Contacts
CLIENT ACCESS

Privacy policy

It applies to all persons who access our website at https://bgestsolutions.com/ (“Website”), contract or request information about our business advisory services (“Services”), or participate in activities organized by our company, such as presentations, working breakfasts, webinars, conferences, seminars, and other events of a similar nature. We recommend that you read this Privacy Notice in its entirety to ensure you are fully informed.

 

1. Controller of the processing of personal data

BOOKGEST SOLUTIONS, S.L. (BookGest), with registered office at Paseo de Gracia 103, 6th floor, 08008 Barcelona (Spain), is the entity responsible for processing your personal data for the purposes described below.

2. Data protection officer

You may contact our Data Protection Officer at the aforementioned BookGest postal address, or at the email address protecciondatosbgs@bgestsolutions.com

3. How do we obtain your personal data?

The data we hold about you has been obtained through the commercial or contractual relationships that you, or the company, entity, or organization for which you work or collaborate, have maintained, or currently maintain, with BookGest, or with the professionals who make up our company.

4. What personal data do we process, for what purpose and for what reason?

Below is a list of these purposes, indicating what data will be processed (type of data) and for what reason or on what grounds we rely on (legal basis). The processing operations listed below are applicable to any category of data subject affected by them, unless otherwise specified. Likewise, we may also process any additional data that you provide to us or that is generated in the course of your relationship with BookGest for the stated purposes.

PROVISION OF BUSINESS ADVISORY SERVICES

TYPE OF DATA
  • Identification data: name, surname.
  • Contact details: email, telephone number.
  • Any personal data you provide to us and that is generated in the course of the relationship.

PURPOSE

We process your data for the exclusive purpose of providing you with the business advisory services that you have requested or contracted from us.

Also to provide you with information and professional collaboration proposals regarding those business advisory services in which you have shown an interest or have requested from us.

LEGAL BASIS

The processing of your personal data is necessary to comply with our contractual or pre-contractual obligations towards you, or towards the organization for which you work or collaborate, in relation to the business advisory services that you have contracted from us, or about which you have requested information from our company.

USER REGISTRATION IN THE BOOKGEST ACCOUNT

TYPE OF DATA

Those requested for restricted client access via the website.

  • Identification data.

PURPOSE

Registration and maintenance of your Bookgest user account, including, where applicable, data modifications and account deletion, in relation to the provision of services from Bookgest to its users.

LEGAL BASIS

The execution of the contractual relationship established as a result of accepting the registration terms and conditions.

RELATIONS WITH CORPORATE / PROFESSIONAL CONTACTS

TYPE OF DATA
  • Identification data: name, surname.
  • Contact details: email, telephone number.
  • Data related to the relationship established with BookGest.

PURPOSE

Maintenance of relationships of any kind with the company, entity, or organization for which you work or collaborate, or with you if you are an independent professional, contacting through the Website or any form, communication channel, or email inbox, including through the delivery of business cards to BookGest staff.

LEGAL BASIS

The legitimate interest of BookGest derived from contact for corporate reasons with the data subjects, which is expressly recognized by privacy regulations. In particular, by the Organic Law on Personal Data Protection and Guarantee of Digital Rights.

REQUESTS, INQUIRIES AND CLAIMS

TYPE OF DATA

Those requested in the personal data collection form and at least the following:

  • Identification data: Name, surname, username.
  • Contact details: e-mail.
  • Data related to the request or application provided by the user.

PURPOSE

To attend to requests, budget requests, suggestions, inquiries, or claims through the “Contact” section of the Platforms, or through other channels.

LEGAL BASIS

It is based on the existing contractual or pre-contractual relationship between the user and BookGest by offering the inquiry response service.

REGISTRATION IN ACTIVITIES AND CONFERENCES ORGANIZED BY BOOKGEST

TYPE OF DATA
  • Identification data: Name, surname.
  • Contact details: email, telephone.
  • Company where you work.

PURPOSE

Management of registration and participation in the activity/conference organized by BookGest for which you register.

LEGAL BASIS

The processing of your personal data responds to the need to comply with our contractual obligations to you.

SENDING OF COMMERCIAL COMMUNICATIONS

TYPE OF DATA
  • Identification data: Name, surname.
  • Contact details: e-mail, Postal code, telephone number.

PURPOSE

Sending of commercial communications, including by electronic means, including email, about products, services, activities, news from BookGest.

In the case of having a prior relationship with BookGest, commercial communications may be sent relating to BookGest services that are of a similar nature to those that motivate the relationship between BookGest and you, or between BookGest and the company, entity, or organization for which you work or collaborate.

LEGAL BASIS

The processing of your personal data is legitimized by the express consent you provide to us. You may withdraw your consent and unsubscribe from these communications at any time.

In the case of having a prior relationship with BookGest, the processing of your personal data for sending promotional information about BookGest activities similar to those motivating the relationship with you, or with the company, entity, or organization for which you work or collaborate, responds to a legitimate interest of our entity and is authorized by current regulations.

LEGAL OBLIGATIONS

TYPE OF DATA
  • Any personal data you provide to us and that is generated in the course of the relationship.

PURPOSE

Compliance with our legal civil, commercial, tax, accounting obligations and those relating to compliance with personal data protection regulations, among others that may apply.

LEGAL BASIS

Complying with a legal obligation.

REGISTRATION/ SUBSCRIPTION TO OFFICIAL BOOKGEST PAGES AND USER PROFILES ON SOCIAL NETWORKS

BookGest has active profiles on different social networks; the following personal data processing operations are applicable to individuals who become data subjects of BookGest by virtue of being a member, following, or being part of said profiles:

TYPE OF DATA

Those personal data allowed by the privacy policy of the social network in which you have a user account/profile, as well as the privacy settings you have as a user of said social network. This data depends on your own privacy configuration of the social network and the privacy policy of said social network.

PURPOSE

Interaction of your profile on the corresponding social network with BookGest, including responding to inquiries and comments published on public profiles.

LEGAL BASIS

BookGest will carry out this personal data processing in compliance with the obligations derived from your status as a registered user on the social network and the conditions of use of said social network.

MANAGEMENT OF CANDIDACIES

TYPE OF DATA

Those deposited by the data subject in the various data entry channels of BookGest, as well as others made available to them, and at least:

  • Identification data: Name, surname, age, Curriculum Vitae.
  • Contact details: e-mail, telephone, address.
  • Browsing data.

Data generated during the selection processes in which you participate will also be subject to processing, which implies the possibility of conducting an analysis of your personal profile to evaluate your suitability for the corresponding vacant position. Among these additional data, data published on social networks whose privacy settings are not restricted to third parties and/or data published on the internet may be processed.

PURPOSE

To attend to incoming job applications and carry out the relevant actions to manage the application and evaluate your suitability to join BookGest.

LEGAL BASIS

The processing of your personal data is legitimized as it is necessary for the application, at the request of the candidate, of pre-contractual measures or the intention to conclude a contract.

5. Are personal data communicated to third parties?

Your data may be transferred to the recipients indicated below, for the reasons explained below:

RECIPIENT

Service providers

PURPOSE

Providers that need to access your data for the provision of services that BookGest has contracted from said providers, and with whom BookGest has signed the necessary confidentiality and personal data processing contracts required by regulations to protect your privacy.

LEGAL BASIS

Contractual relationship.

RECIPIENT

Communications to third parties necessary to provide our services to you

PURPOSE

When necessary to comply with the provision of services you contract from us (banks, insurance companies, public administrations, opposing parties, court procurators, notaries, or other third parties about whom you will be duly informed).

LEGAL BASIS

Necessary to comply with what you request from us (contractual relationship and legal obligation).

RECIPIENT

Public Administrations

Courts and tribunals

Law enforcement agencies

 

PURPOSE

For compliance with the legal obligations to which BookGest is subject due to the development of its activity, and in the cases provided for by Law.

LEGAL BASIS

Complying with a legal obligation.

At BookGest, we will not share your data with other third parties without first obtaining your consent, except in those cases where it is necessary for compliance with the legal or contractual obligations to which BookGest is subject at any given time by its nature and activity.

If BookGest makes other communications of personal data in the future, it will inform you in a timely manner.

6. Are international transfers carried out with your data?

BookGest may contract the services of providers located in countries outside the European Economic Area, based on adequacy decisions of the European Commission. In this case, the country is considered to have regulations equivalent to European ones. In the event that BookGest needs to contract services from providers located in countries that do not have regulations equivalent to European ones, their contracting will include all the guarantees and safeguards required by regulations to preserve your privacy, following verification of the legislation of the country of destination.

Such safeguards may consist of the application of contractual clauses and additional guarantees thereto, in accordance with the regulations of each country of destination, or binding corporate rules approved by data protection authorities. We also inform you that regulations allow us to send your data to said countries if it is necessary to comply with our obligations derived from the service you request from us.

For more information about the guarantees to your privacy, or the countries of destination to which we need to transfer your data to comply with our contractual obligations to you, you may contact BookGest through the addresses indicated in the “Exercise of rights” section of this Privacy Policy.

7. Automated decisions

BookGest does not make decisions that may affect you based solely on the automated processing of your personal data. All decision-making processes related to the processing purposes described above are carried out with human intervention.

The profiling indicated in the candidate management purposes will under no circumstances be used in decision-making by our entity that could have legal effects for you or significantly affect you.

8. Retention period

Your personal data will be kept for as long as your relationship with BookGest is maintained and, after the termination of said relationship for any reason, during the applicable legal limitation periods. In this scenario, they will be processed solely for the purpose of proving compliance with our legal or contractual obligations. Once these limitation periods have expired, your data will be deleted or, alternatively, anonymized.

9. Exercise of rights

You may exercise your rights of access, rectification, erasure and portability, restriction and/or objection to processing, through the indicated postal and email addresses.

Likewise, if you consider that the processing of your personal data violates regulations or your privacy rights, you may file a complaint:

– Through the indicated postal and email addresses.

– Before the Spanish Data Protection Agency, through its electronic office (www.aepd.es), or its postal address.

10. Changes, modifications and updates

BookGest reserves the right to review this Privacy Policy at any time it deems appropriate, in order to reflect regulatory changes, good practices, or to update personal data processing activities. You will be informed about such updates in accordance with regulatory requirements if your rights are significantly affected as a consequence of said modification or update.

DATA PROCESSING FOR WHICH YOU OR YOUR COMPANY ARE RESPONSIBLE

For the provision of our legal advisory services, we may need to process personal data for which you, or your company or organization, are the data controller. Below we present our Privacy Declaration, which details our privacy and confidentiality obligations and commitments in relation to the processing of such data by BookGest.

PRIVACY DECLARATION OF BOOKGEST SOLUTIONS, S.L.RESPECTO AL TRATAMIENTO DE REGARDING THE PROCESSING OF PERSONAL DATA ON BEHALF OF ITS CLIENTS

BOOKGEST SOLUTIONS, S.L., with CIF B85123701, domiciled in Barcelona, Paseo de Gracia 103, 6th floor, 08008 (hereinafter BookGest).

STATES

For the provision of its legal advisory services (hereinafter “the Services”), BookGest needs to process personal data under the responsibility of its clients.

To regulate this access in accordance with the provisions of Regulation (UE) 2016/679 of the European Parliament and of the Council, of April 27, 2016, (hereinafter, GDPR), and its implementing regulations, BookGest commits to the following confidentiality and data processing obligations:

FIRST.- PURPOSE.
The provision of the contracted Services implies the performance by BookGest of the following processing operations: registration, consultation, conservation, dissemination, modification, and erasure of personal data.

SECOND.- DURATION.
The confidentiality obligations of BookGest included in this Privacy Declaration shall be in force throughout the entire duration of the provision of the Services. Notwithstanding the foregoing, BookGest undertakes to continue respecting the obligations established in this Privacy Declaration after the termination, completion, or expiration of the Services.

THIRD.- PURPOSE OF PROCESSING.
Personal data will be processed solely to carry out the provision of the Services. If BookGest considers it necessary to carry out data processing with a different purpose, it must request prior written authorization from the Client. In the absence of such authorization, BookGest may not carry out said processing.

FOURTH.- TYPE OF DATA PROCESSED AND CATEGORIES OF DATA SUBJECTS
4.1 The types of personal data of the Client that BookGest will process are the following:

  • Identification data
  • Personal characteristics data
  • Employment details data
  • Commercial information data
  • Economic, financial, and insurance data
  • Transactions of goods and services data

4.2 The categories of data subjects for whom the client is the data controller, and whose data will be processed by BookGest for the provision of the services, are the following:

  • Clients.
  • Potential Clients.
  • Suppliers.
  • Contact persons.
  • Employees.
  • Third parties related to legal advice.

FIFTH.- OBLIGATIONS OF BOOKGEST
BookGest undertakes to comply with the following obligations:

  1. Process personal data solely to carry out the provision of the contracted Services, complying with the written instructions provided by the Client at any given time (unless there is a regulation that obliges complementary processing; in such case, the processor shall inform the controller of that legal requirement prior to processing, unless such Law prohibits it for important reasons of public interest).

2. Maintain the duty of secrecy regarding the personal data to which it has access, even after the contractual relationship has ended, as well as guarantee that the persons under its charge have committed in writing to maintain the confidentiality of the processed personal data.

3. Guarantee, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as risks of varying probability and severity for the rights and freedoms of natural persons, that it will apply appropriate technical and organizational measures to ensure a level of security appropriate to the risk, which where applicable includes, among others:

  • the pseudonymization and encryption of personal data;
  • the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services;
  • the ability to restore the availability and access to personal data rapidly in the event of a physical or technical incident;
  • a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.

In assessing the appropriate level of security, account shall be taken in particular of the risks that are presented by data processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed. In any case, taking into account the type of processing to be performed, at least the security measures identified in the Annex to this Privacy Declaration will be complied with.

  1. Keep under its control and custody the personal data accessed on the occasion of providing the Service and not to disclose, transfer, or in any other way communicate them, even for their preservation, to other persons external to it and to the provision of the Service. However, the Client may expressly authorize the Processor in writing to resort to another Processor (hereinafter, the “Subcontractor”), whose identification details (full corporate name and Tax ID/NIF) and subcontracted services must be communicated to the Client, prior to the provision of the service, with a minimum of one (1) month’s notice. BookGest shall inform the Client in the same way of any planned changes concerning the addition or replacement of Subcontractors, thereby giving the controller the opportunity to object to such changes.

In the event of making use of the power recognized in the previous paragraph, BookGest is obliged to transfer and communicate to the Subcontractor the set of obligations derived for BookGest from this Privacy Policy and, in particular, the provision of sufficient guarantees that it will apply appropriate technical and organizational measures so that the processing conforms to applicable regulations.

In any case, access to the data carried out by natural persons providing their services to BookGest acting within its organizational framework by virtue of a commercial and non-labor relationship is authorized. Likewise, access to data is authorized for companies and professionals that BookGest has contracted within its internal organizational scope to provide general or maintenance services (IT services, advice, audits, etc.), provided that such tasks have not been arranged by BookGest for the purpose of subcontracting all or part of the Services it provides to the Client with a third party.

In the event that the Subcontractor provides its services from countries that do not have personal data protection regulations equivalent to European ones (“Third Countries”), BookGest undertakes to:

  • Inform the Client of this circumstance, and, if applicable, collaborate with the Client in processing the corresponding prior authorization for the international transfer of data to the corresponding Third Country; and
  • To establish as many safeguards as are required by European personal data protection regulations regarding international data transfers to Third Countries, and in particular to sign agreements with data importers in Third Countries based on the Model Clauses approved for this purpose by the European Union authorities.
  1. Delete or return to the Client, at their choice, all personal data to which it has had access to provide the Service. Likewise, BookGest undertakes to delete existing copies unless there is a legal rule requiring the preservation of personal data. However, BookGest may retain the data, duly blocked, as long as liabilities could derive from its relationship with the Client.

2. Notify the client without undue delay of any personal data security breaches of which it becomes aware, supporting the Client in notifying the Spanish Data Protection Agency or another competent Supervisory Authority, and where applicable, the data subjects of the security breaches that occur, as well as providing support, when necessary, in conducting data protection impact assessments and prior consultation with the Spanish Data Protection Agency, when appropriate, as well as assisting the Client so that they can comply with the obligation to respond to requests for the exercise of rights.

3. Cooperar with the Spanish Data Protection Agency or another Supervisory Authority, at its request, in the performance of its duties.

4. Make available to the Client all the information necessary to demonstrate compliance with the obligations established in this Privacy Declaration and to allow and contribute to the performance of audits, including inspections, by the Client or a third party authorized by them.

ANNEX 1

General security measures (required whenever any of the identified processing operations occur):

  • Implementation of an inventoried procedure and control of entry and exit of media and documents.
  • Definition and implementation of a procedure for the pseudonymization of personal data in cases where it is technically possible.
  • Identification, dissemination, and documentation of the roles and obligations of staff with access to the data.
  • Definition and implementation of a user identification and authentication procedure.
  • Definition and implementation of a data access control procedure.
  • Definition and implementation of an incident logging procedure.
  • Definition and implementation of a backup copy procedure.
  • Definition of the archiving criteria for media and storage devices.
  • Definition and implementation of regular security audits to regularly test, assess, and evaluate the effectiveness of technical and organizational measures to ensure the security of processing.
  • Appointment of a security manager(s) or, where applicable, a Data Protection Officer.
  • Definition and implementation of physical access controls.
  • Definition and implementation of a service continuity plan.

Special security measures (required whenever several of the identified processing operations occur, or any of them deemed particularly sensitive):

  • Definition and implementation of a backup and recovery procedure.
  • Definition and implementation of a media encryption procedure.
  • Definition and implementation of a procedure for the anonymization of personal data in cases where it is technically possible.
  • Definition and implementation of a data access log procedure.
  • Definition and implementation of a communications encryption procedure.