Privacy Policy

Félix José Rodríguez processes personal data of its customers, suppliers and staff in the ordinary course of its business: contact management and customer service, quotes, orders and invoicing, commercial communications, staff recruitment and management, and supplier relations. We apply the principles of data minimisation, transparency and security required by the GDPR and the LOPDGDD, with retention periods differentiated by purpose and guaranteed rights of access, rectification, erasure and objection for the individuals whose data we process.


Below is a detailed description of each of the data processing activities carried out by Félix José Rodríguez, including its purpose, legal basis, group affected, data processed, recipients, retention period and security measures.


· Suppliers and subcontracting

Purpose: Purchasing management, control of subcontractors, risk prevention where applicable.

Legal basis: Performance of a contract and legal compliance.

Group: Suppliers and their contact staff.

Data processed: Identification, contact details, position, banking and compliance data.

Recipients: Financial institutions and public authorities where applicable.

Retention: Legal periods arising from the contractual and tax relationship.

Security: Measures adapted to the GDPR.


· Contact and customer service

Purpose: Managing enquiries, requests for information, incidents and related communications.

Legal basis: Consent of the data subject and/or legitimate interest in responding to requests.

Group: Contact persons, customers and prospective customers.

Data processed: Identification and contact details. Content of the enquiry.

Recipients: No transfers are envisaged. Data processors providing communication or support services.

Retention: Until the request is resolved and, where applicable, the legal periods for handling or complaints.

Security: Measures adapted to the risk (access control, encryption in transit, etc.).


· Contract management, orders and invoicing

Purpose: Managing quotes, orders, service provision, invoicing and after-sales service.

Legal basis: Performance of a contract and compliance with tax and accounting legal obligations.

Group: Customers and, where applicable, contact persons of client companies.

Data processed: Identification, contact, billing and payment details; data necessary for service provision.

Recipients: Financial institutions, the Tax Administration and other bodies as legally required.

Retention: For the duration of the relationship and legal periods arising from liability and tax obligations (6 years under the Commercial Code, 4 years under the General Tax Law).

Security: Measures adapted to the GDPR.


· Marketing and commercial communications

Purpose: Sending news, offers or invitations. Managing subscriptions and preferences.

Legal basis: Consent for commercial communications. Legitimate interest for communications about similar services to existing customers, with the option to object.

Group: Subscribed individuals and customers.

Data processed: Identification, contact details, communication preferences; campaign metrics.

Recipients: Email marketing or CRM providers acting as data processors.

Retention: Until the data subject unsubscribes or objects.

Security: Measures adapted to the GDPR. Unsubscribe option available in every communication.


· Systems security and integrity

Purpose: Minimum technical logs, incident detection and analysis of fraudulent use.

Legal basis: Legitimate interest in maintaining information and systems security.

Group: Users of the systems or websites.

Data processed: Technical identifiers, IP addresses, access logs. Communication content is not monitored.

Recipients: Law enforcement and authorities, where applicable.

Retention: Logs kept for as long as necessary for security purposes and legal periods.

Security: Measures adapted to the GDPR.


· Handling of rights requests (GDPR)

Purpose: Handling requests for access, rectification, erasure, objection, restriction and portability.

Legal basis: Compliance with a legal obligation (Art. 12 GDPR).

Group: Data subjects exercising their rights.

Data processed: Identification data and data relating to the request itself.

Recipients: No transfers are envisaged except where legally required.

Retention: 5 years from resolution.

Security: Measures adapted to the GDPR.


· Human Resources (recruitment and staff)

Purpose: Managing applications, recruitment processes and staff records.

Legal basis: Pre-contractual measures, performance of a contract and compliance with employment obligations.

Group: Candidates and staff.

Data processed: Identification and contact details; academic and professional data; employment data of staff.

Recipients: No transfers are envisaged except where legally required.

Retention: Applications kept for up to 12 months unless erasure is requested; staff data kept according to legal periods.

Security: Measures adapted to the GDPR.


· CCTV on the premises

Purpose: Security and, where applicable, workplace monitoring in accordance with regulations.

Legal basis: Legitimate interest in the security of people and property.

Group: Staff, customers, visitors.

Data processed: Image.

Recipients: Law enforcement or courts upon request.

Retention: Maximum 30 days unless blocked due to a request.

Security: Informative signage and technical measures. Included only if the client has cameras.


Any data subject may exercise their rights of access, rectification, erasure, objection, restriction and portability by contacting Félix José Rodríguez, and may file a complaint with the Spanish Data Protection Agency (www.aepd.es) if they consider that the processing does not comply with current regulations.