Andalú Mística has created this privacy policy (“Privacy Policy”) to communicate its policies and practices relating to using and disclosing information about you obtained on the andalumistica.com website.
Please read this Privacy Policy carefully. Andalú Mística reserves the right to change or update this Privacy Policy periodically. You can view the most current version of the Privacy Policy by clicking on the hyperlink “Privacy Policy” located at the bottom of the andalumistica.com website.
Andalú Mística processes your personal data in accordance with the requirements of (EU) 2016/679 – General Data Protection Regulation (GDPR), EU-U.S. Privacy Shield framework as well as the current domestic Data Protection legislation.
Categories of Personal Data that Andalú Mística processes
1. Your contact information – names, postal address, mobile or phone number, email address
2. Your IP address
3. Purchase details, including the payment method and transaction number
4. History of your order
5. Customer service information – all kinds of communication and correspondence between you and our customer service department.
6. In exceptional circumstances, you may be required to provide us with additional ID card details to certify your identity
7. In a few cases, you may provide us with your photos, videos, or others if you declare your interest in participating in one of our campaigns, or other events.
8. Andalú Mística reserves the right to send all its customers an invitation to participate in satisfaction surveys. However, participation is always optional.
9. Andalú Mística does not process or store data from your bank cards or other financial instruments.
Lawfulness of processing
Andalú Mística processes your personal data only after receiving your consent.
Andalú Mística processes your personal data, which is necessary for the performance of your contract.
Andalú Mística processes your personal data necessary to comply with tax, financial, or other domestic legislation requirements.
We process your personal data for the following purposes:
For accurate and correct execution and delivery of your order.
To provide precise and accurate communication with you about the status of your order.
For warranty within the warranty period of the products
For customer satisfaction and loyalty programs
For tax requirements and accounting legislation – to declare and count our sales.
In exceptional circumstances, Andalú Mística may process additional identification information of yours to avoid financial fraud or identity theft.
As an exception, Andalú Mística can process additional data such as photos, videos, and other media for various campaigns or lotteries only when customers participate in these events.
To be able to send our newsletter and promotional materials, only in cases when customers give their consent for that.
The time for which your personal data will be stored:
Andalú Mística stores the personal data you have submitted during your account registration on our Site, as long as your account remains active.
Andalú Mística stores your personal data during the production and delivery of products and the time specified in the Return Policy for the possible returns and product warranty, but not longer than 2 years or longer than the warranty time.
If we require additional data to verify your identity, we will store these data until the legal requirement to keep these data is no longer in place.
In the case of collecting personal data for particular campaigns, lotteries, and any other promotions, the period of processing shall be specified in every case, and the participants shall be informed thereof.
Potential recipients of your personal data:
Andalú Mística does not provide your personal data to third parties unless legally required to do so or except for the operational necessities listed below:
Andalú Mística provides your name, address, and phone number to the courier company that delivers your product.
Andalú Mística may confirm your personal data with payment service providers to prevent financial fraud or identity theft in exceptional circumstances.
Andalú Mística transfers the necessary personal data to accountancy service providers and tax and other public authorities when specific legislation requires this.
Your rights as a data subject
At any time, you have the right to:
Get access to your personal data that Andalú Mística processes and receive a copy.
To ask for the erasure of personal data concerning you (the right to be forgotten) if you believe it is no longer necessary for the purposes for which it was collected or processed. Please note that this right can not be exercised if a particular law expressly provides for a fixed term to be retained.
Ask for rectification of inaccurate personal data in cases where they do not correspond to the truth.
To exercise one of the above rights, send us an e-mail message with your request on our contact page or an e-mail to andalumistica.com. We will answer you in a short time.
When you are concerned that your rights are violated, you have the right to complain to a supervisory authority, as noted below.
Our recommendations to you regarding your personal data protection:
Please keep your password secure and do not share it with third parties.
If you are using a public computer (in a library or internet cafe), always make sure you log out of your account before turning off the computer.
Andalú Mística guarantees that we don’t contact any third parties other than the ones mentioned in this privacy policy regarding your order.
Andalú Mística guarantees that we do not require our clients to disclose their passwords to use the website. Andalú Mística does not require our clients to disclose data from their bank accounts or other financial instruments. Any such request made to you by phone, chat or e-mail should be ignored.
If someone has addressed such a request to you, please contact and inform Andalú Mística immediately.
How do we protect your Personal Data?
Andalú Mística assures that we have taken all administrative, technical and physical measures to protect your personal data against accidental, unlawful or unauthorised destruction, loss, access, disclosure or use.
Andalú Mística has adopted its own internal ethics rules for the processing of personal data. Our employees have gone through special training on the principles of the right to protection of personal data and the essential obligations of companies according to GDPR.
We secure our website and other systems by using technical and organisational measures against the loss, destruction, access, modification or distribution of your data by unauthorised persons. Despite the regular checks, complete protection against all threats is not possible.
Who is responsible for processing your personal data?
Andalú Mística, Madrid, Spain, 28017, Timoteo Domingo str., 16
Andalú Mística processes our customers’ personal data according to a specially signed agreement. We collect the same categories of personal data of our customers; we proceed with them only for the purposes specified in this Privacy Policy.
Automated Storage
If you request a file from the website, certain access data is stored by default.
This data set consists of:
The page that was requested from the file
The name of the file
The date and time of request
The retention period
The amount of data transferred
The access status (file transmitted, file not found, etc.)
A description of the type and the version of the browser
The installed operating system
The screen resolution and colour depth
Additional personal data is only stored if voluntarily given by you, e.g. during registration or the implementation of a contract. You will find more information under the “optional details” heading.
Data Security
We guarantee the security of your card details, transactions, social security numbers and any other form of personal data as they will be transmitted securely between you as a customer and our domain. Thanks to the SSL security technology, which serves to transfer information between a client and a server without it being leaked to any third parties and ensuring the shared details are used solely for the purposes the client has agreed upon browsing the respective website.
SSL
We ensure that your data will be handled confidentially and encrypted with SSL (Secure-Socket-Layer) secure server software. The encrypted information of your order, your name, address, credit card or bank details cannot be read by any third party. This is shown by a small “lock” icon for any website which uses SSL and is situated at the very beginning of your address bar, right before the web address.