Privacy policy
Object
This Privacy Policy informs about the way in which Col·legi Oficial de Biòlegs de la Comunitat Valenciana processes the personal data of the people with whom it interacts through its website and other channels, such as forms, email, telephone, postal communications, contracts and in-person attention.
In particular, information is provided on the identity of the person responsible, the data processed, its origin, the purposes and legal bases of the treatment, the recipients, the conservation periods and the rights of the interested parties, in accordance with Regulation (EU) 2016/679, General Data Protection (RGPD), and Organic Law 3/2018, on the Protection of Personal Data and guarantee of digital rights (LOPDGDD).
This Policy complements the specific information provided in the forms, contracts, procedures and other means used to collect personal data. In case of discrepancy, the specific information corresponding to the specific treatment will prevail.
The COBCV keeps its Treatment Activity Record updated. The public inventory of activities related to the exercise of public law powers can be consulted at: Registry of Treatment Activities.
Who is responsible for the processing of your personal data?
- Entity: Col·legi Oficial de Biòlegs de la Comunitat Valenciana (hereinafter COBCV or Entity)
- CIF/NIF: G97056758
- Legal nature: Public Law Corporation
- Postal address: Carrer de la Travessia, 15E, Marina de València, 46024 València
- Phone: 963 833 717
- Email: valencia@cobcv.com
- Website: https://cobcv.com/es
- Registration data: Registered in the Registry of Professional Associations of the Valencian Community with number 90.
Contact the Data Protection Officer
The COBCV has appointed a Data Protection Officer and has communicated his appointment to the Spanish Data Protection Agency.
Interested persons can contact the Data Protection Officer to make inquiries, make complaints or request advice on any issue related to the processing of their personal data or the exercise of their rights:
BUSINESS ADAPTER, S.L.
Ronda Guglielmo Marconi, 11, 26, (Parque Tecnológico) 46980 Paterna (Valencia).
E-mail: fmoya@businessadapter.es (ref. COBCV) or through this Customer Service Form
What data will we process, how do we obtain it and for what purpose?
The COBCV will process different categories of personal data depending on the relationship maintained with each person, the public and collegiate functions exercised and the services requested. Not all categories listed below will be covered for all interested parties:
Identification data: name and surname, DNI, NIE or equivalent document, membership number, signature, image and voice.
Contact information: postal address, telephone number and email.
Academic and professional data: qualifications, training, professional experience, specialty, professional situation, membership in professional associations, resume and employment data.
Membership data: number and membership status, date of registration and withdrawal, type of membership, membership rights and obligations, positions, participation in membership bodies and services used.
Economic, banking and billing data: bank account, installments, direct debits, invoices, payments, collections, returns, amounts and concepts.
Contractual and commercial data: contracted or requested services, budgets, orders, communications and history of the relationship.
Insurance data: insured status, policy or certificate number, coverage type, validity and data necessary to manage registrations, cancellations or incidents.
Electoral data: inclusion in the census, voter or candidate status, candidacies, endorsements, participation and results. The individual direction of the vote will not be recorded or associated with the identity of the voter.
Data on government bodies: position, appointment, dismissal, attendance, representations, interventions, agreements, minutes, abstentions and conflicts of interest.
Deontological and sanctioning data: reported facts, allegations, evidence, infractions, resolutions, sanctions, claims and appeals.
Labor and Social Security data: data necessary for hiring, payroll, working hours, permits, contributions and management of the employment relationship.
Data related to claims, procedures and legal defense: facts, allegations, documentation provided, resolutions and data related to administrative or judicial procedures.
Data from the internal information channel: identity and contact of the informant when identified, link with the COBCV, reported facts, affected people, witnesses, evidence and investigative actions.
Website navigation and usage data: IP address, online identifiers, device, browser, technical logs, pages visited, preferences and data obtained through cookies or similar technologies.
Social network data: name or profile identifier, image, published content, comments, reactions, messages and information that the person makes accessible through the social network.
The COBCV will not request special categories of data unless they are necessary for a specific purpose and there is authorization in accordance with article 9 RGPD. In particular, data from special categories of data provided in claims, complaints, deontological files, sanctioning procedures or legal defense actions may be processed.
In these cases, reinforced minimization, confidentiality, access control and conservation measures will be applied.
The COBCV may also process data related to convictions and criminal offenses when there is legal authorization, especially in the internal information channel, deontological or sanctioning procedures and legal defense actions.
The COBCV will only process adequate, relevant data limited to what is necessary for each purpose. The data will be accessible exclusively to authorized persons who need to use it due to their functions, subject to the duty of confidentiality and the technical and organizational security measures established by COBCV.
Data can be obtained:
Directly from the interested person or their representative.
From the census, records and internal files of COBCV.
From other professional associations and regional or general councils.
From public administrations, judicial bodies and public registries.
From employers, clients, suppliers or entities with which the interested person is related.
From whistleblowers, claimants, witnesses, people investigated or third parties who provide information.
From sources accessible to the public, when their use is lawful.
From social networks, employment platforms and other services used voluntarily by the interested person.
From suppliers who act as data processors following instructions from COBCV.
When the data is not obtained directly from the interested person, COBCV will provide the information required by article 14 RGPD, unless any of the legally provided exceptions apply.
Mandatory and voluntary data will be identified in the forms and procedures. Failure to provide mandatory data may prevent the registration process, providing the requested service, formalizing or executing a contractual relationship, fulfilling a legal obligation or responding to a request. Failure to provide voluntary data will not produce these consequences.
The categories of data that we can process about a person will depend on the relationship they maintain with the COBCV, as shown below:
Collegiate and pre-collegiate people:
Identification, contact, academic and professional, collegiate, economic, banking, billing and insurance data necessary to process pre-registration or membership, maintain the collegiate relationship, collect fees and provide services will be processed.
The data may be obtained from the person themselves, their representative, other professional associations, professional councils, administrations and registries when there is legal authorization.
Clients and users of billed services
Identification, contact, professional, contractual, commercial, economic, banking and billing data of clients who are natural persons, self-employed persons and representatives or contact persons of clients who are legal entities will be processed.
The data may be obtained directly from the interested person, from the entity they represent or from the documentation generated during the contracting and provision of the service.
Information requesters:
The identification and contact data necessary to respond will be processed, as well as the content of the query and the information that the person voluntarily provides.
The data may be received in person, by telephone, email or through the forms enabled on the website.
Suppliers:
Identification, contact, professional, contractual, economic, banking and billing data of suppliers who are natural persons, self-employed persons, representatives and contact persons of suppliers who are legal entities will be processed.
The data may be obtained directly from the interested person or the entity for which they provide services.
Job Seekers:
Identification, contact, academic, professional, curricular and data generated during interviews or selection tests will be processed. No special categories of data or information from third parties that is not necessary for the selection process should be provided.
The data may be provided directly by the candidate or come from employment platforms, selection companies or professional sources when there is a valid legal basis.
People who use social networks:
The identifying data, name or user identifier, profile image, comments, reactions, messages and other information that the person communicates to COBCV or makes accessible through the configuration of the social network will be processed.
The use of each social network is also subject to the conditions and privacy policies of its owner. For more information see our Social Media Policy.
Subscribers to communications and newsletters:
The email address and, when requested, the name, preferences and language necessary to manage the subscription will be processed. The person may unsubscribe using the link incorporated in each communication.
The data will be obtained from the person themselves through the subscription forms or channels and, where appropriate, from the collegial relationship maintained with the COBCV.
Claimants and people affected by claims:
Identification and contact data and the information included in the claim, allegations, evidence, communications and resolution will be processed. Data of affected persons, representatives, witnesses and third parties related to the events may also be processed.
It is requested not to provide personal data that is not necessary to process the claim.
The data may be obtained from claimants, affected persons, representatives, witnesses, related third parties, internal files, administrations and judicial bodies.
Reporting persons, affected and related to internal channel communications
Our internal channel allows anonymous or identified communications to be submitted. When the reporting person is identified, their identification, contact and professional data may be processed, as well as data relating to affected persons, witnesses and third parties, the reported facts, evidence and investigative actions.
This treatment will be governed by Law 2/2023 and by the specific information of the internal information system, which can be consulted at: Internal complaints channel.
Visitors:
To control access to our facilities, identification data, contact data, entity of origin, person visited, date and time of entry and exit and other information strictly necessary to manage the visit and guarantee security will be processed.
The data is obtained when the visit itself provides it when requesting access to our facilities or when your interlocutor at COBCV provides it to us to allow you access to these when you arrive.
Users of this website:
When using the website, the IP address, device and browser data, technical logs, pages visited, preferences and identifiers obtained through cookies or similar technologies may be processed.
Non-necessary cookies will only be installed after obtaining the user's consent. Detailed information and modification of preferences can be found in the Cookies Policy and in the configuration panel available on the website.
The data may be obtained from the device and browser used, from server logs, from web forms and from cookies or similar technologies, in accordance with the preferences expressed by the user.
Members and participants in collegiate bodies
Identification data, contact data, membership data, professional data, positions, attendance, representation, interventions, non-secret votes, minutes, agreements, abstentions and conflicts of interest related to the General Meeting and the Governing Board will be processed.
The data may be obtained from the person themselves, from the collegiate census, from representation documents, from proposals, interventions and votes and from the minutes and documentation of the General Meeting, the electoral process, agreements, administrations, professional councils and public records.
Participants in electoral processes
Identification, collegiate, contact, eligibility, candidatures, endorsements, participation, complaints and results will be processed. The individual meaning of the vote will be secret and cannot be linked to the identity of the voter.
The data may be obtained from the person themselves, from the collegiate census, from candidates and guarantors, from the Governing Board, from the electoral table and from the voting systems, complaints and electoral records.
People related to deontological and sanctioning files
Identification, contact, professional data, facts, allegations, evidence, reports, infractions, resolutions, sanctions and appeals of complainants, investigated persons, representatives, witnesses and third parties will be processed.
The data may be obtained from complainants, claimants, investigated persons, representatives, witnesses, experts, third parties, other professional associations, administrations, judicial bodies and internal files.
People who contact the DPD or exercise rights
Identification data, contact data, identity accreditation, content of the query or request, documentation provided, communications and response will be processed. These procedures may require processing data from other COBCV activities.
The data may be obtained from the person themselves, their representative, the internal units and files of the COBCV, those in charge of processing and data protection authorities, the systems and activities of the COBCV and the DPD.
People related to procedures and legal defense
Identification, contact, professional, economic data and data included in claims, administrative files, judicial procedures, evidence, resolutions and communications with legal professionals will be processed.
The data may be obtained from the parties to the procedure, representatives, lawyers, attorneys, experts, insurers, witnesses, administrations, judicial bodies, public registries and internal files.
Check-in and check-out
Identification, contact and representation data will be processed, as well as the date and time of presentation or sending, registration number, medium used, sender and recipient body or person, subject and personal data included in the registered documentation.
The data may be obtained from senders, recipients, representatives, administrations, judicial bodies, other professional associations, clients, suppliers and internal units of COBCV.
Incidents and security breaches
Identification and contact data of the affected persons, communicators and users involved will be processed; technical and security data, such as IP addresses, identifiers, access logs, dates, times, affected devices and systems; and the categories of personal data compromised by the incident. Data on the origin, scope, consequences, investigation, corrective measures and notifications made may also be processed. The specific categories of data affected will depend on each incident and may correspond to any of the COBCV processing activities. Its processing will be limited to what is necessary to detect, contain, investigate, document and, where appropriate, notify the security breach.
The data may be obtained from affected persons, authorized personnel, technical systems and records, data processors, technology providers, third parties and competent authorities.
Specific information on data collection
Specific information corresponding to the treatment carried out will be provided in each form, procedure or means of collection. Said information will identify, among other things, the purpose, legal basis, recipients, conservation and way of exercising the rights.
When the data is not obtained directly from the interested person, COBCV will provide the information provided for in article 14 RGPD, unless a legal exception is applicable.
The data categories actually processed are identified in the COBCV Processing Activities Register.
What will your data be processed for?
COBCV will process personal data for the purposes indicated below, depending on the relationship maintained with each interested person. The data will not be used for purposes incompatible with those for which they were collected.
Collegiate and pre-collegiate people
Process requests for membership, transfer, modification and withdrawal. Articles 6.1.c) and 6.1.e) RGPD: compliance with legal obligations and exercise of public functions attributed to COBCV.
Process pre-registration applications and provide services voluntarily requested by pre-registered persons. Article 6.1.b) RGPD: application of pre-contractual measures or provision of the requested service.
Check the incorporation and professional practice requirements. Articles 6.1.c) and 6.1.e) RGPD: compliance with collegiate legislation and exercise of public powers.
Keep the census and school records updated. Articles 6.1.c) and 6.1.e) RGPD: compliance with legal obligations and exercise of collegiate functions.
Manage fees, direct debits, collections, returns and billing. Articles 6.1.c) and 6.1.e) RGPD: compliance with collegiate obligations; and article 6.1.c) RGPD: compliance with accounting and tax obligations.
Provide voluntary training, advice, insurance and other collegiate services. Article 6.1.b) RGPD: execution of the contractual relationship or provision of the requested service.
Issue certificates and accreditations and answer questions about the collegiate situation. Articles 6.1.c) and 6.1.e) RGPD: compliance with legal obligations and exercise of public powers.
Communicate data to professional councils, administrations, judicial bodies and registries when mandatory. Article 6.1.c) RGPD: compliance with a legal obligation.
Fulfill the functions of organization, representation and defense of the profession. Article 6.1.e) RGPD: fulfillment of a mission carried out in the public interest or in the exercise of public powers.
Clients and users of billed services
Respond to requests for information, budgets and measures prior to hiring. Article 6.1.b) RGPD: application of pre-contractual measures requested by the interested person.
Formalize, manage and execute the contracting of services. Article 6.1.b) RGPD: execution of a contract.
Maintain communications necessary to provide the service. Article 6.1.b) RGPD: execution of the contract.
Manage orders, incidents, payments, collections and billing. Article 6.1.b) RGPD: execution of the contract.
Comply with accounting, tax and administrative obligations. Article 6.1.c) RGPD: compliance with legal obligations.
Manage claims and responsibilities derived from the service. Article 6.1.f) RGPD: legitimate interest in addressing claims and defending the rights of the COBCV; and, when there is a procedure, article 9.2.f) RGPD: formulation, exercise or defense of claims.
Persons requesting information
Receive, record, analyze and respond to general queries. Article 6.1.f) RGPD: legitimate interest in addressing the communications received.
Answer queries related to public functions or collegiate services. Article 6.1.e) RGPD: fulfillment of a mission carried out in the public interest.
Respond to requests for information related to the possible contracting of a service. Article 6.1.b) RGPD: application of pre-contractual measures.
Verify identity or representation when necessary. Article 6.1.c) RGPD: compliance with legal obligations; or article 6.1.f) RGPD: legitimate interest in avoiding improper access or delivery of information.
Refer the query to the competent unit and keep a record of the response. Articles 6.1.e) and 6.1.f) RGPD: exercise of collegiate functions and legitimate interest in properly managing communications.
Suppliers
Request and evaluate offers and budgets. Article 6.1.b) RGPD: application of pre-contractual measures when the supplier is a natural person.
Select, hire and manage natural person suppliers. Article 6.1.b) RGPD: execution of a contract.
Process the data of representatives and contact persons of suppliers, legal entities. Article 6.1.f) RGPD: legitimate interest in managing the relationship with the supplying entity.
Manage orders, deliveries, services and incidents. Articles 6.1.b) and 6.1.f) RGPD: contractual execution or management of the relationship with the represented entity.
Process invoices, payments, withholdings and accounting or tax obligations. Article 6.1.c) RGPD: compliance with legal obligations.
Control access and permissions necessary to provide the service. Article 6.1.f) RGPD: legitimate interest in protecting facilities, systems and information.
Manage contractual responsibilities. Article 6.1.f) RGPD: legitimate interest in formulating, addressing or defending claims.
Job seekers
Receive, manage and evaluate applications for specific positions. Article 6.1.b) RGPD: application of pre-contractual measures requested by the candidate.
Conduct interviews and selection tests. Article 6.1.b) RGPD: application of pre-contractual measures.
Check training, experience and professional suitability. Article 6.1.b) RGPD: application of pre-contractual measures.
Check professional references where necessary and where appropriate guarantees have been provided. Article 6.1.f) RGPD: legitimate interest in verifying professional suitability, after weighing interests.
Keep the candidacy for future processes not initially requested. Article 6.1.a) RGPD: consent of the candidate.
Comply with legal obligations related to selection and equal opportunities. Article 6.1.c) RGPD: compliance with legal obligations.
People who use social networks
Manage institutional profiles and respond to comments, queries and messages. Article 6.1.f) RGPD: legitimate interest in managing institutional presence and attending to voluntary interactions.
Inform about activities, services, calls and professional matters. Articles 6.1.e) and 6.1.f) RGPD: exercise of collegiate functions and legitimate interest in institutional communication.
Moderate content and avoid illicit uses. Article 6.1.f) RGPD: legitimate interest in protecting the profiles, users and reputation of COBCV.
Manage activities or contests on social networks. Article 6.1.b) RGPD: execution of the bases or conditions of participation.
Publish images or content when it is necessary to obtain authorization. Article 6.1.a) RGPD: consent.
Prepare aggregate reach statistics. Article 6.1.f) RGPD: legitimate interest in evaluating institutional communication, provided that invasive profiles are not created.
For more information, consult our Social Media Policy.
People subscribed to newsletters
Manage the registration, sending and cancellation of voluntary newsletters. Article 6.1.a) RGPD: consent.
Adapt shipments to selected preferences. Article 6.1.a) RGPD: consent.
Maintain proof of consent and withdrawals. Article 6.1.c) RGPD: compliance with proactive responsibility obligations and electronic communications regulations.
Send necessary institutional communications to members. Articles 6.1.c) and 6.1.e) RGPD: compliance with legal obligations and exercise of collegiate functions. These communications should not be confused with promotional newsletters.
Obtain opening or interaction statistics. Article 6.1.a) RGPD: consent when unnecessary tracking technologies are used.
Claimants and people affected by claims
Receive, record, analyze and resolve claims. Articles 6.1.c) and 6.1.e) RGPD: compliance with legal obligations and exercise of public functions when the claim is collegial.
Manage complaints about private services. Article 6.1.f) RGPD: legitimate interest in addressing complaints and improving services.
Verify identity and representation. Article 6.1.c) RGPD: compliance with legal guarantees of the procedure.
Request allegations, evidence or additional information. Articles 6.1.c) and 6.1.e) RGPD: processing of the procedure and exercise of collegiate functions.
Communicate the resolution and adopt corrective measures. Articles 6.1.c) and 6.1.e) RGPD: compliance with obligations and powers attributed to COBCV.
Address administrative or judicial resources and responsibilities. Article 6.1.f) RGPD and, with respect to special categories, article 9.2.f) RGPD: formulation, exercise or defense of claims.
Internal information system
Receive, record and analyze anonymous or identified communications. Article 6.1.c) RGPD: compliance with the obligations established by Law 2/2023.
Determine admission and process the investigation. Article 6.1.c) RGPD: compliance with a legal obligation.
Maintain communication with the reporting person and protect them from retaliation. Article 6.1.c) RGPD: compliance with Law 2/2023.
Investigate the facts and guarantee the rights of the affected people. Article 6.1.c) RGPD: compliance with legal obligations.
Adopt corrective, disciplinary or legal measures. Articles 6.1.c) and 6.1.f) RGPD: compliance with legal obligations and defense of the rights of the COBCV.
Treat special categories that appear in communications. Article 9.2.g) RGPD: reasons of essential public interest covered by Law 2/2023.
Process data on possible criminal offenses. Article 10 RGPD and Law 2/2023.
Communicate the facts to competent authorities. Article 6.1.c) RGPD: compliance with a legal obligation.
Maintain the system logbook. Article 6.1.c) RGPD: compliance with Law 2/2023.
More information in the terms of the internal complaints channel.
Visiting people
Identify and authorize access to facilities. Article 6.1.f) RGPD: legitimate interest in controlling and protecting the facilities.
Inform the person or unit visited. Article 6.1.f) RGPD: legitimate interest in organizing the visits.
Record entries and exits. Article 6.1.f) RGPD: legitimate interest in maintaining access security and traceability.
Protect people, documentation, facilities and systems. Article 6.1.f) RGPD: legitimate interest in guaranteeing security.
Investigate incidents. Article 6.1.f) RGPD: legitimate interest in clarifying facts and demanding responsibilities.
Users of the website
Allow access, navigation and use of the website. Article 6.1.f) RGPD: legitimate interest in providing and maintaining the web service.
Respond to forms and requests. Articles 6.1.b), 6.1.e) or 6.1.f) RGPD, depending on whether it is a pre-contractual request, a collegiate function or a general consultation.
Maintain security and detect improper access, fraud or errors. Article 6.1.f) RGPD: legitimate interest in guaranteeing the security of the website.
Remember privacy preferences. Article 6.1.c) RGPD: compliance with obligations related to consent and cookies.
Install necessary technical cookies. Article 6.1.f) RGPD: legitimate interest in allowing the requested operation of the website.
Use analytical, advertising or third-party cookies that are not necessary. Article 6.1.a) RGPD: consent.
Comply with legal obligations applicable to the website. Article 6.1.c) RGPD: compliance with legal obligations.
For more information visit our Cookies Policy.
Participants in the General Meeting
Call and organize sessions. Articles 6.1.c) and 6.1.e) RGPD: compliance with statutory obligations and exercise of collegiate functions.
Check the membership status and the rights to attend, speak and vote. Articles 6.1.c) and 6.1.e) RGPD.
Manage attendees and performances. Articles 6.1.c) and 6.1.e) RGPD.
Process call requests, proposals, interventions, requests and questions. Articles 6.1.c) and 6.1.e) RGPD.
Manage deliberations and votes. Articles 6.1.c) and 6.1.e) RGPD.
Prepare, approve, sign, certify and safeguard minutes and agreements. Articles 6.1.c) and 6.1.e) RGPD.
Communicate and execute agreements. Articles 6.1.c) and 6.1.e) RGPD.
Control the management of the Governing Board. Article 6.1.e) RGPD: exercise of the functions attributed to the General Meeting.
Members of the Governing Board
Manage appointments, acceptance of positions, substitutions and dismissals. Articles 6.1.c) and 6.1.e) RGPD: compliance with regulations and collegiate statutes.
Call and organize meetings and manage participation. Articles 6.1.c) and 6.1.e) RGPD.
Prepare, sign, certify and safeguard minutes and agreements. Articles 6.1.c) and 6.1.e) RGPD.
Manage powers of representation, delegations and authorizations. Articles 6.1.c) and 6.1.e) RGPD.
Execute and track agreements. Article 6.1.e) RGPD: exercise of government and administration functions.
Manage abstentions, incompatibilities and conflicts of interest. Article 6.1.c) RGPD: compliance with legal and statutory obligations.
Communicate the composition of the body to registries and administrations. Article 6.1.c) RGPD: compliance with a legal obligation.
Comply with obligations of transparency and good governance. Article 6.1.c) RGPD: compliance with legal obligations.
Participants in electoral processes
Call and organize electoral processes. Articles 6.1.c) and 6.1.e) RGPD: compliance with the Statutes and exercise of collegiate functions.
Prepare, update and display the electoral roll. Articles 6.1.c) and 6.1.e) RGPD.
Check voter and eligible status. Articles 6.1.c) and 6.1.e) RGPD.
Receive, verify, correct and proclaim candidacies. Articles 6.1.c) and 6.1.e) RGPD.
Manage guarantees, auditors and representatives. Articles 6.1.c) and 6.1.e) RGPD.
Manage the polling station and voting systems. Articles 6.1.c) and 6.1.e) RGPD.
Guarantee the authenticity, integrity and secrecy of the vote. Articles 6.1.c) and 6.1.e) RGPD.
Count the votes and announce the results. Articles 6.1.c) and 6.1.e) RGPD.
Process electoral claims and appeals. Articles 6.1.c) and 6.1.e) RGPD.
Communicate elected officials to competent registries and organizations. Article 6.1.c) RGPD: compliance with legal obligations.
The identity of the voter can never be linked to the meaning of their vote.
Deontological and sanctioning files
Receive complaints about possible professional breaches. Articles 6.1.c) and 6.1.e) RGPD: compliance with legal obligations and exercise of public powers.
Carry out prior information and research actions. Articles 6.1.c) and 6.1.e) RGPD.
Initiate, process and resolve files. Articles 6.1.c) and 6.1.e) RGPD.
Manage allegations, evidence, reports and hearings. Articles 6.1.c) and 6.1.e) RGPD.
Exercise the functions of deontological and disciplinary control. Article 6.1.e) RGPD: exercise of public powers.
Impose and execute sanctions. Articles 6.1.c) and 6.1.e) RGPD.
Process resources. Articles 6.1.c) and 6.1.e) RGPD.
Treat special categories necessary to resolve the file. Article 9.2.g) RGPD: reasons of essential public interest protected by collegiate legislation; or article 9.2.f) RGPD: formulation, exercise or defense of claims.
Process data related to criminal offenses when necessary. Article 10 RGPD, only when there is legal authorization.
Communicate information to authorities and judicial bodies. Article 6.1.c) RGPD: compliance with legal obligations.
People who contact the DPD
Receive and record queries, doubts, complaints and claims. Article 6.1.c) RGPD: compliance with the obligations relating to the DPD.
Verify identity or representation when necessary. Article 6.1.c) RGPD: compliance with legal guarantees.
Analyze the issue and request information from the units involved. Article 6.1.c) RGPD: compliance with the functions of the DPD.
Advise and respond to the interested person. Article 6.1.c) RGPD: compliance with the obligations established by the RGPD and the LOPDGDD.
Monitor compliance and cooperate with supervisory authorities. Article 6.1.c) RGPD: compliance with legal obligations.
Persons exercising data protection rights
Receive and register requests. Article 6.1.c) RGPD: compliance with a legal obligation.
Verify identity and representation. Article 6.1.c) RGPD.
Locate the affected data and treatments. Article 6.1.c) RGPD.
Address the rights of access, rectification, deletion, opposition, limitation and portability. Article 6.1.c) RGPD: compliance with articles 15 to 21 RGPD.
Address rights related to automated decisions. Article 6.1.c) RGPD: compliance with article 22 RGPD.
Communicate the actions to managers and recipients. Article 6.1.c) RGPD.
Respond to complaints from authorities and judicial bodies. Article 6.1.c) RGPD.
Keep evidence of the request and response. Article 6.1.c) RGPD: compliance with the principle of proactive responsibility.
People related to procedures and legal defense
Receive and analyze claims, requirements and legal communications. Article 6.1.f) RGPD: legitimate interest in defending the rights and interests of COBCV.
Exercise public functions or defend collegiate decisions. Articles 6.1.c) and 6.1.e) RGPD: compliance with obligations and exercise of public powers.
Request legal advice and prepare actions or resources. Article 6.1.f) RGPD: legitimate interest in legal defense.
Manage administrative, judicial, arbitration or extrajudicial procedures. Article 6.1.f) RGPD and article 9.2.f) RGPD: formulation, exercise or defense of claims.
Collect, provide and safeguard evidence. Article 6.1.f) RGPD and, with respect to special categories, article 9.2.f) RGPD.
Communicate data to lawyers, attorneys, experts, insurers and competent bodies. Articles 6.1.c), 6.1.e) or 6.1.f) RGPD, depending on the procedure.
Execute resolutions and demand accountability. Articles 6.1.c) and 6.1.f) RGPD.
Check-in and check-out
Receive, identify, record and distribute documents. Articles 6.1.c) and 6.1.e) RGPD: compliance with obligations and exercise of public functions.
Record communications related to services or private relationships. Article 6.1.f) RGPD: legitimate interest in maintaining the organization and documentary traceability.
Assign date, number and proof of presentation or shipment. Articles 6.1.c) and 6.1.e) RGPD.
Identify senders, recipients and representatives. Articles 6.1.c), 6.1.e) or 6.1.f) RGPD, depending on the nature of the communication.
Send the documentation to the competent unit and monitor it. Articles 6.1.e) and 6.1.f) RGPD.
Accredit the reception, content and sending of communications. Articles 6.1.c) and 6.1.f) RGPD.
Comply with administrative and statutory obligations. Article 6.1.c) RGPD: compliance with legal obligations.
Incident and security breach management
Detect, record, analyze and contain incidents. Articles 6.1.c) and 6.1.f) RGPD: compliance with security obligations and legitimate interest in protecting systems.
Identify the systems, data and people affected. Article 6.1.c) RGPD: compliance with articles 32 to 34 RGPD.
Determine the origin, scope, consequences and level of risk. Article 6.1.c) RGPD: compliance with legal obligations.
Recover information and take corrective measures. Articles 6.1.c) and 6.1.f) RGPD.
Coordinate the response with managers and technology providers. Article 6.1.c) RGPD: compliance with security and management obligations of those in charge.
Document the gap and the actions taken. Article 6.1.c) RGPD: compliance with article 33.5 RGPD.
Notify the breach to the supervisory authority. Article 6.1.c) RGPD: compliance with article 33 RGPD.
Communicate it to affected people when appropriate. Article 6.1.c) RGPD: compliance with article 34 RGPD.
Collaborate with authorities, judicial bodies and security forces. Article 6.1.c) RGPD: compliance with legal obligations.
Address special categories affected by the incident. Articles 9.2.f) or 9.2.g) RGPD, as necessary for the defense of claims or for reasons of essential public interest.
More information for interested people:
In the forms, contracts, procedures, speeches and other means used to collect personal data, the COBCV will provide the specific information required by the regulations. This information may be provided through a layered system, incorporating basic information at the time of collection and a link or reference to the corresponding additional information.
When the treatment is based on consent, this must be granted through a free, specific, informed and unequivocal statement, and may be withdrawn at any time. The withdrawal will not affect the legality of the treatment carried out previously.
When the treatment is based on a legal obligation, the exercise of public powers, the execution of a contract or a legitimate interest, it will not be necessary to request consent, without prejudice to the obligation to inform the interested person.
The data will not be subsequently processed for purposes incompatible with those for which they were collected. If COBCV intends to use them for a different purpose, it will inform the interested person in advance and determine the applicable legal basis, unless the new processing is expressly authorized by the regulations.
Data retention
Personal data will be kept for the time necessary to fulfill the purpose for which it was collected and, where appropriate, as long as the legal, collegial, employment, contractual or service provision relationship with the interested person is maintained.
Category
Documentation
Applicable standard or criterion
Conservation period or criterion
Collegiate People
Customers
Suppliers
Accounting
Art. 30 of the Commercial Code
Six years since the last entry made in the books.
Collegiate People
Customers
Suppliers
Invoices and tax documentation
Articles 66 to 70 of Law 58/2003, General Tax
Four years from the end of the regulatory period for submitting the corresponding declaration or self-assessment, without prejudice to interruptions in the statute of limitations.
Collegiate People
College record
COBCV Legislation and Statutes
As long as the membership is maintained. After withdrawal, the information necessary to prove the collegiate status will be kept and the rest will be blocked during the applicable liability periods.
Collegiate People
Complaints, actions, resolutions, sanctions and appeals
Collegiate legislation, COBCV Statutes and administrative procedure regulations
During the processing of the file and until the resolution is final. Subsequently, during the appeal periods, prescription of responsibilities and cancellation of sanctions provided for in the regulations and the Statutes.
Customers
Suppliers
Other persons linked by private contractual relationships
General
Art. 1964.2 of the Civil Code
Five years:
Personal actions that do not have a special term expire five years after compliance with the obligation can be required. In continuing obligations to do or not to do, the term will begin each time they are breached.
Job seekers
Curriculum and documentation of the selection process
COBCV Conservation Policy
Until the completion of the process. It may be kept for a maximum of one year for future processes when the person has consented.
Visitors
Facility access record
COBCV safety and conservation policy
For the time necessary to control the visit and, at most, one month, unless there is an incident or a conservation obligation.
Website users
Cookies and similar technologies
AEPD Cookie Policy and Cookie Guide
During the period indicated for each cookie. The election on consent must be renewed, at most, every twenty-four months
Website users
Technical and safety records
COBCV Security Policy
During the time strictly necessary to guarantee safety and, in general, a maximum of twelve months, except in the event of an incident or pending liability.
Information requesters
Questions and answers
COBCV Conservation Policy
During the time necessary to respond and, at most, one year to prove the care provided, unless the consultation gives rise to another procedure or relationship.
Informants
Affected people
Communications, investigations and record book
Articles 26.2 and 32.3 and 32.4 of Law 2/2023
The data will remain in the channel only for the time necessary to decide whether to initiate an investigation. If it does not start in three months, they will be removed from the channel; Unprocessed communications may only be kept anonymous to prove the operation of the system. Data from initiated investigations will be kept for the necessary and proportionate time, without in any case exceeding ten years.
Irrelevant data will be deleted immediately. If it is proven that the information is false, it will be deleted, unless it may constitute a criminal offense, in which case it will be kept while the judicial procedure is being processed.
Customers
Contracts, accepted budgets, orders, contractual communications, proof of provision, invoices and collection documentation
Art. 30 of the Commercial Code; arts. 66 to 70 of the General Tax Law; art. 1964.2 of the Civil Code
During the contractual relationship. Invoices and accounting documentation: 6 years from the last entry. Tax documentation: 4 years, except for special deadlines. Contractual documentation: 5 years from when compliance with the obligation can be required.
Suppliers
Contracts, offers, orders, delivery notes, invoices, bank details, payment receipts and commercial communications
Art. 30 of the Commercial Code; arts. 66 to 70 of the General Tax Law; art. 1964.2 of the Civil Code
During the contractual relationship. Invoices and accounting documentation: 6 years from the last entry. Tax documentation: 4 years, except for special deadlines. Contractual documentation: 5 years from when compliance with the obligation can be required.
People who use social networks
Messages, comments, requests, interactions and data visible on social profiles
Art. 5.1.e RGPD; COBCV internal conservation policy; conditions of the corresponding social network
As long as it is necessary to attend to the interaction or request. Subsequently, the data managed directly by the COBCV will be deleted, unless it must be kept blocked to meet responsibilities. The content published on the social network will be subject to its own conservation policy.
Newsletter Subscribers
Email address, date and means of obtaining consent, preferences, shipments made and unsubscription requests
Arts. 5.1.e and 7.1 RGPD; art. 21 of Law 34/2002; COBCV internal conservation policy
Until withdrawal of consent or request for withdrawal. Afterwards, the information strictly necessary to prove consent and cancellation will be kept blocked for a maximum of 3 years.
Claims management
Claim, data of the parties, communications, documentation provided, actions carried out and response or resolution
Art. 5.1.e RGPD; art. 1964.2 of the Civil Code when applicable; corresponding sector regulations
During the processing. Once completed, it will be kept blocked during the statute of limitations for possible liabilities. In general, 5 years when personal actions may arise without a special period.
General Meeting
Calls, agendas, lists of attendees, accreditations, voting delegations, interventions, votes, minutes, agreements and certifications
COBCV Statutes; regulations governing professional associations; COBCV document management policy
Calls, accreditations, voting delegations and auxiliary documentation: 5 years from the celebration. Minutes, agreements and certifications: permanent conservation for their legal and institutional value.
Governing Board
Calls, agendas, lists of attendees, preparatory documentation, formalized deliberations, votes, minutes, agreements, appointments and certifications
COBCV Statutes; regulations governing professional associations; COBCV document management policy
Auxiliary documentation: during the processing of the matter and 5 additional years. Minutes, agreements, appointments and certifications: permanent conservation for their legal and institutional value.
Electoral processes
Electoral census, candidacies, endorsements, proclamations, credentials, ballots, votes by mail, complaints, minutes, results and certifications
COBCV Statutes; collegiate electoral regulations; COBCV document management policy
Census, candidacies, ballots, votes, accreditations and auxiliary documentation: until the claim and challenge deadlines end and, at most, 5 years from the final proclamation, except in open procedures. Minutes, results, proclamations and certifications: permanent conservation.
Queries, complaints and suggestions to the DPD
Queries and complaints received, communications, documentation provided, actions taken and responses issued
Arts. 38 and 39 RGPD; arts. 72 to 74 LOPDGDD; COBCV internal conservation policy
During the processing. Once completed, the documentation necessary to prove the performance of the COBCV will be kept blocked for 3 years, unless there is a claim or open procedure.
Attention to the exercise of data protection rights
Requests for access, rectification, deletion, opposition, limitation and portability; identity accreditations; communications and responses
Arts. 12 to 22 RGPD; arts. 12 to 18 and 72 to 74 LOPDGDD
During the processing. Once completed, it will be kept blocked for 3 years to prove correct attention to the right, unless there is a claim or open procedure.
Legal defense
Judicial, administrative and extrajudicial files; writings, evidence, reports, communications, resolutions and representation documentation
Applicable procedural regulations; art. 1964.2 of the Civil Code when applicable; art. 32 LOPDGDD
During the processing of the procedure. Once completed, it will be kept blocked until the applicable actions and responsibilities expire. The resolutions and documents that continue to produce legal effects will be kept as long as they subsist.
Check-in and check-out
Registry entries, date and time, identity of the sender or recipient, receiving body, reference, proof of presentation or shipment and registered documents
Art. 16 of Law 39/2015 when applicable; collegiate regulations; COBCV document management and archiving policy
The entries and supporting documents necessary to prove the presentation or referral: permanent conservation. The registered documents will be kept for the period corresponding to the file or activity to which they are related.
Incidents and security breaches
Record of incidents, affected people, risk analysis, measures adopted, communications to the DPD, notifications to the AEPD and communications to the affected people
Arts. 33.5 and 34 RGPD; arts. 72 to 74 LOPDGDD; COBCV internal conservation policy
During incident management. Once this is closed, the documentation necessary to prove compliance will be kept for 3 years. If there is an investigation, claim or procedure, it will be kept until its completion and the responsibilities have expired.
When the data is no longer necessary, it will be deleted or, when legally required, it will remain blocked during the statute of limitations of possible liabilities. During the blockade they will only be available to judges and courts, the Public Prosecutor's Office, competent public administrations and data protection authorities. Once these periods have expired, they will be destroyed or anonymized.
Profiling
The COBCV does not carry out treatments aimed at creating profiles of the interested parties, in the sense established in article 4.4 of the RGPD.
The management of academic and professional information of members does not constitute, in itself, profiling, as it is not used to automatically evaluate or predict aspects related to their professional performance, economic situation, preferences, interests, behavior or personal characteristics.
Likewise, COBCV does not adopt decisions based solely on the automated processing of personal data that produce legal effects on the interested parties or significantly affect them in a similar way.
If treatments of this nature are implemented in the future, the COBCV will inform the affected persons in advance about their operation, purpose, legal basis, importance and anticipated consequences, and will apply the guarantees required by article 22 of the RGPD, including, where applicable, the right to obtain human intervention, express their point of view and challenge the decision by writing to: valencia@cobcv.com
Recipients
Personal data may be communicated to third parties when the communication is necessary to comply with a legal obligation, exercise the public functions attributed to COBCV, execute a contractual relationship, satisfy a duly weighed legitimate interest or when the interested person has given their consent.
Depending on the processing activity, the data may be communicated to:
Public administrations, public organizations, control authorities and other competent entities, when necessary to comply with a legal obligation or exercise the public functions attributed to the COBCV.
The State Tax Administration Agency, the General Treasury of Social Security and other competent bodies in tax, labor and Social Security matters.
Banking entities and payment service providers, to manage collections, payments, transfers and direct debits.
The General Council of Official Colleges of Biologists, other colleges and professional councils, when communication is necessary to process memberships, transfers, accreditations, incompatibilities, electoral processes or exercise the functions legally attributed to COBCV.
Insurance entities and insurance brokerages, when necessary to manage insurance linked to the membership or services requested by the members.
Courts, tribunals, Public Prosecutor's Office, Security Forces and Corps, lawyers, solicitors, experts and other professionals or competent authorities, when necessary to comply with a legal obligation or formulate, exercise or defend claims.
Claimants, complainants, affected or interested in administrative, deontological, sanctioning or judicial procedures, exclusively when the communication is legally provided for and respecting the rights of the other affected persons.
Polling stations, candidates and members with the right to participate, with respect to the data whose communication or publication is necessary to develop the electoral processes of the COBCV, in accordance with its Statutes and electoral regulations.
Entities in charge of preventing occupational risks, mutual societies collaborating with Social Security, medical services and insurance entities, with respect to workers and when legally necessary.
Within the framework of the Internal Information System, data may be communicated to the Public Prosecutor's Office when the facts could constitute a crime, to the European Public Prosecutor's Office when they affect the financial interests of the European Union and to the competent administrative or judicial authorities when legally appropriate. Communications may also be sent to the Independent Whistleblower Protection Authority or the competent regional authority, including the Valencian Anti-Fraud Agency, within their respective areas of competence.
The identity of the reporting person will not be communicated to the person affected by the information and may only be communicated to the judicial authority, the Public Prosecutor's Office or the competent administrative authority within the framework of an investigation, in the cases established in Law 2/2023.
The COBCV may allow access to data to providers that provide advisory services, computer maintenance, hosting, communications, administrative management, document destruction or other necessary services. These providers will act as data processors and will be subject to the corresponding contract regulated in article 28 of RGPD.
International data transfer
The COBCV does not carry out international transfers of personal data outside the European Economic Area.
If it were necessary to hire suppliers that involved an international transfer of data, this would only be carried out when there was an adequacy decision from the European Commission or through one of the guarantees provided for in articles 46 et seq. of the RGPD. In the absence of a decision of adequacy or adequate guarantees, it would only be carried out when one of the exceptions in article 49 of RGPD is applicable.
Security Measures
The COBCV has adopted the appropriate technical and organizational measures to guarantee a level of security appropriate to the risk, in accordance with article 32 of the RGPD.
These measures are intended to protect the confidentiality, integrity, availability and resilience of processing systems and services, as well as to prevent the loss, alteration, destruction, access or unauthorized communication of personal data.
To determine the applicable measures, the state of the art, the costs of application, the nature, scope, context and purposes of the processing, as well as the probability and severity of the risks to the rights and freedoms of individuals, are taken into account.
The COBCV periodically reviews and updates the measures implemented and, especially, when relevant changes occur in treatments, systems or providers, or when a security incident occurs.
Your Rights
You can exercise the following rights at any time in relation to your personal data:
Right of Access:
Obtain confirmation of whether or not we are processing your personal data and, if so, access them and the information provided for in article 15 of RGPD.
Right of Rectification:
Ask us to rectify your personal data when it is inaccurate, as well as to complete it when it is incomplete.
Right of Opposition:
Object, for reasons related to your particular situation, to processing based on the fulfillment of a mission carried out in the public interest, the exercise of public powers or legitimate interest. COBCV will stop processing the data unless it proves compelling legitimate reasons that prevail over the interests, rights and freedoms of the interested party, or when the processing is necessary to formulate, exercise or defend claims.
In the Internal Information System, when the person to whom the facts refer exercises their right to object, it will be presumed that there are compelling legitimate reasons that legitimize the processing of their data, unless proven otherwise, in accordance with article 31.4 of Law 2/2023.
Right of Deletion:
Request the deletion of your data when any of the circumstances provided for in article 17 of the RGPD occur, among others, when the data is no longer necessary for the purposes for which it was collected or when you withdraw your consent if this was the basis of the treatment.
Right to Limitation of treatment:
You may ask us to exercise this right when one or more of these situations occur:
When you dispute the accuracy of your data, during a period that allows the person responsible to verify its accuracy.
When the processing is unlawful and you oppose the deletion of your data and request instead the limitation of its use.
When the data are no longer needed for the purposes of the processing, but the interested party needs them for the formulation, exercise or defense of claims.
When you have objected to the processing pursuant to Article 21(1), while it is verified whether the legitimate reasons of the controller prevail over those of the interested party.
Portability Right:
Receive the personal data that you have provided to COBCV in a structured, commonly used and machine-readable format, and transmit them to another controller, when the treatment is based on consent or a contract and is carried out by automated means. This right will not be applicable to the treatments necessary to fulfill a mission carried out in the public interest or exercise public powers.
Right not to be subject to automated decisions:
Not be subject to a decision based solely on automated processing, including profiling, that produces legal effects or significantly affects you, except in the cases provided for in article 22.2 of the RGPD.
Right to withdraw consent:
Withdraw consent at any time when this is the legal basis of the treatment. The withdrawal will not affect the legality of the processing carried out previously.
How you can exercise your rights
To exercise any of your rights, you must write to Col·legi Oficial de Biòlegs de la Comunitat Valenciana, either by postal mail to the address: C/ Travesía, 15E, CP 46024 València (València) or to the email: valencia@cobcv.com, stating the rights you wish to exercise. If you act on behalf of another person, you must prove your representation. If there are reasonable doubts regarding the identity of the person making the request, we may request that additional information be provided to confirm their identity.
The request will be attended to without undue delay and in any case within a maximum period of one month from its receipt, extendable in complex cases in accordance with article 12 of RGPD. The exercise of rights is free of charge, unless the requests are manifestly unfounded or excessive.
We inform you that you have the right to make a claim before the Spanish Data Protection Agency at: C/ Jorge Juan, 6, 28001 Madrid or www.aepd.es.
If you wish to send any suggestion or query regarding the processing of your personal data, you can contact the data protection officer at: fmoya@businessadapter.es or through this Customer Service Form
Update of this Policy
COBCV reserves the right to modify this Policy without prior notice. That is why we recommend consulting it every time you visit our website. Updated August 5, 2026.