Privacy Policy of KESSLER OFFSHORE ENGINEERING S.L

 

1. Identity and details of the data controller

In compliance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter, GDPR), and Organic Law 3/2018, of 5 December, on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD), the user is informed of the following:

  • Identity of the controller: KESSLER OFFSHORE ENGINEERING S.L
  • Tax ID (NIF/CIF): B56358120
  • Postal address: Poligono Empresarial de Levante n.1 mod.4 Cádiz 11011 Cádiz ES
  • Contact email address: contact@kessleroffshoregroup.com

KESSLER OFFSHORE ENGINEERING S.L, as data controller, guarantees the protection of all personal data that the user provides through the Website and assumes the obligation to process such data in accordance with the provisions of current legislation on personal data protection and this Privacy Policy.

2. Principles applicable to data processing

KESSLER OFFSHORE ENGINEERING S.L applies the following guiding principles in the processing of users’ personal data, in accordance with Article 5 of the GDPR:

  • Principle of lawfulness, fairness, and transparency: personal data shall be processed lawfully, fairly, and in a transparent manner in relation to the data subject. At all times, the user’s consent shall be requested, or the processing shall be based on another legitimate legal basis, informing in advance with full transparency about the purposes of such processing.
  • Principle of purpose limitation: personal data shall be collected for specified, explicit, and legitimate purposes and shall not be further processed in a manner that is incompatible with those purposes.
  • Principle of data minimisation: personal data shall be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. Only strictly essential data will be collected for each specific purpose.
  • Principle of accuracy: personal data shall be accurate and, where necessary, kept up to date. Every reasonable step shall be taken to ensure that personal data that are inaccurate are erased or rectified without delay.
  • Principle of storage limitation: personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
  • Principle of integrity and confidentiality: personal data shall be processed in such a manner as to ensure appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical and organisational measures.
  • Principle of accountability: KESSLER OFFSHORE ENGINEERING S.L is responsible for compliance with the above principles and is able to demonstrate such compliance to the competent supervisory authorities.

3. Personal data collected and purposes of processing

KESSLER OFFSHORE ENGINEERING S.L collects and processes personal data that the user voluntarily provides through the contact and enquiry forms available on the Website, as well as data generated automatically during browsing (IP address, usage data, cookies), as set out in our Cookie Policy. As this Website is exclusively oriented towards the provision of professional services and does not constitute an e-commerce platform, no data relating to orders, payments, shopping carts, shipments, or product transactions are collected. The specific purposes for which personal data are processed are detailed below, along with the legal basis that legitimises each processing under Article 6 of the GDPR:

Processing purpose Data processed Legal basis (Art. 6 GDPR)
Management of enquiries and information requests received through the contact form, including responding to questions raised and following up on communications initiated by the user. First name and surname, email address, telephone number (if provided), message content, and associated metadata (date, time, IP address). Consent of the data subject (Art. 6.1.a) or, where applicable, performance of pre-contractual measures at the request of the data subject (Art. 6.1.b).
Provision of the professional services contracted by the user with KESSLER OFFSHORE ENGINEERING S.L, including the administrative, technical, and operational management necessary for the proper execution of the professional engagement, as well as communications inherent to the development of the contracted service. Identification data (name, surname, NIF/CIF where applicable), contact data (email, telephone, postal address), contractual data, and documentation related to the service provided. Performance of a contract to which the data subject is party (Art. 6.1.b).
Sending of commercial and promotional communications about services provided by KESSLER OFFSHORE ENGINEERING S.L, sector news, articles of interest, events, or training seminars, provided that the user has given their express consent through the corresponding subscription checkbox. First name and surname, email address. Explicit consent of the data subject (Art. 6.1.a).
Web analytics via Google Analytics 4 (GA4) through Google Site Kit, with the aim of obtaining statistical and anonymised information about users’ browsing (pages visited, time spent, traffic source, device type, approximate geographical location), for the continuous improvement of the Website’s content, usability, and user experience. IP address (anonymised), client identifiers, browsing data, site interaction data, browser and device type. Explicit consent of the data subject (Art. 6.1.a).
Compliance with legal obligations applicable to KESSLER OFFSHORE ENGINEERING S.L, in particular those relating to commercial, tax, and accounting legislation, anti-money laundering and counter-terrorist financing regulations (where applicable), and legislation on personal data protection. Identification and contact data, contractual data, invoicing and accounting data. Compliance with a legal obligation to which the controller is subject (Art. 6.1.c).
Safeguarding of legitimate interests of KESSLER OFFSHORE ENGINEERING S.L, such as information security, fraud prevention, defence against claims, and protection of computer systems against unauthorised access, malicious attacks, or misuse of the Website. IP address, browsing data, server activity logs, security data. Legitimate interest pursued by the data controller (Art. 6.1.f).

KESSLER OFFSHORE ENGINEERING S.L does not use users’ personal data for automated decision-making that produces significant legal effects for the data subject, nor does it create user profiles for purposes other than those expressly indicated in this policy. In the event that a new processing purpose not contemplated in this policy is envisaged, the prior consent of the data subject shall be requested, or the processing shall be based on the corresponding legal basis, informing the user appropriately before proceeding with the new processing.

4. Retention of personal data

Personal data shall be retained for the time strictly necessary for the purpose for which they were collected and, in any case, for the legal limitation periods that may be applicable. The following table shows the indicative retention periods according to the purpose of processing:

Purpose Retention period
Enquiries and information requests Data will be kept for the time necessary to handle and resolve the enquiry raised and, once completed, for a maximum period of one (1) year for follow-up and quality control purposes, unless the user requests earlier deletion.
Provision of contracted services Data will be kept for the duration of the contractual relationship between the user and KESSLER OFFSHORE ENGINEERING S.L and, once terminated, for the legal limitation periods of the obligations arising from the contract, which generally shall be five (5) years in accordance with the Spanish Commercial Code, and ten (10) years in the case of tax documentation with tax significance.
Commercial communications Data will be kept as long as the user maintains their subscription and does not express their wish to unsubscribe. Each commercial communication will offer a simple and free mechanism to withdraw consent and request removal from the distribution list. Once the unsubscribe request is processed, data will be blocked for the legal limitation periods to address potential liabilities.
Web analytics (GA4) Browsing data processed by Google Analytics 4 is kept in accordance with the periods and policies established by Google. Event-level data is retained for a period of fourteen (14) months by default. After that period, user identifiers are automatically deleted. The IP address is anonymised before storage.
Legal obligations Data will be kept for the periods established by the applicable legislation in each case. By way of example: commercial and accounting documentation (6 years, Art. 30 of the Commercial Code), tax documentation (4 to 10 years, General Tax Law), and employment and social security documentation (4 years).
Security and fraud prevention Server activity logs are kept for a period of twelve (12) months for security and diagnostic purposes. After this period, data is securely deleted, unless it must be kept as evidence in the context of an ongoing security investigation or judicial proceeding.

Once the indicated retention periods have elapsed, KESSLER OFFSHORE ENGINEERING S.L shall proceed to the deletion or blocking of personal data, as appropriate in each case, ensuring that the blocked data remains available only to the competent authorities during the limitation period of the actions that may arise from the processing, and proceeding to its definitive destruction once said period has expired.

5. Data recipients and transfers to third parties

The user’s personal data will not be transferred, sold, or shared with third parties except in the cases provided for in this policy or where there is a legal obligation to do so. KESSLER OFFSHORE ENGINEERING S.L may communicate the user’s personal data to the following categories of recipients:

Recipient Role Purpose of communication
Web hosting provider Data processor Hosting of the servers and technical infrastructure that supports the Website. The servers are located within the European Economic Area (EEA) and are subject to the security measures required by the GDPR. The web hosting provider acts as a data processor and processes data following the documented instructions of KESSLER OFFSHORE ENGINEERING S.L.
Email and messaging service provider Data processor Management of the sending and receiving of electronic communications with users and clients, including responses to enquiries, notifications related to contracted services, and sending of commercial communications (where the user has given their consent).
Google LLC (Google Analytics 4 / Google Site Kit) Data processor / Joint controller (partial) Analysis of web traffic and audience measurement of the Website in accordance with the terms set out in Google’s data protection agreement. Google processes browsing data in an aggregated and anonymised manner and may use such data for the improvement of its own services. Data may be transferred to Google servers in the United States under the EU-US Data Privacy Framework (DPF).
CRM software provider (if applicable) Data processor Centralised management of relationships with clients and contacts, including the recording, tracking, and management of commercial interactions and service requests, provided that KESSLER OFFSHORE ENGINEERING S.L uses a CRM tool. The CRM provider acts as a data processor and processes data in accordance with a data processing agreement.
Public administrations and judicial authorities Legal recipient Compliance with legal obligations of KESSLER OFFSHORE ENGINEERING S.L, including requirements of the Tax Agency, the Labour and Social Security Inspectorate, and courts and tribunals in the exercise of their jurisdictional function.
Law enforcement agencies Legal recipient Cooperation with competent authorities in the context of investigations of cybercrime, fraud prevention, and protection of the Website’s security.

Except in legally established cases, KESSLER OFFSHORE ENGINEERING S.L shall not carry out international transfers of personal data to countries that do not offer a level of protection equivalent to that of the GDPR. In relation to Google Analytics 4, the transfer of data to the United States is based on the European Commission’s adequacy decision regarding the Data Privacy Framework (DPF). KESSLER OFFSHORE ENGINEERING S.L periodically verifies that data processors maintain the certifications and data protection guarantees required at any given time.

4. Mandatory nature of data provision and consequences of not providing data

In accordance with Article 13(2)(e) of the GDPR, data subjects are informed of the following:

  • The provision of personal data requested through the contact and enquiry forms on the Website is necessary for KESSLER OFFSHORE ENGINEERING S.L to properly address and manage users’ requests, enquiries and communications. Failure to provide the minimum necessary data (indicated on each form with an asterisk or prominently) prevents KESSLER OFFSHORE ENGINEERING S.L from addressing the enquiry or request submitted.
  • The provision of personal data requested for contracting the professional services offered by KESSLER OFFSHORE ENGINEERING S.L is a necessary requirement for the conclusion and performance of the corresponding service contract. If the data subject does not provide the required data, KESSLER OFFSHORE ENGINEERING S.L will not be able to formalise the contract or provide the requested services.
  • The provision of personal data for subscribing to commercial communications, newsletters or bulletins is voluntary. Failure to provide such data does not in any way affect the contractual or service relationship, and its effects are limited to the non-receipt of such communications. The user may withdraw their consent at any time.

5. Records of Processing Activities (Art. 30 GDPR)

In accordance with Article 30 of the GDPR, KESSLER OFFSHORE ENGINEERING S.L maintains a Record of Processing Activities (ROPA) that documents all personal data processing activities carried out under its responsibility as data controller. This record, kept in writing including in electronic format, contains the following updated information: the name and contact details of the data controller and, where applicable, the Data Protection Officer; the purposes of the processing; a description of the categories of data subjects and of the categories of personal data; the categories of recipients to whom the personal data have been or will be disclosed; transfers of personal data to third countries and the documentation of suitable safeguards; the envisaged time limits for erasure of the different categories of data; and a general description of the technical and organisational security measures implemented. KESSLER OFFSHORE ENGINEERING S.L shall make the Record of Processing Activities available to the Spanish Data Protection Agency (AEPD) upon request in the exercise of its supervisory functions.

6. Data Protection by Design and by Default (Art. 25 GDPR)

KESSLER OFFSHORE ENGINEERING S.L applies, both at the time of determining the means of processing and at the time of the processing itself, appropriate technical and organisational measures designed to implement data protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing, in order to meet the requirements of the GDPR and protect the rights of data subjects. In particular, KESSLER OFFSHORE ENGINEERING S.L applies the following data protection by design and by default measures:

  • Data minimisation: only personal data strictly necessary, adequate and relevant for each processing purpose is collected. Forms are configured to exclusively request the essential data fields.
  • Limitation of processing by default: personal data is not processed, by default, for purposes other than those for which it was collected, unless the data subject has given their explicit consent for such additional purposes.
  • Pseudonymisation: whenever technically possible and proportionate, pseudonymisation techniques are applied to reduce risks for data subjects.
  • Transparency: information on the processing of personal data is provided in a concise, easily accessible manner and in clear and plain language.

7. Data Subject Rights

The GDPR and the LOPDGDD grant data subjects the following rights in relation to the processing of their personal data. KESSLER OFFSHORE ENGINEERING S.L guarantees the exercise of these rights free of charge, unless the requests are manifestly unfounded or excessive, in which case a reasonable fee based on the administrative costs incurred may be charged, or the request may be refused:

6.1. Right of access (Art. 15 GDPR)

The data subject has the right to obtain from KESSLER OFFSHORE ENGINEERING S.L confirmation as to whether or not their personal data are being processed and, if so, the right to access such data and to receive detailed information about the purposes of the processing, the categories of data concerned, the recipients or categories of recipients to whom the data have been or will be disclosed, the envisaged retention period or the criteria used to determine it, the existence of automated decision-making, and the applicable safeguards in the event of international transfers. Furthermore, the data subject has the right to obtain a copy of the personal data undergoing processing. For any additional copy requested, KESSLER OFFSHORE ENGINEERING S.L may charge a reasonable fee based on administrative costs.

6.2. Right to rectification (Art. 16 GDPR)

The data subject has the right to obtain without undue delay the rectification of inaccurate personal data concerning them. Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement. KESSLER OFFSHORE ENGINEERING S.L shall rectify or complete the data within a maximum period of thirty (30) calendar days from receipt of the request.

6.3. Right to erasure or “right to be forgotten” (Art. 17 GDPR)

The data subject has the right to obtain without undue delay the erasure of personal data concerning them where one of the following grounds applies: (a) the data are no longer necessary in relation to the purposes for which they were collected; (b) the data subject withdraws consent on which the processing is based and there is no other legal ground for the processing; (c) the data subject objects to the processing and there are no overriding legitimate grounds for the processing; (d) the data have been unlawfully processed; (e) the data must be erased for compliance with a legal obligation; (f) the data have been collected in relation to the offer of information society services to children. The right of erasure shall not apply to the extent that processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest in the area of public health, for archiving purposes in the public interest, for scientific or historical research purposes or statistical purposes, or for the establishment, exercise, or defence of legal claims.

6.4. Right to restriction of processing (Art. 18 GDPR)

The data subject has the right to obtain restriction of processing of their data where: (a) the accuracy of the personal data is contested by the data subject, for a period enabling KESSLER OFFSHORE ENGINEERING S.L to verify the accuracy of the personal data; (b) the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead; (c) KESSLER OFFSHORE ENGINEERING S.L no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise, or defence of legal claims; (d) the data subject has objected to processing pending the verification whether the legitimate grounds of the controller override those of the data subject. During the restriction period, the data may only be processed, with the exception of storage, with the data subject’s consent or for the establishment, exercise, or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest.

6.5. Right to data portability (Art. 20 GDPR)

The data subject has the right to receive the personal data concerning them, which they have provided to KESSLER OFFSHORE ENGINEERING S.L, in a structured, commonly used, and machine-readable format, and to transmit those data to another controller without hindrance from KESSLER OFFSHORE ENGINEERING S.L, where: (a) the processing is based on consent or on a contract, and (b) the processing is carried out by automated means. In exercising this right, the data subject may request that the data be transmitted directly from one controller to another where technically feasible. Portability shall not adversely affect the rights and freedoms of others.

6.6. Right to object (Art. 21 GDPR)

The data subject has the right to object, on grounds relating to their particular situation, at any time to the processing of personal data concerning them which is based on the legitimate interest of the controller (Art. 6.1.f) or on the public interest (Art. 6.1.e), including profiling based on those provisions. KESSLER OFFSHORE ENGINEERING S.L shall no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or for the establishment, exercise, or defence of legal claims. Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to the processing of personal data concerning them for such marketing, which includes profiling to the extent that it is related to such direct marketing.

6.7. Right not to be subject to automated individual decision-making (Art. 22 GDPR)

The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. However, KESSLER OFFSHORE ENGINEERING S.L does not currently adopt automated decisions that produce legal or significant effects on data subjects, so in principle this right shall not be applicable. In the event that such procedures are implemented in the future, the data subject shall be informed in advance and the safeguards required by the GDPR shall be obtained.

6.8. Right to withdraw consent (Art. 7.3 GDPR)

The data subject has the right to withdraw at any time the consent previously given for any of the processing purposes based on it, without affecting the lawfulness of processing based on consent before its withdrawal. The withdrawal of consent may be made at any time by sending a communication to contact@kessleroffshoregroup.com, or through the specific unsubscribe and revocation mechanisms provided in each of the communication channels. The withdrawal of consent shall be as easy as it was to give it.

Exercise of rights

To exercise any of the aforementioned rights, the user must send a written request to the email address contact@kessleroffshoregroup.com, or by post to the address Poligono Empresarial de Levante n.1 mod.4 Cádiz 11011 Cádiz ES, indicating in the subject line “Exercise of GDPR Rights” and duly identifying themselves by providing their first name and surname and, where necessary to verify identity, a copy of their national identity document, passport, or equivalent document. If the request is submitted by a legal representative, the representation must be accredited by means of a legally valid document. KESSLER OFFSHORE ENGINEERING S.L shall respond to the request within a maximum period of one (1) month from receipt thereof, extendable by a further two (2) months if necessary, taking into account the complexity and number of requests; in the latter case, the data subject shall be informed of the extension within the first month, indicating the reasons for the delay.

If the data subject considers that KESSLER OFFSHORE ENGINEERING S.L has not satisfactorily addressed the exercise of their rights, or wishes to lodge a complaint regarding data protection, they may contact the Spanish Data Protection Agency (AEPD) through its electronic headquarters at https://www.aepd.es, or by writing to the following postal address: Agencia Española de Protección de Datos, C/ Jorge Juan, 6, 28001 Madrid. It is recommended to first consult KESSLER OFFSHORE ENGINEERING S.L on any data protection matter via the email address contact@kessleroffshoregroup.com in order to resolve it in an agile and satisfactory manner.

7. Security measures

In compliance with Article 32 of the GDPR, KESSLER OFFSHORE ENGINEERING S.L has adopted the appropriate technical and organisational measures to ensure a level of security appropriate to the risk posed by the processing of personal data, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons. The measures implemented include, by way of illustration and not limitation:

  • Encryption of communications: all communications between the user’s browser and the Website server are carried out via HTTPS connections (TLS 1.2 or higher), guaranteeing the confidentiality and integrity of the transmitted data.
  • Logical access control: restricted access to personal data through robust authentication systems (high-complexity passwords, two-factor authentication for administrative access) and minimum privilege policies, so that each authorised user accesses exclusively the data necessary for the performance of their duties.
  • Protection against unauthorised access: implementation of web application firewalls (WAF), intrusion detection and prevention systems (IDS/IPS), and continuous monitoring of server activity to identify and block unauthorised access, brute force attacks, or attempts to exploit vulnerabilities.
  • Periodic updates: keeping the WordPress CMS, Google Site Kit, all plugins, extensions, themes and components installed on the Website, as well as server dependencies up to date, applying security patches released by developers immediately to mitigate known vulnerabilities.
  • Backup copies: performing periodic backups (daily and weekly) of the database and Website files, stored in encrypted form in secure locations. These backups allow data restoration in the event of an incident.
  • Pseudonymisation and anonymisation: application of pseudonymisation and anonymisation techniques to personal data in contexts where full identification of the data subject is not necessary, such as in Google Analytics 4 statistical reports (IP anonymisation).
  • Media management: devices and media containing personal data are subject to specific policies on use, custody, and secure destruction at the end of their useful life.
  • Staff training and awareness: persons authorised to process personal data have received specific training in data protection and information security and are subject to an express duty of confidentiality.
  • Periodic assessments: carrying out security audits and data protection impact assessments (DPIA) when the processing, by its nature, scope, or purposes, is likely to result in a high risk to the rights and freedoms of natural persons.

8. Notification of personal data breaches

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, KESSLER OFFSHORE ENGINEERING S.L shall notify such breach to the Spanish Data Protection Agency (AEPD) without undue delay and, at the latest, within seventy-two (72) hours of becoming aware of it, in accordance with Articles 33 and 34 of the GDPR. When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, KESSLER OFFSHORE ENGINEERING S.L shall communicate the breach to the data subject without undue delay, describing in a clear and transparent manner the nature of the breach, the data affected, the possible consequences, and the measures taken or proposed to remedy the breach and mitigate its adverse effects. Communication to the data subject shall not be required where any of the exceptions provided for in Article 34.3 of the GDPR apply.

10. Applicable law and reference regulations

This Privacy Policy is governed in each and every one of its aspects by Spanish and European Union legislation, as well as by the following international reference regulatory provisions:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, General Data Protection Regulation (GDPR).
  • Organic Law 3/2018 of 5 December, on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD).
  • Law 34/2002 of 11 July, on Information Society Services and Electronic Commerce (LSSI-CE).
  • UK GDPR (Data Protection Act 2018): regarding the processing of personal data of UK residents, KESSLER OFFSHORE ENGINEERING S.L applies the provisions of the UK GDPR, which maintains a level of protection essentially equivalent to the European GDPR. The United Kingdom benefits from an adequacy decision of the European Commission dated 28 June 2021.
  • LGPD (Lei Geral de Proteção de Dados Pessoais, Law No. 13,709/2018): in relation to the processing of personal data of residents in Brazil, KESSLER OFFSHORE ENGINEERING S.L respects the principles and rights set out in the Brazilian General Data Protection Law, ensuring an adequate level of protection.
  • PIPEDA (Personal Information Protection and Electronic Documents Act): regarding the processing of personal data of residents in Canada, KESSLER OFFSHORE ENGINEERING S.L applies the principles of personal information protection set out in PIPEDA, which has been recognized by the EU as legislation offering an adequate level of protection.
  • Other applicable data protection regulations, including sector-specific regulations affecting the professional activity of KESSLER OFFSHORE ENGINEERING S.L.

KESSLER OFFSHORE ENGINEERING S.L undertakes to apply the highest standard of protection among those provided for in the reference regulations, guaranteeing in all cases a level of protection in accordance with the GDPR, considered the most demanding international benchmark standard in terms of personal data protection.

For any dispute that may arise from the application of this Privacy Policy or the processing of the user’s personal data, the parties submit, at their choice, to the courts and tribunals that are competent in accordance with the applicable procedural legislation. Users are advised, prior to the exercise of judicial actions, to contact KESSLER OFFSHORE ENGINEERING S.L at contact@kessleroffshoregroup.com to try to resolve the dispute amicably.

10. Links to third-party sites

This Website may contain links to third-party websites that are not owned or controlled by KESSLER OFFSHORE ENGINEERING S.L. KESSLER OFFSHORE ENGINEERING S.L assumes no responsibility whatsoever for the content, privacy policies, or data processing practices of such external sites, whose access and use is the sole responsibility of the user. Users are advised, when accessing a third-party site, to consult its corresponding privacy policy and terms of use.

11. Updates to the Privacy Policy

KESSLER OFFSHORE ENGINEERING S.L reserves the right to modify this Privacy Policy to adapt it to legislative, doctrinal, or jurisprudential changes, as well as to modifications in data processing procedures or the services provided. Any modification will be published on this same page with due notice. If the changes are substantial, KESSLER OFFSHORE ENGINEERING S.L will communicate them via a prominent notice on the Website or, where legally required, via direct notification to the affected users. Users are advised to periodically review this policy to stay informed about how we protect their data.

12. Contact

For any query, suggestion, or complaint relating to this Privacy Policy or the processing of your personal data, the user may contact KESSLER OFFSHORE ENGINEERING S.L through the following channels:

  • Email: contact@kessleroffshoregroup.com
  • Postal address: Poligono Empresarial de Levante n.1 mod.4 Cádiz 11011 Cádiz ES
  • Contact form: available on the Website

We are committed to addressing your queries with the utmost speed and diligence.

 

Additional Information for California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you the following additional rights:

  • Right to Know: you may request information about the categories and specific pieces of personal information we have collected about you.
  • Right to Delete: you may request deletion of personal information we hold, subject to certain legal exceptions.
  • Right to Correct: you may request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing: we do not sell or share personal information with third parties for cross-context behavioural advertising.
  • Right to Non-Discrimination: we will not discriminate against you for exercising your CCPA/CPRA rights.

To exercise these rights, contact us at contact@kessleroffshoregroup.com. We will respond within 45 days.