Galería Cayón

Privacy Policy

Data Protection Information

Below, we inform you about the details regarding the processing of your personal information, in accordance with the applicable data protection regulations:

Data Controllers:

GALERÍA CAYÓN, S.L.
C/ Blanca de Navarra 7, 28010 Madrid
B85754836

www.galeriacayon.com
+34 913 106 289
juan@galeriacayon.com

CAYÓN ART FAIRS, S.L.
C/ Miguel Ángel 24, 28010 Madrid
B87591889

You may contact either of the above entities—only one is sufficient—to exercise any of your rights.


Purpose of Processing:

Management of client databases, documentation, and execution of various contractual relationships, invoicing and payments; as well as maintaining and promoting commercial and advertising activity via email, postal mail, messaging services, and telephone calls.

We also process data to comply with legal obligations, such as the prevention of money laundering and terrorist financing.

Additionally, for security reasons, our premises are equipped with video surveillance systems.

We understand that you give your consent by contacting us, visiting us, carrying out occasional transactions at the gallery premises or art fair stands, or browsing our website.


Legal Basis:

We require your data to carry out contractual relationships, based on your interest in our products and activities, as well as to comply with legal obligations (labour, commercial, and administrative).

We hold your data because you have shown interest in our activities at some point since the companies were established and began operating (2009 and 2016). Furthermore, we rely on our legitimate interest, in accordance with current regulations, to develop our commercial activity.

As neither the purpose nor the legal basis has changed, we will continue to process your data unless you inform us otherwise.


Recipients:

Data will not be transferred to third parties, either nationally or internationally, except where required by law.

Client and supplier data may be shared between the aforementioned companies, which have the same ownership structure and similar activities (retail art gallery operations and participation in international art fairs and transactions).

We may also engage external service providers for auxiliary processing that may involve limited access to data (such as postal services, logistics and customs services, telecommunications providers, consultancy services, IT tools for email distribution, and banking entities), strictly for the purpose of delivering the contracted service. These providers will process data responsibly, only for the specified purpose, without retaining or using it for other activities.


Your Rights:

You have the right to:

  • Access your data and know whether it is being processed
  • Rectify or update your data
  • Request its deletion (subject to legal obligations)
  • Request data portability
  • Object to or request restriction of processing

You may also withdraw your consent at any time. In such cases, your data will be deleted, except where legal obligations require its retention in a blocked form.

To exercise your rights, you may contact either data controller, providing proof of identity. If you do not receive a response or believe your request has not been properly addressed, please inform us so we can review and resolve the issue.

You may also lodge a complaint with the Spanish Data Protection Agency:
www.agpd.es
C/ Jorge Juan 6, 28001 Madrid


Categories of Data:

The data processed does not fall under special categories or sensitive data. It does not include criminal records or involve large-scale monitoring.

It consists of standard data typical for a small retail business: identification details of clients and suppliers, standard website cookies, records of occasional transactions, and related information within our art gallery activities.


Data Retention:

Your data will be retained for as long as you remain interested in our activities and until you request its deletion.


Security:

Absolute security does not exist; however, we strive to implement reasonable measures and procedures to prevent data breaches and ensure proper, lawful, relevant, limited, responsible, and up-to-date use of your data.

We recognize the importance of safeguarding your rights and therefore rely on external consultancy services for IT applications and tools, as we are not IT specialists. In particular, we ensure that software licenses are up to date and that antivirus systems and firewalls are active and properly maintained.

If you receive information that does not concern you (for example, an email not intended for you), or if you detect a security vulnerability or potential improvement in data protection practices that we could reasonably implement, please contact the data controller.

Thank you.