——————————— SECOND LAYERS ————————————
Updated 02/07/2024
The data controller analyses users’ browsing and behaviour in order to understand how its tools are used and to adapt them to their needs, as well as to improve its communication, marketing and customer service activities.
Data controllers | ARAVEN GROUP, S.L. and co-controller SHOP AND ROLL ESPAÑA, for the analysis of data extracted when opening and interacting with e-mails. |
Legal basis | Insofar as the execution of the contract justifies it: the processing is necessary for the execution of a contract to which the data subject is party or for the implementation at their request of pre-contractual measures (art. 6.1.b of the GDPR). In all other cases, the data subject gave their consent to the processing of their personal data for one or more specific purposes (art. 6.1.a GDPR). In order to obtain this consent, the data subject will be informed separately from any purchase and sale agreement, general terms and conditions or service contract. This processing is carried out on browsing data collected from the website, apps, etc. |
Purposes of the processing | In the event that the analytical processing is based on the execution of a contract, the analytics necessary for the execution of the contract will be performed: for example, the number of times each user has accessed the information or, if downloaded, the acknowledgement that they have accessed the information security communications sent to them by the data controller will be analysed, without any additional processing being carried out for this reason. In all other cases, where prior acceptance by the data subject is required, the purpose of the analytical processing of personal data will be:
|
Group | Users who access websites, applications or social profiles managed by the data controller, as well as those who open or respond to communications sent by the data controller. |
Categories of data | The analytics service providers aggregate the data they obtain to provide the data controller with quantitative information on the browsing and behaviour of people, without it being possible to identify the individual. The data processed are:
Particularly, in the case of e-mail analytics and in addition to the above, data will be obtained and analysed on the number of openings, time of opening, day of opening, forwarding, conversions (in the case of incorporating forms in e-mail), user clicks within internal links of the e-mail (with exits to: landing, website, direct mail to personal contact…), device from which it is opened, hardware, block and software, e-mail bounces, and unsubscribes. |
Target category | No data communications are envisaged. |
Data processors
| Google LLC – Google Analytics – https://analytics.google.com/analytics/web/ |
International transfers | The processor is Google Ireland, and the sub-processor is Google LLC, 1600 Amphitheatre Parkway Mountain View, CA USA. Security measure: data protection agreement with standard clauses through Google Workspace (formerly GSuite). https://privacy.google.com/businesses/processorterms/
|
Deletion period | The data will be kept for the time necessary to comply with the purpose for which they were collected and to determine any possible liabilities that may derive from said purpose and from the processing of the data. |
Additional information | No data protection impact assessment is required for this processing, for the data processed and as the data controller executes it, in accordance with the provisions of article 35 of the GDPR and article 28 of the Spanish Organic Data Protection Law (LOPD). |
Tagging of users according to their activity on the website, in the different companies of the Group and through advertising creativities in order to send them advertising and promotional content adapted to their preferences.
Data controller | The data controller is ARAVEN GROUP, S.L. and the co-controller is SHOP AND ROLL ESPAÑA. |
Legal basis | The data subject gave their consent to the processing of their personal data for one or more specific purposes (art. 6.1.a GDPR). In order to obtain this consent, the data subject will be informed separately from any purchase and sale agreement, general terms and conditions or service contract, and it will be obtained in the same way. |
Purposes of the processing | Tagging of users according to their activity on the website, on the sites and through advertising creativities in order to send them advertising and promotional content adapted to their preferences. |
Group | · Lead (people who can potentially become customers) · Users · Any other person |
Categories of data |
|
Target category |
|
Data processors | |
International transfers | No international transfers are envisaged. |
Deletion period | Until the data subject requests the cancellation or deletion of their data. |
Additional information | Not required for this processing, for the data processed and as the data controller executes it, in accordance with the provisions of article 35 of the GDPR and article 28 of the Spanish Organic Data Protection Law (LOPD). |
Sending of personalised messages with advertising and promotional content.
Likewise, surveys and consultations are carried out with different groups included in their processing in order to draw up reports on different areas and subjects, including their positioning in the market; to find out customer satisfaction.
Data controller | The data controller is ARAVEN GROUP, and the co-controller is SHOP AND ROLL ESPAÑA. |
Legal basis | The data subject gave their consent to the processing of their personal data for one or more specific purposes (art. 6.1.a GDPR):
For persons who have contracted with the controller: processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject that require the protection of personal data, in particular where the data subject is a child (art. 6.1.f of the GDPR). |
Purposes of the processing | · Sending of advertising or promotional communications by electronic, postal and telephone means.
|
Group | Customers and persons interested in the activities and information about the activities, products and services of the data controller or the content it creates, publishes or promotes:
|
Categories of data |
|
Category of recipients | No personal data transfers are envisaged. |
Data processors
| · Commercial agents: Where commercial purposes make it advisable due to the location of the data subject and the opportunities that the controller may offer them in their environment, data may be disclosed to commercial agents (acting as processors) with whom the controller has established and maintains security measures appropriate to the level of risk to personal data through processor contracts and on whom the controller conducts regular audits and inspections. · Peer-to-peer audience platforms to which the data controller allows access to data for the sole purpose of displaying targeted advertising to other peer users. |
International transfers | Not envisaged. |
Deletion period |
|
Additional information | No data protection impact assessment is required for this processing, for the data processed and as the data controller executes it, in accordance with the provisions of article 35 of the GDPR and article 28 of the Spanish Organic Data Protection Law (LOPD). |
The data controller promotes its activities through prize draws, raffles and other random combination games for advertising or promotional purposes, as well as through other non-random actions such as direct giveaways and juried competitions. As indicated in the terms and conditions, this processing activity is related to the activities of taking and using photographs and videos, as well as sending commercial advertising and promotional communications.
Data controller | The data controller is ARAVEN GROUP, and the co-controller is SHOP AND ROLL ESPAÑA. |
Legal basis | The data subject gave their consent to the processing of their personal data for one or more specific purposes (art. 6.1.a GDPR). |
Purposes of the processing |
|
Group |
|
Categories of data |
|
Target category |
|
Data processors |
|
International transfers | No international personal data transfers are envisaged |
Deletion period | The data will be kept for the time necessary to comply with the purpose for which they were collected and to determine any possible liabilities that may derive from said purpose and from the processing of the data. |
Additional information | No data protection impact assessment is required for this processing, for the data processed and as the data controller executes it, in accordance with the provisions of article 35 of the GDPR and article 28 of the Spanish Organic Data Protection Law (LOPD). Other related processing activities (see them for more information):
|
Photography and image and/or voice recording for (1) promotional activities and (2) advertising or promotional purposes of the data controller.
Data controller | The data controller is ARAVEN GROUP, and the co-controller is SHOP AND ROLL ESPAÑA. |
Legal basis | In the case of staff of Group companies: in connection with the management of their file, accreditations or other specific cases, and in the case of speakers at events and congresses, processing is necessary for the performance of a contract to which the data subject is a party or for the implementation of pre-contractual measures at the request of the data subject (art. 6.1.b of the General Data Protection Regulation).
For the case of recordings and broadcasts of attendees’ speeches at specific events: processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject that require the protection of personal data, in particular where the data subject is a child (art. 6.1.f of the General Data Protection Regulation).
Express consent for the other purposes, as set out in:
|
Purposes of the processing | Taking photographs and recording images and voice for:
|
Group |
|
Categories of data |
|
Target category | The data will be published on the pages and websites of the controller and disclosed to the media, where consent has been obtained from the data subject for such processing or, as the case may be, where it is necessary for the execution of a contract to which the data subject is a party or where the aforementioned legitimate interest of the controller has to be satisfied. In the case of publication on social networks, the terms and conditions of use thereof may apply. |
Data processors | Companies and agencies for content management, editing and delivery of audiovisual material. |
International transfers | No international personal data transfers are envisaged. |
Deletion period | The data will be kept for the time necessary to comply with the purpose for which they were collected and to determine any possible liabilities that may derive from said purpose and from the processing of the data. In all other cases, the processing of personal data will continue until the user withdraws their consent. |
Additional information | No data protection impact assessment is required for this processing, for the data processed and as the data controller executes it, in accordance with the provisions of article 35 of the GDPR and article 28 of the Spanish Organic Data Protection Law (LOPD). |
Provision of vacancies and selection of staff, both employees and external.
Data controller | The data controller is ARAVEN GROUP, and the co-controller is SHOP AND ROLL ESPAÑA. |
Legal basis | The processing is necessary for the execution of a contract to which the data subject is party or for the implementation at their request of pre-contractual measures (art. 6.1.b of the GDPR). Background checks on the data subject will be based on compliance with a legal obligation applicable to the controller (art. 6.1.c of the General Data Protection Regulation). The proactive search for candidates and details about them in third-party databases is based on the legitimate interest of discovering them for positions or getting to know them better in order to know whether the position fits their profile (art. 6.1.f of the General Data Protection Regulation). |
Purposes of the processing | Analysis and matching of the professional background of candidates. Analysis of the candidate’s personality when this is decisive for the envisaged tasks (e.g., teaching). The controller will analyse the documents submitted by the candidate, all content that is public and directly accessible through search engines, the profiles held on professional social networks, the data obtained in the entrance tests and the information revealed in the job interview, with the aim of assessing their candidacy and being able, if necessary, to offer them a position. This analysis may be conducted in order to discover and assess candidates you need for certain positions or assignments. |
Group | · Participants in selection processes. · Professionals with public profiles. |
Categories of data |
|
Target category | Companies at or with which the employee has worked, in order to check the data and verify their veracity. |
Data processors | Selection and Recruitment Companies
|
International transfers | No international personal data transfers are envisaged. |
Deletion period | The data will be kept for the time necessary to comply with the purpose for which they were collected and to determine any possible liabilities that may derive from said purpose and from the processing of the data. In the event that the candidate is not selected, the controller may keep their CV for a maximum of two years in order to incorporate it in future calls for applications, unless the candidate indicates otherwise or expresses a wish to keep it for a longer period, until the candidate withdraws their consent. |
Additional information | No data protection impact assessment is required for this processing, for the data processed and as the data controller executes it, in accordance with the provisions of article 35 of the GDPR and article 28 of the Spanish Organic Data Protection Law (LOPD). |
The controller manages payments, collections, recoveries and, where appropriate, any activity related to financial and/or economic activities.
Data controller | The data controller is ARAVEN GROUP, and the co-controller is SHOP AND ROLL ESPAÑA. |
Legal basis | GDPR: art. 6.1.b) Processing necessary for the execution of a contract to which the data subject is party or for the implementation at their request of pre-contractual measures. GDPR: art. 6.1.c). Processing necessary for compliance with a legal obligation applicable to the controller. GDPR: art.6.1.e). Processing necessary for the fulfilment of a mission carried out in the public interest or in the exercising of public powers conferred on the data controller, in accordance with the applicable regulations: · General Spanish Law 58/2002, of 17 December, on Taxation. · General Spanish Law 38/1998, of 17 November, on Subsidies. · Spanish Law 35/2006, of 28 November, on Personal Income Tax and partially amending the laws on Corporate Income Tax, Non-Resident Income Tax and Wealth Tax. · Spanish Law 37/2002, of 28 December, on Value Added Tax. |
Purposes of the processing | Necessary management of personal data in order to make payments, collections, recoveries and, where appropriate, refunds, etc. Registration and verification of data relating to VAT, Personal Income Tax, registrations with the Tax Authorities and Social Security, bank certificates, etc. |
Group |
|
Categories of data | · Name, surname(s). · Telephone. · Postal and electronic address. · ID number. · Signature, electronic signature. · Economic, financial and insurance data. · Bank and business details. · Certificates issued by the Public Administration for data subjects. |
Target category | · Financial institutions. · State Tax Administration Agency |
Data processors | Collection and recovery management companies and offices
|
International transfers | No international personal data transfers are envisaged. |
Deletion period | The data will be kept for the time necessary to comply with the purpose for which they were collected and to determine any possible liabilities that may derive from said purpose and from the processing of the data. Depending on the case, they may be kept for the periods established in the various applicable standards. |
Additional information | No data protection impact assessment is required for this processing, for the data processed and as the data controller executes it, in accordance with the provisions of article 35 of the GDPR and article 28 of the Spanish Organic Data Protection Law (LOPD). |
Processing activity related to the management of employment contracts for SHOP AND ROLL staff, including the management of training for them and other activities inherent to the employment relationship.
Data controller | ARAVEN GROUP and the co-controller is SHOP AND ROLL ESPAÑA. |
Legal basis | The management of the employment or commercial relationship has the following legal bases:
|
Purposes of the processing | Management of the employment relationship with the contracted staff:
· Issuance and payment of the payroll, as well as all the products derived from it. |
Group | · Contracted staff |
Categories of data |
· Details of their professional development working for the controller: training received, courses, conferences, etc. |
Target category |
|
Data processors | |
International transfers | No international personal data transfers are envisaged. |
Deletion period | The data will be kept for the time necessary to comply with the purpose for which they were collected and to determine any possible liabilities that may derive from said purpose and from the processing of the data. At the end of the contract, the retention periods will be, depending on the type of personal data, in accordance with the applicable regulations. |
Additional information | No data protection impact assessment is required for this processing, for the data processed and as the data controller executes it, in accordance with the provisions of article 35 of the GDPR and article 28 of the Spanish Organic Data Protection Law (LOPD). |
The controller hires professionals, suppliers, collaborating companies and commercial and business partners for different actions. To do so, they must contact the professionals or natural persons who perform their activities and/or represent the companies that sell products or provide services to them.
Data controller | The data controller is ARAVEN GROUP, and the co-controller is SHOP AND ROLL ESPAÑA. |
Legal basis | The processing is necessary for the execution of a contract to which the data subject is party or for the implementation at their request of pre-contractual measures (art. 6.1.b of the GDPR). The processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party and do not override the interests and fundamental rights and freedoms stipulated in (art. 6.1.f of the GDPR). |
Purposes of the processing | · Registration and management of contact details of suppliers and commercial and business partners.
|
Group | Service providers or vendors and, if they are legal entities, the physical contact persons. |
Categories of data | · Identification data · Details of the position: entity or body and position held.
|
Target category | · Financial institutions · State Tax Administration Agency
|
Data processors | Not envisaged
|
International transfers | No international personal data transfers are envisaged. |
Deletion period | The data will be kept for the time necessary to comply with the purpose for which they were collected and to determine any possible liabilities that may derive from said purpose and from the processing of the data. |
Additional information | No data protection impact assessment is required for this processing, for the data processed and as the data controller executes it, in accordance with the provisions of article 35 of the GDPR and article 28 of the Spanish Organic Data Protection Law (LOPD). |
Dealing with requests to exercise the rights established in the GDPR.
Data controller | ARAVEN GROUP and the co-controller is SHOP AND ROLL ESPAÑA. |
Legal basis | The processing is necessary for compliance with a legal obligation applicable to the controller (art. 6.1.C of the GDPR). Specifically, in order to receive, manage and respond to requests for the data subject’s rights (Chapter III of the GDPR). |
Purposes of the processing | To receive, manage and respond to requests for the data subject’s rights (Chapter III of the GDPR). |
Group | Any person |
Categories of data | · Identification data: name and surname(s), ID, address, telephone number, type of relationship with the controller, and signature. · Data relating to the corresponding exercise request. |
Target category | No transfers are envisaged. |
Data processors | Not envisaged
|
International transfers | No international personal data transfers are envisaged. |
Deletion period | They will be kept for the time necessary to resolve complaints and to determine any possible liabilities that may arise from this purpose and from the processing of the data. |
Additional data | No data protection impact assessment is required for this processing, for the data processed and as the data controller executes it, in accordance with the provisions of article 35 of the GDPR and article 28 of the Spanish Organic Data Protection Law (LOPD). |
Registration and management of queries made to Group companies regarding the activities of the entities.
Data controller | ARAVEN GROUP and the co-controller is SHOP AND ROLL ESPAÑA. |
Legal basis | The data subject gave their consent to the processing of their personal data for one or more specific purposes (art. 6.1.a GDPR). |
Purposes of the processing | Registration and management of queries about the controller’s activities. |
Group | Any person |
Categories of data | · Identification data: name, surname(s), address, e-mail address and telephone number. · Data that can be incorporated into the query. |
Target category | Not envisaged. |
Data processors | Not envisaged
|
International transfers | No international personal data transfers are envisaged. |
Deletion period | They will be kept for the time necessary to process and respond to the query and to determine any possible liabilities that may arise from this purpose and from the processing of the data. |
Additional data | No data protection impact assessment is required for this processing, for the data processed and as the data controller executes it, in accordance with the provisions of article 35 of the GDPR and article 28 of the Spanish Organic Data Protection Law (LOPD). |
To ensure the security of people, goods and installations in physical and electronic spaces.
Registration and control of visits for the sole purpose of guaranteeing security.
Data controller | SHOP AND ROLL ESPAÑA. |
Legal basis | The processing is necessary for the fulfilment of a mission carried out in the public interest or in the exercising of public powers conferred on the data controller. (art. 6.1.e of the GDPR). Processing necessary for reasons of essential public interest as determined by law. Art. 9.2.g) of the GDPR. |
Purposes of the processing | The purpose of both physical security and registration and control of access is to guarantee the security of people, goods and installations in physical and electronic spaces. |
Group | Any natural person who visits the facilities or activities of the controller:
|
Categories of data | · Identification data: name and surname(s), ID number, physical and e-mail address, telephone number · Professional data: company and position. · Reason for the visit. |
Target category | · State Security Forces and Corps. · Public Prosecutor’s Office. · Judicial Bodies. |
Data processors | Not envisaged
|
International transfers | No international personal data transfers are envisaged. |
Deletion period | Maximum 30 days from the date of collection. |
Additional information | No data protection impact assessment is required for this processing, for the data processed and as the data controller executes it, in accordance with the provisions of article 35 of the GDPR and article 28 of the Spanish Organic Data Protection Law (LOPD). |
The data controller analyses the browsing behaviour of users through the website and the different social profiles in order to prevent and block logical attacks.
Data controller | ARAVEN GROUP and the co-controller is SHOP AND ROLL ESPAÑA. |
Legal basis | The processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party and do not override the interests and fundamental rights and freedoms stipulated in (art. 6.1.f of the GDPR). In particular, these legitimate interests consist of preventing unauthorised access to or destruction or alteration of the data and systems, as well as preventing access to the data and systems from being blocked or other unauthorised processing by third parties. |
Purposes of the processing | To analyse:
In both cases, part of the processing is carried out by the data controller directly or on its behalf. However, most of the processing is carried out by third parties to whom the service has been contracted under which they perform processing for this purpose, but according to their own criteria of choice of purposes and means. |
Group | Users accessing websites or social profiles managed by the controller. |
Categories of data | · IP addresses. · Browser user agent string. |
Target category | Not envisaged. If applicable, Courts and Tribunals and State Security Forces and Corps. |
Data processors | Forensic and information security management companies.
|
International transfers | International transfers are envisaged to the data processors (indicate, at least, those which could carry out international transfers, together with the country) or recipients of transfers indicated: Google LLC (United States). |
Deletion period | They are kept for as long as necessary to ensure the purpose of the processing. |
Additional information | No data protection impact assessment is required for this processing, for the data processed and as the data controller executes it, in accordance with the provisions of article 35 of the GDPR and article 28 of the Spanish Organic Data Protection Law (LOPD). |
Video surveillance of the perimeter and accesses to the facilities or premises in order to guarantee the security of persons, goods and installations in the buildings.
Data controller | SHOP AND ROLL ESPAÑA. |
Legal basis | Processing necessary for the fulfilment of a mission carried out in the public interest or in the exercising of public powers. Art. 6.1.e) of the GDPR. Processing necessary for reasons of essential public interest as determined by law. Art. 9.2.g) of the GDPR. Spanish Law 5/2014, of 4 April, on Private Security. |
Purposes of the processing | To ensure the security of people, goods and installations. Compliance with employment and/or contractual obligations. |
Group | Natural persons who visit the facilities of any of the Group’s companies. |
Categories of data | · Image and/or photograph. |
Target category | · State Security Forces and Corps. · Judicial Bodies. · Public Prosecutor’s Office. |
Data processors | Security Companies
|
International transfers | No international personal data transfers are envisaged. |
Deletion period | Within 30 days of their collection. |
Additional information | No data protection impact assessment is required for this processing, for the data processed and as the data controller executes it, in accordance with the provisions of article 35 of the GDPR and article 28 of the Spanish Organic Data Protection Law (LOPD). |
Implementation of and access to a Whistleblowing Channel in accordance with the applicable regulations.
Data controller | The data controller is ARAVEN GROUP, and the co-controller is SHOP AND ROLL ESPAÑA. |
Legal basis | Processing necessary for the purposes of the legitimate interests pursued by the controller or by a third party (art. 6.1.f) GDPR) and, where applicable, for compliance with a legal obligation applicable to the controller (art. 6.1.c) GDPR). |
Purposes of the processing | Management of a whistleblowing channel, in accordance with the provisions of the Internal Policy and Manuals on Regulatory Compliance and Avoidance of Criminal Risks for ARAVEN GROUP. |
Group | · Employees · Collaborators · Persons affected in Suppliers/Customers. · Managers of the entities. · Other |
Categories of data | · Identification data: ID number, name and surname(s), postal address, e-mail address and telephone number. (In the case of anonymous reports, this data may be collected during the internal investigation) · Other personal data contained in the reports or obtained during the investigation. |
Target category | · Spanish Data Protection Agency in inspection processes in application of Spanish Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights. · State Security Forces and Corps, with prior judicial authorisation and in the exercise of their judicial police functions. · Judges and courts under the terms defined by procedural legislation. In these cases, before making the data available to third parties, it ensures that these authorities request and access the data in accordance with the Laws. |
Data processors | Not envisaged
|
International transfers | No international personal data transfers are envisaged. |
Deletion period | The data will be kept for the time necessary to deal with and manage the reports and to conduct the necessary investigations. It is also kept for the purpose of carrying out or making the necessary decisions in relation to each report, in compliance with the corresponding legal obligations. The information will be kept duly blocked for the additional periods necessary for the limitation of possible legal liabilities. |
Additional information | The technical, organisational and operational data security and data protection measures are applied in accordance with Directive (EU) 2019/1937. |
Processing carried out in the event of activities performed outside Spain.
Data controller | ARAVEN GROUP and the co-controller is SHOP AND ROLL ESPAÑA. |
Legal basis | The processing is necessary for the execution of a contract to which the data subject is party or for the implementation at their request of pre-contractual measures (art. 6.1.b GDPR). In specific cases, the data subject gave their consent to the processing of their personal data for one or more specific purposes (art. 6.1.a GDPR). |
Purposes of the processing | Management, administration and control of activities performed in other countries, whether in the EU or elsewhere, as well as in other international organisations. |
Group | · Employees of the Group’s companies.
|
Categories of data | · Identification data: name, surname(s), postal address and e-mail address. · Economic-financial data: bank details.
|
Data processors | Travel agencies and companies that organise transfers and obtain visas.
|
International transfers | International data transfers are envisaged in the cases set forth in article 49.1 of the GDPR: (a) the data subject has explicitly consented to the proposed transfer, having been informed of the possible risks to them of such transfers due to the absence of an adequacy finding and appropriate guarantees; (b) the transfer is necessary for the execution of a contract between the data subject and the controller or for the execution of pre-contractual measures taken at the request of the data subject. |
Deletion period | – The data will be kept for the duration of the legal relationship between the data subject and ARAVEN. |
Additional information | No data protection impact assessment is required for this processing, for the data processed and as the data controller executes it, in accordance with the provisions of article 35 of the GDPR and article 28 of the Spanish Organic Data Protection Law (LOPD). |