Last updated: June 15, 2025

1. Who We Are (Data Controller)

This website, marinascateni.com, is operated by:

  • Name/Company Name: Marina Scateni
  • Address: Urbanización Naricha 40b, 29780 Nerja, (Malaga, Spain)
  • Contact Email for Privacy Matters: info@marinascateni.com

As the Data Controller, we are committed to protecting your privacy and personal data in accordance with the General Data Protection Regulation (GDPR - EU Regulation 2016/679) and applicable Spanish legislation (Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales - LOPDGDD).

2. Personal Data We Collect

We collect different types of personal data depending on your interactions with our website:

2.1 Data provided directly by the user:

  • Shipping Data: When you make a purchase through our e-commerce, we collect your first name, last name, shipping address, phone number, and email address. This data is essential for processing and shipping your order.
  • Email Address for Subscription: If you subscribe to our newsletter or create an account on the site, we collect your email address.
  • Contact Data: If you contact us via email or contact forms.

Note on Payments: Payments on our site are handled via Stripe. This means that we do not directly collect or store your credit card data or other sensitive payment-related information. All payment transactions occur directly on Stripe's secure servers, with Stripe acting as an independent data controller for payment data.

2.2 Data collected automatically (via Cookies or similar technologies):

When you browse our site, we may automatically collect certain information, such as your IP address, browser type, operating system, pages visited, and access date and time. This data is used to improve site functionality and user experience. For more details on the use of cookies, please refer to our dedicated Cookie Policy.

We use Google Analytics to collect anonymous information about site usage, such as the number of visitors and most popular pages. The data collected is aggregated and does not individually identify the user.

3. Purposes and Legal Bases for Processing

We process your personal data for the following purposes and based on the following legal bases:

  • Performance of a Contract (Art. 6.1 b GDPR): To process and manage your orders, including product shipping and order-related communication.
  • Consent (Art. 6.1 a GDPR): For sending newsletters, marketing communications, and other promotional information, only if you have provided your explicit consent. You have the right to withdraw consent at any time.
  • Compliance with Legal Obligations (Art. 6.1 c GDPR): To comply with legal, tax, and accounting obligations, such as invoice retention.
  • Legitimate Interest (Art. 6.1 f GDPR): To improve the functionality and user experience of our website, for traffic analysis, and to prevent fraud or misuse of our services.

4. Methods of Processing

The processing of your personal data is carried out using computer and/or telematic tools, with logic strictly related to the indicated purposes and, in any case, in a manner that guarantees the security and confidentiality of the data itself, in compliance with GDPR provisions.

5. Recipients of Personal Data

Your personal data may be disclosed to the following recipients, who act as Data Processors or independent Data Controllers, depending on the service:

  • Stripe, Inc.: For payment processing.
  • Inmotion Hosting (USA): Our web hosting service provider, where the website is hosted.
  • Analytical service providers: Such as Google LLC (for Google Analytics).
  • Judicial or Administrative Authorities: If required by law or for the protection of our rights.

6. International Data Transfer

Please be informed that your personal data is transferred outside the European Economic Area (EEA), specifically to the United States of America, as our hosting server (Inmotion Hosting) is located in California, and Stripe and Google are US companies. To ensure an adequate level of protection for your personal data, the transfer is based on Standard Contractual Clauses (SCCs) adopted by the European Commission, which provide appropriate safeguards for international data transfers.

7. Data Retention Period

Your personal data will be stored for the time strictly necessary to achieve the purposes for which it was collected and in compliance with applicable legal and tax obligations:

  • Shipping and purchase data: Retained for the duration of the contract and for a subsequent period necessary to comply with legal obligations (e.g., tax, accounting) or for defense in legal proceedings, typically up to 10 years in Spain.
  • Email address for newsletters: Retained until you withdraw your consent.
  • Browse data and cookies: Retained for shorter periods, as specified in the Cookie Policy, or until deleted from your browser settings.

8. Data Subject Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of Access: Request access to your personal data and obtain information about its processing.
  • Right to Rectification: Request the correction of inaccurate or incomplete personal data.
  • Right to Erasure (Right to be Forgotten): Request the deletion of your personal data in certain circumstances.
  • Right to Restriction of Processing: Request the restriction of the processing of your data in certain circumstances.
  • Right to Data Portability: Receive your personal data in a structured, commonly used, and machine-readable format, and transmit it to another controller.
  • Right to Object: Object to the processing of your personal data for legitimate reasons or for direct marketing purposes.
  • Right to Withdraw Consent: Withdraw consent at any time for processing based on this legal basis, without affecting the lawfulness of processing based on consent before its withdrawal.
  • Right to Lodge a Complaint: File a complaint with the competent supervisory authority (the Agencia Española de Protección de Datos - AEPD in Spain) if you believe that the processing of your personal data violates the GDPR.

To exercise your rights, you can contact us at the email info@marinascateni.com. We may ask you to verify your identity before fulfilling your request.

9. Cookie Policy

Our website uses cookies to enhance the Browse experience. Cookies are small text files stored on your device. We use essential technical cookies for the site's operation and analytical cookies to understand how users interact with the site. For non-essential cookies, your consent is required via a banner. You can find more details about our cookie usage policy and how to manage your preferences by visiting our dedicated Cookie Policy.

10. Minors

Our website and services are not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a minor has provided us with personal data without parental consent, we will immediately delete it.

11. Changes to this Privacy Policy

We reserve the right to modify this Privacy Policy at any time. Any changes will be published on this page with the date of the last update. We encourage you to regularly review this page to stay informed about our data protection practices.