Legal
Privacy policy
What data we process when you shop at this store, what we use it for, and how you can exercise your rights.
Spanish is the legally operative version of this document. The Asturian, English and French versions are courtesy translations; in the event of any discrepancy, the Spanish text prevails.
1. Data controller
In accordance with Regulation (EU) 2016/679, General Data Protection Regulation (GDPR), and Spanish Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Digital Rights Guarantee (LOPDGDD), the controller responsible for processing personal data collected through this Site is:
- Identity: Tever Díaz García, natural person.
- Tax ID (NIF): 71661831H.
- Address: C/ Xeneral Elorza 72, 1D, 33001 Uviéu, Asturies, Spain.
- Contact: [email protected].
- Data Protection Officer (DPO): appointing a DPO is not required. The owner operates, as a sole individual, a low-volume merchandise store, without large-scale processing, without special categories of data, and without regular and systematic large-scale monitoring of data subjects — none of the mandatory-appointment scenarios under art. 37.1 GDPR apply.
2. Personal data processed
The following data is collected through the checkout process:
- Full name (required) — buyer identification, shipping, invoicing.
- Email address (required) — order confirmation, order-related communications, order lookup without an account.
- Phone number (required) — exclusively for delivery incidents (contact for the carrier/manufacturing provider in case of a delivery problem).
- Shipping address (required) — physical delivery of the product.
- Billing address (optional, defaults to shipping address) — only if the customer provides a different one.
- Tax ID / VAT number (required) — legal obligation to issue an invoice.
- Order history (generated, not entered by the user) — order management, after-sales support, lookup via email + access code.
No special categories of data are requested (art. 9 GDPR: health, ideology, sexual orientation, etc.). There are no user accounts or profiles: the Site does not store passwords or browsing history linked to a persistent identity beyond the order itself.
The Tax ID is stored separately and is never sent to the manufacturing provider (Printful) — it is reserved exclusively for invoicing purposes, as a data minimisation measure by design (art. 25 GDPR).
Payment data: the Site does not collect or store card data. Payment is processed entirely through Stripe (Payment Intents API); La Vieya Asturies's server never receives or sees the card number, CVC or expiry date — these travel directly from the customer's browser to Stripe.
3. Legal basis for processing
In accordance with art. 6.1 GDPR:
- Performance of a contract (art. 6.1.b): processing of name, email, phone, shipping/billing address — necessary to manage the purchase, manufacture and deliver the product.
- Compliance with a legal obligation (art. 6.1.c): processing of the Tax ID, necessary to issue an invoice under tax regulations (Invoicing Regulation, RD 1619/2012, and Veri*Factu regulations).
- No data is processed on the basis of consent within the purchase process itself. The Site does not currently send commercial communications or marketing emails.
4. Data recipients (transfers and data processors)
Data is shared with the following third parties, strictly to the extent necessary to provide the contracted service:
- Printful (on-demand manufacturing provider): receives name, full shipping address, and phone number if provided — never email, never Tax ID. Purpose: manufacturing and shipping the product. Acts as data processor (art. 28 GDPR).
- Stripe (payment gateway): manages payment data entirely; it never passes through La Vieya Asturies's server. May also receive name/email for payment processing and fraud prevention. Acts as data processor (art. 28 GDPR) and, for its fraud-prevention function, as an independent controller under its own privacy policy.
Data is not shared with third parties for marketing purposes. Data is not sold to third parties.
5. Retention period
As a general legal reference, the general tax obligation to retain supporting documents for economic transactions is 4 years (art. 66 et seq. of the General Tax Law 58/2003) and 6 years for commercial purposes (art. 30 of the Commercial Code). Once the applicable retention period has elapsed, data will be deleted or anonymised, unless there is a legal obligation to retain it in a blocked state.
6. Commercial communications / marketing
The Site does not currently send commercial communications or marketing emails. If a marketing channel (newsletter, offers) is activated in the future, this section will be updated to include the legal basis of consent (art. 6.1.a GDPR) and the opt-out mechanism, in accordance with art. 21 of Law 34/2002 (LSSI-CE) on unsolicited commercial communications.
7. Invoicing and Veri*Factu
To issue invoices, the Site processes the Tax ID provided at checkout. Anti-fraud invoicing regulations (RD 1007/2023, developing art. 29.2.j of General Tax Law 58/2003, introduced by Law 11/2021 on measures to prevent and combat tax fraud) require invoicing software systems to meet integrity, traceability and non-alterability requirements for invoicing records.
8. Rights of data subjects
Any individual has the right to:
- Access their personal data (art. 15 GDPR).
- Rectify inaccurate data (art. 16 GDPR).
- Request erasure of their data (art. 17 GDPR), where applicable.
- Request restriction of processing (art. 18 GDPR).
- Object to processing (art. 21 GDPR).
- Data portability (art. 20 GDPR).
- Withdraw consent at any time, where processing is based on it, without affecting the lawfulness of processing prior to withdrawal (art. 7.3 GDPR).
These rights may be exercised by writing to [email protected], stating "GDPR rights request" as the subject and attaching a copy of an identity document. Data subjects also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es) if they consider that processing does not comply with applicable regulations.
9. Data processors and safeguards
Printful and Stripe act as data processors (art. 28 GDPR) for the purposes described in section 4, under the terms of their respective standard data processing agreements (DPA).
10. Security
The owner applies appropriate technical and organisational measures to protect personal data against unauthorised access, loss or alteration, in accordance with art. 32 GDPR, including encryption in transit (HTTPS) across the entire Site.
11. Cookies
See the Cookie Policy for details on the use of cookies and local storage on the Site.
