Legal

Privacy Policy

Information pursuant to Articles 13 and 14 of the General Data Protection Regulation (GDPR) and the Spanish Data Protection Act (Ley Orgánica 3/2018, LOPDGDD). Last updated: September 2026.

1. Controller

Jandía Westerland, S.A.
Paseo de las Damas 6, Urbanización Bellavista, 07609 Llucmajor (Mallorca), Spain
Email: webmaster@jandia-westerland.eu

Further details can be found in the legal notice. No data protection officer has been appointed, as the legal requirements for doing so are not met. Please send any questions about data protection to the email address above.

2. Visiting the website

When you visit our pages, your browser transmits technically necessary data to the server: IP address, date and time, the address requested, browser type and operating system, and the previously visited page (referrer). Our hosting provider processes this data in server logs in order to deliver the website and to ensure its security and stability.

Legal basis

Article 6(1)(f) GDPR – our legitimate interest in a secure and functioning website.

No tracking or third-party services

We use no analytics or advertising tools, no social media plugins and, on the public website, no cookies. Fonts, style sheets and images are loaded exclusively from our own web space; no data is transmitted to third parties such as Google when you visit.

3. Hosting

The website is hosted by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. STRATO processes the data on our behalf on servers in Germany (Article 28 GDPR). How long STRATO keeps server logs is set out in STRATO’s privacy policy (in German). No data is transferred to countries outside the EU.

4. Shareholder portal

The shareholder portal is open exclusively to shareholders for whom the Board of Directors has set up an account. In this context we process:

  • Account data: username, name displayed in the forum, role (shareholder or board), date the account was set up. We do not store the password itself, only an irreversible, salted hash (PBKDF2-SHA256).
  • Forum posts: content, time and the author’s displayed name. Posts are visible to all signed-in members of the portal.
  • Usage status: which topics you have already read (for the “Neu”, i.e. new, marker) and whether you have opened a topic (for the view counter).
  • Sign-in log: time, IP address and result of sign-in attempts. For a successful sign-in the username is recorded, for a failed one only whether the name exists; passwords are never logged.

Purposes and legal bases

Providing the portal to shareholders and informing them about company matters (Article 6(1)(b) and (f) GDPR); protecting the portal against unauthorised access by means of the sign-in log and a temporary lock after repeated failed attempts (Article 6(1)(f) GDPR).

Retention period

  • Account data: until the account is deleted.
  • Forum posts: until they are deleted by you or the Board of Directors; when an account is deleted, its posts are kept unless you request their deletion.
  • Failed sign-in attempts (for the temporary lock): 15 minutes.
  • Sign-in log: deleted after two months at the latest.

Cookie

After you sign in, the portal sets a single session cookie (“jandia_portal”) so that your password does not have to be verified again, at considerable computing effort, on every page view. It is technically necessary, contains no passwords and is deleted when you close the browser. Your consent is not required for this (Article 22(2) LSSI-CE, Section 25(2) no. 2 TDDDG).

5. Contact by email

If you write to us by email, we process your details in order to deal with your enquiry (Article 6(1)(b) or (f) GDPR) and delete them as soon as they are no longer needed for that purpose, unless statutory retention obligations apply.

6. Your rights

You have the right of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18) and data portability (Article 20), and the right to object to processing based on legitimate interests (Article 21 GDPR). Simply contact webmaster@jandia-westerland.eu.

You also have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR). The authority responsible for us is the Agencia Española de Protección de Datos (C/ Jorge Juan 6, 28001 Madrid, www.aepd.es); you may also contact the supervisory authority where you live.

No automated decision-making, including profiling, takes place.