Privacy Policy
- Data Controller
The data controller is HILEX TRANSFORMACIONES METÁLICAS, S.L.U., CIF B53429106, with registered office at Calle Zamora 2 y 4, 03440 Ibi (Alicante).
Tel.: (+34) 966 55 41 91
Email: hilex@hilex.eu
The entity does not have a Data Protection Officer (DPO) as it is not mandatory under Art. 37 of the GDPR. For any questions regarding data protection, you may write to us at the contact details provided.
- Privacy Principles
- We only request data when necessary to provide a service or comply with a legal obligation.
- We do not share data with third parties unless there is a legal obligation or express consent.
- We will not use the data for purposes incompatible with those reported.
- We apply appropriate technical and organizational measures (Art. 24, 25, and 32 of the GDPR).
- No automated decisions will be made nor will profiles be created with the data provided.
If you are under 14 years of age, you need the consent of your parents or guardians to provide us with personal data.
- Applicable Regulations
- Regulation (EU) 2016/679 (GDPR).
- Organic Law 3/2018, on the Protection of Personal Data and guarantee of digital rights (LOPDGDD).
- Law 34/2002, on Information Society Services and Electronic Commerce (LSSI-CE).
- Processing Activities
A) Employees
Legal basis: Art. 6.1.b) GDPR (performance of a contract) and 6.1.c) GDPR (legal labor, tax, and Social Security obligations).
Purpose: comprehensive labor management (payroll, time control, occupational risk prevention, training, contributions, etc.).
Recipients: TGSS (Social Security), AEAT (Tax Agency), mutual insurance companies, financial institutions, trade unions, occupational risk prevention services, and main contractors where applicable.
Retention: for the duration of the relationship and applicable legal limitation periods.
B) Contacts (customers, suppliers, and prospects)
Legal basis: consent of the data subject or legitimate interest in maintaining the professional relationship (Art. 6.1.a and 6.1.f GDPR).
Purpose: handling requests, sending information, and follow-up.
Recipients: no transfers are planned.
Retention: until consent is withdrawn or the relationship ends.
C) Exercise of rights
Legal basis: Art. 6.1.c) GDPR (legal obligation).
Purpose: managing requests for access, rectification, erasure, objection, restriction, and portability.
Recipients: AEPD (Spanish Data Protection Agency) in case of protection of rights.
Retention: 5 years from the request.
D) Candidates (HR)
Legal basis: Art. 6.1.b) GDPR (pre-contractual measures).
Purpose: management of CVs and selection processes.
Recipients: no transfers are planned.
Retention: during the process and up to a maximum of 1 year.
E) Suppliers
Legal basis: Art. 6.1.b) GDPR (performance of a contract) and 6.1.c) GDPR (tax obligations).
Purpose: management of purchases, payments, and control of subcontractors.
Recipients: AEAT, financial institutions.
Retention: for the duration of the relationship and legal periods.
F) Customers
Legal basis: Art. 6.1.b) GDPR (performance of a contract), 6.1.c) GDPR (legal obligation) and, for commercial communications, 6.1.a) GDPR (consent).
Purpose: design, manufacture, and supply of metal products; invoicing and after-sales service.
Recipients: AEAT, financial institutions.
Retention: duration of the relationship and tax limitation periods.
G) Video surveillance
Legal basis: Art. 6.1.f) GDPR (legitimate interest: security of persons, property, and facilities).
Purpose: access control and security.
Public information: areas marked with an information sign; expanded information available upon request.
Retention: maximum 30 days, except for retention to prove facts (retention and making available to the competent authority).
Recipients: Law Enforcement Agencies and, where appropriate, judicial bodies.
H) Security breach management
Legal basis: Art. 6.1.c) GDPR (legal obligation).
Purpose: detection, analysis, and notification of breaches in accordance with Arts. 33 and 34 of the GDPR.
Notification: to the AEPD within 72 hours of detection; communication to data subjects when appropriate (high risk).
Recipients: AEPD and, where appropriate, Law Enforcement Agencies.
- Rights of data subjects
You may exercise your rights of access, rectification, erasure, objection, restriction, and portability (Arts. 15 to 22 of the GDPR) by writing to HILEX TRANSFORMACIONES METÁLICAS, S.L.U., Calle Zamora 2 y 4, 03440 Ibi (Alicante), or by email to hilex@hilex.eu, attaching a copy of your identity document.
If you consider that your rights have not been addressed, you may file a complaint with the Spanish Data Protection Agency.
- Security measures
We apply appropriate technical and organizational measures based on the risk, including access controls, backup copies, encryption where appropriate, activity logs, staff training, and incident management procedures.
- Links to third-party sites
This site may include links to external pages. We are not responsible for their content or their privacy policies. We recommend reviewing them before providing personal data.
- Third-party data
If you provide us with data from third parties, you declare that you have previously informed them in accordance with Art. 14 of the GDPR and, where appropriate, obtained their consent.
- Changes to the privacy policy
We may update this policy to adapt it to regulatory or processing changes. Please review this page periodically.