Privacy-Policy

DINA RAHWAN KHADIR, informs users of the website about its policy regarding the processing and protection of personal data of users and clients.

And guarantees at all times the full and complete compliance with the obligations set forth by the regulations on data protection and information society services: Regulation (EU) 2016/679 of the European Parliament and of the Council, of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR), the Organic Law 3/2018, of December 5, on Personal Data Protection and guarantee of digital rights (LOPDGDD), and Law 34/2002, of July 11, on Information Society Services and Electronic Commerce (LSSIce).

DATA CONTROLLER

Dina Rahwan Khdair

C.I.F. (Tax ID): 41595012H

Address: Gran Via Jaume I, 41-43, Ent. 1a, 17001 Girona

Registered Psychologist with number 26.978, COPC (Official College of Psychologists of Catalonia)

Phone: +34 671 232 783

Email:

PURPOSES OF DATA PROCESSING
Purpose of processing                     Legal basis for processing
Managing inquiries or any type of request made through the contact forms available on the website Legitimate interest of the Company to attend to information requests via the web. Consent expressly given at the time of data collection through web forms.
Sending newsletters, commercial communications, and promotions. Consent expressly given at the time of data collection through web forms.
Managing incidents and website maintenance. Legitimate interest of the Company

TERMINI DE CONSERVACIÓ DE LES DADES
Purpose of processing Retention period
Managing inquiries or any type of request made through the contact forms available on the website. We will process your data for the time necessary to attend to your request or petition.
Sending newsletters, commercial communications, and promotions We will process your data until you unsubscribe.
Managing incidents and website maintenance. We will process your data for the time necessary to comply with the applicable legal statute of limitations.

RECIPIENTS OF THE DATA

To fulfill the purposes indicated in this Privacy Policy, it is necessary for us to give access to your personal data to third parties that support us in the services we offer you (Data Processors).

Data processors, for the execution of a contract or provision of a service to the Controller, must follow its instructions and ensure the same levels of security.

COOKIES

Regarding the use of cookies and other tracking technologies, please consult the Cookie Policy of this Website. In this case, the legal basis for processing your data is your consent given when accepting the loading of cookies in your browser.

USERS’ RIGHTS

The user has the right to:
  • Request access to their personal data that is being processed and receive this information in writing by the requested means.
  • Request the rectification of inaccurate personal data or, where appropriate, request its deletion when, among other reasons, the data is no longer necessary for the purpose for which it was collected.
  • Request the limitation of the processing of their data.
  • Object to the processing of their personal data where applicable, in which case their data will cease to be processed except for legitimate reasons.
  • Right to data portability. The data subject has the right to receive the personal data if it has been provided in a structured, commonly used, and machine-readable format, and to transmit it to another controller, if the following requirements are met:
  • The processing is based on consent or a contract.
  • The processing is carried out by automated means.
  • • Right to withdraw the consent given.
  • • Right to file a complaint with the Spanish Data Protection Agency.

The User may exercise the aforementioned rights at the postal or email address of the Controller, proving their identity with a scanned copy of their ID card or equivalent document, and specifying the right they wish to exercise.

SOURCE OF THE DATA

Personal data must be provided by the data subject themselves on an absolutely voluntary basis. The lack of some data or the failure to answer questions that may be posed to the data subject in registration processes or through electronic forms may result in the inability to access certain services for the provision of which it is essential to have this personal data. In this case, the Data Controller must inform of the mandatory or necessary nature of providing personal data for the operation of the service.

The Controller ensures the confidentiality of your personal data and guarantees its security, adopting the necessary measures to prevent its alteration, loss, processing, or unauthorised access.

INFORMATION PROVIDED BY THE DATA SUBJECT

Minors under 18 years of age may not provide their personal data without the prior consent of their parent(s) and/or legal guardians.

The data subject, by entering their data in the contact forms or submitted in download forms, expressly and freely and unequivocally accepts that their data are necessary for the Controller to attend to their request, and the inclusion of data in the remaining fields is voluntary.

The data subject guarantees that the personal data provided to the provider are truthful and is responsible for communicating any modification thereof.

All data requested through the website are necessary for the provision of an optimal service to the data subject. If all data are not provided, it is not guaranteed that the information and services provided by the Controller will be completely tailored to their needs.

SECURITY MEASURES

That in accordance with the provisions of current regulations on personal data protection, the Controller is complying with all the provisions of the GDPR and LOPDGDD regulations for the processing of personal data under its responsibility, and manifestly with the principles described in Article 5 of the GDPR and Article 4 of the LOPDGDD, by which they are processed lawfully, fairly, and transparently in relation to the data subject and are adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.

The controller guarantees that it has implemented appropriate technical and organisational policies to apply the security measures established by the GDPR and the LOPDGDD in order to protect the rights and freedoms of the data subject and has communicated to them the appropriate information so that they can exercise them.

SECURITY BREACHES

The Controller will report any security breach that affects the database used by this website, or that affects any of our third-party services, to each and every person whose data may have been affected, and to authorities, within 72 hours of detecting the breach.

APPLICABLE LAW AND JURISDICTION

The right is reserved to file civil or criminal actions deemed necessary for the improper use of the Website and Contents.

The relationship between the User and the Controller shall be governed by current regulations applicable in Spanish territory. Should any dispute arise in relation to the interpretation and/or application, the parties shall submit their conflicts to ordinary jurisdiction, submitting to the judges and courts that correspond according to law.