Privacy policy

Last updated: 11 August 2026

At VIDORIA, S.L. we handle the personal data you give us with one simple principle: we use it only for what you gave it to us for, and we do nothing with it that we have not told you about here. This policy explains what data we collect, why, for how long we keep it, and what you can ask of us at any time.

1. Who is the data controller

  • Company: VIDORIA, S.L.
  • Tax ID (CIF): B-43487511
  • Registered address: Ctra. Reus – Cambrils, km 4.5 · 43206 Reus (Tarragona) · Spain
  • Telephone: +34 977 75 04 23
  • Email: info@vidoria.com
  • Company registry: Commercial Registry of Tarragona, Volume 1253, Companies Section, Folio 113, Sheet T-13926, 2nd entry, 13 November 1996. Health Registry 164028/CAT.

For any question about your personal data or about this policy, write to info@vidoria.com with “Data protection” in the subject line.

2. What data we process and where it comes from

2.1. Contact form

When you complete the form on our contact page, you provide us with:

  • First name and surname
  • Company
  • Email address
  • Country
  • Type of enquiry (bulk, private label, our own brands or other)
  • The content of the message you write

All fields except the message are required in order for us to reply; if you do not provide them, we cannot process the enquiry. We do not ask for any special category data (health, political opinions, ethnic origin, etc.) and we ask you not to include such data in the message field.

2.2. Direct communications

If you write to us by email, call us, or contact one of our commercial offices, we will process the identification and professional data you provide in that communication, together with its history.

2.3. Browsing data

When you visit the website, technical and usage data is collected through cookies and similar technologies: IP address (truncated within the analytics tool), device and browser type, language, pages visited and time spent. Full details are in our Cookie policy.

2.4. Commercial relationship

If we end up working together, we will also process the contact details of the people in your organisation, billing data, and the data needed to manage orders, shipments and export documentation.

3. Why we use your data and on what legal basis

Purpose Legal basis
Responding to your commercial enquiry, preparing quotations and sending you the information or catalogue you request. Your consent, given by ticking the box on the form (Art. 6.1.a GDPR), and pre-contractual measures taken at your request (Art. 6.1.b GDPR).
Managing the commercial relationship: orders, samples, production, shipments, invoicing and export documentation. Performance of a contract or commercial relationship (Art. 6.1.b GDPR).
Complying with our legal obligations in commercial, accounting, tax, customs and food safety matters. Compliance with a legal obligation (Art. 6.1.c GDPR).
Analysing how the website is used in order to improve it (aggregated browsing statistics). Your consent, given through the cookie panel (Art. 6.1.a GDPR).
Protecting the form against automated submissions and abuse. Our legitimate interest in the security of our systems (Art. 6.1.f GDPR).
Sending you commercial communications about products and services similar to those you have already requested or contracted. Legitimate interest (Art. 6.1.f GDPR and Art. 21.2 of Spanish Law 34/2002, LSSI). You may object at any time and in every communication.

We do not carry out automated decision-making or profiling that produces legal effects concerning you.

4. How long we keep your data

  • Enquiries that do not lead to a commercial relationship: up to 1 year from the last contact, unless you ask us to delete them sooner.
  • Customer and supplier data: for the duration of the commercial relationship and, afterwards, blocked for the applicable statutory limitation periods — 4 years for tax matters (Spanish General Tax Act) and 6 years for commercial matters (Art. 30 of the Spanish Commercial Code).
  • Browsing data: the retention period of each cookie, set out in the Cookie policy.
  • Proof of consent: for as long as the processing remains in force and during the limitation periods for any resulting claims.

5. Who else has access to your data

We do not sell or transfer your data to third parties for their own purposes. The following service providers do access it, acting as data processors and under an Article 28 GDPR agreement:

  • Web hosting and email: Dinahosting, S.L. (Spain).
  • Web analytics: Google Ireland Limited (Ireland) and Google LLC (USA), through Google Analytics, only if you have accepted analytics cookies.
  • Form protection: Google Ireland Limited / Google LLC, through reCAPTCHA.
  • Web fonts: Google Ireland Limited / Google LLC (Google Fonts) and Adobe Systems Software Ireland Limited / Adobe Inc. (Adobe Fonts).
  • Commercial offices and agents: if your enquiry relates to a market served by one of our offices or agents in China, Taiwan, South Korea or Germany, we may pass on your contact details and the content of your enquiry so that they can assist you in your language and time zone.

We will also disclose data to public authorities, customs authorities, banks and certification bodies where there is a legal obligation or where it is necessary to perform the commercial relationship.

6. International data transfers

Some of the providers listed above are located outside the European Economic Area, mainly in the United States. These transfers rely on the European Commission’s Adequacy Decision of 10 July 2023 concerning the EU–US Data Privacy Framework, to which Google LLC and Adobe Inc. are certified, and, in the alternative, on the Standard Contractual Clauses approved by the European Commission.

Where your enquiry is handled by our offices in China, Taiwan or South Korea, the transfer is based on Article 49.1.b) GDPR, being necessary for the performance of a contract or of pre-contractual measures taken at your request.

7. Your rights

You may exercise the following rights at any time:

  • Access: to know what data of yours we process.
  • Rectification: to correct data that is inaccurate or incomplete.
  • Erasure: to ask us to delete data when it is no longer necessary.
  • Objection: to object to processing based on our legitimate interest, including receiving commercial communications.
  • Restriction: to ask us to suspend processing while a claim is being resolved.
  • Portability: to receive your data in a structured, commonly used format, or to have us send it to another controller.
  • Withdrawal of consent at any time, without affecting the lawfulness of processing carried out beforehand.

To exercise them, write to info@vidoria.com or to Ctra. Reus – Cambrils, km 4.5, 43206 Reus (Tarragona), Spain, stating which right you are exercising and enclosing a copy of a document proving your identity. We will reply within a maximum of one month.

If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan 6, 28001 Madrid — www.aepd.es), which is our lead supervisory authority, or with the supervisory authority of the EU Member State where you reside.

8. Information security

We apply appropriate technical and organisational measures to protect your data against destruction, loss, alteration or unauthorised access, taking into account the state of the art and the risks of the processing. The website operates over HTTPS with an SSL certificate.

9. Minors

This website is aimed exclusively at professionals and businesses. We do not knowingly collect data from children under 14. If we find that we have received data from a minor without the consent of the person holding parental responsibility, we will delete it.

10. Changes to this policy

We may update this policy to reflect legislative or case-law developments or changes in our processing activities. The version in force is always the one published on this page, bearing the update date shown at the top.