Basmat uses its own and third-party cookies to improve, personalize and analyze your browsing. If you continue visiting this website, we will assume that you accept its use. For more information or to change cookie preferences, see our cookie policy.

WEBSITE PRIVACY POLICY

In accordance with the provisions of the legislation on the protection of personal data (Regulation (EU) 2016/679 and Organic Law 3/2018), we hereby inform you that BAGLINOX S.L. has adopted the necessary technical and organisational measures to ensure that the rights of data subjects are respected; we also wish to inform you of the data processing that will be carried out via this website.

Similarly, through the following privacy policy, BAGLINOX S.L. will comply with the obligations set out in Law 34/2002 on Information Society Services and Electronic Commerce.

1. Identity of the data controller

The data controller for the personal data collected on this website is:

Company name: BASMAT MATTING SYSTEMS S.L.

CIF: B31966294

Adress: Pol. Industrial Comarca 1, Calle M, 17 – 31160 Orkoien, Navarra

Email: basmat@basmat.com  

Details of the Data Protection Officer: Consulting & Strategy GFM S.L.

DPO contact details: dpo@gfmservicios.com

2. Purposes of personal data processing

The data controller will process the data collected and managed via this website in order to facilitate and fulfil the commitments and services agreed between the data controller and the user via the website; as well as to maintain the relationship established through the forms completed by the user or to respond to a request or enquiry.

At the time the personal data is collected, the user will be informed of the specific purpose or purposes for which the personal data will be processed; that is to say, the use or uses to which the information collected will be put.

Furthermore, in accordance with the provisions of the GDPR and the LOPD, unless the exception set out in Article 30(5) of the GDPR applies, a record of processing activities is maintained which specifies, according to their purposes, the processing activities carried out by the data controller and the other circumstances set out in the GDPR.

The processing of the user’s personal data shall be subject to the following principles set out in the GDPR and the LOPD:

• Principle of lawfulness, fairness and transparency: the User’s consent must be obtained at all times, following the provision of fully transparent information regarding the purposes for which personal data is collected.

• Principle of purpose limitation: personal data shall be collected for specified, explicit and legitimate purposes.

• Principle of data minimisation: the personal data collected shall be limited to what is strictly necessary in relation to the purposes for which it is processed.

• Principle of accuracy: personal data must be accurate and kept up to date.

• Principle of storage limitation: personal data shall only be retained in a form that permits the identification of the User for as long as is necessary for the purposes of its processing.

• Principle of integrity and confidentiality: personal data shall be processed in such a way as to ensure its security and confidentiality.

• Principle of proactive accountability: the Data Controller shall be responsible for ensuring that the above principles are complied with.

3. Legal basis for the processing of personal data

The processing of personal data shall be lawful, in accordance with the provisions of Article 6 of the GDPR (EU) 2016/679, on the following legal grounds:

a. Consent of the data subject (Article 6(1)(a)): for the processing of personal data where the purpose is not necessary for the functioning of the website or for the provision of the requested services or enquiries made.

b. Performance of a contract (Article 6(1)(b)): for processing operations relating to the provision of a service or the purchase of a product or service.

c. Legitimate interests of the data controller (Article 6(1)(f)): for processing operations relating to the operation of the website, as well as those arising from the data controller’s own business activities.

In cases where the processing of personal data is based on the data subject’s consent, the data controller undertakes to obtain the data subject’s free, explicit, voluntary and unambiguous consent. Similarly, the user shall have the right to withdraw their consent at any time and as easily as they gave it. As a general rule, the withdrawal of consent shall not affect the use of the website.

On occasions when the user is required or able to provide their data via forms in order to make enquiries, request information or for reasons related to the content of the website, they will be informed if the completion of any such form is mandatory, as these fields are essential for the proper execution of the operation in question.

4. Categories of personal data, source and retention period.

The categories of data processed on this website are limited to identification and contact details. In certain cases, other personal data may be processed, such as date of birth or gender.

Under no circumstances will categories of special-category personal data be processed, in accordance with the provisions of Article 9 of the GDPR (EU) 2016/679. Should a specific data processing operation involve the processing of these categories of data, the data subject’s consent will be obtained in accordance with the terms set out in the previous section.

The personal data processed via this website will be provided by the data subject themselves or by their legal representative.

In accordance with Articles 8 of the GDPR and 7 of the LOPD, only persons aged 14 or over may lawfully give their consent to the processing of their personal data. In the case of a child under the age of 14, the consent of their legal representatives will be required for the processing, and this will only be considered lawful to the extent that they have authorised it.

The personal data processed will be retained for the periods laid down by law and, in any event, for as long as the data controller may be held liable. Where the user has given their consent, the data will be retained until they request its erasure or withdraw their consent.

5. Recipients of the personal data processed

The personal data processed on this website will be shared with those individuals and/or organisations associated with the data controller, where necessary for the provision of the services offered through the website; such as: IT companies, banks and building societies.

Similarly, it may be shared with law enforcement agencies and judicial authorities, where they so require.

6. Exercising data subjects’ rights

Users may exercise the following rights, as recognised under the GDPR and the LOPD, vis-à-vis the data controller:

• Right of access: the right to obtain confirmation as to whether or not the data controller is processing their personal data and, if so, to obtain information regarding their specific personal data and the processing that has been or is being carried out, as well as, amongst other things, the available information on the origin of such data and the recipients of any communications made or planned in relation to it.

• Right to rectification: the right to have your personal data amended where it is found to be inaccurate or, having regard to the purposes of the processing, incomplete.

• Right to erasure (‘the right to be forgotten’): the right, unless otherwise provided for by applicable legislation, to have your personal data erased when it is no longer necessary for the purposes for which it was collected or processed; the User has withdrawn their consent to the processing and there is no other legal basis for it; the User objects to the processing and there is no other legitimate reason to continue with it; the personal data has been processed unlawfully; the personal data must be erased in compliance with a legal obligation; or the personal data has been obtained as a result of a direct offer of information society services to a child under the age of 14.

In addition to erasing the data, the data controller, taking into account the available technology and the cost of implementation, must take reasonable steps to inform other controllers processing the personal data of the data subject’s request to remove any links to that personal data.

• Right to restriction of processing: the right to restrict the processing of your personal data. You have the right to obtain restriction of processing where you contest the accuracy of your personal data; the processing is unlawful; the data controller no longer needs the personal data, but you need it to establish, exercise or defend legal claims; and where you have objected to the processing.

• Right to data portability: Where processing is carried out by automated means, you have the right to receive your personal data from the data controller in a structured, commonly used and machine-readable format, and to transmit that data to another data controller. Where technically feasible, the data controller will transmit the data directly to that other data controller.

• Right to object: the right to prevent the processing of your personal data or to have such processing ceased.

• Right not to be subject to a decision based solely on automated processing, including profiling: the right not to be subject to an individualised decision based solely on the automated processing of your personal data, including profiling, unless otherwise provided for by applicable legislation.

Users may therefore exercise their rights via the data controller’s website, using the form provided for this purpose, after providing appropriate proof of their identity.

Should their rights not be upheld or should they feel that their rights have been infringed, they may contact the Data Protection Officer of the data controller; they may also lodge a complaint with the competent supervisory authority (Spanish Data Protection Agency, www.aepd.es).

7. Security measures

The data controller undertakes to adopt the necessary technical and organisational measures, in accordance with the level of security appropriate to the risk posed by the data collected, so as to ensure the security of personal data and to prevent the accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed, or unauthorised disclosure of or access to such data.

The website has an SSL (Secure Socket Layer) certificate, which ensures that personal data is transmitted securely and confidentially, as the transmission of data between the server and the User, and vice versa, is fully encrypted.

However, as the data controller cannot guarantee the impregnability of the internet or the total absence of hackers or others who may fraudulently access personal data, the data controller undertakes to notify the User without undue delay should a personal data breach occur that is likely to result in a high risk to the rights and freedoms of natural persons. 

In accordance with Article 4 of the GDPR, a personal data breach is defined as any breach of security leading to the accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed, or to the unauthorised disclosure of or access to such data.

Personal data shall be treated as confidential by the data controller, who undertakes to ensure, through a legal or contractual obligation, that such confidentiality is respected by its employees, associates and any person to whom the information is made available.

The website may contain hyperlinks or links providing access to third-party websites other than that of the Website Owner and which are therefore not operated by the Website Owner. The owners of such websites will have their own data protection policies and shall, in each case, be responsible for their own data files and privacy practices.

 

8. Acceptance and changes to this privacy policy

Users must have read the terms and conditions regarding the protection of personal data contained in this Privacy Policy and must consent to the processing of their personal data so that the Data Controller may process such data in the manner, within the timeframes and for the purposes indicated.

The Data Controller reserves the right to amend this Privacy Policy at its own discretion, or in response to changes in legislation, case law or the guidelines of the Spanish Data Protection Agency. Users will not be explicitly notified of any changes or updates to this Privacy Policy. Users are advised to check this page regularly to keep abreast of the latest changes or updates.

Last updated: November 2025