Privacy Policy (GDPR)
2.1 Data controller
Corporate name: Marta Chavert Alonso, trading as Cmtilines
NIF/CIF: 77012586F
Registered office: Avenida de Vigo 99, 36940, Cangas, Pontevedra
Contact email: cmtilines@gmail.com
2.2 Data collected and purposes of processing
We process the personal data you provide to us when making a purchase, creating an account, subscribing to commercial communications, or contacting us, for the following purposes:
Order, invoicing, and shipping management.
Customer service and dispute resolution.
Sending commercial communications, only if you have given your express consent.
Compliance with legal obligations (tax, accounting, etc.).
Prevention of fraud and transaction security.
2.3 Legal basis for processing
Execution of a contract: for order management and the business relationship (Art. 6.1.b GDPR).
Legal obligation: to comply with accounting, tax, and consumer obligations (Art. 6.1.c GDPR).
Consent: for sending commercial communications (Art. 6.1.a GDPR). You may withdraw it at any time.
Legitimate interest: for the prevention of fraud (Art. 6.1.f GDPR).
2.4 Data retention
Data will be retained for the time necessary to fulfill the purpose for which they were collected and during the applicable legal limitation periods. Specifically:
Customer and transaction data: 6 years in accordance with tax and commercial legislation.
Commercial communications data: until consent is withdrawn.
2.5 Disclosure of data to third parties
Your data may be disclosed to:
Transport and logistics companies, for order delivery.
Payment gateways (e.g., Redsys, PayPal, Stripe), for payment management.
Public administrations, when required by current regulations.
We do not disclose your data to third parties for their own commercial purposes without your express consent.
2.6 International transfers
In the event of using service providers located outside the European Economic Area (e.g., analytics or marketing services), we guarantee that such transfers are carried out with the appropriate safeguards (standard contractual clauses approved by the European Commission or other GDPR-compliant mechanisms).
2.7 Rights of the data subjects
You may exercise the following rights at any time by writing to the address or email address indicated in section 2.1, attaching a copy of your ID card or other identity document:
Access: to know what data we process about you.
Rectification: to correct inaccurate or incomplete data.
Erasure ("the right to be forgotten"): to request the deletion of your data when it is no longer necessary.
Limitation of processing: to request that we restrict the use of your data under certain circumstances.
Portability: to receive your data in a structured and commonly used format.
Objection: to object to processing based on legitimate interest or for marketing purposes.
Likewise, you have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) if you consider that the processing does not comply with the GDPR.
2.8 Security
We apply the appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR.

