【 Privacy Policy 】
Effective Date: 1 January 2026 Atelier NISHI, located in Malaga, Spain (“we,” “us,” or “our”), operates this website and is the Data Controller responsible for your personal data. We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR) and relevant Spanish laws (LOPDGDD).
1. Legal Basis for Processing
We process your personal data under the following legal bases:
- Contractual Necessity: To process and deliver your orders.
- Legal Obligation: To comply with tax, accounting, and consumer protection laws.
- Legitimate Interests: To improve our services, prevent fraud, and conduct direct marketing (where permitted).
- Consent: When you opt-in to cookies or subscribe to our newsletter.
2. Data We Collect
We collect and process the following types of information:
- Personal Identification: Name, billing/shipping address, email address, and phone number.
- Payment Information: Processed securely via third-party providers. We do not store full credit card details.
- Technical & Usage Data: IP address, browser type, device information, and how you interact with our site (via Google Analytics).
- Location Data: Only if you explicitly grant permission through your device settings.
3. Cookies and Tracking
We use cookies to enhance your experience. Upon your first visit, you may Accept or Reject non-essential cookies. You can manage your preferences at any time through your browser settings.
4. Data Sharing and International Transfers
We do not sell your data. We share information only with trusted service providers:
- Logistics: For shipping your orders.
- Payment Gateways: For secure transaction processing.
- IT/Cloud Services: For website hosting and security.
- Professional Advisors: For legal and tax compliance.
As we operate globally, your data may be transferred to and processed in countries outside the EEA (such as Japan or the USA). We ensure these transfers are protected by Standard Contractual Clauses (SCCs) or other legal safeguards approved by the EU Commission.
5. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes we collected it for, including any legal, accounting, or reporting requirements (typically 5 to 10 years for tax purposes in Spain).
6. Your Rights (GDPR)
Under the GDPR, you have the following rights:
- Access & Portability: Request a copy of your data.
- Rectification: Correct inaccurate information.
- Erasure (“Right to be Forgotten”): Request deletion of your data (subject to legal retention requirements).
- Restriction & Objection: Object to processing based on legitimate interests or direct marketing.
- Withdraw Consent: Withdraw consent for marketing or cookies at any time.
To exercise these rights, please contact us via our Contact Form or email us directly at
ateliernishi-es@sangkyap.net
. You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD).
7. Security
We implement robust technical and organizational measures to protect your data. However, no electronic transmission is 100% secure, and we cannot guarantee absolute security.
Contact Us
If you have any questions about this Privacy Policy, please reach out to:
Website: Atelier NISHI
Email: ateliernishi-es@sangkyap.net
Contact Form