Skip to content Skip to footer

This privacy policy complies with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR), with Organic Law 3/2018 of 5 December on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD), as well as, insofar as it does not conflict with the aforementioned legislation, with Organic Law 15/1999 on the Protection of Personal Data (LOPD) and its implementing regulations, and/or any regulations that may replace or update them in the future.

Our organisation is committed to the privacy of your personal data. The personal data provided are necessary to deliver our services and are processed lawfully, fairly and transparently, ensuring an adequate level of security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, through the application of technical and organisational measures.

Through this document, we aim to provide you, in a transparent and fair manner, with all the necessary information relating to the processing of your personal data carried out by this organisation.

I.- DATA CONTROLLER

IDENTITY: FOUNDATION FOR THE CONSERVATION OF IBIZA AND FORMENTERA

TAX ID (C.I.F. / N.I.F.): G57940678

ADDRESS: C/ VENDA DE CAN LLÀTZER, 25, 07814 SANTA EULALIA DEL RÍO (BALEARIC ISLANDS)

TELEPHONE: 634072653

E-MAIL: info@ibizapreservation.org

DATA PROTECTION OFFICER: dpo@procoden.es

II.- RECIPIENTS OF PERSONAL DATA

1.- The personal data provided will not be disclosed to any third parties unless otherwise specified in the relevant specific processing activities.

2.- Optionally, for the contracting of cloud computing services and/or services for the sending of emails, communications, as well as other related IT services, personal data may be:

  • Disclosed to IT service companies located within the European Economic Area (EEA), or
  • Where some of our suppliers or service providers are located outside the European Economic Area (EEA), we guarantee that international data transfers will be carried out in accordance with applicable regulations. In particular, in the case of providers located in the United States, such transfers may be covered by the EU–US Data Privacy Framework (https://www.dataprivacyframework.gov), recognised as adequate by the European Commission on 10 July 2023, or by standard contractual clauses approved by the European Commission.

3.- Optionally, to public administrations and other bodies when required in compliance with legal obligations.

III.- LEGAL BASIS FOR THE PROCESSING OF PERSONAL DATA

For each specific processing of personal data, we will inform you of the legal basis that legitimises it.

IV.- RIGHTS

RIGHT OF ACCESS

This is the right to obtain confirmation from the data controller as to whether or not personal data concerning the data subject are being processed and, where that is the case, access to the personal data and the following information: the purposes of the processing; the categories of personal data concerned; the recipients or categories of recipients to whom the personal data have been or will be disclosed; the retention period or the criteria used to determine that period; the existence of the right to request rectification or erasure of personal data or restriction of processing or to object to such processing; the right to lodge a complaint with the Spanish Data Protection Agency (AEPD); the existence, where applicable, of automated decision-making, including profiling; and, where data are transferred to third countries, the right to be informed of the appropriate safeguards applied.

RIGHT OF RECTIFICATION

This is the right to request the rectification of personal data where they are inaccurate, including the right to have incomplete data completed. It should be noted that by providing personal data through any means, you guarantee that they are true and accurate and undertake to notify us of any changes or modifications. Any damage caused by the communication of incorrect, inaccurate or incomplete information in website forms shall be the sole responsibility of the data subject.

RIGHT OF ERASURE

This is the right to request the erasure of personal data when, among other circumstances, they are no longer necessary for the purpose for which they were collected, are otherwise being processed unlawfully, or consent is withdrawn. It should be noted that erasure will not apply where the processing of personal data is necessary, among other cases, for compliance with legal obligations or for the establishment, exercise or defence of legal claims.

RIGHT TO RESTRICTION

This is the right to request the restriction of the processing of personal data, which means that in certain cases you may ask us to temporarily suspend the processing of your personal data or to retain them beyond the necessary period when you may need them.

RIGHT TO WITHDRAW CONSENT

This is the right to withdraw the consent you have provided by ticking “I have read and accept the privacy policy” at any time and as specified in the corresponding section “Exercise of rights” or in the specific processing of commercial communications or newsletters. It should be noted that this right will not apply where, among other cases, the processing of personal data is necessary to comply with a legal obligation, for the performance and maintenance of a contractual relationship, or for the establishment, exercise or defence of legal claims. Likewise, the withdrawal of consent will not have retroactive effect and will not affect the lawfulness of processing based on consent prior to its withdrawal.

RIGHT TO DATA PORTABILITY

This is the right to receive the personal data concerning you that you have provided to us, in a structured, commonly used and machine-readable format, and to transmit them to another controller, provided that the processing is based on your consent and is carried out by automated means.

RIGHT TO OBJECT

This is the right to object to the processing of your personal data based on our legitimate interest. We will cease processing unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims.

RIGHT TO LODGE A COMPLAINT WITH A SUPERVISORY AUTHORITY

If you believe that we are processing your personal data incorrectly, you may contact us or you also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD):

https://www.agpd.es/portalwebAGPD/index-ides-idphp.php

EXERCISE OF RIGHTS

You may exercise your rights by sending a letter to the postal address indicated above or by email to info@ibizapreservation.org, in both cases enclosing a copy of your ID card, NIE, passport or equivalent document.

V.- PROCESSING OF PERSONAL DATA

GENERAL PROVISIONS

The personal data requested in each specific processing activity are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed, in compliance with the principle of data minimisation.

The personal data requested in each specific processing activity are strictly necessary; refusal to provide them would make it impossible to deliver the requested service.

The disclosure of personal data envisaged in each specific processing activity is, in some cases, necessary for the performance and maintenance of a contract and, in other cases, for compliance with an applicable legal obligation of the data controller.

DONATE / JOIN THE CIRCLE FORMS

Personal data will be processed to channel financial donations.

The legal basis legitimising the processing of personal data is explicit consent given by ticking “I have read and accept the privacy policy”.

Personal data will be disclosed to the companies managing donations, the company managing the CRM (where consent has been given to receive the newsletter), and to Conservation Collective, IbizaPreservation’s partner foundation in the United Kingdom.

Personal data will be retained for the period established by law from the moment they cease to be processed, without prejudice to the exercise of the rights available to you as a data subject.

NEWSLETTER SUBSCRIPTION

Personal data will be processed to manage subscription to our Newsletter, including the sending of personalised or non-personalised information about our activities, projects, events, campaigns, programmes and other institutional actions through various means such as telephone, email, SMS, mobile applications, as well as any analogous procedure. It should be noted that this type of data processing may involve analysing your user profile to determine your preferences in order to send you information more aligned with your interests.

You may request to unsubscribe from this type of processing, depending on the medium used, as follows:

Email: Via the link provided in each electronic communication or by an analogous procedure specified in the privacy policy.
WhatsApp (other apps): By requesting removal directly from the group administrators.
SMS: By requesting unsubscription.

The legal basis legitimising the processing of personal data is the explicit consent provided by ticking “I have read and accept the privacy policy” on the website, via a physical document or by email, as applicable.

Personal data will be disclosed to the company managing the Foundation’s newsletter distribution. Where the communication channel used is WhatsApp, personal data will be disclosed to WhatsApp Ireland Limited, which is located within the EEA.

Personal data will be retained until consent is withdrawn in the manner indicated in this section.

EMAIL

Personal data included in emails will be processed to maintain communications related to enquiries, requests for information or support, and to manage the relationship between the parties.

The legal basis legitimising the processing of personal data is the data subject’s consent to receive certain types of communications (Article 6.1.a GDPR) and legitimate interest in responding to enquiries (Article 6.1.f GDPR).

Data will not be disclosed to third parties, except to the email service and cloud storage providers, to third parties where it is necessary to communicate the data in order to process the request, or where required by legal obligation.

International data transfers are carried out to GOOGLE, LLC through the use of the email application GMAIL. Data processors: IT services.

Data are collected directly from the data subject or from authorised sources in connection with the provision of services or products. No data are obtained from third parties without consent, nor are special category data processed without explicit authorisation.

Personal data will be retained for the period necessary to fulfil the purpose for which they were collected and while legal liabilities may arise from such processing, without prejudice to the exercise of the rights available to you as a data subject.

IMAGES

Personal data relating to images will be processed for the following purposes:

Where authorisation is given for the capture and/or dissemination of images, they will be processed to manage the authorisation for the capture of images/photographs in which the data subject appears individually or in a group, within the context of activities carried out by the data controller.

Authorisation to capture and disseminate images: the purpose of capturing images is to document, disseminate and promote the entity’s activities, events or services, publishing them on its own media such as the website, social networks, newsletters or promotional material, as well as in the media, and to ensure compliance with legal obligations such as security or access control.

The legal basis legitimising the use of images is the explicit consent of the data subject or their legal representative.

Data are obtained directly from the adult data subject who authorises the capture and/or dissemination of images, or from legal representatives in the case of minors under 18 years of age; where minors are over 14 years of age, their own authorisation is also required.

Images will be retained until consent is withdrawn.

Images may be disclosed, where applicable, for dissemination through the entity’s own media.

EVENT REGISTRATION

Personal data collected in the registration form will be processed to manage registration and participation in the event or activity, communicate practical or administrative information regarding the event (schedules, changes, reminders), issue accreditations, certificates or attendance confirmations where applicable, manage payments or registration fees, send information related to the event, and comply with legal and administrative obligations arising from the organisation of the event.

The legal basis legitimising the processing of personal data is the performance of a contract (management of registration and participation), the consent of the data subject expressed at the time of registration, and compliance with the organiser’s legal obligations (fiscal, accounting or security).

Data are obtained directly from the data subject or, in the case of minors, from their parent or legal guardian.

Data will be disclosed to third-party companies or bodies managing event registration or booking platforms. They may also be disclosed to competent public administrations in compliance with legal obligations, or to collaborating entities where necessary for the management or subsequent justification of the event, always within the declared purposes, as well as to service providers acting as data processors.

Data will be retained for as long as necessary for the organisation and management of the event or activity and subsequently for the applicable legal retention periods.

RECEIPT OF CVs BY EMAIL

Personal data included in CVs, as well as those collected during selection processes, will be processed to manage recruitment processes within the Foundation, including interviews, tests and related communications, and to assess the suitability of candidates. Data may also be retained for future recruitment processes where the candidate is not selected and such retention is authorised.

The legal basis legitimising the processing of personal data is the legitimate interest of the data controller and the consent of the data subject granted by voluntarily submitting their CV by email.

As a necessary contractual requirement, personal data may be disclosed to other organisations forming part of the same group for the same stated purpose.

Personal data are obtained directly from the candidate through submission of their CV by email.

Personal data will be retained for a period of two years from the moment processing ceases, without prejudice to the exercise of the rights available to you as a data subject. After this period or upon withdrawal of consent, data will be securely deleted.

DONATIONS

Personal data of members and donors are processed for the following purposes: managing financial contributions (regular fees or one-off donations), issuing receipts, certificates and tax confirmations for contributions made, maintaining the administrative and accounting relationship arising from their status as a member or donor, informing them about campaigns, activities and projects related to the Foundation’s aims, and complying with applicable legal and fiscal obligations.

The legal bases legitimising the processing are the consent given, the performance of a contract or associative relationship, and compliance with legal obligations, particularly those arising from fiscal and accounting regulations.

Data may be disclosed to banking institutions for the management of payments or direct debits, to the tax authorities for compliance with legal obligations, to accounting or tax advisers for the financial management of the foundation, and to technology providers offering hosting, communications or management software services, under confidentiality and data processing agreements. Under no circumstances will data be disclosed to third parties for commercial purposes.

The international data transfers carried out are as follows:

Raisely: https://support.raisely.com/article/255-security-at-raisely https://support.raisely.com/article/458-is-raisely-gdpr-compliant

Conservation Collective: https://conservation-collective.org/privacy-safeguarding/

For services located in third countries, compliance with the standard contractual clauses approved by the European Commission is guaranteed.

Data will be retained for as long as the member or donor relationship is maintained and subsequently for the legally required periods.

WHATSAPP

Personal data will be processed for the following purposes:

To respond to enquiries, requests for information, or to manage the pre-contractual or contractual relationship between the parties.
Inclusion in a WhatsApp group to send you informational, commercial or update communications about our services via a broadcast group.

The legal basis legitimising the processing of personal data is the explicit consent given by signing the corresponding authorisation for the processing of personal data.

Personal data collected will not be disclosed to third parties, except where required by legal obligation. However, it should be noted that:

By using WhatsApp, your data are processed by WhatsApp Ireland Limited (Meta Platforms, Inc.), which acts as the communication service provider.
If you are part of a WhatsApp group, your phone number and profile name will be visible to the other group members.

The use of WhatsApp involves an international transfer of your data to the United States, which is necessary for the provision of the messaging service. This transfer is carried out under the appropriate data protection safeguards offered by the service provider.

Personal data will be retained until consent is withdrawn, unless they must be retained to maintain the relationship between the parties or for the years required to comply with legal obligations.

Go to Top