Privacy policy
Last updated: 25 September 20261. Data controller
- Controller: DECOR AND GO EMBASSY, S.L. (VIBECALET)
- CIF (Tax ID): B10605582
- Address: Avda. de la Libertad, 4, Bloque D, planta 3.ª, puerta 5, 03730 Xàbia (Alicante)
- Email: info@vibecalet.com
- Phone: +34 628 681 023
2. What data we process
The data you provide in the contact form or by email (name, company, email address, phone number and the content of your message) and, if you are a client, the data needed to provide the service: your team’s contact details, billing, tickets and documents shared in the portal.
3. For what purpose and on what legal basis
4. Who it is disclosed to
We do not share your data with third parties unless required by law (for example, to the Agencia Tributaria, the Spanish Tax Agency).
To provide the service we use providers acting as data processors, with a signed contract and appropriate safeguards: mainly the server hosting provider, whose servers are located in the European Union.
If you accept analytics or advertising cookies, Google Ireland Limited receives the browsing data described in the cookie policy.
5. International transfers
Client and portal data is stored in the European Union. Only if you accept analytics or advertising cookies may Google process browsing data in the United States, with the safeguards of the EU-US Data Privacy Framework.
6. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability by writing to info@vibecalet.com or to our registered office, stating which right you wish to exercise.
You can also withdraw your consent at any time and, if you believe we have not handled your data properly, lodge a complaint with the Agencia Española de Protección de Datos (AEPD, Spanish Data Protection Agency) (www.aepd.es).
7. Data we process on behalf of our clients
When we manage your company’s data within our applications (for example, data about your customers or employees), we act as data processors and sign with you the contract required by Article 28 of the GDPR.
8. Security
We apply technical and organisational measures to protect your data: encrypted connections, access control, two-step verification, backups and activity logging. We explain them on the Security page.