Logo de la inmobiliaria Mais en costa adeje, Tenerife

MAISONS

Privacy and Data Protection Policy

In compliance with the provisions of Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data hereinafter, the “GDPR”, and Article 11 of Organic Law 3/2018 of 5 December 2018 on Personal Data Protection and the Guarantee of Digital Rights, we hereby inform you of the following:

The User must carefully read this Privacy Policy, which has been drafted in clear and accessible language to facilitate its understanding, with the aim of enabling the User to decide freely, knowingly and voluntarily whether they wish to provide their own personal data or that of third parties to Mentores En Activos Inmobiliarios, S.L. hereinafter, the “Entity”.

Information on the Data Controller

  • COMPANY NAME: Mentores En Activos Inmobiliarios, S.L.
  • Tax Identification Number: B70370077
  • REGISTERED ADDRESS: Calle La Borda, Edificio Amanecer, Local 3, 38670 Adeje, Santa Cruz de Tenerife
  • EMAIL ADDRESS OF THE DATA PROTECTION AND PRIVACY OFFICER: in**@**************ia.com

Purpose, Legal Basis and Retention of Your Personal Data

The Entity shall process the personal data provided by the User for the following purposes and for the retention periods indicated below:

  • To manage the provision and performance of the contracted services and/or products, as well as the drafting, monitoring and management of contracts, offers and service proposals, including the data of the persons whose involvement is necessary for such purposes. The legal basis for this processing is the performance of a contract or the application of pre-contractual measures at the request of the data subject. In this case, we shall retain the personal data for as long as the contractual or pre-contractual relationship remains in force and, once it has ended, for the legally required periods in order to address any potential liabilities arising therefrom.
  • To manage and respond to communications, any type of request, suggestion, complaint or petition submitted by whistleblowers/users through the Internal Reporting System, in accordance with Law 2/2023 of 20 February, regulating the protection of persons who report regulatory infringements and the fight against corruption. These communications may involve their management and forwarding, where appropriate, to the department responsible for their due handling and for compliance with the applicable regulatory framework. The legal basis for this processing is compliance with legal obligations applicable to the Entity. Data relating to reports received and internal investigations shall be retained for the period necessary and proportionate for the purposes of complying with the Whistleblower Protection Law, and in no case for longer than ten years. Three months after receipt, the communications shall be deleted, except where retention is necessary to prove and evidence the existence and operation of the System and/or on the basis of other regulatory compliance requirements associated with the information, with the identity of the whistleblower being anonymised in an independent area with appropriate security measures.
  • To send informative communications about products or services similar to those already contracted by the Client. The legal basis for this processing is the legitimate interest of the Entity, within the framework of a prior contractual relationship and provided that such communications refer to the Entity’s own products or services similar to those initially contracted, always guaranteeing the possibility to object in each communication. In the case of electronic communications, this processing is based on the provisions of Article 21.2 of Law 34/2002 on Information Society Services and Electronic Commerce hereinafter, the “LSSI”. Personal data shall be retained until the right to object is exercised or the data subject requests to unsubscribe from receiving such communications.
  • Within the framework of managing employment relationships, the Entity may process personal data of employees, candidates or related personnel for the following purposes:
    • To manage the employment relationship, including the formalisation, performance and termination of the employment contract, as well as administrative, accounting and payroll management.
    • To manage attendance control, time recording and compliance with working hours.
    • To organise and manage mandatory training activities or training activities necessary for the performance of the job.
    • To comply with obligations relating to occupational risk prevention, health surveillance and psychosocial risk management.
    • To exercise the employer’s monitoring powers provided for under employment regulations, in accordance with Article 20.3 of the Workers’ Statute.
    • To manage internal communications necessary for the proper performance of work activities, including operational notices, alerts or access to corporate tools and documentation. Such communications may be made through personal contact channels provided by the data subject, where necessary for the development of the employment relationship, with corporate channels being used preferably where available.
    • To verify the absence of conflicts of interest or situations that may compromise the integrity, security or regulatory compliance of the Entity.
    • To guarantee the application of equality, non-discrimination, harassment prevention and protection policies for vulnerable groups in the workplace.
    • To process the image of employees for corporate or dissemination purposes, where express prior consent has been obtained.

The legal basis for these processing activities is, depending on the specific nature of each processing operation, the performance of the employment contract Article 6.1.b GDPR, compliance with legal obligations Article 6.1.c GDPR, the legitimate interest of the Entity Article 6.1.f GDPR or the consent of the data subject Article 6.1.a GDPR, where necessary. Personal data shall be retained for the duration of the employment relationship and, once it has ended, for the legally required periods in order to address any potential liabilities.

  • To send commercial communications, newsletters or mailings, where such communications are not covered by a prior contractual relationship under the terms indicated above. The legal basis for this processing is the consent of the data subject, granted freely, specifically, knowingly and unequivocally. Personal data shall be retained until the consent given is withdrawn or until the data subject requests to unsubscribe from receiving such communications.
  • To manage the receipt and assessment of applications, CVs and recruitment processes, including unsolicited applications submitted through the website or the contact email address, as well as their consideration for current or future vacancies that match the candidate’s profile. The legal basis for this processing is the consent of the data subject, expressed by submitting their application. Personal data shall be retained until consent is withdrawn and, in any event, for a maximum period of one year from receipt of the curriculum vitae.
  • To guarantee the security of persons, property and facilities through video surveillance systems. The legal basis for this processing of personal data is the legitimate interest of the Entity in preserving the security of its facilities, persons and property. Images shall generally be retained for a maximum period of 30 days from their capture, unless they must be retained for a longer period in order to prove the commission of acts against the integrity of persons, property or facilities, or to comply with a legal obligation.
  • To manage the professional relationship with suppliers, collaborators and third parties, including the maintenance of the commercial, administrative, accounting and billing relationship arising from the services contracted by the Entity. The legal basis for this processing is the performance of the contract and compliance with the legal obligations applicable to the Entity. Personal data shall be retained for the time necessary to manage the contractual relationship and, subsequently, for the legally required periods.
  • To manage and control internal regulatory compliance mechanisms, policies and procedures, including internal control actions and the prevention, detection and investigation of regulatory breaches or breaches of internal policies. The legal basis for this processing is compliance with legal obligations and, where appropriate, the public interest or the legitimate interest of the Entity in ensuring regulatory compliance and the integrity of its organisation. Personal data shall be retained for the time strictly necessary to process, investigate and close the actions and, subsequently, for the legally required periods.
  • To manage requests to exercise data protection rights received through the channel enabled by the Entity for this purpose. The legal basis for this processing is compliance with a legal obligation applicable to the data controller. Personal data shall be retained for the time necessary to process and resolve the request and, subsequently, for the legally required periods in order to prove that it has been properly handled.
  • To manage and respond to reports or communications concerning the prevention of and action against harassment, violence or particularly serious conduct, especially those affecting specially protected groups, including, where applicable, trans persons, LGBTI persons and minors, as well as to process any internal actions that may be appropriate. The legal basis for this processing is compliance with legal obligations, substantial public interest and, where applicable, the establishment, exercise or defence of legal claims, depending on the specific nature of the communication and of the data processed. Personal data shall be retained for the time strictly necessary to process the communication, conduct the investigation and adopt the appropriate measures and, subsequently, for the legally required periods. Where such communications are channelled through the Internal Reporting System, the periods provided for in Law 2/2023 of 20 February shall apply.
  • To comply with legal obligations applicable to the Entity, in commercial, tax, accounting, administrative, anti-money laundering, employment, data protection or any other matters that may be legally required. The legal basis for this processing is compliance with a legal obligation. Personal data shall be retained for the periods provided for in the applicable regulations in each case.
  • Likewise, the Entity may process personal data for any other purposes that are necessary to comply with legal obligations or specific regulatory requirements applicable to its activity.

The personal data processed generally come from the data subject. However, in certain cases, the data may come from third parties with whom the data subject has a relationship, such as client companies, collaborating entities or suppliers, as well as from publicly accessible sources, where legally appropriate. In such cases, the data subject shall be informed in the terms established in Article 14 of the GDPR.

Recipients of Your Personal Data and International Transfers

The Entity may disclose the personal data of the data subject to the following recipients, where necessary depending on the purpose of the processing and on the corresponding legal basis in each case:

  • Competent Public Administrations, such as the Social Security authorities, the Spanish Tax Agency, grant-managing bodies or the Public Prosecutor’s Office, where the disclosure of personal data is necessary to comply with legal obligations applicable to the Entity.
  • Mutual insurance companies collaborating with the Social Security system, occupational risk prevention services or other similar entities, where necessary to comply with employment, health and safety obligations or for the protection of employees.
  • Legal representatives of employees, including works councils, trade unions and prevention delegates, in cases where employment regulations apply.
  • Clients or entities linked to the provision of services, exclusively where it is essential to identify employees for the proper performance of the contracted service, with any disclosure being limited in all cases to adequate, relevant and not excessive data, in accordance with the principle of data minimisation.
  • Service providers acting as processors, with whom the Entity has entered into the corresponding data processing agreement in accordance with Article 28 of the GDPR.
  • Personal data may be disclosed, where necessary, to the competent authorities, the Public Prosecutor’s Office, judicial bodies or third-party processors providing services linked to the management of the Internal Reporting System, under the appropriate contractual and confidentiality safeguards.
  • Judicial authorities, the Public Prosecutor’s Office and Law Enforcement Authorities, where disclosure is necessary to comply with a legal obligation, for the establishment, exercise or defence of legal claims, or in compliance with requests or orders from such authorities.

As a general rule, no international transfers of personal data are envisaged. However, where technology service providers are used that may involve the processing of data outside the European Economic Area, such transfers shall be carried out in full compliance with Articles 44 et seq. of the GDPR, through the adoption of appropriate safeguards, such as the execution of standard contractual clauses approved by the European Commission or other valid mechanisms under the applicable regulations.

Personal Data Protection Rights

In order to guarantee transparency in the processing of your personal data, we inform you of the rights granted to you by Data Protection regulations. Each of these rights and how you may exercise them in relation to the personal data we hold are detailed below:

  • Right of access: You have the right to know whether the Entity is processing your personal data.
  • Right to rectification: You have the right to request the correction of inaccurate data.
  • Right to erasure: You have the right to request the deletion of your personal data where they are no longer necessary for the purpose for which they were collected.
  • Right to restriction of processing: You have the right to request that the use of your data be restricted, with the data being retained only for the defence of legal claims.
  • Right to object: You have the right to object to the processing of your personal data, unless legitimate grounds exist or the data are needed for the defence of legal claims.
  • Right to data portability: You have the right to receive the data in a structured and readable format in order to transfer them to another controller, where technically feasible.
  • Right to withdraw consent: You have the right to withdraw the consent given at any time, except where the processing is based on law or is necessary for a contracted service, without retroactive effect.
  • Right not to be subject to automated decision-making: You have the right not to be subject to automated decisions based on personal data that significantly affect you, such as profiling.

You may notify and process the exercise of your Rights and report any indication or knowledge you may have of possible security breaches, cyberattacks and/or possible breaches or irregularities concerning Data Protection regulations through the email address or channel enabled by the Entity for this purpose: https://www.corporate-line.com/cnormativo-grupomais

In the event of disagreements with the Entity in relation to the processing of your data, you have the right to lodge a complaint with the corresponding Data Protection Supervisory Authority. In Spain, this Authority is the Spanish Data Protection Agency (www.aepd.es).

The Entity may request additional information to confirm the identity of the applicant where there are reasonable doubts as to their identity and shall respond to the request within a maximum period of one month from receipt, which may be extended in particularly complex cases.

Internal Reporting System

The Entity has implemented an Internal Reporting System, hereinafter “SIIF”, which constitutes a fundamental pillar for supervision, control and prevention in the field of regulatory compliance, reflecting the highest commitment, rigour and professionalism in matters of security, confidentiality, data protection, experience, independence and knowledge in the handling of communications received.

The internal reporting channels integrated into the System have been implemented through technical tools that include all the necessary requirements to provide and guarantee the aforementioned commitments. Likewise, the SIIF guarantees the basic principles of anonymity, proper registration, preservation and non-alteration, prevention of conflicts of interest, protection of the whistleblower and prevention of retaliation.

Through this System, every whistleblower must report in good faith any indication, suspicion or evidence of possible regulatory breaches, offences, unethical conduct and, in general, any breach of the protocols, rules and codes of conduct of the Entity.

Access to the SIIF has been enabled in a separate section of our website.

Processing of Personal Data in the Internal Reporting System

Within the framework of the Internal Reporting System, SIIF, the Entity shall process personal data for the purpose of managing and handling the communications received, as well as analysing, verifying and investigating the reported facts, adopting, where appropriate, the corresponding corrective, disciplinary or legal measures.

This processing is carried out in compliance with the legal obligations established in Law 2/2023 of 20 February, regulating the protection of persons who report regulatory infringements and the fight against corruption, as well as, where applicable, on the basis of the Entity’s legitimate interest in preventing and detecting unlawful conduct or conduct contrary to internal regulations.

Within the framework of these actions, the following categories of personal data may be processed:

  • Identification and contact details of whistleblowers, affected persons and third parties involved.
  • Professional and employment data linked to the relationship with the Entity.
  • Information relating to the reported facts, including descriptions, assessments or associated documentation.
  • Where applicable, special categories of data pursuant to Article 9 of the GDPR, where their processing is strictly necessary for the investigation and there is sufficient legal basis under the applicable regulations.

Personal data may come from the whistleblower, whether identified or anonymous, from the affected persons or from third parties participating in the investigation.

Confidentiality and Protection of the Whistleblower

The Entity guarantees the confidentiality of the identity of the whistleblower, as well as that of any third party mentioned in the communication and of the affected persons. Access to the data shall be restricted exclusively to authorised personnel involved in the management and investigation of the communications.

Likewise, any form of retaliation, discrimination or unfavourable treatment against the whistleblower or against those who cooperate in the investigation is expressly prohibited, in accordance with the terms provided for in Law 2/2023.

The exercise of data protection rights may be limited where necessary to preserve the confidentiality of the whistleblower’s identity, avoid obstruction of the investigation or ensure the proper conduct of the proceedings, in accordance with the terms provided for in the applicable regulations.

Security and Control Measures

General

The Entity shall process personal data by applying appropriate technical, legal, organisational and security measures in order to guarantee the confidentiality and integrity of the information it manages, in accordance with the provisions of the applicable regulations.

Cybersecurity

As a specific concept complementary to the above, the Entity applies cybersecurity measures to prevent and manage possible attacks and fraud by cybercriminals that threaten the privacy and protection of the data processed and accessed by our Entity within the scope of its activities and operations.

In this regard, we wish to warn that, in the event of possible risk situations arising from communications whose content and/or format raise doubts as to their authenticity, we recommend disregarding them and contacting the Entity through the contact details indicated in this Privacy Policy.

Likewise, any request you receive originating from our Entity concerning changes to payment methods, requests for data or contact persons or confidential information, non-public information, bank details and/or credit card details and/or other official data, should not be acted upon without direct confirmation from our Entity through another alternative means.

We appreciate and require your cooperation in communicating and reporting any notification relating to this type of request and other possible cyberattack risk situations in which our Entity may be used, as well as any possible security risk of which you may become aware.

Assistance and Support

Data subjects may communicate to the Entity any questions regarding the processing of their personal data or the interpretation of our Policy by contacting the Data Protection and Privacy Officer through the email addresses indicated at the beginning of this Policy.

Updates and Amendments

The Entity reserves the right to amend and/or update the information on data protection whenever necessary for proper compliance with the applicable regulations in this area. If any amendment is made, the new text shall be published in this same section of the website.