Privacy Policy

ORGANIC TERRA RICA S.L., with tax ID B44690162 and registered office at Avda. de la Estación, nº 40, 3º-A, informs users and interested third parties below about the processing of personal data it carries out, pursuant to the General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

  1. Data Controller

Personal data will be processed by ORGANIC TERRA RICA S.L. as the Data Controller.
Contact details for the Data Protection Coordinator: loa@organicterrarica.es

  1. Purposes of Processing, Legal Basis and Categories of Data

Data processing is grouped into categories for clarity:

  1. Legal, Tax, and Administrative Management

    Customer and Supplier Management
  • Purpose: Tax, accounting and administrative management, invoicing, payments, professional communication.
  • Legal basis: Contract performance (Art. 6(1)(b) GDPR); legitimate interest (professional contact); legal obligation (Art. 6(1)(c) GDPR).
  • Data processed: First and last name, tax ID/National ID number, address, telephone number, email, signature, electronic signature, bank details, goods and services bought, commercial licenses, economic transactions, payments.

Accounting and Tax Services

  • Purpose: Accounting records, reconciliations, tax filings, financial management.
  • Legal basis: Contract performance; legal obligation (tax and commercial).
  • Data processed: Identification, personal characteristics, employment, bank, financial, tax, payroll, deductions and administrative sanctions data.

Legal Services

  • Purpose: Legal assistance in administrative, civil, criminal, and labor proceedings.
  • Legal basis: Contract performance; legal obligation; legitimate interest (legal defense).
  • Data processed: Identifying, employment, economic, banking, court decision, sensitive or criminal data where necessary.
  1. Agricultural and Food Sector Certifications

    Organic Certification / Demeter / Global GAP / IFS Broker
  • Purpose: Compliance with international standards and document verification to maintain quality certifications.
  • Legal basis: Contract performance; legal obligation (sector-specific regulations).
  • Data processed: First and last name, ID number, address, telephone number, email, signature, employment and academic details.
  1. Regulatory Compliance and Data Protection

    GDPR implementation and oversight
  • Purpose: Data protection compliance assessment, internal audits and document review.
  • Legal basis: Legal obligation; contract performance.
  • Data processed: Identity, contact, legal representation, employee, customer and supplier data.

Rights Management

  • Purpose: Handling access, rectification, erasure, portability etc. requests.
  • Legal basis: Legal obligation (Chapter III GDPR).
  • Data processed: Identifying information, personal characteristics, electronic signature, contact details.
  1. Marketing, Promotions and Commercial Communication

    Marketing, controlling and customer loyalty
  • Purpose: Promotions, market research, financial analysis, sending newsletters and personalized campaigns.
  • Legal basis: Consent (non-customers); legitimate interest (existing customers).
  • Data processed: Name, telephone number, email, address, preferences, commercial activity, financial data, subscriptions.
  1. IT Services and Infrastructure

    IT support, software, and digital security
  • Purpose: System maintenance, access control, information protection, operational continuity.
  • Legal basis: Contract performance; legitimate interest.
  • Data processed: Identifying information, emails, access logs, IP addresses, metadata, backups.
  1. Data Retention

The data will be retained:

  • In accordance with tax and accounting regulations: 6 years
  • Tax and employment data: 4 years minimum
  • Certifications: up to 5 years after last renewal
  • Marketing communications: until consent is withdrawn or relationship ends
  • Legal files: up to 15 years (if procedural rules apply)
  • GDPR data subject rights: 3 years minimum
  1. Data Sharing and Processors

Possible recipients:

  • Public administrations (e.g., AEAT, Social Security, CAECV, Agrocolor)
  • Financial institutions and insurers
  • Certification and auditing entities
  • Tech companies: INVA BPO, UCS Datacenter, B.i.Team, Lehmann Natur, Dropbox (DPF-certified)
  • Legal firms such as Andersen Legal
  1. Exercise of Rights

Data subjects may exercise the following rights:

  • Right of access, rectification, erasure, objection, restriction, portability.

Contact: loa@organicterrarica.es (include a copy of your ID and clearly specify the right you wish to exercise).

You may also file a complaint with the Spanish Data Protection Authority: www.aepd.es

  1. Security Measures

ORGANIC TERRA RICA S.L. applies technical and organizational measures in line with its internal Security Annex III to protect data and prevent unauthorized access, loss, alteration or disclosure.