Privacy Policy
Introduction
In compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council, of April 27, 2016, this Privacy Policy sets forth the terms of use and protection of information provided by clients or interested parties. The Company is committed to the security of personal data. When we request personal information that can identify you, we do so ensuring that it will only be used in accordance with the terms of this document.
We are committed to keeping your information secure. We use and update systems to ensure there is no unauthorized access.
Data Controller
We hereby inform you that the data controller for your data is CALEDONIA SOCIEDAD DE VALORES, S.A., hereinafter referred to as THE COMPANY.
Company Name: CALEDONIA SOCIEDAD DE VALORES, S.A. Tax ID (CIF): A-56551716
Its registered office is at: Calle Serrano 21, 1a Planta, 28001, Madrid (Madrid)
Registered in the Commercial Registry of Madrid, Volume 45995, Folio 1 et seq., Page M-808183, Entry 1. To contact us through any of the following channels:
Email: protecciondedatos@caledonia.es
Information Collected and Its Purpose
The information we collect is necessary for establishing contractual relationships and/or providing you with information about activities, products, or services related to THE COMPANY.
We inform you that the personal data provided by the client or interested party, as well as any data that may be provided in the future within the framework of their relationship with this COMPANY, refers to:
Purpose: contractual relationships.
Information from the following types of personal data may be collected:
- Identification and Contact Data
- Information required for the prevention of money laundering, including banking and economic data.
- Information required by securities market regulations for the assessment of your investment objectives, knowledge, and investment experience.
- Information derived from transactions in financial instruments or investment services in which THE COMPANY has participated.
- Identification codes or keys for access and operation within the COMPANY’s systems
- Data derived from operations
Purpose: commercial activity and other communications
The personal data collected are the identification and contact details necessary to send information. For example, by way of illustration and not limitation: name, surname, postal address, telephone number, or email, depending on the interested party’s preferences for reception and available sending alternatives.
Communications about activities, products, or services may be carried out by any means, including electronic means. The interested party must explicitly authorize the sending of commercial communications by checking the corresponding boxes in any data request forms, for example, those included on our website.
Data Retention
The personal data provided will be retained as long as necessary to respond to the contractual relationship, to respond to requests made, and in any case, as long as deletion is not requested by the interested party, as well as the time necessary to comply with the legal obligations corresponding to each data type. The interested party may exercise their rights at any time, as well as make a request regarding them.
Based on the obligation derived from the Law on the Prevention of Money Laundering and Financing of Terrorism, THE COMPANY will retain personal data for a period of 10 years from the termination of the business relationship.
Recipients
The potential recipients to whom THE COMPANY may disclose personal data are:
- Public and private bodies and institutions to which there is a legal obligation to
- Third-party service providers with whom a data processing agreement has been signed
We will not transfer your personal data to any third-party company that intends to use it for direct marketing actions or similar activities.
Rights of the Interested Party
Any person has the right to obtain confirmation as to whether or not THE COMPANY is processing personal data concerning them. In relation to the data obtained and subject to its availability and exceptions where limited by applicable law, you are granted the following rights:
- Right of access: the right to be informed and request access to the personal data about you that we process;
- Right to rectification: the right to request that we correct or update your personal data when it is inaccurate or incomplete;
- Right to erasure or suppression: the right to request that your personal data be deleted;
- Right to restriction of processing: the right to request that the processing of all or some of your personal data be temporarily or permanently stopped;
- Right to data portability: the right to request a copy of your personal data in electronic format and the right to transmit such data for use in a third-party service; and
- Right not to be subject to automated decision-making: the right not to be subject to decisions based solely on automated decision-making, including profiling, when the decision may have a legal effect on you or produce a similar significant effect.
The interested party may exercise these rights by sending an email to protecciondedatos@caledonia.es, duly identifying themselves by sending a photocopy of their ID and clearly indicating the right they wish to exercise. Likewise, the request may be made by postal mail to the address indicated above.
Finally, we inform interested parties that they may file a complaint related to the processing of their personal data with the Supervisory Authority (www.aepd.es).
International Transfer
In some cases, THE COMPANY may need to use the services of third parties established outside Spain. Should this occur, THE COMPANY ensures that data will be sent to countries with an equivalent level of data protection to that of the European Union or, if not, will use the mechanisms provided in current legislation to obtain the client’s consent or the authorization for transfer from the Spanish Data Protection Agency.
Security
THE COMPANY has adopted the necessary technical measures to prevent alteration, loss, unauthorized processing, or access to the personal data provided by the user. However, in the event of any improper access to data that could entail serious negative consequences for interested parties, THE COMPANY will duly inform the interested parties within a reasonable timeframe so that they can take appropriate measures, and if necessary, the AEPD will be notified.

