Privacy Policy

1. Identity of the Data Controller

In compliance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 on Data Protection (LOPDGDD), we inform users that the personal data collected through this website will be processed by:

2. Purposes of Data Processing

The Data Controller will process the user's personal data for the following purposes:

  • Customer account management: creation, maintenance, and administration of the user account on the website.
  • Order processing and service provision: managing purchases, shipping and delivery of orders, payments, invoicing, and customer service related to orders or incidents.
  • Responding to requests or inquiries: replying to questions sent through contact forms, email, or phone.
  • Sending commercial communications (only with consent): newsletters, promotions, and offers related to VIÑAS MURILLO products.
  • Compliance with legal obligations: tax, accounting, consumer protection, and other applicable regulations.
  • Website security: fraud prevention, access control, and technical operation of the site.
  • Analytics and browsing analysis (only with consent): improvement of the website through analytical cookies, as described in our Cookie Policy.

3. Categories of Data Processed

We may process the following categories of personal data:

  • Identification data: name, surname(s), and, where applicable, ID number.
  • Contact details: address, phone number, and email address.
  • Login credentials: username and encrypted password.
  • Transactional data: order history, payment methods, refunds, and claims.
  • Browsing data: IP address, device identifiers, browsing logs.
  • Preferences and shopping behaviour, including products viewed and cart contents (mainly through technical cookies).

4. Legal Basis for Processing

The legal bases that justify the processing of your data are:

  • Performance of a contract: processing orders, providing services, and managing the customer account.
  • Consent: for sending commercial communications, responding to contact requests, and installing non-essential cookies.
  • Legal obligations: tax, accounting, guarantees, and consumer regulations.
  • Legitimate interest: ensuring website security, preventing fraud, and improving the quality of our services.

5. Recipients of Personal Data

Personal data will not be transferred to third parties unless required by law. However, your data may be shared with:

  • Shipping and courier companies for order delivery.
  • Banks and payment gateways for payment processing.
  • Tax, accounting, or legal advisors for regulatory compliance.
  • Technical service providers responsible for hosting, maintaining, or supporting the website.
  • Analytics and advertising service providers (such as Google), only if you have accepted the corresponding cookies, in accordance with the Cookie Policy.

Under no circumstances will your personal data be sold to third parties.

6. International Data Transfers

The use of third-party services such as Google Analytics or other Google tools may involve the transfer of data to the United States or other countries outside the European Economic Area.

Such transfers are carried out under legally recognized mechanisms (such as the Data Privacy Framework or Standard Contractual Clauses) and only if you have given consent for the use of the corresponding cookies.

7. Data Retention Period

Personal data will be retained as follows:

  • As long as the user maintains an active account.
  • For the time necessary to manage orders and related customer service.
  • For legally required periods (generally 5–6 years) due to tax and accounting regulations.
  • For commercial communications, until the user withdraws consent.
  • For browsing data, according to the periods indicated in the Cookie Policy.

8. User Rights

The user has the right to:

  • Access their personal data.
  • Rectify inaccurate or incomplete data.
  • Erase their data (right to be forgotten).
  • Restrict the processing of their data.
  • Object to the processing of their data, especially when based on legitimate interest.
  • Data portability: receive their data in a structured, commonly used format.
  • Withdraw consent at any time, without affecting the lawfulness of prior processing.

To exercise these rights, users may send a request to:
administracion@vinasmurillo.es

Users also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD): www.aepd.es

9. Data Security

VIÑAS MURILLO S.L. applies appropriate technical and organizational measures to ensure a level of security appropriate to the risk, protecting personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

These measures include encryption protocols, access control systems, and internal data protection policies.

10. Changes to this Privacy Policy

VIÑAS MURILLO S.L. reserves the right to update this Privacy Policy to adapt it to legal or technical developments or changes in the services offered.

Users are encouraged to review this policy periodically to stay informed about how and why we process their personal data.