1. Data collected:
Simple browsing. Simply visiting and browsing this Como&Lex Consulting (“Coca-Molina”) website (the “Website”) does not lead to any data being automatically recorded that allows Users to be identified by name. However, certain information is collected and recorded on Coca-Molina’s systems (e.g., internet browser type, operating system, IP address from which the Website’s pages are accessed). This is to improve the User’s browsing and the running of the Website itself.
Access to content or services that request data. Without prejudice to the above, in order to access certain information or to use certain content or services on the Website, Coca-Molina may require certain personal data from the User, which may include, primarily, the User’s name, surname, e-mail address, company, position, and professional contact information. In these cases, Coca-Molina will provide Users with the necessary information before processing their data.
2. Controller
Coca-Molina, with address at C/Coromines, 116, Esc. A, 1ª, 2ª, 08201, Sabadell (Spain), is the controller of any data collected or generated as a result of Users’ access, use and browsing on the Website. It is also responsible for the control of the Website.
3. Purposes of processing.
As well as managing requests for information, content, or services expressly asked for by Users, or with their consent, Coca-Molina has a legitimate interest in using the information collected or generated to:
improve the Website, its management and its security, carry out studies to analyse the relevance and use of the Website, including the use of anonymised information, and when permitted by the applicable regulations, inform Users about current legal developments through publications, seminars, and other initiatives.
4. Communication
The data will not be passed on to third parties except, where appropriate, to competent authorities in the exercise of their duties.
Coca-Molina and its branches around the world form a law firm with international operations and sometimes the development and implementation of a professional relationship may require data transfers to other countries, some of which may not offer a level of data protection similar to that of the EU. However, if any of our service providers or IT systems are located outside the EU, Coca-Molina will adopt all applicable safeguards in accordance with applicable regulations to ensure proper data management.
5. Legal basis for processing and period data is kept
The legal basis that allows Coca-Molina to process User data is Users’ access to and browsing of the Website of their own free will;
Users’ requests for information or certain content or services; Coca-Molina’s compliance with legal obligations; the firm’s legitimate interest in improving the Website and its security, as well as carrying out studies and analyses on the operation and use of the Website; and, if a User consents or Coca-Molina’s legitimate interest applies, the sending of information and legal updates.
Data will be kept for as long as contractual obligations arise from the services or content requested by Users, and subsequently until the expiry of any legal, contractual, or ethical responsibilities that require it to be retained (e.g., until the expiry of any liability arising from data protection or cybersecurity regulations). If data is processed to send current legal information, it may be retained as long as the User does not object to receiving information through any of the various free, easy-to-use means available.
6. Users’ rights
Users may exercise their rights of access, rectification, erasure, objection, restriction of processing, and portability, where applicable, concerning the processing for which Coca-Molina is responsible, by writing to the Data Protection Officer at the e-mail address info@cocamolina.com, providing proof of identity. They can also contact the Spanish Data Protection Agency.
Coca-Molina Information Security Policy
Como&Lex Consulting (hereinafter “Coca-Molina”) considers that information, especially that relating to its clients, and the different information systems used to process it, are critical assets that must be adequately protected, regardless of its form and means of storage, to ensure the proper functioning of Coca-Molina, safeguarding the operations of its business and proper service to its clients.
The security policy (hereinafter, the “Policy”) is intended to ensure proper management of elements of information and systems based on three key points:
- Its confidentiality, ensuring it can only be accessed by authorised people, processes or systems in a controlled way, preventing unauthorised disclosure.
- Its integrity, preventing it from being maliciously manipulated by unauthorised third parties;
- Its availability, through authorisation, and its recovery in the event of security incidents that cause it to be lost or corrupted.
- To achieve the established information security aims, the Policy establishes a series of procedures and actions complying with the various applicable standards and requirements in force at any given time and maintaining a balance between risk levels and the efficient use of resources under criteria of proportionality.
- The policy applies to all members of Coca-Molina and is established at group level in Spain and Portugal. It is also mandatory for its subsidiaries and branches. This Policy will also be extended to third parties directly or indirectly involved in the proper operation of the services involved at Coca-Molina. The fundamental principles for developing Coca-Molina’s express commitment to the continuous improvement of the information security management system are as follows:
- Ensuring that Coca-Molina’s Information Systems have the appropriate level of security and resilience suggested by the Coca-Molina Information Security Committee.
- Establishing a policy of minimum privilege, assigning users the minimum access levels or permissions necessary to limit the content and number of people with access to information.
- Maintaining a closed-by-default access control policy, ensuring that information and the systems that process or store it are initially closed, and allowing subsequent access only when necessary.
- Specifying a set of clearly defined roles and responsibilities regarding information security.
- Segregating information security duties and responsibilities so they are clearly defined and assigned in Coca-Molina’s organisational chart, preventing potential conflicts of interest, and making sure that no more people than necessary are aware of any information.
- Providing Coca-Molina with analysis, prevention, detection, response, and recovery procedures and tools for that allow it to adapt quickly to changes in the technological environment and new threats.
- Designing and implementing multiple levels of security that are consistent with the risk analysis carried out on the various assets that encompass the information, encouraging deep protection.
- Raising awareness among all Coca-Molina employees about security risks and ensuring they have information security training and the technological capabilities necessary to protect the security of Coca-Molina’s information systems.
- Working with relevant government agencies and organisations to improve Coca-Molina’s safety and compliance with current legislation.
- Establishing quick, accessible communication channels for potential security incidents.
- Supporting a process of continuous review and updating of the security management model to make sure it is always adapted to emerging threats that could affect Coca-Molina.