to remedy or mitigate the effects.
- Contact details where more information can be obtained (DPO, security officer, etc.).
12. Use of Artificial Intelligence Systems
12.1 Obligation to Inform about the Use of AI: The Data PROCESSOR undertakes to immediately inform the Data CONTROLLER about the intended use of any AI system that processes information of the contracting company, whether personal data or otherwise; and whether such use is carried out directly by the PROCESSOR or indirectly by any of its SUB-PROCESSORS.
12.3 Use of Information in AI Development: The use of information of the contracting company, the data CONTROLLER, to develop, train or improve general-purpose artificial intelligence models, whether those of the provider or of a third party, is prohibited. In the event that this is done, the PROCESSOR must request authorisation and notify the CONTROLLER.
12.4 Review and Approval: Before implementing any new use of AI or changing the AI methods or tools already used in the processing of personal data, the PROCESSOR must obtain the written approval of the Data CONTROLLER.
16. Applicable Legislation and Jurisdiction
This contract shall be governed by the clauses contained herein and, for matters not provided for, by the Spanish and European regulations applicable in the field of personal data processing.
The parties, for any matter relating to the interpretation or application of this contract, expressly submit, with waiver of their own jurisdiction, to the jurisdiction of the Courts and Tribunals of the city of the CONTROLLER.
DUKAT ORB SL — NIF B75963934 · Passeig del Bellesguard, 12 - 08320 El Masnou (Barcelona) ESPAÑA · compliance@dukat.es
Document in accordance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD). Last updated: 29-06-2026. Last updated: 29-06-2026
