Compliance and data protection rights
Last updated: January 15, 2025
The General Data Protection Regulation (GDPR) is the European regulation that governs the processing of personal data. At AstroWeb, we are committed to fully complying with this regulation and protecting your rights as a user.
We are governed by the following principles:
We process your personal data based on the following legal grounds:
When you register, subscribe to our newsletter or accept cookies, you give explicit consent for the processing of your data.
To provide you with our services, process payments and manage your account, we need to process your data as part of contract performance.
To improve our services, prevent fraud and maintain the security of our website, we process data based on our legitimate interest.
We comply with legal obligations such as billing, accounting and compliance with tax regulations.
As a user, you have the following rights:
You can request information about what personal data we have about you and how we use it.
You can request the correction of inaccurate or incomplete data.
You can request the deletion of your personal data in certain circumstances.
You can request that we limit the processing of your data in certain situations.
You can request to receive your data in a structured format and transfer it to another controller.
You can object to the processing of your data for direct marketing purposes.
You can withdraw your consent at any time.
We detail how we process your personal data:
We retain your data only for the necessary time:
We share data only in the following circumstances:
We work with trusted providers who help us operate: payment processors, hosting, web analytics.
We may share data when required by law or competent authorities.
To protect our rights, property or security, or that of our users.
We only share data with third parties when you give explicit consent.
We implement technical and organizational security measures:
Some of our providers may be located outside the EEA. We ensure that these transfers comply with GDPR:
In case of personal data breach that may pose a risk to your rights and freedoms:
We have designated a Data Protection Officer (DPO) to oversee our GDPR compliance. You can contact the DPO:
If you are not satisfied with our response to your data protection inquiries, you have the right to file a complaint with the relevant supervisory authority in your country.
In Spain: Spanish Data Protection Agency (AEPD)
You can file your complaint through their official website.
We are committed to keeping our GDPR compliance updated. Any significant change in our practices will be communicated through our website.
To exercise your GDPR rights or make inquiries about data protection:
We will respond to all requests within a maximum of 30 days.