Privacy policy

PRIVACY POLICY

1. Who is responsible for processing your data?

In compliance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD), users are informed that the data controller for the information collected through this website is:

Owner: Virginia María Velasco Ramírez
Trade name: Alma Eko
Tax ID (NIF): 33528259D
Registered address: Calle Lago Enol, 37, 28521 Rivas Vaciamadrid, Madrid, Spain
Contact email: info@almaeko.com
Activity: Online sale of ecological products

The owner does not have a Data Protection Officer, as there is no legal obligation to appoint one. However, any privacy-related queries will be handled at the above address.


2. What personal data do we collect?

The data we process may include:

  • Identification details: name, surname, address, email, telephone number, ID number (NIF/NIE).

  • Purchase information: order history, payment methods, delivery addresses.

  • Technical information: IP address, browser, operating system.

  • Communication and marketing preferences (where applicable).


3. For what purposes do we process your data?

Personal data is processed for the following purposes, depending on the channel or form used:

  • Managing product purchases and deliveries.

  • Handling customer service queries or requests for information.

  • Sending newsletters or promotional communications (only with consent).

  • Managing user accounts and access to the website.

  • Complying with legal, accounting, and tax obligations.


4. How long do we keep your data?

Data will be retained only for as long as necessary to fulfill the purpose for which it was collected and, subsequently:

  • Enquiries not resulting in a purchase: 12 months

  • Customers: 6 years from the last purchase (for accounting and tax compliance)

  • Newsletter subscribers: until unsubscribed

  • Anonymized technical data: no defined retention period


5. Who do we share your data with?

Your data will not be shared with third parties except where required by law or when essential to provide our services. In such cases, it will be shared only with the following types of data processors:

  • eCommerce platform: Shopify (Canada)

  • Newsletter manager: Klaviyo (USA, with Standard Contractual Clauses)

  • Transport and delivery services: contracted logistics companies

  • Payment gateways: Stripe, PayPal, Klarna, or other integrated providers

New payment methods may be added over time.

Klarna acts as an independent controller for credit assessments and payment collection.
You can review its Privacy Policy here: https://www.klarna.com/es/privacidad/

  • Accounting and tax advisor: external professional firm

All providers act under data processing agreements and apply appropriate security measures.

In some cases, we use third-party tools (Meta/Facebook, Google, TikTok), which may involve data sharing with these providers when their pixels, tags, or related programs are used (e.g., Google Ads, Google Merchant Center, Meta Pixel, TikTok Pixel/TikTok Shop).

The data shared typically includes online identifiers (cookies, IP addresses, device IDs), browsing information, and conversion events (e.g., page visits or purchases).

The purpose of this processing is to measure performance, improve advertising campaigns, and, where applicable, personalize ads on these platforms. The lawful basis for this processing is user consent, given through the cookie banner and adjustable at any time.

These providers may carry out international data transfers to the United States.
Such transfers are based on the Standard Contractual Clauses approved by the European Commission and, where applicable, the EU-U.S. Data Privacy Framework.


6. Do we transfer data outside the European Economic Area?

Yes. International data transfers are made to Klaviyo and Shopify. Both companies adhere to the Data Privacy Framework or use Standard Contractual Clauses approved by the European Commission to ensure an adequate level of data protection.


7. What are your rights as a user?

You may exercise the following rights:

  • Access: Know what data we process about you.

  • Rectification: Correct inaccurate or incomplete data.

  • Erasure: Request deletion of your data when no longer necessary.

  • Restriction: Temporarily limit data processing.

  • Objection: Object to specific processing activities such as advertising.

  • Portability: Request your data in an interoperable format.

  • Withdrawal of consent: At any time, without retroactive effect.

To exercise these rights, you may contact us by email at info@almaeko.com, including a copy of your ID document and specifying the right you wish to exercise.

If you believe your rights have been violated, you may file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.


8. What security measures do we apply?

Personal data is processed confidentially, and appropriate technical and organizational measures have been adopted to ensure its integrity, availability, and confidentiality.
This website uses SSL encryption for secure data transmission.


9. Do we process data from minors?

Purchases or subscriptions by minors under 14 years of age are not permitted without the express consent of parents or guardians. Only adults or legally emancipated minors may enter into contracts.


10. Changes to the Privacy Policy

Alma Eko reserves the right to modify this Privacy Policy to adapt it to legal or technical developments.
Any changes will be announced visibly on the website or communicated directly when they significantly affect your rights.