Privacy Policy
Version, July 10th 2025
Index
-
Purpose of the Privacy Policy
-
Definitions
-
Identity of the Data Controller
-
Applicable Laws and Regulations
-
Principles Applicable to Personal Data Processing
-
Data Processing Activities
-
Necessary and Updated Information
-
Personal Data of Minors
-
Technical and Organizational Security Measures
-
Data Subjects’ Rights
-
Complaints to the Supervisory Authority
-
Acceptance and Changes to the Privacy Policy
1. PURPOSE OF THE PRIVACY POLICY
This “Privacy and Data Protection Policy” aims to inform about the conditions governing the collection and processing of personal data by AB INGENIERÍA CIVIL, SL – PRESSTOK, making every effort to protect the fundamental rights, honor, and freedoms of individuals whose personal data is processed, in accordance with the laws and regulations in force under the European Union and the Spanish Member State, specifically those mentioned in the “Data Processing Activities” section of this Privacy Policy.
Through this Privacy and Data Protection Policy, users of the website https://www.presstok.com are informed of all relevant details about how data is processed, the purposes, possible data access by third parties, and users’ rights.
2. DEFINITIONS
“Personal data”: Any information about an identified or identifiable natural person (“the website user”).
“Processing”: Any operation performed on personal data (automated or not), including collection, recording, structuring, storage, use, transmission, etc.
“Restriction of processing”: Marking personal data to limit its future processing.
“Profiling”: Automated processing of personal data to evaluate aspects of a person (performance, preferences, behavior, location, etc.).
“Pseudonymization”: Processing data so it cannot be attributed to a person without additional information kept separately.
“File”: Structured set of personal data accessible according to specific criteria.
“Data controller”: The person or entity determining the purposes and means of processing.
“Data processor”: The entity processing data on behalf of the controller.
“Recipient”: Entity to whom personal data is disclosed.
“Third party”: Any entity other than the data subject, controller, processor, or authorized persons.
“Consent of the data subject”: Freely given, specific, informed, and unambiguous indication of consent.
“Personal data breach”: A breach that results in accidental or unlawful destruction, loss, alteration, or unauthorized access to personal data.
“Genetic data”: Personal data relating to inherited or acquired genetic characteristics.
“Biometric data”: Personal data obtained from technical processing related to physical, physiological, or behavioral traits.
“Health data”: Personal data related to physical or mental health, including healthcare services.
“Main establishment”: Refers to the central administration or location responsible for decisions on data processing in the EU.
“Representative”: A designated EU-based person/entity representing the controller or processor under Article 27 of the GDPR.
“Company”: Any natural or legal person engaged in economic activity, regardless of legal form.
“Supervisory authority”: Independent public authority set up by a Member State under Article 51 of the GDPR. In Spain, it is the Agencia Española de Protección de Datos.
“Cross-border processing”: Processing of data affecting multiple Member States or carried out by entities in more than one Member State.
“Information society service”: A service usually provided for payment, at a distance, electronically, and at the individual request of a recipient.
3. IDENTITY OF THE DATA CONTROLLER
The Data Controller is:
AB INGENIERÍA CIVIL, SL – PRESSTOK
CIF: B 22226518
Address: Avenida del Pilar 14, 22400, Monzón (Huesca), Spain
Email: ventas@presstok.com
Phone: +34 974 401 135
4. APPLICABLE LAWS AND REGULATIONS
This Privacy and Data Protection Policy is based on:
-
GDPR: Regulation (EU) 2016/679 on the protection of natural persons with regard to personal data processing and the free movement of such data.
-
LOPD/GDD: Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights.
-
LSSICE: Law 34/2002 on Information Society Services and Electronic Commerce.
5. PRINCIPLES APPLICABLE TO PERSONAL DATA PROCESSING
-
Lawfulness, fairness, and transparency: Data must be processed lawfully, fairly, and transparently.
-
Purpose limitation: Data collected for specific purposes must not be used in ways incompatible with those purposes.
-
Data minimization: Only data necessary for the intended purposes will be collected.
-
Accuracy: Data must be accurate and kept up to date.
-
Storage limitation: Data should be retained only as long as necessary.
-
Integrity and confidentiality: Security of data must be ensured against unauthorized access or loss.
-
Accountability: The entity must demonstrate compliance with the above principles.
6. DATA PROCESSING ACTIVITIES
Processing activities are classified as follows:
6.1 Main Processing Activities
These are necessary for providing the service.
| Online Selling | |
| Legal Bases
|
(Art. 6.1.b GDPR) Existence of a contractual relationship with the data subject through a contract or pre-contract. |
| Purposes | E-commerce; Carrying out sales through the online store. The consequence of not providing us with this data will be the impossibility of contacting you and providing a response to your request, delivering the service, or supplying the requested product. You have the right to receive an answer to any question, inquiry, or clarification that may arise from this form by calling us, sending us an email, or visiting our facilities. |
| Categories of Data and Data Subjects
|
E-commerce Customers (Identification data; Economic, financial, and insurance data; Transactions of goods and services) |
| Data Source | The data subject themselves or their legal representative |
| Category of Recipients | Tax Authorities; Banks, savings banks, and credit unions; Otherwise, we do not share your data with anyone, but we may allow its processing by third parties only for technical, legal, and/or service provision purposes. |
| International Transfer | Non are planned |
| Retention Period | As long as the commercial relationship is maintained. We keep your data while the contractual relationship lasts or until you request its deletion, or for the necessary time if there is any legal obligation or legitimate interest in this regard. |
| Security Measures | The implemented security measures correspond to those described in the documents that make up the organization’s Data Protection and Information Security Policy. |
6.2 Optional Processing Activities (if the user has given their consent)
These are personal data processing activities whose purposes are not essential for the provision of the service and are carried out only if the user has selected YES in the consent for these activities to take place.
| Online Selling | |
| Legal Bases
|
(Art. 6.1.a GDPR) Consent of the data subject; (Art. 6.1.f GDPR) Legitimate interest of the Data Controller or third parties; Organic Law on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) 3/2018, Regulation (EU) 2016/679 on the protection of personal data. |
| Purposes | Management and contact with users: The data requested through the contact form, sent via email, or provided through the phone number published on our website will be used to respond to your inquiry and send you information about our organization and services. The consequence of not providing us with this data will be the impossibility of contacting you and providing a response to your request. You have the right to receive a response to any question, inquiry, or clarification arising from this form or any other contact methods published on the corporate website, by calling us, sending us an email, or visiting our facilities. |
| Categories of Data and Data Subjects
|
Web users (Identification data) |
| Data Source | The data subject themselves or their legal representative |
| Category of Recipients | We do not share your data with anyone, but we may allow its processing by third parties solely for technical, legal, and/or service provision purposes. |
| International Transfer | They are not anticipated |
| Retention Period | Others. We keep your data only for the time necessary to respond to the information request or if there is any legal obligation or legitimate interest in this regard. |
| Security Measures | The security measures implemented correspond to those described in the documents that make up the organization’s Data Protection and Information Security Policy. |
7. NECESSARY AND UPDATED INFORMATION
Fields marked with an asterisk (*) in forms are mandatory. Omission may prevent the requested service. The user must provide truthful and updated information and report any changes to ventas@presstok.com. Clicking “Accept” (or equivalent) confirms the accuracy of the data provided and acceptance of the policy.
8. PERSONAL DATA OF MINORS
Per GDPR and LOPD/GDD, only individuals aged 14 or older may give valid consent for personal data processing. Minors under 14 need prior consent from parents/guardians, who bear full responsibility for actions performed on the website.
9. TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
The Controller takes necessary measures to guarantee data security, including:
-
Ensuring confidentiality, integrity, availability, and resilience.
-
Restoring access to data after a physical or technical incident.
-
Regularly assessing the effectiveness of security measures.
-
Pseudonymizing and encrypting sensitive data.
Additional principles include:
-
Compliance: Align with all applicable laws.
-
Risk management: Minimize risks to acceptable levels.
-
Awareness and training: Promote information security among users.
-
Proportionality: Balance security with the nature of the data.
-
Responsibility: All personnel must comply with security measures.
-
Continuous improvement: Regularly review and enhance security controls.
10. DATA SUBJECTS’ RIGHTS
Under data protection laws, users are entitled to the following individual and non-transferable rights:
-
Right of access: Know if personal data is being processed and access that data.
-
Right to rectification: Correct inaccurate or incomplete data.
-
Right to erasure (“right to be forgotten”): Request deletion of data no longer necessary or unlawfully processed.
-
Right to restriction: Limit data processing under certain circumstances.
-
Right to data portability: Receive data in a structured format and transfer it to another controller.
-
Right to object: Object to processing of personal data.
-
Right not to be subject to automated decisions: Including profiling, unless legally authorized.
-
Right to withdraw consent: At any time.
Contact to exercise rights:
AB INGENIERÍA CIVIL, SL – PRESSTOK
Avenida del Pilar 14, 22400, Monzón (Huesca), Spain
Phone: +34 974 401 135
Email: ventas@presstok.com
Website: https://www.presstok.com
11. RIGHT TO LODGE A COMPLAINT
Users have the right to file a complaint with the Spanish Data Protection Agency (AEPD) if they believe their rights have been violated.
AEPD Contact Info:
Email: info@aepd.es
Phone: 900 293 183
Website: https://www.aepd.es
Address: C/. Jorge Juan, 6. 28001 Madrid, Spain
12. ACCEPTANCE AND CHANGES TO THE PRIVACY POLICY
Users must read and accept this Privacy Policy to allow data processing. The Controller reserves the right to change this Policy based on legal updates or regulatory guidance. Changes that affect processing purposes, retention periods, data sharing, or user rights will be explicitly communicated to users.

Español
Deutsch
Français
Italiano