Data Subject Right Policy

POLICY ON THE EXERCISE OF DATA SUBJECT RIGHTS GOURMET CATERING & EVENTS GROUP

GRUPO GOURMET CATERING & EVENTOS

1 March 2026

POLICY ON THE EXERCISE OF DATA SUBJECT RIGHTS

The entry into force of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“GDPR”), and the Spanish Organic Law on the Protection of Personal Data and Guarantee of Digital Rights (“LOPDGDD”), has required companies to comply with a series of obligations regarding the processing of data subjects’ personal data.

Current legislation in this area, based, among other principles, on the principle of proactive responsibility or accountability (provided for in Article 5 of the GDPR), requires companies not only to comply with data protection legislation but also to be able to demonstrate such compliance.

A. SCOPE OF THE POLICY AND DATA SUBJECT RIGHTS

The purpose of this Policy is to establish the rules and guidelines to be followed for handling, processing and resolving requests by data subjects to exercise the rights provided for in Articles 15 to 22 of the GDPR in relation to the companies belonging to the GOURMET CATERING & EVENTS group (hereinafter, the “Group”), which are the following (hereinafter, the “Companies”):

  1. 1. YUWAX PROMOCIONES, S.L.
  2. 2. NOPAR SERVICIOS DE RESTAURACIÓN VALENCIANA, S.A.
  3. 3. SERVICIOS LOGÍSTICOS DE CATERING, S.L.
  4. 4. SERVINOPAR, S.L.
  5. 5. CATERING MC 2014, S.L.
  6. 6. CATERVALENCIA, S.L.
  7. 7. HUERTO SAN VICENTE CATERING, S.L.
  8. 8. VALENCIA CATERING Y ESPACIOS, S.L.
  9. 9. PAL ART SERVICIOS VALENCIA, S.L.
  10. 10. CATERMURCIA, S.L.
  11. 11. NAVIBER CATERING LA, S.L.
  12. 12. NEW CAT, S.A.

The Companies shall act, as applicable, as Data Controllers.

At present, the rights granted to data subjects under the GDPR are those set out below:

1. RIGHT OF ACCESS

The right of the data subject to obtain information as to whether their personal data are being processed and, specifically, the following matters, which are closely related to the content of Article 13 of the GDPR concerning the information duty incumbent upon the Data Controller:

  • Purpose of the processing
  • Categories of the data subject’s data being processed
  • The recipients or categories of recipients to whom the personal data have been or will be disclosed.
  • The data retention period, where possible, and, where this is not possible, the criteria used to determine that period.
  • The existence of the data subject’s right to exercise their rights.
  • The right to lodge a complaint with a supervisory authority.
  • The source of the data where they have not been obtained directly from the data subject.
  • The existence of automated decision-making.
  • The right to be informed of the safeguards adopted in the event of international data transfers.

Accordingly, the Companies, in their capacity as Data Controllers, shall provide the data subject with a copy of the personal data undergoing processing, without prejudice to the possibility of complying with this right, where possible, by providing remote access to a secure system that gives the data subject access to the data.

2. RIGHT TO RECTIFICATION

The right of the data subject to request the rectification and completion of personal data that are inaccurate or incomplete.

Unless this proves impossible or involves disproportionate effort, the Company shall communicate any rectification carried out to the various recipients or transferees to whom the data subject’s personal data have been disclosed and shall also inform the data subject of those recipients whenever the data subject so requests.

3. RIGHT TO ERASURE (RIGHT TO BE FORGOTTEN)

The right of the data subject to request the erasure of personal data concerning them where any of the circumstances provided for in Article 6 of the GDPR that legitimise their processing applies:

  • The data subject has objected to the processing despite having initially consented to the processing of their personal data.
  • The data subject’s personal data have been processed unlawfully.
  • There is a legal obligation applicable to the Data Controller requiring the erasure of the data subject’s personal data.

4. RIGHT TO RESTRICTION OF PROCESSING

The right to request the restriction of the processing of personal data where any of the following circumstances applies:

  • Where the data subject has contested the accuracy of their data, while the Data Controller determines their accuracy.
  • Where, although the processing of personal data is unlawful and would result in the erasure of the data, the data subject requests restriction for the establishment, exercise or defence of legal claims.
  • Where the data are no longer necessary and, although erasure of the data would otherwise be appropriate, the data subject requests restriction for the exercise of their right of defence.
  • Where the data subject has objected to the processing of their personal data, while the Data Controller verifies the objection.

During the period in which the restriction of processing remains in force, the Company shall process the personal data only:

  1. 1. With the data subject’s consent.
  2. 2. For the establishment, exercise or defence of legal claims.
  3. 3. For the protection of the rights of another natural or legal person on grounds of public interest.

In all cases, the Company shall inform the data subject before the restriction of processing is lifted, once the circumstances that allowed the restriction of the processing of personal data have ceased to apply.

5. RIGHT TO DATA PORTABILITY

The right of the data subject to receive the personal data provided in a structured, commonly used and machine-readable format and to transmit those data to other Data Controllers, unless their direct transmission to another Data Controller is technically impossible.

For this purpose, the processing of personal data must be based on the data subject’s consent or on the performance of a contract and must be carried out by automated means.

6. RIGHT TO OBJECT

The right of the data subject to prevent the processing of their personal data or to have such processing cease where the data are processed on grounds of public interest, in the exercise of official authority or for the purposes of the legitimate interests pursued by the Data Controller.

7. RIGHT TO WITHDRAW CONSENT

The right of the data subject to withdraw the consent initially given at any time, and the Data Controller must facilitate the withdrawal of such consent.

8. RIGHT NOT TO BE SUBJECT TO PROCESSING BASED SOLELY ON AUTOMATED INDIVIDUAL DECISION-MAKING

The right of every data subject not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, unless the processing is covered by one of the exceptions set out in Article 22 of the GDPR.

B. PROCESSING AND HANDLING OF REQUESTS TO EXERCISE RIGHTS

Once a request to exercise rights has been received, the respective Company shall contact and forward it to the person responsible for data protection matters in order to analyse its content and proceed with its processing and resolution, and shall also acknowledge receipt of the request.

Requests to exercise rights shall be resolved, in compliance with data protection legislation, within one (1) month from the date on which the request was received.

Notwithstanding the foregoing, if, following a preliminary analysis of the content of the request, it is particularly complex or the volume of requests is high, the Company may extend the period for resolving it by a further two (2) months, a circumstance that must be communicated to the data subjects within the first month of the period for resolving the request.

Where the Companies consider that the request to exercise rights should not be acted upon, they must nevertheless respond to the data subject, stating the reasons for the refusal, within one month of receipt of the request and informing the data subject of the possibility of taking legal action or lodging a complaint with the supervisory authority (AEPD).