Privacy Policy
I. PRIVACY AND DATA PROTECTION POLICY
Respecting the provisions of current legislation, Maindrop (hereinafter also the “Website”) undertakes to adopt the necessary technical and organizational measures, according to the security level appropriate to the risk of the collected data.
Laws incorporated into this privacy policy
This privacy policy is adapted to the current Spanish and European regulations regarding the protection of personal data on the internet. In particular, it complies with the following provisions:
- Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016 (GDPR).
- Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).
- Royal Decree 1720/2007, of December 21, which approves the Development Regulation of Organic Law 15/1999 (RDLOPD).
- Law 34/2002, of July 11, on Information Society Services and Electronic Commerce (LSSICE).
Identity of the data controller
The data controller for the personal data collected on Maindrop is:
- Atlas Engion SL
- NIF/CIF: B09652223
- Registry: Registro Mercantil de Girona, T 3362, F 96, S 8, H GI 69722, I/A 1
- Representative: Juan Luis Pintiado Pibernat
- Address: C/ Emili Grahit, 91, Parc Científic i Tecnològic de Girona
- Contact phone: +34 872 206 327
- Contact email: hello@maindrop.io
Personal data registry
In compliance with the GDPR and the LOPDGDD, the personal data collected by Maindrop through the forms available on its pages will be incorporated and processed in a file for the following purposes:
- To facilitate, streamline, and fulfill the commitments established between Maindrop and the user.
- To respond to user inquiries or requests
Additionally, a record of processing activities is maintained in accordance with the provisions of Article 30.5 of the GDPR.
Principles applicable to the processing of personal data
The processing of the user’s personal data will be governed by the following principles:
- Principle of lawfulness, fairness, and transparency: Informed consent from the user will be required at all times.
- Principle of purpose limitation: Data will be collected for specific, explicit, and legitimate purposes.
- Principle of data minimization: Only data strictly necessary will be collected.
- Principle of accuracy: The data will be accurate and up to date.
- Principle of storage limitation: The data will be retained only for as long as necessary.
- Principle of integrity and confidentiality: The data will be processed securely and confidentially.
- Principle of proactive responsibility: The data controller will ensure compliance with these principles.
Categories of personal data
The categories of data processed by Maindrop are only identifying data. No sensitive data, as defined in Article 9 of the GDPR, are processed.
Legal basis for the processing of personal data
The legal basis for the processing of personal data is the user’s consent.
- The user may withdraw their consent at any time, without affecting the use of the Website.
- When data is required for forms, the user will be informed if its completion is mandatory.
Purposes of personal data processing
The personal data collected is processed for the following purposes:
- To facilitate and fulfill the commitments established with the user.
- To respond to user inquiries or requests.
- For commercial purposes, personalization, statistical operations, and activities inherent to the corporate purpose of Maindrop.
Personal data retention periods
Personal data will be retained for the minimum necessary period, which will be:
- 6 months, or until the user requests its deletion.
Recipients of personal data
The user’s personal data will not be shared with third parties.
Personal data of minors
Only individuals over 14 years of age may give their consent for data processing. For minors under 14, parental or guardian authorization is required.
Security and confidentiality of personal data
Maindrop is committed to adopting appropriate technical and organizational measures to ensure the security of personal data, preventing its alteration, loss, or unauthorized access.
In the event of a security breach that presents a high risk, the user will be informed without undue delay.
Rights derived from personal data processing
he user may exercise the following rights with Maindrop:
- Right of access: To obtain information about their data and its processing.
- Right of rectification: To request the correction of inaccurate data.
- Right to erasure (“right to be forgotten”): To request the deletion of their data.
- Right to restriction of processing: To restrict the processing of their data.
- Right to data portability: To request the transfer of their data to another controller.
- Right to object: To request the cessation of the processing of their data.
- Right not to be subject to automated decisions: To avoid decisions based solely on automated processing.
To exercise these rights, the user must send a request to:
- Postal address: C/ Emili Grahit, 91, Parc Científic i Tecnològic de Girona
- Email: hello@maindrop.io
It should include:
- Name, surname, and a copy of the ID card.
- Request with specific reasons.
- Notification address.
- Date and signature.
Links to third-party websites
The Website may include links to third-party pages, which will have their own privacy policies.
Complaints to the supervisory authority
The user has the right to file a complaint with a supervisory authority, such as the Spanish Data Protection Agency (AEPD): https://www.aepd.es.
II. ACCEPTANCE AND CHANGES TO THE PRIVACY POLICY
Use of the Website implies acceptance of this Privacy Policy. Maindrop reserves the right to modify this policy, and it is recommended that the user review it periodically.