Privacy Policy

Last updated: March 11, 2026

INFORMATION ABOUT PERSONAL DATA AND PRIVACY POLICY

This privacy policy describes the processing of personal data that PERFUMES Y DISEÑO COMERCIAL, S.L. carries out in its online store www.otzlabmadrid.com (hereinafter, the “Website”) with personal data of users who browse and place orders through it (hereinafter, the “Users”).

This policy only reflects the processing actually carried out by PYD in the context of the purchase process and browsing on the Website.

  1. WHO IS RESPONSIBLE FOR PROCESSING YOUR DATA?

The entity responsible for processing the personal data collected and processed through the use of the Website is PERFUMES Y DISEÑO COMERCIAL, S.L. (hereinafter, “PYD”), with Tax ID No. B-81061616. Users may contact PYD through the following means:

 

  1. WHAT TYPE OF PERSONAL INFORMATION DOES PYD PROCESS AND HOW IS THE DATA OBTAINED?

PYD will collect data directly from Users, mainly the following data and/or categories of data:

  • Identification and contact details (i.e. name, surname, email address, postal address and postcode, telephone number).
  • Data necessary for invoicing and payment of the order.
  • Data related to browsing, such as IP address, technical cookie identifiers and, when the User consents, analytical data, as detailed in the Cookies Policy.

The Website does not have a conventional user registration with a password. Access to orders associated with an email address is provided through a passwordless verification system, the sole purpose of which is to allow the User to view orders linked to their email address. This access does not involve the creation of a separate profile or a private area with additional features.

If the User does not provide the data necessary to process the order, the purchase cannot be completed.

  1. FOR WHAT PURPOSE DO WE PROCESS YOUR PERSONAL DATA AND WHAT IS THE LEGAL BASIS FOR THIS?

Below are the different purposes for which PYD will process its Users' personal data, as well as the legal bases applicable to each of them:

a. PYD will process Users' personal data as necessary to perform the Contract in relation to the following purposes:

  • to manage Users' orders (i.e., to process and deliver the order and inform them of its status by email, SMS, and/or any other channel available at any given time).

 

  • to contact the User in the event that PYD needs to inform them or ask them any questions regarding their order (e.g., confirmation of shipment).

 

  • Respond to all queries that the User may have in relation to their order.

 

  • Manage and issue documents certifying the sale (e.g., simplified electronic invoice, sales invoice, Tax Free).

 

  • Manage returns and the right of withdrawal, coordinating with the User via email or form.

 

b. PYD will process Users' personal data when they have given their express consent for the following purposes:

  • send commercial communications to Users via email related to our products or promotions.

 

  • use cookies and similar technologies in accordance with the provisions of the Cookies Policy.

 

The interested party may withdraw their consent at any time by sending a request to do so to the email address privacidad@pyd.es.

c. PYD will process Users' personal data whenever necessary to comply with the legal obligations applicable to it.

d. PYD will process Users' personal data for the purpose of ensuring that the Website is a secure site based on PYD's legitimate interest in ensuring that transactions and access to the Website do not pose a risk to the privacy or any other rights and freedoms of Users.

 

  1. HOW LONG IS PERSONAL DATA STORED?

In order to ensure that personal data is adequate, relevant, and limited to what is necessary for the purposes for which it is processed, PYD will retain personal data only for the period of time necessary to fulfill the purpose for which it was collected, taking into account the need to respond to questions that arise or resolve problems, make improvements, activate services, and comply with the requirements of applicable law.

Once the relationship between the User and PYD has ended, their personal data will be blocked from all PYD systems for the sole purpose of making it available to the competent authorities to deal with any administrative or judicial responsibilities and the exercise or defense of claims. Finally, once the period for blocking personal data has elapsed, it will be permanently deleted.

For its part, any data processing carried out by PYD with the express consent of Users for this purpose will be carried out as long as the consent given is not revoked and, after such revocation, the data will be kept, duly blocked, in accordance with the provisions of the previous paragraph.

  1. WITH WHOM IS PERSONAL DATA SHARED?

Users' personal data will be communicated to third parties in compliance with the legal obligations that apply in each case, such as to public administrations and/or bodies when required by tax, labor, social security, or any other applicable regulations.

Likewise, the data may be communicated to those third parties that are necessary for the execution of the contract, as well as to the companies that provide the transport services necessary for the delivery of the purchased products.

On the other hand, PYD may hire third parties who will have access to personal data as a result of the provision of services. In these cases, PYD will have signed the corresponding data processor agreement in accordance with the provisions of the applicable regulations. These third parties belong to the technology services sector, such as Shopify (e-commerce platform), hosting services, analytical tools, or newsletter delivery services, which will only process the data in accordance with PYD's instructions.

  1. HOW DOES PYD PROTECT PERSONAL DATA?

The PYD website uses information security techniques such as firewalls, automated anti-attack systems, access control procedures, and cryptographic mechanisms, all with the aim of preventing unauthorized access to data and ensuring its confidentiality. Periodic security audits are also carried out to perform risk assessments and frequent checks.

PYD states that it has adopted all the necessary technical and organizational measures to guarantee the security of the personal data it processes, as well as to prevent its loss, alteration, and/or access by unauthorized third parties, in accordance with the provisions of the General Data Protection Regulation.

When PYD uses technology providers to provide services (such as e-commerce platforms or content management systems, analytical tools, or newsletter delivery services), these providers act as data processors and apply their own security measures in accordance with industry standards, ensuring that they process the data in accordance with PYD's instructions and that they have sufficient measures in place to protect it.

  1. WHAT ARE USERS' RIGHTS IN RELATION TO THEIR PERSONAL DATA?

Users have the rights detailed below. They may exercise these rights by sending an email to privacidad@pyd.es. In the event of reasonable doubts about the identity of the person exercising the right, PYD may request additional documentation to verify their identity.

 

Right of access

Right to obtain confirmation as to whether or not PYD is processing personal data concerning the User, as well as to access the personal data that PYD has about them.

Right of rectification

Right to request that PYD rectify personal data when it is inaccurate or complete it when it is incomplete. Users have the option of directly correcting their data in their user account by accessing the “My Account” section in their profile.

Right to erasure    

Right to have PYD delete the User's personal data when, among other reasons, it is no longer necessary for the purposes for which it was collected.

Right to restriction

Right to request that processing be restricted, in which case we will only retain the data for the exercise or defense of claims.

Right to portability

Right to receive personal data in a structured, commonly used, and machine-readable format, and to have us transmit it to another controller when the processing is based on consent or derives from the performance of a contract, provided that it is carried out by automated means.

Right to object

Right to object to personal data being processed based on the public or legitimate interest pursued by PYD, including profiling. In this case, PYD will stop processing the data, unless there are compelling legitimate reasons or it is necessary for the exercise or defense of possible claims. You also have the right to object to the processing of data for direct marketing purposes.

Right to lodge a complaint

Right to request the protection of the competent local Supervisory Authority, which in Spain is the Spanish Data Protection Agency (www.aepd.es).

 

  1. CHANGES TO THE PRIVACY POLICY?

This privacy policy will always be available on the Website. However, in the event that PYD proceeds to make a substantial and relevant modification to its content, Users will be notified via the Website or their email address, thereby complying with the duty of information provided for in the GDPR, so that, if they so wish, they may exercise their rights as data subjects.

 

Need more information?

Contact us