Español Français
PRIVACY POLICY FOR THE INTERNAL REPORTING SYSTEM
ON THE COMPANY WEBSITE


BASIC DATA PROTECTION INFORMATION
Responsible for
Processing
Shopping Basket SL, holder of Spanish Tax Identification Number (C.I.F.) B64754765, with registered office at Calle Aribau 168, 6ª, 08036, Barcelona. Contact email address: [email protected]
Purpose of
processing
To process, review, investigate, and resolve reports or communications received through the Internal Reporting System concerning breaches of applicable regulations or the entity's Code of Ethics, in accordance with Spanish Law 2/2023 of February 20.
Legal Basis Processing is necessary for compliance with a legal obligation to which the Data Controller is subject, pursuant to Spanish Law 2/2023 of February 20, and, where applicable, for the performance of a task carried out in the public interest.
Recipients Personal data will be processed in strict confidence. It will only be disclosed to third parties, including courts, the Public Prosecutor's Office, or competent administrative authorities, where such disclosure is strictly necessary for the investigation of facts that may constitute a criminal or administrative offense.
Data Retention
period
Personal data will be retained within the Internal Reporting System only for as long as strictly necessary to determine whether an investigation into the reported facts should be initiated. In any event, if no investigative action has been initiated within three (3) months from receipt of the report, the data must be deleted from the system, except in the cases provided for under applicable law. The data may nevertheless be retained outside the system where necessary for the continuation of an investigation or in connection with judicial or administrative proceedings.
Rights Data subjects have the rights of access, rectification, erasure, restriction of processing, and objection, as well as the right not to be subject to a decision based solely on automated processing, under the conditions established by applicable data protection laws. These rights may be exercised by submitting a written request to the Data Controller.
Under no circumstances will the identity of the reporting person be disclosed in connection with the exercise of the right of access by the person concerned by the report.
ADDITIONAL DETAILED INFORMATION

1. Confidentiality and Anonymity

The system is designed to allow reports to be submitted anonymously where the reporting person chooses not to identify themselves.
Where the reporting person chooses to provide identifying information, their identity will be treated as confidential information and will not be disclosed to the persons concerned by the reported facts or to third parties unrelated to the investigation, except where disclosure is permitted or required under applicable law.
The identity of the reporting person may only be disclosed to a judicial authority, the Public Prosecutor's Office, or the competent administrative authority in the context of a criminal, disciplinary, or administrative investigation, in accordance with applicable law.

2. Rights of the Person Concerned by the Report

Persons to whom the reported facts relate will be informed of the existence of the report and of the facts attributed to them in accordance with the time limits and conditions established by applicable law. Such information may be delayed where providing it at an earlier stage could facilitate the concealment, destruction, or alteration of evidence. Under no circumstances will the identity of the reporting person, or any information that could directly or indirectly identify them, be disclosed to the persons concerned by the report.

3. Data Protection Officer (DPO)

The company has appointed a Data Protection Officer, who may be contacted regarding any questions concerning the processing of personal data at the following email address: [email protected]

4. Complaints

If you believe that the processing of your personal data does not comply with applicable data protection laws, you have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos – AEPD) or, where applicable, with the competent supervisory authority.