Legal
Privacy policy
What data we process when you shop at this store, what we use it for, and how you can exercise your rights.
Spanish is the legally operative version of this document. The Asturian, English and French versions are courtesy translations; in the event of any discrepancy, the Spanish text prevails.
1. Data controller
In accordance with Regulation (EU) 2016/679, General Data Protection Regulation (GDPR), and Spanish Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Digital Rights Guarantee (LOPDGDD), the controller responsible for processing personal data collected through this Site is:
- Identity: Tever Díaz García, natural person.
- Tax ID (NIF): 71661831H.
- Address: C/ Xeneral Elorza 72, 1D, 33001 Uviéu, Asturies, Spain.
- Contact: [email protected].
- Data Protection Officer (DPO): appointing a DPO is not required. The law only requires one above a certain volume or type of processing (art. 37.1 GDPR) — for example, large-scale processing of sensitive data or systematic monitoring of individuals. This store does neither: it only handles the data needed to ship and invoice orders.
2. Personal data processed
The following data is collected through the checkout process:
- Full name (required) — buyer identification, shipping, invoicing.
- Email address (required) — order confirmation, order-related communications, order lookup without an account.
- Phone number (required) — exclusively for delivery incidents (contact for the carrier/manufacturing provider in case of a delivery problem).
- Shipping address (required) — physical delivery of the product.
- Billing address (optional, defaults to shipping address) — only if the customer provides a different one.
- Tax ID / VAT number (required) — legal obligation to issue an invoice.
- Order history (generated, not entered by the user) — order management, after-sales support, lookup via email + access code.
No special categories of data are requested (art. 9 GDPR: health, ideology, sexual orientation, etc.). There are no user accounts or profiles: the Site does not store passwords or browsing history linked to a persistent identity beyond the order itself.
The Tax ID is never sent to the manufacturing provider (Printful): it is reserved exclusively for invoicing, as a data minimisation measure by design (art. 25 GDPR). It is sent, along with the rest of the billing data, to the system that issues the invoice — see section 4.
Payment data: the Site does not collect or store card data. Payment is processed entirely through Stripe (Payment Intents API); La Vieya Asturies's server never receives or sees the card number, CVC or expiry date — these travel directly from the customer's browser to Stripe.
3. Legal basis for processing
In accordance with art. 6.1 GDPR:
- Performance of a contract (art. 6.1.b): processing of name, email, phone, shipping/billing address — necessary to manage the purchase, manufacture and deliver the product.
- Compliance with a legal obligation (art. 6.1.c): processing of the Tax ID, necessary to issue an invoice under tax regulations (Invoicing Regulation, RD 1619/2012, and Veri*Factu regulations).
- No data is processed on the basis of consent within the purchase process itself. The Site does not currently send commercial communications or marketing emails.
4. Data recipients (transfers and data processors)
Data is shared with the following third parties, only to the extent necessary to provide the contracted service:
- Printful (on-demand manufacturing): receives name, full shipping address, and phone number if provided — never email, never Tax ID. Used to manufacture and ship the product. Acts as data processor (art. 28 GDPR).
- Stripe (payment gateway): manages payment data entirely; it never passes through La Vieya Asturies's server. May also receive name/email to process the payment and prevent fraud. Acts as data processor (art. 28 GDPR) and, for its own fraud-prevention function, as an independent controller under its own privacy policy.
- Dolibarr / Xiringase (invoicing system): receives name, email, Tax ID, billing address and the order amount, solely to issue the invoice. Acts as data processor (art. 28 GDPR).
Data is not shared with third parties for marketing purposes. Data is not sold to third parties.
5. International transfers
Stripe and Printful may process data outside the European Economic Area (both are headquartered in the United States). Each relies on a different safeguard:
- Stripe: certified under the EU-U.S. adequacy framework (Data Privacy Framework, Commission Implementing Decision (EU) 2023/1795), reinforced with Standard Contractual Clauses (art. 46 GDPR) as an additional safeguard.
- Printful: through Standard Contractual Clauses (art. 46 GDPR), under Commission Implementing Decision (EU) 2021/914.
Dolibarr/Xiringase processes data within Spain, with no international transfer.
6. Retention period
Order data (identification, address, invoice) is kept for as long as legally required: 4 years for tax purposes (art. 66 et seq. of the General Tax Law 58/2003) and 6 years for commercial purposes (art. 30 of the Commercial Code). After that, it is deleted or anonymised, unless the law requires it to be kept in a blocked state instead.
7. Commercial communications / marketing
This store does not send advertising or newsletters by email. If that changes in the future, this page will be updated to explain the legal basis (your consent, art. 6.1.a GDPR) and how to opt out, in accordance with art. 21 of Law 34/2002 (LSSI-CE).
8. Invoicing and Veri*Factu
The Tax ID you provide at checkout is used to issue your invoice, through Dolibarr/Xiringase (see section 4). Anti-fraud invoicing regulations (RD 1007/2023, known as Veri*Factu) require the invoicing software used to guarantee that invoicing records cannot be altered or deleted once issued.
9. Your rights over your data
You have the right to:
- Access your personal data (art. 15 GDPR).
- Rectify inaccurate data (art. 16 GDPR).
- Request erasure of your data (art. 17 GDPR), where applicable.
- Request restriction of processing (art. 18 GDPR).
- Object to processing (art. 21 GDPR).
- Request data portability (art. 20 GDPR).
- Withdraw your consent at any time, where processing is based on it, without affecting what was processed before (art. 7.3 GDPR).
To exercise any of these rights, write to [email protected] with the subject "GDPR rights request" and attach a copy of an identity document. If you believe your data has not been handled properly, you can also complain to the Spanish Data Protection Agency (AEPD, www.aepd.es).
10. Data processors and safeguards
Printful, Stripe and Dolibarr/Xiringase act as data processors (art. 28 GDPR) for the purposes described in section 4, under their respective data processing agreements (DPA).
11. Security
We apply technical and organisational measures to protect your data against unauthorised access, loss or alteration (art. 32 GDPR), including encryption in transit (HTTPS) across the entire Site.
12. Cookies
See the Cookie Policy for details on the use of cookies and local storage on the Site.

