Privacy Policy
The purpose of this Privacy Policy is to inform users of the Espacio de Datos del Valle de la Lengua (EDVAL) website about the processing of personal data that may be collected via the website, in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD).
Access to and navigation of the public section of the EDVAL portal does not generally require users to provide personal data. However, certain forms, contact channels, requests for information, registration procedures, communications, incidents, complaints, restricted areas or digital services may require the processing of personal data.
This policy relates to the processing of personal data carried out via the EDVAL website and should be interpreted without prejudice to any specific information provided, where applicable, in forms, registration procedures, contracts, participation agreements, terms of use, specific policies or applicable documentation under the EDVAL Governance Model.
1. Who is the data controller?
The data controller for personal data processed via the EDVAL portal is:
Data Controller: Fundación para la Transformación de La Rioja
Tax ID No.: G26466748
Address: C/ Vara de Rey, 3, 26071 Logroño
Contact email: info@ftrioja.org
Telephone: 941 27 01 01 - ext. 36812
Website: www.valledelalengua.es/el-projecto-edval/en
The Foundation for the Transformation of La Rioja acts as the promoting body for the Valle de la Lengua Data Space (EDVAL), without prejudice to the participation of other bodies, organisations, participants, collaborators, technology providers or data processors in the design, development, operation, maintenance or evolution of the portal.
2. How can you contact the
Data Protection Officer (DPO)?
You can contact the Data Protection Officer via the following channels:
Email: dpo@ftrioja.org
You may also contact the Foundation via the contact channels set out in this Privacy Policy or on the EDVAL website.
3. What personal data may we process?
The following categories of personal data may be processed via the EDVAL portal, as applicable:
- Identifying data, such as first name and surname.
- Contact details, such as email address, telephone number, postal address or professional details.
- Data relating to the entity or organisation to which the individual belongs.
- Data relating to the role, function or position held by the individual within a participating or interested entity.
- Data included in forms, applications, enquiries, communications, incidents, complaints or claims.
- Data necessary to manage registration, authentication, access control or the use of restricted features.
- Technical or browsing data necessary to ensure the functioning, security and traceability of the portal, such as IP address, date and time of access, technical records or logs.
Where the user accesses only the public section of the portal or consults descriptive information, records or metadata associated with datasets, generally speaking, it will not be necessary for them to provide personal data, without prejudice to any technical or browsing data that may be necessary for the operation and security of the portal.
Generally speaking, the processing of special categories of personal data is not envisaged via the EDVAL portal.
4. What do we use your personal data for?
Personal data processed via the EDVAL website may be used for the following purposes, depending on how the user utilises the site:
- To enable access to, navigation of, and use of the EDVAL website.
- To respond to enquiries, requests for information, communications, incidents, complaints or claims received via contact forms, support channels or other channels provided by EDVAL.
- To manage, where applicable, registration processes, authentication, user sign-ups or access to restricted areas of the website.
- Process applications for membership, participation, validation or access to EDVAL services.
- Manage relations with participating entities, representatives, contact persons or authorised users.
- Manage identities, authentication, representation and access control to restricted services.
- Formalise, manage and retain evidence relating to the Membership and Participation Agreement, conditions of participation, applicable documentation and actions linked to the EDVAL Governance Model.
- Ensure the security, availability, integrity, traceability and proper functioning of the portal and associated services.
- Prevent, detect and manage unauthorised access, misuse or security incidents.
- Comply with applicable legal, administrative, contractual, technical, audit, reporting, transparency and accountability obligations.
- Facilitate, where appropriate, the management of disputes, complaints or incidents between EDVAL participants.
Furthermore, the portal may allow users to view descriptive information, records or metadata associated with datasets, linguistic resources, data assets or services available within the EDVAL framework. Such viewing is for information or descriptive purposes only and does not, in itself, imply access to any personal data that may be contained in the datasets, nor does it permit their download, reuse, exploitation or exchange.
5. What is the legal basis for the processing?
The legal basis for the processing will depend on the specific purpose and may mainly be:
- Performance of a contract or implementation of pre-contractual measures, where the processing is necessary to manage applications for membership, participation, validation, access to services or relations with participating entities.
- Compliance with legal obligations, where processing is necessary to meet regulatory, administrative, security, audit, evidence retention, transparency or cooperation with authorities obligations;
- Performance of a task carried out in the public interest, where applicable due to the public nature of the controller or the public purpose linked to the development, management and governance of EDVAL.
- Consent of the data subject, where necessary for specific purposes, such as the use of certain non-technical cookies, voluntary communications or specific forms.
- Legitimate interest, where applicable and provided that the rights and interests of the data subjects do not override them, for strictly necessary purposes linked to the security of the portal, prevention of misuse, management of technical incidents or retention of reasonable evidence of operation.
Where processing is based on consent, this may be withdrawn at any time, without this affecting the lawfulness of the processing carried out previously.
6. Who will have access to your data?
In general, personal data will be processed by the Fundación para la Transformación de La Rioja and by authorised staff who need access to it in order to fulfil the stated purposes.
Furthermore, the following may access personal data where necessary:
- Technology providers or service providers responsible for hosting, maintenance, support, security, communications, development, operation or the evolution of the portal.
- Sub-processors involved in the provision of technical services, infrastructure, hosting, maintenance, support or security.
- Bodies, entities or participants of EDVAL, where necessary to manage requests for membership, participation, support, incidents, disputes, complaints, access to services or operational relationships within the Data Space.
- Public administrations, supervisory authorities, judicial bodies or competent bodies, where there is a legal obligation to do so.
Suppliers processing personal data on behalf of the Foundation must act in accordance with the relevant data processing agreement and provide sufficient guarantees in accordance with applicable regulations.
7. Will any international data transfers take place?
As a general rule, no international transfers of personal data outside the European Economic Area are envisaged.
Should it be necessary to carry out an international data transfer, this will be done in accordance with the safeguards provided for in the applicable data protection legislation.
8. How long will we keep your data?
Personal data will be retained for as long as necessary to fulfil the purpose for which it was collected and to address any potential liabilities arising from that purpose and the processing.
In particular:
- Data relating to enquiries, requests, communications, incidents, complaints or claims will be retained for as long as necessary for their processing and follow-up.
- Data associated with processes of membership, participation, registration or access to restricted services will be retained for as long as the relationship with the participating entity or authorised user continues and, subsequently, for the applicable statutory periods.
- Technical records, logs and security evidence will be retained for the period necessary to ensure security, traceability, auditing, incident investigation and regulatory compliance.
- Data processed on the basis of consent will be retained until such consent is withdrawn, unless there is another legal basis permitting its retention.
When the data is no longer necessary, it will be deleted, blocked or anonymised in accordance with applicable regulations.
9. What are your rights?
The data subject may exercise the following rights, in accordance with the terms set out in the applicable regulations:
Right of access: The data subject may ask the Data Controller for details of the data being processed and, if so, which specific personal data are being processed.
Right to rectification: The data subject may ask the Data Controller to correct their personal data if they are inaccurate.
Right to erasure: The data subject may request that the Data Controller erase their personal data when, amongst other reasons, the data is no longer necessary for the purposes for which it was collected.
Right to object: The data subject may object to the Data Controller processing their personal data.
Right to restriction of processing: The data subject may request that the Data Controller temporarily refrain from processing their personal data in specific circumstances.
Right to data portability: The data subject may request that the Data Controller provide their personal data in a structured, commonly used and machine-readable format.
Right to withdraw consent at any time, where the processing is based on consent.
Right not to be subject to automated individual decision-making, including profiling, where applicable.
EDVAL’s data rights management procedure expressly covers the rights of access, rectification, erasure, restriction, data portability, objection, withdrawal of consent and rights relating to automated decision-making.
10. How can you exercise your rights?
The data subject may exercise their rights by submitting a request to the Fundación para la Transformación de La Rioja via the following channel:
Email: dpo@ftrioja.org
The request must provide proof of the data subject’s identity and specify the right they wish to exercise. Where necessary, additional information may be requested to verify identity, confirm representation or locate the data or records concerned.
Requests will be dealt with in accordance with the rights management procedure applicable to EDVAL. Generally speaking, the FTR will respond within one month of receiving the request; this period may be extended by up to two additional months in cases of particular complexity or a high volume of requests, in accordance with the terms set out in the applicable regulations.
In certain cases, the exercise of rights may be subject to legal or technical limitations, particularly where the data has been anonymised, cannot reasonably be linked to the data subject, or has been irreversibly incorporated into aggregated datasets, models or publications. In such cases, the Foundation will provide a reasoned explanation of the applicable legal or technical grounds.
11. Where can I make a complaint?
If you feel that your rights have been infringed, you may lodge a complaint with the Spanish Data Protection Agency (AEPD) using any of the following methods:
Online portal: www.aepd.es
Postal address: Spanish Data Protection Agency, C/ Jorge Juan, 6, 28001 Madrid
Telephone: Tel. 901 100 099 / Tel. 91 266 35 17
Lodging a complaint with the Spanish Data Protection Agency is free of charge and does not require the assistance of a solicitor or legal representative.
12. Is profiling carried out or are automated decisions made?
As a general rule, the EDVAL portal will not profile users or make automated decisions with legal effects or similar significant effects.
Should any processing operations involving profiling or automated decision-making take place in the future, data subjects will be informed in advance, with details of the logic applied, the significance and anticipated consequences, as well as the rights they may exercise.
13. Will we use your data for other purposes?
We will not use your personal data for purposes that are incompatible with those set out in this Privacy Policy. Should it be necessary to process your data for other purposes, we will provide you with the relevant information in advance and, where appropriate, we will seek your consent or rely on the appropriate legal basis in accordance with the applicable regulations.
14. Cookies and similar technologies
The EDVAL website may use cookies or similar technologies, whether its own or those of third parties, in accordance with the terms set out in the applicable regulations. Full details regarding the use of cookies, their purposes, settings, acceptance, refusal or withdrawal of consent will be available in the relevant Cookie Policy and, where applicable, in the settings panel provided on the website.
15. Changes to the Privacy Policy
The Foundation for the Transformation of La Rioja may amend this Privacy Policy where necessary due to regulatory, technical, organisational or operational changes, or due to developments in the website or EDVAL itself.
The current version of the Privacy Policy will be the one published on the website at any given time.