Since 1957 creating
unforgettable experiences
Since 1957 creating
unforgettable experiences
GRUPO GOURMET CATERING & EVENTOS
1 March 2026
The entry into force of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“GDPR”), and the Spanish Organic Law on the Protection of Personal Data and Guarantee of Digital Rights (“LOPDGDD”), has required companies to comply with a series of obligations regarding the processing of data subjects’ personal data.
Current legislation in this area, based, among other principles, on the principle of proactive responsibility or accountability (provided for in Article 5 of the GDPR), requires companies not only to comply with data protection legislation but also to be able to demonstrate such compliance.
The purpose of this Policy is to establish the rules and guidelines to be followed for handling, processing and resolving requests by data subjects to exercise the rights provided for in Articles 15 to 22 of the GDPR in relation to the companies belonging to the GOURMET CATERING & EVENTS group (hereinafter, the “Group”), which are the following (hereinafter, the “Companies”):
The Companies shall act, as applicable, as Data Controllers.
At present, the rights granted to data subjects under the GDPR are those set out below:
The right of the data subject to obtain information as to whether their personal data are being processed and, specifically, the following matters, which are closely related to the content of Article 13 of the GDPR concerning the information duty incumbent upon the Data Controller:
Accordingly, the Companies, in their capacity as Data Controllers, shall provide the data subject with a copy of the personal data undergoing processing, without prejudice to the possibility of complying with this right, where possible, by providing remote access to a secure system that gives the data subject access to the data.
The right of the data subject to request the rectification and completion of personal data that are inaccurate or incomplete.
Unless this proves impossible or involves disproportionate effort, the Company shall communicate any rectification carried out to the various recipients or transferees to whom the data subject’s personal data have been disclosed and shall also inform the data subject of those recipients whenever the data subject so requests.
The right of the data subject to request the erasure of personal data concerning them where any of the circumstances provided for in Article 6 of the GDPR that legitimise their processing applies:
The right to request the restriction of the processing of personal data where any of the following circumstances applies:
During the period in which the restriction of processing remains in force, the Company shall process the personal data only:
In all cases, the Company shall inform the data subject before the restriction of processing is lifted, once the circumstances that allowed the restriction of the processing of personal data have ceased to apply.
The right of the data subject to receive the personal data provided in a structured, commonly used and machine-readable format and to transmit those data to other Data Controllers, unless their direct transmission to another Data Controller is technically impossible.
For this purpose, the processing of personal data must be based on the data subject’s consent or on the performance of a contract and must be carried out by automated means.
The right of the data subject to prevent the processing of their personal data or to have such processing cease where the data are processed on grounds of public interest, in the exercise of official authority or for the purposes of the legitimate interests pursued by the Data Controller.
The right of the data subject to withdraw the consent initially given at any time, and the Data Controller must facilitate the withdrawal of such consent.
The right of every data subject not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, unless the processing is covered by one of the exceptions set out in Article 22 of the GDPR.
Once a request to exercise rights has been received, the respective Company shall contact and forward it to the person responsible for data protection matters in order to analyse its content and proceed with its processing and resolution, and shall also acknowledge receipt of the request.
Requests to exercise rights shall be resolved, in compliance with data protection legislation, within one (1) month from the date on which the request was received.
Notwithstanding the foregoing, if, following a preliminary analysis of the content of the request, it is particularly complex or the volume of requests is high, the Company may extend the period for resolving it by a further two (2) months, a circumstance that must be communicated to the data subjects within the first month of the period for resolving the request.
Where the Companies consider that the request to exercise rights should not be acted upon, they must nevertheless respond to the data subject, stating the reasons for the refusal, within one month of receipt of the request and informing the data subject of the possibility of taking legal action or lodging a complaint with the supervisory authority (AEPD).