Privacy Policy
1. Introduction
SATORISAN (hereinafter referred to as "we" or "the Company") is committed to protecting your personal data and privacy. This Privacy Policy applies to users (hereinafter referred to as "you") who browse, register, and purchase goods through the official Satorisan Spain website (es.satorisan.com). It explains how we collect, use, disclose, protect, and store your personal data when you use our website and purchase our products. We comply with the European Union’s General Data Protection Regulation (GDPR) as well as Spain’s Organic Law on the Protection of Personal Data and Guarantee of Digital Rights (Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y Garantía de los Derechos Digitales, hereinafter referred to as LOPDGDD). Any business processing personal data within Spain must comply with both the EU GDPR and Spanish data protection laws.
2. Data Controller
The Data Controller for this website is SATORISAN. Our registered address is Alameda de Recalde, 51, and our contact email is dangthuythuy13065@gmail.com. You may contact us regarding any data protection-related matters using the contact details provided above.
3. Personal Data We Collect
When you use our website, we may collect the following categories of personal data:
- Account and Order Information: Name, email address, postal address, telephone number, order details, and payment information.
- Browsing and Technical Information: IP address, device type, browser information, access times, and browsing behavior records (collected via technologies such as Cookies).
- Communication Records: When you contact our customer service team, we may record the content of our communications in order to improve the quality of our service.
4. Legal Basis for Data Processing and Purposes of Use
We process your personal data only when there is a lawful basis to do so. In accordance with Article 6 of the GDPR, we rely on the following legal bases:
- Performance of a Contract (GDPR Article 6(1)(b)): Processing your orders, completing payments, arranging for shipping and delivery, and handling returns and exchanges.
- Legitimate Interests (GDPR Article 6(1)(f)): Used to improve our website and products, implement security measures, and prevent fraudulent activities. - Your Consent (GDPR Article 6(1)(a)): Sending you marketing information and delivering personalized advertisements, provided you have explicitly opted in by checking the relevant box.
- Compliance with Legal Obligations (GDPR Article 6(1)(c)): Retaining necessary transaction records to fulfill tax and accounting legal obligations.
5. Data Retention Period
We retain your personal data only for as long as is necessary to fulfill the purposes outlined in this Privacy Policy:
- Order Information: Retained continuously throughout the duration of your active account. After your account is closed, we will continue to retain relevant transaction records as required by law (typically for ten years) to fulfill tax and legal obligations.
- Marketing Information: Retained until you withdraw your consent or unsubscribe from marketing communications.
- Browsing Data: Retained for a shorter duration—typically no longer than 26 months—based on data analytics requirements.
6. Data Recipients and Sharing
We share your personal data with the following third parties only when necessary:
- Logistics Service Providers: To deliver your orders.
- Payment Service Providers: To securely process your payments.
- Technology Providers: To host our website and provide data analytics services.
- Legal and Regulatory Authorities: When required by applicable laws and regulations, or to protect our legitimate interests.
All third-party service providers are required to comply with GDPR regulations and enter into appropriate Data Processing Agreements.
7. Data Security
We have implemented appropriate technical and organizational measures—including Transport Layer Security (TLS/SSL) encryption, access controls, and regular security audits—to protect your personal data against unauthorized access, loss, or destruction. Furthermore, we require our employees and relevant third parties to adhere to strict confidentiality obligations when handling personal data.
8. Your Data Protection Rights
In accordance with the EU General Data Protection Regulation (GDPR) and Spain’s LOPDGDD, you have the following rights regarding your personal data:
- Right of Access: To obtain a copy of the personal data we hold about you.
- Right to Rectification: To request that we correct any inaccurate or incomplete personal data.
- Right to Erasure (Right to be Forgotten): To request the deletion of your personal data under certain circumstances.
- Right to Restriction of Processing: To request the suspension of the processing of your personal data under certain circumstances. - Right to Data Portability: To have your data transferred to you or to a third party, to the extent that is technically feasible.
- Right to Object: To object to the processing of your personal data based on legitimate interests or for direct marketing purposes.
If you wish to exercise any of the aforementioned rights, please submit a written request using the contact details provided at the end of this Privacy Policy. We will respond to your request within one month of receipt. You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD – *Agencia Española de Protección de Datos*) at any time.
9. Direct Marketing
We will send you emails regarding new products, special offers, and promotional activities only with your explicit consent. You may withdraw your consent at any time by using the "Unsubscribe" link found in every marketing email or by contacting us directly. Furthermore, Spanish law mandates that email marketing must adhere to the principle of prior explicit consent (prior opt-in consent).
10. Cookies and Similar Technologies
Our website uses cookies and other tracking technologies to enhance your browsing experience and analyze website traffic.
- Strictly Necessary Cookies: Cookies that are essential for ensuring the basic functionality of the website (such as shopping carts and payment processes); these do not require your consent.
- Functional and Analytical Cookies: Used to remember your preferences and to generate anonymous visitor statistics. According to the latest guidelines from the Spanish Data Protection Agency (AEPD), such cookies may not be placed without your explicit consent. Your consent must be provided through a clear affirmative action (e.g., clicking "Accept"); merely continuing to browse or scrolling down the page does not constitute valid consent.
- Advertising and Marketing Cookies: Enabled only after you have actively opted in to provide your consent.
When you visit our website for the first time, we will request your consent via a cookie banner. You may also withdraw or modify your consent preferences at any time by clicking the "Cookie Settings" link located at the bottom of the website.