Legal
Privacy policy
What personal data TenKnocks processes through this website, for what purpose, and what rights the User has.
Last updated:
I. PRIVACY AND DATA PROTECTION POLICY
In accordance with the legislation in force, TenKnocks undertakes to adopt the technical and organisational measures necessary for a level of security appropriate to the risk of the data collected.
The laws this privacy policy follows
This privacy policy is adapted to the Spanish and European rules in force on the protection of personal data on the internet. Specifically, it observes:
- Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR).
- Ley Orgánica 3/2018, of 5 December, on the protection of personal data and the guarantee of digital rights (LOPD-GDD).
- Ley 34/2002, of 11 July, on information society services and electronic commerce (LSSI-CE).
Identity of the controller
The controller of the personal data collected at TenKnocks is Yaroslav Lytvynchuk, holder of NIF Z3706375E (hereinafter, the Controller). Their contact details are:
Address: C/ Sant Josep de Pignatelli 16, 2, 46025 València, España
Telephone: +34 666 306 094
Email: hello@tenknocks.com
What data is processed through this Website
This Website has no forms, no user registration, no analytics tools and no third-party components. It collects no personal data by itself.
The personal data the Controller processes arrives through the contact channels the User chooses to use: a telephone call, a WhatsApp message or an email sent to the details published in the Legal notice. In those cases the data processed is what the User provides on their own initiative — their name, their telephone number or their email address — and the content of their message.
In serving the pages, the hosting provider records technical connection data, including the IP address, in order to deliver the requested content and keep the service secure.
Calls
The telephone number shown on this Website is the contact number of TenKnocks. Calls received on it are not recorded.
Principles applied to the processing of personal data
The processing of the User’s personal data is subject to the following principles, set out in article 5 GDPR and in article 4 and following of Ley Orgánica 3/2018:
- Lawfulness, fairness and transparency: processing rests on one of the legal bases in article 6 GDPR, and the User is informed transparently of the purposes for which their personal data is processed.
- Purpose limitation: personal data is collected for specified, explicit and legitimate purposes.
- Data minimisation: the personal data collected is only what is strictly necessary in relation to the purposes for which it is processed.
- Accuracy: personal data must be accurate and kept up to date.
- Storage limitation: personal data is kept in a form which permits identification of the User only for as long as the purposes of the processing require.
- Integrity and confidentiality: personal data is processed in a manner that ensures its security and confidentiality.
- Accountability: the Controller is responsible for ensuring that the principles above are complied with.
Legal basis for the processing of personal data
When the User makes contact to find out about the service, the legal basis is the taking of steps at the request of the data subject prior to entering into a contract and, where applicable, the performance of that contract (article 6.1.b GDPR).
Where a commercial relationship exists, the processing of invoicing data also answers to the Controller’s legal obligations in commercial and tax matters (article 6.1.c GDPR).
The processing of the technical connection data needed to serve the pages and keep the Website secure rests on the Controller’s legitimate interest in the service working and being protected (article 6.1.f GDPR).
The Website does not ask for the User’s consent because it carries out no processing that depends on it: it installs no cookies, builds no profiles, and sends no commercial communications to anyone who has not asked for them.
Purposes of the processing
Personal data is processed only in order to:
- answer the User’s enquiry or request and, where applicable, prepare and provide the agreed service;
- issue and keep invoices and comply with the accounting and tax obligations that fall on the Controller;
- serve the pages of the Website and keep them secure.
No profiles are built, no automated decisions with legal effects for the User are taken, no data is passed on for advertising purposes, and no commercial communications are sent beyond the answer to what the User has themselves asked for.
Retention periods
Personal data is kept only for as long as the purposes of its processing require and, in any event, for the following periods:
- Enquiries by telephone, WhatsApp or email that do not lead to a commercial relationship: for as long as they are needed to deal with them; they are then erased, and in any case when the User asks.
- Clients and invoicing: for the duration of the relationship and, afterwards, for the legal periods: 5 years (article 1964.2 of the Código Civil), 6 years (article 30 of the Código de Comercio) and those of the tax rules, up to 10 years where the documentation supports tax bases, amounts or deductions offset or pending offset (article 66 bis of Ley 58/2003, General Tributaria).
Once those periods have passed, the data is erased or, where appropriate, blocked under article 32 of Ley Orgánica 3/2018.
Recipients of the personal data
The User’s personal data is neither sold nor passed to third parties for their own purposes. It is accessed by the providers that render services to the Controller and that act as processors under contract, in accordance with article 28 GDPR:
- Hosting, content delivery and mail routing: Cloudflare, Inc., which serves the pages of the Website, processes the technical connection data, and forwards to the Controller’s mailbox the messages sent to the address published in the Legal notice.
The mailbox those messages finally reach is hosted on a service of Google Ireland Limited, which processes them under its own terms and its own privacy policy.
Where the User chooses to write on WhatsApp, the conversation takes place inside a service operated by WhatsApp Ireland Limited, under its own terms and its own privacy policy, which the User accepts as against that company by using the application.
Data is also communicated to the Spanish tax authority (Agencia Estatal de Administración Tributaria) and to other public bodies on the terms required by the applicable legislation (article 6.1.c GDPR).
International transfers. Cloudflare, Inc. is established in the United States. Its transfers rest on the EU-U.S. Data Privacy Framework, in respect of which the European Commission adopted Implementing Decision (EU) 2023/1795 of 10 July 2023 and, additionally, on the standard contractual clauses incorporated into its data processing addendum.
Secrecy and security of personal data
TenKnocks undertakes to adopt the technical and organisational measures necessary for a level of security appropriate to the risk of the data collected, so as to guarantee the security of personal data and prevent the accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed, or its unauthorised disclosure or access.
The Website holds an SSL (Secure Socket Layer) certificate, which ensures that personal data is transmitted securely and confidentially, the transmission of data between the server and the User, and back, being fully encrypted.
Since TenKnocks cannot, however, guarantee that the internet is impregnable or that hackers or others will never gain fraudulent access to personal data, the Controller undertakes to notify the User without undue delay when a personal data breach occurs that is likely to result in a high risk to the rights and freedoms of natural persons. Following article 4 GDPR, a personal data breach means a breach of security leading to the accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed, or the unauthorised disclosure of, or access to, such data.
Personal data is treated as confidential by the Controller, who undertakes to inform of, and to guarantee by legal or contractual obligation, that such confidentiality is respected by their employees, associates, and everyone to whom they make the information accessible.
Rights arising from the processing of personal data
The User has, and may therefore exercise against the Controller, the following rights recognised in the GDPR and in Ley Orgánica 3/2018:
- Right of access: the User’s right to obtain confirmation as to whether or not TenKnocks is processing their personal data and, if so, to obtain information about their specific personal data and the processing TenKnocks has carried out or carries out, including the information available on the origin of that data and the recipients of any disclosures made or planned.
- Right to rectification: the User’s right to have inaccurate personal data corrected or, having regard to the purposes of the processing, completed.
- Right to erasure (“the right to be forgotten”): the User’s right, provided the legislation in force does not establish otherwise, to obtain the erasure of their personal data where it is no longer necessary for the purposes for which it was collected or processed; where the User has withdrawn consent and the processing has no other legal basis; where the User objects and there is no other legitimate ground for continuing; where the personal data has been unlawfully processed; where it must be erased to comply with a legal obligation; or where it was obtained through a direct offer of information society services to a child under 14. Besides erasing the data, the Controller must, taking account of available technology and the cost of implementation, take reasonable steps to inform controllers processing the personal data of the data subject’s request to erase any link to that data.
- Right to restriction of processing: the User’s right to restrict the processing of their personal data. The User is entitled to obtain restriction where they contest the accuracy of their personal data; where the processing is unlawful; where the Controller no longer needs the personal data but the User needs it to bring claims; and where the User has objected to the processing.
- Right to data portability: where the processing is carried out by automated means, the User is entitled to receive their personal data from the Controller in a structured, commonly used and machine-readable format, and to transmit it to another controller. Where technically feasible, the Controller will transmit the data directly to that other controller.
- Right to object: the User’s right to have their personal data not processed, or to have TenKnocks cease processing it.
- Right not to be subject to a decision based solely on automated processing, including profiling: the User’s right not to be subject to an individual decision based solely on the automated processing of their personal data, including profiling, save where the legislation in force establishes otherwise.
To exercise any of these rights it is enough to send a request to the Controller stating which right is being exercised, by email to hello@tenknocks.com or by post to C/ Sant Josep de Pignatelli 16, 2, 46025 València, España. The Controller will ask for further information only where there are reasonable doubts as to the identity of the person making the request (article 12.6 GDPR), and will reply within one month of receiving it (article 12.3 GDPR).
The User may exercise these rights free of charge.
Links to third-party websites
The Website may include hyperlinks or links that lead to websites of third parties other than TenKnocks, and which are therefore not operated by TenKnocks. The owners of those websites will have their own data protection policies and are themselves responsible, in each case, for their own files and their own privacy practices.
Complaints to the supervisory authority
Should the User consider that there is a problem or an infringement of the rules in force in the way their personal data is being processed, they have the right to an effective judicial remedy and to lodge a complaint with a supervisory authority, in particular in the State of their habitual residence, place of work or place of the alleged infringement. In Spain, the supervisory authority is the Agencia Española de Protección de Datos (https://www.aepd.es/).
II. CHANGES TO THIS PRIVACY POLICY
This Privacy Policy informs the User of the processing the Controller carries out, in compliance with the duty of information in article 13 GDPR. It is not a condition the User has to accept in order to browse the Website: the processing described rests on the legal bases set out above and not on their consent.
TenKnocks reserves the right to amend its Privacy Policy, at its own discretion or prompted by a change in legislation, case law or the doctrine of the Agencia Española de Protección de Datos. Changes or updates to this Privacy Policy will not be notified to the User explicitly. The User is advised to consult this page periodically to keep up with the latest changes or updates.
III. LANGUAGE OF THIS DOCUMENT
This document is also published in Spanish. In the event of any discrepancy between the two versions, the Spanish version prevails.