ES

IT

DE

Privacy Policy and Data Protection

I. PRIVACY POLICY AND DATA PROTECTION

In compliance with current legislation, Auditax NL International (hereinafter also the Website) undertakes to adopt the necessary technical and organizational measures, according to the appropriate level of security for the risk of the collected data. Laws included in this privacy policy This privacy policy is adapted to current Spanish and European regulations on the protection of personal data on the internet. Specifically, it complies with the following rules: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR). Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights (LOPD-GDD). Royal Decree 1720/2007 of 21 December, approving the Regulation implementing Organic Law 15/1999 of 13 December on the Protection of Personal Data (RDLOPD). Law 34/2002 of 11 July on Information Society Services and Electronic Commerce (LSSI-CE).

Identity of the data controller

The controller of the personal data collected on Auditax NL International is: Auditax NL International S.L., with NIF/CIF: B76176965 and registered in: Puerto de Arrecife Commercial Registry with the following registration details: Volume 9, Folio 50, Section 8, Sheet 363, whose representative is: Fiorella di Benedetto (hereinafter, the Controller). Contact details: Address: C/ Dr. Ruperto González Negrín 3 Floor 1, Arrecife, Las Palmas Contact phone: 928811662 Contact email: fiorella@auditaxnl.com

Personal Data Register and Principles

In compliance with the GDPR and LOPD-GDD, we inform you that the personal data collected by Auditax NL International through the forms on its pages will be incorporated and processed in our files in order to facilitate, expedite, and fulfill the commitments established between Auditax NL International and the User or to maintain the relationship established in the forms completed by the User, or to respond to a request or inquiry. Likewise, in accordance with the GDPR and LOPD-GDD, unless the exception provided in Article 30.5 of the GDPR applies, a record of processing activities is maintained. Principles applicable to the processing of personal data The User’s personal data will be processed in accordance with the principles set out in Article 5 of the GDPR and Article 4 et seq. of Organic Law 3/2018: Lawfulness, fairness and transparency principle: User consent will be required with transparent information about the purposes of data collection. Purpose limitation principle: personal data will be collected for specified, explicit and legitimate purposes. Data minimization principle: personal data collected will be strictly necessary for the purposes of processing. Accuracy principle: personal data must be accurate and kept up to date. Storage limitation principle: personal data will be kept only for the time necessary for processing purposes. Integrity and confidentiality principle: personal data will be processed ensuring security and confidentiality. Accountability principle: the Controller will ensure compliance with these principles.

Data categories and Legal basis

Categories of personal data The categories of data processed by Auditax NL International are only identifying data. Special categories of personal data as defined in Article 9 of the GDPR are not processed. Legal basis for processing personal data The legal basis for processing personal data is consent. Auditax NL International undertakes to obtain express and verifiable consent from the User for one or more specific purposes. The User may withdraw consent at any time. Withdrawal of consent will be as easy as giving it. As a general rule, withdrawal will not affect Website use. When the User must or may provide data through forms for inquiries, information requests, or content-related reasons, they will be informed if completion of any field is mandatory.

Purposes of processing

Personal data is collected and managed by Auditax NL International in order to facilitate, expedite, and fulfill commitments between the Website and the User or to maintain the relationship established in the forms or to respond to requests or inquiries. Data may also be used for commercial, personalization, operational, statistical purposes, and activities related to the corporate purpose of Auditax NL International, including data extraction, storage, and marketing studies to tailor content and improve Website quality and navigation. When personal data is obtained, the User will be informed about the specific purpose(s) of processing.

Retention periods and Recipients

Retention periods for personal data Personal data will be retained only for the minimum necessary time, and in any case for: 12 months, or until the User requests deletion. Users will be informed about the retention period or the criteria used to determine it. Recipients of personal data User personal data will be shared with the following recipients or categories of recipients: If the Controller intends to transfer data to a third country or international organization, the User will be informed of the destination and the existence or absence of an adequacy decision by the Commission.

Minors and Data security

Personal data of minors In accordance with Articles 8 of the GDPR and 7 of Organic Law 3/2018, only persons over 14 years old may legally consent. For minors under 14, parental or guardian consent is required. Secrecy and security of personal data Auditax NL International undertakes to adopt technical and organizational measures to guarantee data security and prevent unauthorized access, loss, alteration, or disclosure. The Website uses an SSL certificate to ensure encrypted data transmission. However, Auditax NL International cannot guarantee absolute security and will notify Users without undue delay of any data breach posing high risk to rights and freedoms. Personal data will be treated as confidential by the Controller, who will ensure confidentiality obligations for employees, partners, and any person granted access.

Rights derived from the processing of personal data

The User may exercise the following rights under the GDPR and Organic Law 3/2018: Right of access: to obtain confirmation and information about personal data processing. Right to rectification: to correct inaccurate or incomplete data. Right to erasure ("right to be forgotten"): to obtain deletion of data when legally applicable. Right to restriction of processing: to limit data processing under certain conditions. Right to data portability: to receive data in a structured, commonly used format and transmit it to another controller. Right to object: to object to processing of personal data. Right not to be subject to automated decision-making, including profiling.

Exercise of rights

Users may exercise their rights by written communication to the Controller with the reference "GDPR-www.auditaxnli.com", specifying: User name and ID copy. Request details. Address for notifications. Date and signature. Supporting documents. Requests may be sent to: Postal address: C/ Dr. Ruperto González Negrín 3 Floor 1, Arrecife, Las Palmas Email: fiorella@auditaxnl.com

II. ACCEPTANCE AND CHANGES TO THIS PRIVACY POLICY

Third-party website links The Website may include links to third-party websites not operated by Auditax NL International. These sites have their own privacy policies and are responsible for their own practices. Complaints to supervisory authorities Users may file complaints with a supervisory authority. In Spain, this is the Spanish Data Protection Agency (https://www.aepd.es/ ). Acceptance and changes Use of the Website implies acceptance of this Privacy Policy. Auditax NL International reserves the right to modify this policy. Users should periodically review this page for updates. This Privacy Policy was updated to comply with Regulation (EU) 2016/679 and Organic Law 3/2018. This document was generated using a free online privacy policy template generator on 19/01/2023.