Last updated: [DATE OF LAST UPDATE]
This Privacy Policy explains how PiscisPro collects, uses, stores and protects personal data through the website
piscispro.eu and its online store.
PiscisPro sells kits, moulds and materials for making soft plastic fishing lures. The website is operated using
WordPress and WooCommerce and is intended primarily for customers located in Spain and other countries of the
European Union.
This policy has been prepared with reference to Regulation (EU) 2016/679, the General Data Protection Regulation
(GDPR), Spanish Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD), and
Spanish Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE).
1. Summary of the processing of personal data
| Item | Information |
|---|---|
| Data controller | [LEGAL NAME OR BUSINESS NAME] |
| Main purposes | Processing orders, payments, delivery, invoicing, customer service, account management, security, analytics and, where consent has been given, marketing communications. |
| Legal bases | Performance of a contract, compliance with legal obligations, consent and, where appropriate, legitimate interests. |
| Recipients | Payment providers, delivery companies, hosting providers, technical suppliers, analytics providers, email service providers, CRM providers and public authorities where legally required. |
| User rights | Access, rectification, erasure, restriction, objection, portability, withdrawal of consent and the right to lodge a complaint with a supervisory authority. |
| Privacy contact | [PRIVACY EMAIL] |
2. Identity of the data controller
The data controller responsible for the processing of personal data through this website is:
- Trade name: PiscisPro
- Legal name or business name: [LEGAL NAME OR BUSINESS NAME]
- NIF, CIF or NIE: [NIF/CIF/NIE]
- Registered or tax address: [FULL ADDRESS]
- Website: piscispro.eu
- Privacy email: [PRIVACY EMAIL]
- Telephone: [TELEPHONE]
- Registration details: [REGISTRATION DETAILS, IF APPLICABLE]
- Data Protection Officer: [DPO, IF APPLICABLE]
3. Personal data we collect
Depending on how a user interacts with the website, PiscisPro may collect the following categories of data:
- Identification data, such as name and surname.
- Contact data, such as email address, telephone number and postal address.
- Order data, such as purchased products, quantities, prices, discounts and order status.
- Delivery data, including the recipient’s name, delivery address and delivery instructions.
- Billing and tax data, including billing address and tax identification details where required.
- Account data, such as username, encrypted password, account preferences and order history.
- Customer service communications, including messages, enquiries, complaints and return requests.
- Marketing preferences and newsletter subscription records.
- Technical data, such as IP address, browser type, device information, operating system and access logs.
- Usage data, such as viewed pages, interactions, traffic source and website navigation data.
- Security and fraud-prevention data.
- Cookie identifiers and similar online identifiers, subject to the user’s consent where required.
PiscisPro does not intentionally request special categories of personal data, such as health data, biometric data,
political opinions, religious beliefs or data relating to a person’s sex life or sexual orientation.
4. How personal data is collected
Personal data may be collected through the following channels:
- Checkout and purchase forms.
- User account registration and account-management forms.
- Contact and customer-support forms.
- Newsletter subscription forms.
- Email, telephone or other direct communications.
- Returns, refund and complaint procedures.
- Cookies, analytics tools and similar technologies.
- Payment, delivery and technical service providers.
- Security, fraud detection and server log systems.
5. Processing activities
| Activity | Data processed | Purpose | Legal basis | Recipients | Retention period |
|---|---|---|---|---|---|
| Purchase and order management | Name, contact details, address, order details and transaction references | To process, confirm, prepare and manage purchases | Performance of a contract | PiscisPro staff, WooCommerce service providers and relevant technical suppliers | For the duration of the contractual relationship and afterwards for the applicable legal limitation periods |
| Payment processing | Transaction reference, amount, payment status and limited payment metadata | To collect payment and manage payment incidents or refunds | Performance of a contract and compliance with legal obligations | [PAYMENT PROVIDER] | For the time required to complete the transaction and for applicable accounting, tax and dispute periods |
| Shipping and delivery | Name, telephone number, email, delivery address and delivery instructions | To deliver the order and provide delivery updates | Performance of a contract | [DELIVERY COMPANY] | For the time required to complete delivery and manage possible delivery claims |
| Invoicing and accounting | Identity, billing address, tax details, order and payment information | To issue invoices and comply with accounting and tax requirements | Compliance with legal obligations | Accounting advisers, tax authorities and competent public bodies | For the statutory accounting and tax retention periods |
| Customer service | Name, contact details, order details and content of communications | To answer questions and manage incidents, complaints, returns and refunds | Performance of a contract, pre-contractual measures or legitimate interests in managing customer relationships and defending legal claims |
Customer-support and technical service providers where necessary | Until the enquiry is resolved and afterwards for applicable limitation periods |
| Contact forms | Name, email, telephone number and message content | To respond to requests for information | Consent or pre-contractual measures requested by the user | [CRM] and technical form-processing providers, where applicable | Until the request is answered and for a reasonable follow-up period |
| User account registration | Name, email, username, encrypted password, addresses and account history | To create and manage the user account | Performance of a contract or pre-contractual measures | Hosting, WordPress and WooCommerce technical providers | While the account remains active and afterwards for applicable legal or dispute periods |
| Newsletter and commercial communications | Name, email address, subscription date, consent record and communication interactions | To send marketing messages where the user has requested them | Consent and, where legally applicable, the existing-customer exception under electronic-commerce law | [EMAIL MARKETING SERVICE] | Until consent is withdrawn or the user unsubscribes, plus the period required to retain proof of consent |
| Website analytics | IP address, device data, browser data, cookie identifiers and usage information | To measure website performance and understand how users interact with the website | Consent for non-essential analytics cookies | [ANALYTICS TOOL] | According to the configured cookie and analytics retention periods |
| Fraud prevention and security | IP address, device data, access logs, transaction metadata and suspicious activity records | To detect abuse, fraud, unauthorised access and security incidents | Legitimate interests in protecting the website, customers and transactions, and compliance with legal obligations where applicable |
Hosting, security and payment providers, and competent authorities where legally required | For the period necessary to investigate incidents and defend against claims |
| Compliance with legal obligations | Identity, transaction, billing, communication and order data | To comply with tax, accounting, consumer, judicial and regulatory obligations | Compliance with legal obligations | Courts, public authorities, tax authorities and law-enforcement bodies where legally required | For the retention periods established by applicable law |
6. Data required to make a purchase
Certain personal data must be provided in order to place an order. Mandatory fields are identified in the checkout
form.
These details may include:
- Name and surname.
- Billing and delivery address.
- Email address.
- Telephone number.
- Payment selection and transaction information.
- Any tax information legally required for invoicing.
If mandatory data is not provided, PiscisPro may be unable to accept, process or deliver the order.
7. Orders, payment, invoicing and shipping
Personal data provided during checkout is processed to confirm the purchase, collect payment, prepare the products,
issue the corresponding documentation and deliver the order.
Payment-card or bank details may be processed directly by [PAYMENT PROVIDER]. Where payment is
handled by an external provider, PiscisPro should not receive or store complete card details. PiscisPro may receive
a transaction identifier, payment status, amount, date and limited technical information needed to reconcile the
payment.
Delivery details may be disclosed to [DELIVERY COMPANY] to arrange shipment, delivery and related
communications.
Billing and tax records may be retained for the statutory periods required under Spanish accounting and tax law.
8. User accounts
Where account registration is enabled, users may create an account to manage their addresses, view order history
and access functions made available by the store.
Users are responsible for keeping their login credentials confidential and for notifying PiscisPro if they believe
their account has been accessed without authorisation.
9. Customer service and enquiries
When a user contacts PiscisPro, the information provided will be processed to understand and respond to the request.
The legal basis may be the performance of a contract, steps taken at the user’s request before entering into a
contract, consent, or a legitimate interest in providing customer support and defending against claims.
10. Newsletter and commercial communications
PiscisPro will send newsletters or promotional communications only where a valid legal basis exists.
Where consent is required, subscription must be voluntary, specific, informed and unambiguous. The user may
unsubscribe at any time through the unsubscribe mechanism included in the communication or by contacting
[PRIVACY EMAIL].
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
Acceptance of this Privacy Policy does not constitute general consent for all marketing or optional processing
activities. Information duties and consent are legally distinct requirements.
11. Abandoned-cart communications
[CONFIRM WHETHER ABANDONED-CART RECOVERY IS USED.]
If abandoned-cart recovery is used, this section must identify the service involved, the data processed, the legal
basis, the retention period and whether reminder emails are sent.
If this functionality is not used, this section should be removed before publication.
12. Analytics and measurement
PiscisPro may use [ANALYTICS TOOL] to understand website usage and improve technical performance.
Where analytics involves non-essential cookies or comparable identifiers, those technologies will not be activated
until the user has provided valid consent through [COOKIE CONSENT MANAGER].
Users must be able to reject non-essential cookies as easily as they can accept them.
13. Cookies and similar technologies
The website may use technical cookies that are necessary for essential functions such as shopping-cart management,
checkout security, session maintenance and user authentication.
Analytics, advertising, personalisation and other non-essential cookies require prior consent where applicable.
More detailed information about cookie names, purposes, providers, duration and consent controls must be included in
a separate Cookie Policy.
14. Recipients and data processors
PiscisPro may engage third-party service providers that process personal data on its behalf. These suppliers must
process the data only according to documented instructions and must provide appropriate security and confidentiality
commitments.
Possible categories of providers include:
- Hosting provider: [HOSTING PROVIDER]
- Payment provider: [PAYMENT PROVIDER]
- Delivery company: [DELIVERY COMPANY]
- Email marketing service: [EMAIL MARKETING SERVICE]
- CRM provider: [CRM]
- Analytics provider: [ANALYTICS TOOL]
- Cookie-consent manager: [COOKIE CONSENT MANAGER]
- Accounting, legal and tax advisers.
- Website maintenance and cybersecurity providers.
Personal data may also be disclosed to public authorities, courts, tax authorities, regulators or law-enforcement
bodies where disclosure is required by law.
15. International data transfers
Some service providers may process data outside the European Economic Area.
Where an international transfer takes place, PiscisPro will verify that an appropriate transfer mechanism is in
place, such as:
- An adequacy decision adopted by the European Commission.
- Standard Contractual Clauses approved by the European Commission.
- Other safeguards recognised under applicable data-protection law.
- A valid derogation applicable to a specific situation.
The final version of this policy must identify any confirmed international transfers and the safeguards used by each
relevant provider.
16. Retention periods
Personal data will be retained only for as long as necessary for the purpose for which it was collected.
After the active processing period ends, data may be blocked or securely retained for the periods required to comply
with tax, accounting, consumer-protection, contractual, regulatory or legal-claims obligations.
General criteria include:
- Order data: for the duration of the customer relationship and applicable legal limitation periods.
- Accounting and tax data: for the statutory periods applicable in Spain.
- Customer-service communications: until resolution and for the period necessary to manage claims.
- User-account data: while the account remains active and for applicable legal periods afterwards.
- Newsletter data: until the user unsubscribes or withdraws consent.
- Consent records: for as long as necessary to demonstrate that valid consent was obtained.
- Security logs: for a proportionate period necessary to detect and investigate incidents.
- Cookie data: according to the duration stated in the Cookie Policy.
17. User rights
Users may exercise the following rights under applicable data-protection law:
- Access: to obtain confirmation of whether personal data is being processed and receive a copy.
- Rectification: to correct inaccurate or incomplete personal data.
- Erasure: to request deletion where the legal requirements are met.
- Restriction: to request restricted processing in certain circumstances.
- Objection: to object to processing based on legitimate interests or direct marketing.
- Portability: to receive certain data in a structured, commonly used and machine-readable format.
- Withdrawal of consent: at any time where processing is based on consent.
- Automated decisions: not to be subject to a decision based solely on automated processing that
produces legal or similarly significant effects, where the applicable legal requirements are met.
18. How to exercise data-protection rights
Requests may be sent to [PRIVACY EMAIL] or to the postal address
[FULL ADDRESS].
The request should include:
- The user’s name and contact details.
- The right being exercised.
- Sufficient information to identify the relevant account, order or communication.
- Any supporting information needed to process the request.
PiscisPro may request reasonable proof of identity where necessary to prevent unauthorised disclosure or alteration
of personal data.
19. Withdrawal of consent
Where processing is based on consent, the user may withdraw that consent at any time.
Withdrawal will not affect the lawfulness of processing carried out before withdrawal and will not affect processing
that is based on another valid legal basis, such as compliance with a legal obligation or performance of a contract.
20. Complaints to the supervisory authority
Users who believe that their personal data has been processed unlawfully may lodge a complaint with the Spanish
Data Protection Agency, the Agencia Española de Protección de Datos.
Before lodging a complaint, users may contact PiscisPro at [PRIVACY EMAIL] so that the matter can be reviewed.
21. Data relating to minors
The online store is not intentionally directed at children and does not knowingly collect personal data from minors
who are not legally authorised to enter into the relevant transaction.
Where parental or guardian authorisation is legally required, an order or consent submitted by a minor may be
rejected or cancelled until the required authorisation is verified.
22. Information security
PiscisPro will apply technical and organisational measures appropriate to the risks involved in processing personal
data.
These measures may include:
- Encrypted transmission using HTTPS.
- Restricted administrative access.
- Strong authentication and password controls.
- Software updates and vulnerability management.
- Backups and recovery procedures.
- Access logging and security monitoring.
- Data-minimisation and retention controls.
- Contracts and confidentiality obligations for service providers.
No internet-based service can guarantee absolute security. Users should also take appropriate precautions to protect
their credentials and devices.
23. Automated decision-making and profiling
[CONFIRM WHETHER AUTOMATED DECISION-MAKING OR PROFILING IS USED.]
Unless expressly stated otherwise, PiscisPro does not make decisions based solely on automated processing that
produce legal effects or similarly significant effects for users.
Security and fraud-detection tools may generate risk indicators, but relevant decisions should be subject to human
review where required by law.
24. Third-party links
The website may include links to third-party websites or services. PiscisPro is not responsible for the privacy
practices of external websites.
Users should review the privacy information provided by each third party before submitting personal data to that
service.
25. Changes to this Privacy Policy
PiscisPro may update this Privacy Policy to reflect changes in the website, services, suppliers, processing
activities or applicable legal requirements.
Where a change materially affects users, PiscisPro may provide an additional notice through the website, account
area or other appropriate communication channel.
26. Date of last update
This Privacy Policy was last updated on [DATE OF LAST UPDATE].
27. Information the owner must complete before publishing this policy
This document must not be published as a final Privacy Policy until all placeholders have been replaced with
accurate and verified information.
- [LEGAL NAME OR BUSINESS NAME]
- [NIF/CIF/NIE]
- [FULL ADDRESS]
- [PRIVACY EMAIL]
- [TELEPHONE]
- [REGISTRATION DETAILS, IF APPLICABLE]
- [DPO, IF APPLICABLE]
- [PAYMENT PROVIDER]
- [DELIVERY COMPANY]
- [HOSTING PROVIDER]
- [EMAIL MARKETING SERVICE]
- [CRM]
- [ANALYTICS TOOL]
- [COOKIE CONSENT MANAGER]
- [DATE OF LAST UPDATE]
- [CONFIRM WHETHER ABANDONED-CART RECOVERY IS USED]
- [CONFIRM WHETHER AUTOMATED DECISION-MAKING OR PROFILING IS USED]
Before publication, the owner should also verify:
- Which cookies and tracking tools are actually active.
- Whether Google Analytics, advertising pixels or similar services are installed.
- Whether newsletter or email-marketing services are active.
- Whether abandoned-cart recovery emails are sent.
- Whether customer accounts are currently enabled.
- Which payment and delivery providers receive personal data.
- Whether any provider transfers data outside the European Economic Area.
- The actual retention settings configured in WordPress, WooCommerce and connected services.
- Whether a Data Protection Officer is legally required.