Privacy Policy
PRIVACY POLICY WEBSITE
karvora.com
Version as of June 1, 2026
1.- OBJECTIVE OF THE PRIVACY POLICY
The purpose of this “Privacy and Data Protection Policy” is to clean and make known the conditions governing the collection and processing of personal data by Future Euro Trade S.L., making every effort to ensure the fundamental rights, honor, and freedoms of the individuals whose personal data are processed, in compliance with the current regulations and laws governing the Protection of Personal Data according to the European Union and the Spanish Member State, and specifically, those expressed in the “Processing Activities” section of this Privacy Policy.
Therefore, this Privacy and Data Protection Policy informs the Website users of all details of interest regarding how these processes are carried out, for what purposes, which other entities may have access to their data, and what the users’ rights are.
2.- DEFINITIONS
“Personal data”: Any information relating to an identified or identifiable natural person (“the Website user”); an identifiable natural person is one whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
“Processing”: Any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
“Restriction of processing”: The marking of stored personal data with the aim of limiting their processing in the future.
“Profiling”: Any form of automated processing of personal data consisting of using personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
“Pseudonymisation”: The processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
“Filing system”: Any structured set of personal data accessible according to specific criteria, whether centralized, decentralized, or dispersed on a functional or geographical basis.
“Controller”: The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
“Processor”: A natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.
“Recipient”: A natural or legal person, public authority, agency, or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.
“Third party”: A natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data.
“Consent of the data subject”: Any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
“Personal data breach”: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
“Genetic data”: Personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question.
“Biometric data”: Personal data resulting from specific technical processing relating to the physical, physiological, or behavioral characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data.
“Data concerning health”: Personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status.
“Main establishment”: a) as regards a controller with establishments in more than one Member State, the place of its central administration in the Union, unless the decisions on the purposes and means of the processing of personal data are taken in another establishment of the controller in the Union and the latter establishment has the power to have such decisions implemented, in which case the establishment which has taken such decisions is to be considered to be the main establishment; b) as regards a processor with establishments in more than one Member State, the place of its central administration in the Union, or, if the processor has no central administration in the Union, the establishment of the processor in the Union where the main processing activities take place in the context of the activities of an establishment of the processor to the extent that the processor is subject to specific obligations under this Regulation.
“Representative”: A natural or legal person established in the Union who, designated by the controller or processor in writing pursuant to Article 27 of the GDPR, represents the controller or processor with regard to their respective obligations under this Regulation.
“Enterprise”: A natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity.
“Supervisory authority”: An independent public authority which is established by a Member State pursuant to Article 51 of the GDPR. In the case of Spain, it is the Spanish Data Protection Agency (Agencia Española de Protección de Datos).
“Cross-border processing”: a) processing of personal data which takes place in the context of the activities of establishments in more than one Member State of a controller or a processor in the Union where the controller or processor is established in more than one Member State; or b) processing of personal data which takes place in the context of the activities of a single establishment of a controller or a processor in the Union but which substantially affects or is likely to substantially affect data subjects in more than one Member State.
“Information society service”: Any service within the meaning of Article 1(1)(b) of Directive (EU) 2015/1535 of the European Parliament and of the Council, meaning any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient of services.
3.- IDENTITY OF THE DATA CONTROLLER
The Data Controller is the natural or legal person, of a public or private nature, or administrative body, who alone or jointly with others determines the purposes and means of the processing of personal data, in the event that the purposes and means of the processing are determined by European Union Law or the Spanish Member State Law.
Regarding the aspects expressed in this Data Protection Policy, the identity and contact details of the Data Controller are:
Future Euro Trade S.L. – CIF B96760806
Ctra. Vila-Real Onda Km6. 12200, Onda (Castellón), Spain
Email: administracion@fetfuture.com
Phone: 964626795
4.- APPLICABLE LAWS AND REGULATIONS
This Privacy and Data Protection Policy is developed based on the following data protection regulations and laws:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. Hereinafter GDPR.
- Organic Law 3/2018 of December 5 on the Protection of Personal Data and Guarantee of Digital Rights. Hereinafter LOPD/GDD.
- Law 34/2002 of July 11 on Information Society Services and Electronic Commerce. Hereinafter LSSICE.
5.- PRINCIPLES APPLICABLE TO THE PROCESSING OF PERSONAL DATA
The personal data collected and processed through this website will be treated in accordance with the following principles:
- Principle of lawfulness, fairness, and transparency: Any processing of personal data carried out through this Website shall be lawful and fair, making it entirely clear to the user when personal data concerning them are being collected, used, consulted, or otherwise processed. Information regarding the processing carried out will be provided beforehand, easily accessible and easy to understand, using clear and plain language.
- Principle of purpose limitation: All data will be collected for specified, explicit, and legitimate purposes and will not be further processed in a manner that is incompatible with those purposes.
- Principle of data minimization: Collected data will be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.
- Principle of accuracy: Data will be accurate and, where necessary, kept up to date, taking every reasonable step to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay.
- Principle of storage limitation: Data will be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
- Principle of integrity and confidentiality: Data will be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures.
- Principle of accountability: The entity owning the Website shall be responsible for compliance with the principles set out in this section and shall be able to demonstrate it.
6.- DATA PROCESSING ACTIVITIES
Below are details of the data processing activities carried out through the Website, specifying each of the following sections:
- Activity: Name of the data processing activity
- Purposes: Each of the uses and operations carried out with the data collected
- Legal basis: The legal basis that legitimizes the data processing
- Processed data: Typology of processed data
- Source: Where the data are obtained from
- Retention: Period during which the data are kept
- Recipients: Third-party individuals or entities to whom the data are provided
- International transfers: Cross-border shipments of data outside the European Union
6.1 MAIN PROCESSING ACTIVITIES
These are data processing activities whose purposes are necessary and essential for the provision of services.
6.2 OPTIONAL PROCESSING ACTIVITIES (if the user has ticked their acceptance)
These are personal data processing activities whose purposes are not essential for the provision of the service and which are only carried out if the user has marked YES in the consent for carrying out these activities.
Website Inquiries
|
Legal bases |
Explicit consent of the data subject |
|
Purposes |
Responding to inquiries received through the web electronic form |
|
Categories of data and groups |
Web contacts (Identifying data) |
|
Data source |
The data subject themselves or their legal representative |
|
Category of recipients |
None planned |
|
International transfer |
None planned |
|
Retention period |
For a period of 1 year from the last confirmation of interest |
|
Security measures |
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate: 1. a) the pseudonymisation and encryption of personal data; 2. b) the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services; |
7.- NECESSARY AND UPDATED INFORMATION
All fields marked with an asterisk (*) in the Website forms are mandatory, so that the omission of any of them could lead to the impossibility of providing you with the requested services or information.
You must provide true information, so that the information provided is always updated and contains no errors. You must communicate to the Data Controller as soon as possible any modifications and rectifications of your personal data as they occur, via an email to the address: administracion@fetfuture.com.
Likewise, by clicking on the “I Accept” button (or equivalent) incorporated into the aforementioned forms, you declare that the information and data you have provided in them are accurate and true, and that you understand and accept this Privacy Policy.
8.- DATA OF MINORS
In compliance with the provisions of Article 8 of the GDPR and Article 7 of the LOPD/GDD, only those over 14 years of age may grant their consent for the lawful processing of their personal data by Future Euro Trade S.L..
Therefore, minors under 14 years of age may not use the services available through the Website without prior authorization from their parents, guardians, or legal representatives, who will be solely responsible for all acts performed through the Website by the minors in their charge, including filling out the electronic forms with the personal data of said minors and checking, where applicable, the boxes that accompany them.
9.- TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
The Data Controller adopts the necessary organizational and technical measures to guarantee the security and privacy of your data, avoiding its alteration, loss, unauthorized processing or access, depending on the state of technology, the nature of the stored data, and the risks to which they are exposed.
Among others, the following measures stand out:
- Guarantee the permanent confidentiality, integrity, availability, and resilience of processing systems and services.
- Restore availability and access to personal data quickly in the event of a physical or technical incident.
- Regularly verify, assess, and evaluate the effectiveness of the technical and organizational measures implemented to ensure the security of processing.
- Pseudonymize and encrypt personal data if sensitive data are processed.
On the other hand, the Data Controller has decided to manage information systems according to the following principles:
- Principle of regulatory compliance: All information systems will adjust to the applicable legal regulatory and sectorial framework affecting information security, especially those related to personal data protection, systems security, data, communications, and electronic services.
- Principle of risk management: Risks will be minimized to acceptable levels, seeking a balance between security controls and the nature of information. Security objectives must be established, reviewed, and consistent with information security aspects.
- Principle of awareness and training: Training, sensitization programs, and awareness campaigns will be articulated for all users with access to information regarding information security.
- Principle of proportionality: The implementation of controls that mitigate asset security risks will be carried out seeking a balance between security measures, nature, information, and risk.
- Principle of responsibility: All members of the Data Controller will be responsible for their conduct regarding information security, complying with established rules and controls.
- Principle of continuous improvement: The degree of effectiveness of security controls implemented in the organization will be recurrently reviewed to increase the adaptation capacity to the constant evolution of risk and the technological environment.
10.- RIGHTS OF DATA SUBJECTS
Current data protection regulations protect the user regarding a series of rights related to the use given to their data. All and each of these rights are personal and non-transferable, meaning they can only be exercised by the data owner, after verification of their identity.
The rights of Website users are detailed below:
- Right of access: The right of the Website user to obtain confirmation as to whether or not the Data Controller is processing their personal data and, if so, to obtain information about their specific personal data and the processing that the Data Controller has carried out or is carrying out, as well as, among other things, the information available on the origin of said data and the communications made or planned for them.
- Right to rectification: The right of the Website user to have inaccurate personal data rectified or, taking into account the purposes of processing, completed if incomplete.
- Right to erasure: Often known as the “right to be forgotten”, it is the right of the Website user, provided that current legislation does not establish otherwise, to obtain the erasure of personal data concerning them when they are no longer necessary in relation to the purposes for which they were collected or processed; the User has withdrawn consent and there is no other legal ground for processing; the User objects to processing and there are no overriding legitimate grounds; the personal data have been unlawfully processed; or the personal data have been collected in relation to the offer of information society services directly to a minor under 14. In addition to erasing data, the Data Controller, taking into account available technology and the cost of implementation, shall take reasonable steps to inform other controllers processing the personal data of the data subject’s request for erasure of any links to those data.
- Right to restriction of processing: The right of the Website user to restrict the processing of their personal data. The Website user has the right to obtain restriction of processing when they contest the accuracy of the personal data; the processing is unlawful; the Data Controller no longer needs the personal data but they are required by the User for the establishment of claims; or when the Website user has objected to processing.
- Right to data portability: In cases where processing is carried out by automated means, the Website user shall have the right to receive the personal data concerning them from the Data Controller in a structured, commonly used, and machine-readable format, and to transmit those data to another controller. Whenever technically feasible, the Data Controller shall transmit the data directly to that other controller.
- Right to object: The right of the User to object to processing of their personal data or to have the Data Controller cease processing them.
- Right not to be subject to automated decision-making and/or profiling: The right of the Website user not to be subject to a decision based solely on automated processing, including profiling, unless current legislation establishes otherwise.
- Right to withdraw consent: The right of the Website user to withdraw, at any time, the consent given for data processing.The Website user can exercise any of the mentioned rights by contacting the Data Controller, with prior identification of the User, using the following contact information:
- Controller: Future Euro Trade S.L.
- Address: Ctra. Vila-Real Onda Km6. 12200, Onda (Castellón), Spain
- Phone: 964626795
- E-mail: administracion@fetfuture.com
11.- RIGHT TO LODGE A COMPLAINT WITH A SUPERVISORY AUTHORITY
The user is informed of their right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos) if they consider that an infringement of data protection legislation has been committed regarding the processing of their personal data.
Contact information of the supervisory authority:
Agencia Española de Protección de Datos
Email: info@aepd.es
Phone: 912663517
Website: https://www.aepd.es
Address: C/. Jorge Juan, 6. 28001, Madrid (Madrid), Spain
12.- ACCEPTANCE AND CHANGES TO THE PRIVACY POLICY
It is necessary that the Website user has read and agrees with the data protection conditions contained in this Privacy Policy, as well as accepts the processing of their personal data so that the Data Controller can proceed with it in the manner, periods, and purposes indicated.
The Data Controller reserves the right to modify this Privacy Policy, according to its own criteria, or motivated by a legislative, jurisprudencial, or doctrinal change by the Spanish Data Protection Agency. Changes or updates made to this Privacy Policy affecting purposes, retention periods, data transfers to third parties, international data transfers, or any right of the Website User, will be explicitly communicated to the user.
Version as of June 1, 2026