Last modified 26 May 2021

The Privacy Policy is part of the General Conditions governing the Website www.palmainternationalboatshow.com
together with the Cookie Policy and the Legal Notice.

Institut d´Innovació Empresarial de les Illes Balears (hereinafter IDI), reserves the right to modify or
adapt this Privacy Policy at any time. Therefore, we recommend that you review it each time you access the Website. If you have registered on the Website and access your account or profile, you will be informed of any substantial modifications that have been made in relation to the processing of your personal data.

Who is responsible for processing your data?
The data that is collected or that you voluntarily provide us with through the Website while browsing it,
as well as any data that you may provide us with in the contact forms, via email or by telephone,
will be collected and processed by the Data Controller, whose details are indicated below:

The Business Innovation Institute of the Balearic Islands CIF: Q5755018H
Address: Plaza Son Castelló, 1, bajos, 07009, Polígono Son Castelló, Palma de Mallorca.
Tel.: 971178900
Data Protection Officer: dpd@idi.es

If, for any reason, you wish to contact us regarding any matter relating to the processing of your personal data or privacy (with our Data Protection Officer), you can do so by any of the means indicated above.

What data do we collect through the website?
By simply browsing the Website, the IDI will collect information relating to:
– IP Address.
– Browser version.
– Operating system.
– Duration of the visit or browsing of the website.
This information is stored by Google Analytics, for which we refer to Google’s Privacy Policy, as it collects and processes such information.

Similarly, the Website may provide the Google Maps platform, which may have access to your location, if you allow it to do so, in order to provide you with specific details about the distance and/or routes to our head offices. In this regard, we refer to the Privacy Policy used by Google Maps, in order to know the use and processing of such data.

The information that we handle will not be related to a specific user and will be stored in our databases for the purpose of statistical analysis, improvements to the Website, our products and/or services and will help us to improve our strategy. The data will not be communicated to third parties.

User registration on the website
In order to access certain products and/or services, the user must register on the Website. For this purpose, your personal data is requested in the registration form. The necessary and mandatory data to be provided by the user to carry out such registration, are marked with the symbol *. If these fields are not provided, registration will not take place.
The user name and password generated are personal and non-transferable, and the user is responsible for their safekeeping. We do not recommend that you write it down anywhere or give it to third parties.

In this case, the browsing data will be associated with the user’s registration data, identifying
the specific user browsing the Website. This will enable us to personalise the offer of products and/or services that, in our opinion, best suits the user, as well as to recommend certain products and/or services.

The registration data of each user will be incorporated into IDI’s databases, together with the history of operations
carried out by the same, and will be stored therein until the registered user’s account is deleted. Once the account has been deleted, this information will be removed from our databases, and the data relating to the transactions carried out will be kept apart for 10 years, without being accessed or altered, in order to comply with the legal deadlines in force. Data that are not linked to the transactions made will be retained unless you withdraw your consent, in which case they will be deleted immediately (always taking into account the legal deadlines).

The legal basis for the processing of your personal data is the performance of a contract between the parties.
In relation to the sending of communications and promotions by electronic means and the response to requests for information, the legal basis for the processing is the consent of the data subject.

Data will be processed for the following purposes:

  • To manage registration in the user registration area and access to the Website.
  • To manage the services made available to you through the Website.
  • To keep you informed of the processing and status of your request.
  • To respond to your request for information.

Please note that you can receive communications via email and/or telephone, in order to inform you of possible incidents, errors, problems and/or the status of your requests.

The sending of communications will require the user’s express consent at the time of registration. In this regard, the user may revoke the consent given by contacting the IDI, using the means indicated above. In any case, in each commercial communication, the user will be given the possibility to unsubscribe from receiving them, either by means of a link and/or email address.

Sending newsletters
If the option of subscribing to a Newsletter is allowed, it will be necessary to provide us with an email address to
which it will be sent.
This information will be stored in an IDI database, in which it will remain registered until the interested
party requests to unsubscribe or, where appropriate, the IDI ceases to send it.
The legal basis for the processing of this personal data is the express consent given by all those interested
parties who subscribe to this service by ticking the box provided for this purpose.
The data from emails will only be processed and stored for the purpose of managing the sending of the Newsletter by users who request it.

In order to send the Newsletter, the express consent of the user will be requested when registering for it by ticking the box provided for this purpose. In this regard, the user may revoke the consent given by contacting the IDI, using the means indicated above. In any case, in each communication, you will be given the opportunity to unsubscribe from receiving them, either by means of a link and/or email address.

If you are one of the following groups, please consult the drop-down information:
+ WEB OR EMAIL CONTACTS

For what purposes will we process your personal data?

  • To answer your queries, requests or petitions.
  • To manage the requested service, and answer or process your request.
  • Information sent by email, related to your request.
  • Commercial or event information by email, provided that express authorisation has been given.

What is the legitimacy for the processing of your data?

The acceptance and consent of the interested party: In those cases where making a request requires
filling in a form and clicking on the send button, and the completion of the same shall imply that you have been informed and have expressly given your consent to the content of the clause attached to the form or have accepted the privacy policy.

All our forms have a checkbox with the following formula, in order to send the information: “□ I have read and accepted the Privacy policy.”

CLIENTS

For what purposes will we process your personal data?

  • To draw up the budget and monitoring it by means of communications between both parties.
  • Information sent by email, related to your request.
  • Commercial or event information by email, provided that express authorisation has been given.
  • To manage the administrative, communications and logistics services provided by the Data Controller.
  • Invoicing.
  • To carry out the corresponding transactions.
  • Invoicing and declaration of the appropriate taxes.
  • Control and collection procedures.

What is the legitimacy for the processing of your data?
The legal basis is your consent.

SUPPLIERS

For what purposes will we process your personal data?

  • Information sent by email, related to your request.
  • Commercial or event information by email, provided that express authorisation has been given.
  • To manage the administrative, communications and logistics services provided by the Data Controller.
  • Invoicing.
  • To carry out the corresponding transactions.
  • Invoicing and declaration of the appropriate taxes.
  • Control and collection procedures.

What is the legitimacy for the processing of your data?
The legal basis is the acceptance of a contractual relationship, or otherwise your consent to contact
us or offer us your products by any means.

SOCIAL MEDIA CONTACTS

For what purposes will we process your personal data?

  • To answer your queries, requests or petitions.
  • To manage the requested service, and answer or process your request.
  • To get in touch with you and create a community of followers.

What is the legitimacy for the processing of your data?
The acceptance of a contractual relationship in the corresponding social network environment, and in accordance with its privacy policies:
Facebook
Instagram

How long will we keep personal data?
We can only consult or unsubscribe your data in a restricted way by having a specific profile. We will process them for as long as you let us by following us, being a friend or by clicking “like”, “follow” or similar buttons.

Any rectification of your data or restriction of information or publications must be done through the configuration of your profile or user in the social network itself.

IDI USERS

For what purposes will we process your personal data?

  • To answer your queries, requests or petitions.
  • To manage the requested service, and answer or process your request.
  • Information sent by email, related to your request.
  • Commercial or event information by email, provided that express authorisation has been given.

What is the legitimacy for the processing of your data?
The legal basis is the acceptance of a service contract and the consent of the data subject.

HR

For what purposes will we process your personal data?

  • To manage the employment relationship and the employee’s file.
  • To carry out all the administrative, tax and accounting procedures necessary to comply with our contractual commitments, obligations in terms of labour regulations, Social Security, occupational risk prevention, tax and accounting.
  • Salary payment management through a financial institution.
  • Time control through the access control system by fingerprint/card/employee portal (if applicable).
  • To manage the collective insurance / pension plan of the entity.
  • To carry out training activities, both subsidised and non-reimbursed training.

What is the legitimacy for the processing of your data?
The legal basis for processing your data is the performance of your employment contract. Compliance with
the relevant legal obligations. The consent of the data subject.

– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –

Do we include personal data of third parties?
No, as a general rule we only process the data provided to us by the owners. If you provide us with data of third parties,
you must previously inform and request their consent, otherwise we will be exempt from any liability for failure to comply with this requirement.

What about data relating to minors?
We do not process data of children under 14 years of age, so please refrain from providing them if you are under that age

Will we communicate with you by email?

  • We will only do so in order to process your request, if this is one of the contact methods you have provided us with.
  • If we send commercial communications, they will have been previously and expressly authorised by you.

What security measures do we apply?
You can rest assured: We have adopted the highest level of protection for the Personal Data
we handle, and we have installed all the technical means and measures at our disposal, according to the state of
technology, to prevent the loss, misuse, alteration, unauthorised access and theft of Personal Data.
To what extent will decision-making be automated?
The IDI does not use fully automated decision-making processes to enter into, develop or terminate
a contractual relationship with you. If we do use such processes in a particular case, we will keep you informed and inform you of your rights in this respect if required by law.

Will profiling take place?
In order to be able to offer you products and/or services according to your interests and to improve your user experience,
we may create a “profile” on the basis of the information provided. However, no automated decisions will be made on the basis of this profile.

To whom will your data be disclosed?
Your data may be passed on to IDI’s partners in order to offer the best possible service.
It will also be passed on to third parties when there is a legal obligation to do so, as well as to the persons in charge
of the processing necessary for the conclusion of the agreement or service contract.
If you have given us your consent for the processing of your name and images and other
information related to the IDI’s activity, they will be disclosed on the different social networks and website.
International transfers.
Should it be necessary for the IDI to make international data transfers, it
will ensure that such transfers are possible in accordance with the General Data Protection Regulation or any other requirement established by the applicable regulations. For this purpose, the company shall make all the necessary arrangement to ensure a level of data protection equivalent to that provided for in European regulations.
Should you work in a system of shared folders in applications such as Dropbox, Google Drive, Microsoft
OneDrive, Amazon, Apple, HubSpot, etc… an international transfer to the United States will be carried out under the
authorisation of article 49.c) of the General Data Protection Regulationor any other mechanism that guarantees a level of data protection equivalent to that provided for in European regulations.

What rights do you have?

  • To know if we are processing your data or not.
  • To access your personal data.
  • To request rectification of your data if they are inaccurate.
  • To request the deletion of your data if they are no longer necessary for the purposes for which they were collected or if you withdraw your consent.
  • To request the limitation of the processing of your data, in certain situations, in which case we will only
    keep them in accordance with the regulations in force.
  • To submit your data, which will be provided to you in a structured, commonly used or machine-readable format. If you prefer, we can send them to the new data controller appointed by you. This is only valid in certain cases.
  • To file a complaint with the Spanish Data Protection Agency if you believe that we have not treated you correctly.
  • To revoke consent for any processing for which you have consented, at any time.

If you modify any data, please let us know so that we can keep them up to date.

Do you want a form for exercising your rights?

  • We have forms for exercising your rights, which you can request by email or, if you prefer, you can use the forms prepared by the Spanish Data Protection Agency or third parties.
  • These forms must be signed electronically or be accompanied by a photocopy of your ID Card.
  • If someone is representing you, you must attach a copy of their ID card, or have them sign it electronically.
  • The forms can be submitted in person, sent by letter or by mail to the address of the person responsible at the beginning of this text.

You have the right to file a complaint with the Spanish Data Protection Agency if you believe your rights have not been properly respected.

IDI has a maximum period of one month from the date of receipt of your request by us.

You have the right to revoke your consent at any time for any of the processing for which you have given it.

Do we process cookies?
If we use other types of cookies that are not necessary, you can consult the cookie policy in the corresponding link
at the top of our website.

How long will we keep your personal data?

  • Personal data will be kept for as long as you have any association with us.
  • Once you are no longer associated with us, the personal data processed for each purpose will be kept for the legally stipulated periods, including the period in which a judge or court may require them in accordance with the statute of limitations for legal action.
  • The data processed will be kept until the aforementioned legal periods expire, if there is a legal obligation to keep them, or,otherwise, until the interested party requests their deletion or revokes the consent granted.
  • We will keep all information and communications relating to your purchase or the provision of our service, for the duration of the guarantees of the products or services, in order to deal with possible claims.
  • For each data processing operation or data type, we provide you with a specific period, which you can consult in the following table:
FileDocumentRetention
ClientsInvoices10 years
Forms and coupons15 years
Contracts5 years
Human ResourcesPayrolls, TC1, TC2, etc.10 years
Curricula

Until the end of the

selection process, and 1 more year with your

consent

Severance pay docs.

Contracts.

Temporary worker data.

4 years
Worker registration record.Up to 5 years after leaving.
MarketingDatabases or web visitors.For the duration of the processing.
SuppliersInvoices10 years
Contracts5 years
Accounting

Accounts Books and Documents.

Shareholders’ agreements and board of directors’ agreements, articles of association, minutes, regulations of the board of directors and delegated committees.

Financial statements, audit reports

Records and documents relating to grants

6 years
Fiscal

Carrying out the administration, rights and obligations relating to the payment of taxes.

Administration of dividend payments and withholding taxes.

10 years
Health and SafetyWorker Medical Records5 years
InsuranceInsurance policies

6 years (general rule)

2 years (personal injury)

5 years (personal)

10 years (life)

LegalIntellectual and Industrial Property Documents. Contracts and agreements.5 years
Permits, licences, certificates

6 years from the date of expiry of the permit, licence or certificate.

10 years (criminal statute of limitations)

Confidentiality and non-competition agreements

Always the period of duration of the obligation or

confidentiality