PRIVACY POLICY OF THE WEB

I. PRIVACY POLICY AND DATA PROTECTION

In compliance with current legislation, Goldhammer Miniatures (hereinafter also referred to as the Website) commits to adopting the necessary technical and organizational measures, according to the level of security appropriate to the risk of the data collected.

Laws incorporated into this privacy policy

This privacy policy is adapted to the current Spanish and European regulations on the protection of personal data on the internet. Specifically, it complies with the following regulations:

- Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016, concerning the protection of individuals with regard to the processing of personal data and the free movement of such data (GDPR).

- Organic Law 3/2018, of 5 December, on the Protection of Personal Data and guarantee of digital rights (LOPD-GDD).

- Royal Decree 1720/2007, of 21 December, which approves the development regulations of Organic Law 15/1999, of 13 December, on the Protection of Personal Data (RDLOPD).

- Law 34/2002, of 11 July, on Information Society Services and Electronic Commerce (LSSI-CE).

Identity of the data controller

The controller of the personal data collected by Goldhammer Miniatures is: Jorge Fernández Sanz, with NIF: 16598581X (hereinafter, Data Controller). His contact information is as follows:

- Address: C/ García Lorca, 1, Bajo 3  

- Contact phone: +34 677 058 016  

- Contact email: info@goldhammerminiatures.es

Personal Data Registration

In compliance with the GDPR and LOPD-GDD, we inform you that the personal data collected by Goldhammer Miniatures, through the forms available on its pages, will be incorporated and processed in our file for the purpose of facilitating, streamlining, and fulfilling the commitments established between Goldhammer Miniatures and the User, or maintaining the relationship established in the forms that the User completes, or to address a request or inquiry. Likewise, in accordance with the provisions of the GDPR and LOPD-GDD, unless otherwise provided by the exception in Article 30.5 of the GDPR, a record of processing activities is maintained specifying, based on their purposes, the processing activities carried out and other circumstances established in the GDPR.

Principles applicable to the processing of personal data

The processing of the User's personal data will be subject to the following principles set out in Article 5 of the GDPR and Article 4 and subsequent articles of Organic Law 3/2018, of 5 December, on the Protection of Personal Data and guarantee of digital rights:

1. Lawfulness, fairness, and transparency: The User’s consent will be required at all times following fully transparent information on the purposes for which personal data are collected.

2. Purpose limitation: Personal data will be collected for specific, explicit, and legitimate purposes.

3. Data minimization: The personal data collected will only be strictly necessary for the purposes for which they are processed.

4. Accuracy: Personal data must be accurate and kept up to date.

5. Storage limitation: Personal data will only be kept in a form that allows the identification of the User for the time necessary for the purposes of the processing.

6. Integrity and confidentiality: Personal data will be processed in a way that ensures its security and confidentiality.

7. Accountability: The Data Controller will be responsible for ensuring that the above principles are complied with.

Categories of personal data

The categories of data processed by Goldhammer Miniatures are solely identifying data. Under no circumstances are special categories of personal data processed as defined in Article 9 of the GDPR.

Legal basis for the processing of personal data

The legal basis for the processing of personal data is consent. Goldhammer Miniatures is committed to obtaining the User’s explicit and verifiable consent for the processing of their personal data for one or more specific purposes.

The User has the right to withdraw their consent at any time. Withdrawing consent will be as easy as granting it. As a general rule, the withdrawal of consent will not affect the use of the Website.

On occasions when the User must or can provide their data through forms to make inquiries, request information, or for reasons related to the content of the Website, the User will be informed if the completion of any of these forms is mandatory, as they are essential for the proper development of the operation carried out.

Purposes of processing personal data

Personal data are collected and managed by Goldhammer Miniatures to facilitate, expedite, and fulfill the commitments established between the Website and the User or to maintain the relationship established in the forms that the User completes or to respond to a request or inquiry.

Similarly, the data may be used for commercial purposes, including personalization, operations, and statistical analysis, and activities related to the social purpose of Goldhammer Miniatures, as well as for the extraction, storage, and marketing studies to tailor the Content offered to the User and improve the quality, operation, and navigation of the Website.

At the time personal data is obtained, the User will be informed about the specific purposes of the processing of their personal data; in other words, the use or uses that will be made of the information collected.

**Retention periods for personal data**

Personal data will only be retained for the minimum time necessary for the purposes of their processing and, in any case, only for the following period: until the User requests its deletion.

At the time personal data is obtained, the User will be informed about the period for which the personal data will be retained or, when that is not possible, the criteria used to determine this period.

Recipients of personal data

The User’s personal data will not be shared with third parties.

In any case, at the time personal data is obtained, the User will be informed about the recipients or categories of recipients of the personal data.

Personal data of minors

In accordance with Articles 8 of the GDPR and 7 of Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights, only individuals over the age of 14 may lawfully consent to the processing of their personal data by Goldhammer Miniatures. In the case of minors under 14 years of age, parental or guardian consent will be required for the processing, and such consent will only be considered lawful to the extent that it has been authorized by the parents or guardians.

Confidentiality and security of personal data

Goldhammer Miniatures is committed to adopting the necessary technical and organizational measures, according to the level of security appropriate to the risk of the data collected, to ensure the security of personal data and to prevent the accidental or unlawful destruction, loss, or alteration of personal data transmitted, stored, or otherwise processed, or unauthorized disclosure or access to such data.

The Website has an SSL (Secure Socket Layer) certificate, ensuring that personal data is transmitted securely and confidentially, as data is transmitted between the server and the User, and in feedback, fully encrypted.

However, since Goldhammer Miniatures cannot guarantee the complete invulnerability of the internet or the total absence of hackers or others who may fraudulently access personal data, the Data Controller agrees to notify the User without undue delay when a personal data security breach occurs that is likely to pose a high risk to the rights and freedoms of natural persons. In accordance with Article 4 of the GDPR, a personal data breach means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.

Personal data will be treated confidentially by the Data Controller, who commits to ensuring that confidentiality is respected by their employees, associates, and anyone to whom access to the information is granted, through a legal or contractual obligation.

Rights derived from the processing of personal data

The User has several rights over Goldhammer Miniatures and may, therefore, exercise the following rights recognized in the GDPR and Organic Law 3/2018, of 5 December, on the Protection of Personal Data and guarantee of digital rights:

- Right of access

- Right to rectification

- Right to erasure ("the right to be forgotten")

- Right to restriction of processing

- Right to data portability

- Right to object

- Right not to be subject to automated decision-making, including profiling

These rights may be exercised through written communication sent to the Data Controller at the address or email provided, including the User's identification and the specific request.

Links to third-party websites

The Website may include hyperlinks or links that allow access to web pages of third parties other than Goldhammer Miniatures. The owners of these websites will have their own privacy policies, being responsible for their files and their own privacy practices.

Complaints to the supervisory authority

If the User believes there is an issue or violation of current regulations regarding the way their personal data is being processed, they will have the right to effective judicial protection and to file a complaint with a supervisory authority, particularly in the Member State where they have their habitual residence, place of work, or place of the alleged violation. In the case of Spain, the supervisory authority is the Spanish Data Protection Agency (https://www.aepd.es/).

---

II. ACCEPTANCE AND CHANGES TO THIS PRIVACY POLICY

It is necessary that the User has read and agrees with the terms on the protection of personal data contained in this Privacy Policy and accepts the processing of their personal data so that the Data Controller can proceed in the manner, for the periods, and for the purposes indicated. The use of the Website will imply acceptance of its Privacy Policy.

Goldhammer Miniatures reserves the right to modify its Privacy Policy according to its own criteria or due to a legislative, jurisprudential,

 or doctrinal change of the Spanish Data Protection Agency. Changes or updates to this Privacy Policy will not be explicitly notified to the User. Therefore, the User is advised to review this page periodically.

This Privacy Policy was updated on January 1, 2024, to adapt to the General Data Protection Regulation (GDPR) and Organic Law 3/2018, of 5 December, on the Protection of Personal Data and guarantee of digital rights.