Privacy Policy
In compliance with the provisions of the General Data Protection Regulation 2016/679 (GDPR) and the Spanish Organic Law on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) of December 2018, we hereby inform you:
1. Data controller
Identity: BLC MOVING TECHNOLOGIC S.L. with CIF B90226200, hereinafter "the Owner".
Postal address: C/ Arjona 16 local 28 y 29; 41001; SEVILLA – SEVILLA.
Telephone: 634 736 807.
E-mail: info@bylogic.com.
2. Purpose of the data processing
We inform you that the data you provide us is processed for the purpose of managing and responding to requests for information or enquiries received, sending information about products and services of interest to you, as well as facilitating, expediting and fulfilling the commitments established between the Owner and the User and maintaining the relationship that is established.
Likewise, in accordance with the provisions of the GDPR, a record of processing activities is maintained which specifies, according to their purposes, the processing activities carried out and the other circumstances established in the GDPR.
Personal information may not be used for any purposes other than those related to the contracted services or purchased products. No automated decisions will be made on the basis of such a profile.
3. Legal basis for the data processing
The legal basis for the processing carried out is based on:
- The consent granted by the User through acceptance of this Policy and the corresponding checkbox.
- The User has provided their personal data within the framework of a contractual or pre-contractual relationship for the handling of their request and/or enquiry, and therefore its processing is necessary for the maintenance of that relationship.
- The legal obligations applicable to the Owner that require the processing of personal data in accordance with the services provided, such as those related to tax matters.
The User may, at any time, revoke their consent to the processing of their personal data. In no event shall the withdrawal of these consents condition the provision of the service and/or the performance of contracts with the Owner.
4. Personal data processed and its origin
The personal data we process has been provided by the User themselves by sending emails or using the functionalities offered on the Portal.
The use of the contact sections, completion of forms and/or functionalities offered on the Portal is voluntary. However, the completion of certain form fields or their provision through the use of other functionalities is necessary in order to properly handle and manage your request, so the User's refusal to provide the requested information will prevent the Owner from handling and managing it correctly. The User guarantees that the data they provide us is truthful, accurate and complete. Data will be cancelled, deleted or blocked when it is inaccurate, incomplete or no longer necessary or relevant to its purpose in accordance with current legislation. If the personal data provided belongs to a third party, the User guarantees that they have informed them of the Privacy Policy and have obtained their authorisation to provide their data for the purposes indicated above. They likewise guarantee that the data provided is accurate and up to date, being responsible for any damage or harm, direct or indirect, that may be caused as a result of the breach of such obligation. The User undertakes and is responsible for the truthfulness and correctness of the data they provide us, undertaking to keep it duly updated.
The Portal may include links to third-party sites. The aforementioned websites have not been reviewed nor are they subject to controls by the portal. The Owner has a social media presence on Facebook, Twitter, Youtube and Instagram for the purpose of providing information about the services it offers, as well as any other activity and information it wishes to publicise. At no time will it obtain personal data from these of the users who interact on them, unless there is express authorisation. The Owner may not under any circumstances be held responsible for the contents of these websites nor for the measures adopted regarding their privacy or the processing of their personal data. We recommend carefully reading the terms of use and privacy policy of these sites.
If you are interested in activating a link to this page, you must notify the Owner and obtain express consent to create the link. The Owner reserves the right to object to the activation of links on its website.
5. Retention periods for personal data
The personal data provided by the User will be retained for as long as they remain registered for the service, for as long as the business relationship is maintained, for as long as the User does not request its deletion, or for the legally established period. They may likewise be retained when necessary for compliance with a legal obligation or for the formulation, exercise and defence of claims.
If the User revokes their consent or exercises the rights of objection or deletion, their data will be retained blocked at the disposal of the Administration of Justice for the periods legally established to address possible liabilities arising from the processing of personal data.
6. Secrecy and security of personal data
The Owner undertakes to adopt the necessary technical and organisational measures, according to the level of security appropriate to the risk of the data collected, so as to guarantee the security of personal data and prevent the destruction, loss or accidental or unlawful alteration of personal data transmitted, stored or otherwise processed, or the unauthorised communication of or access to such data.
Personal data will be treated as confidential by the data controller, who undertakes to inform of and to guarantee, by means of a legal or contractual obligation, that such confidentiality is respected by its employees, associates, and any person to whom it makes the information accessible.
7. Disclosures and recipients of personal data
The data will not be disclosed to third parties, except in cases legally provided for or where it is necessary to fulfil the purpose of the processing.
8. Processing of Google users' data (use of Google APIs)
In compliance with the Google API Services User Data Policy and the Google APIs Terms of Service, we detail below in a transparent manner how our application interacts with your data:
- Data accessed: our application accesses exclusively the Google user data explicitly authorised by you through the OAuth consent screen. This includes only: the email address, the profile name and Google Calendar data, solely and exclusively if permissions are granted for this purpose, in order to synchronise our application's internal calendars.
- Use of the data: we use this data solely and exclusively to synchronise move/task appointments with your calendar. We do not use this data for any purpose other than the direct operation of the functionalities requested by the user.
- Data sharing (transfer to third parties): Bymovers does NOT share, sell, or transfer your Google user data to third parties under any circumstances, except in cases strictly necessary for the provision of the technical service of the application, by legal obligation, or with your express consent.
- Data storage and protection: we implement robust technical and organisational security measures (such as data encryption and secure HTTPS connections) to protect the confidentiality and integrity of the information obtained. Access tokens are stored securely in databases with restricted access.
- Data retention and deletion: Google data will only be retained for as long as the user's account is active on our platform or as necessary to provide the service. Users may revoke access to their data at any time from their Google account settings or request the complete deletion of their data stored on our platform by sending an email to administracion@bylogic.es.
9. Processing of Microsoft users' data (use of Microsoft APIs)
In compliance with the Microsoft APIs Terms of Use and the Microsoft identity platform policies, we set out below, transparently, how our application interacts with your data:
- Data accessed: our application accesses exclusively the Microsoft user data explicitly authorised by you, or by your organisation's administrator, through the OAuth consent screen. This includes only: your account's profile name and email address, and your Outlook calendar data, solely and exclusively if the corresponding permissions (User.Read and Calendars.ReadWrite) are granted, in order to sync our application's internal calendars.
- Use of the data: we use this data solely and exclusively to sync move appointments and tasks with your calendar, in both directions. We do not use this data for any purpose other than the direct operation of the features requested by the user, nor for profiling, nor for advertising.
- Data sharing (transfer to third parties): byMovers does NOT share, sell or transfer your Microsoft user data to third parties under any circumstances, except where strictly necessary to provide the application's technical service, by legal obligation, or with your express consent.
- Data storage and protection: we implement robust technical and organisational security measures (data encryption and secure HTTPS connections) to protect the confidentiality and integrity of the information obtained. Access and refresh tokens are stored encrypted in databases with restricted access.
- Data retention and deletion: Microsoft data will be kept only for as long as the user's account is active on our platform or is necessary to provide the service. Each user connects and disconnects their own account from their profile settings, and may revoke access at any time from their Microsoft account security settings or, where consent was granted by the organisation's administrator, by withdrawing it from their directory's enterprise applications portal. You may also request the complete deletion of your data stored on our platform by emailing administracion@bylogic.es.
10. Users' rights
What are your rights when you provide us with your data?
The User has the right to obtain confirmation as to whether or not we are processing personal data concerning them. The User has the right to access their personal data, as well as to request the rectification of inaccurate data or, where appropriate, request its deletion when, among other reasons, the data is no longer necessary for the purposes for which it was collected. In certain circumstances, the User may request the restriction of the processing of their data, in which case we will retain it only for the exercise or defence of claims. In certain circumstances and for reasons related to their particular situation, the User may object to the processing of their data, in which case the data controller will cease processing the data, except for compelling legitimate grounds, or the exercise or defence of possible claims. In those cases in which it is legally applicable, they will have the right to data portability, which means that they have the right to receive the personal data relating to them that we are processing and to store it on their own device.
You may exercise before BLC MOVING TECHNOLOGIC S.L., where applicable, the rights of access, rectification, objection, deletion, restriction of processing, portability and to object to being subject to automated individual decisions, by means of a written communication accompanied by a photocopy of the National Identity Document (D.N.I.) addressed to the following address: C/ Arjona 16 local 28 y 29; 41001; SEVILLA – SEVILLA, email administracion@bylogic.es.
We likewise inform you that you may direct any type of complaint regarding the protection of personal data to the Spanish Data Protection Agency (Agencia Española de Protección de Datos), Spain's Supervisory Authority.