Privacy policy

PRIVACY POLICY

Last updated: 13 July 2026

At ROBUST EUROPE, S.L. we take the privacy of our users and customers very seriously. This Privacy Policy describes what personal data we collect, for what purpose, how long we keep it, who we share it with and what rights you have at all times.

We recommend reading this document carefully before providing us with your data. If you have any questions, you can contact us at any time through the channels indicated in section 11.

 

1. DATA CONTROLLER

The controller of your personal data is:

ROBUST EUROPE, S.L.

Tax ID: B22491062

Registered office: Calle Espiño 120, 15405 Ferrol, A Coruña, Spain

Registered with the Commercial Registry of A Coruña, Sheet C-66542, 1st registration entry

Email for privacy matters: info@robust-europe.com

Phone / WhatsApp: +34 640 61 25 56

Hereinafter, "Robust" or "the Controller".

Robust has not appointed a Data Protection Officer (DPO), as the circumstances set out in Article 37 of the GDPR do not apply. For any query or to exercise rights, the User can contact us at the email address above.

 

2. APPLICABLE REGULATIONS

The processing of personal data by Robust is governed by:

Regulation (EU) 2016/679, of 27 April (General Data Protection Regulation, "GDPR").

Organic Law 3/2018, of 5 December, on Personal Data Protection and Guarantee of Digital Rights ("LOPDGDD" — Spanish Data Protection Act).

Law 34/2002, of 11 July, on Information Society Services and Electronic Commerce ("LSSI-CE").

 

3. PURPOSES OF PROCESSING, LEGAL BASIS AND RETENTION PERIODS

The purposes for which we process your personal data, the legal basis legitimising each processing activity and the period during which we keep the information are detailed below.

3.1 Order management and contractual relationship

Purpose

Management of the purchase process: receipt, preparation, dispatch and delivery of orders. Handling of incidents, management of returns and reimbursements. Issuance and sending of invoices.

Data processed

Name and surname, Tax ID (where applicable), postal address, email, phone, payment data (handled directly by the payment gateway — Robust does not store these), order history.

Legal basis

Performance of the sales contract (Art. 6.1.b GDPR).

Retention period

For the duration of the contractual relationship and, subsequently, for the applicable legal periods (6 years for commercial documentation under the Spanish Commercial Code; applicable tax periods; limitation periods for contractual actions).

3.2 Customer service

Purpose

Handling enquiries, suggestions, complaints and technical or after-sales incidents sent through the channels provided (email, WhatsApp, web forms).

Data processed

Name, email, phone, content of the enquiry and any data voluntarily provided by the User.

Legal basis

Legitimate interest (Art. 6.1.f GDPR) and, where applicable, performance of the contract (Art. 6.1.b GDPR).

Retention period

For the time necessary to resolve the enquiry and, subsequently, for the applicable legal periods to evidence the assistance provided.

3.3 Sending of commercial communications (newsletter, offers and news)

Purpose

Sending commercial communications by email about products, offers, launches, blog content or Robust events.

Data processed

Name and email. Where applicable, history of interaction with previous campaigns (opens, clicks) to personalise content.

Legal basis

Express consent of the User (Art. 6.1.a GDPR and Art. 21 LSSI-CE). Additionally, in accordance with Art. 21.2 LSSI-CE, Robust may send commercial communications about similar products to customers who have already made a previous purchase, except where expressly opposed by the customer.

Retention period

Until the User withdraws consent or objects to the processing (each communication sent includes a direct unsubscribe link).

3.4 WhatsApp and messaging communications

Purpose

Handling enquiries and providing commercial and after-sales assistance through WhatsApp Business.

Data processed

Phone number, name, content of messages exchanged.

Legal basis

User's consent when initiating the conversation (Art. 6.1.a GDPR) and/or performance of the contractual relationship (Art. 6.1.b GDPR).

Retention period

For the time necessary to attend to the enquiry and the applicable subsequent legal periods.

3.5 Website analytics and service improvement

Purpose

Analysing browsing behaviour on the Website, measuring audience, identifying trends and improving user experience, products and services.

Data processed

IP address (anonymised), browser type, device, operating system, pages visited, browsing time, traffic source, approximate location.

Legal basis

User's consent given through the cookie banner (Art. 6.1.a GDPR and Art. 22.2 LSSI-CE).

Retention period

In accordance with the periods set out in the Cookie Policy.

3.6 Advertising and remarketing

Purpose

Displaying personalised advertising on third-party platforms (Meta, Google) based on the User's prior browsing of the Website. Measuring the effectiveness of advertising campaigns.

Data processed

Unique cookie and pixel identifiers, browsing behaviour, interactions with adverts.

Legal basis

User's consent given through the cookie banner (Art. 6.1.a GDPR).

Retention period

In accordance with the periods set out in the Cookie Policy.

3.7 Compliance with legal obligations

Purpose

Complying with applicable legal obligations (tax, accounting, commercial, consumer protection).

Data processed

The data necessary to comply with each legal obligation.

Legal basis

Compliance with legal obligation (Art. 6.1.c GDPR).

Retention period

For the legal periods applicable to each obligation.

 

4. ORIGIN OF THE DATA

The personal data processed by Robust comes, in all cases, directly from the User, whether through:

Completion of forms on the Website (registration, purchase, newsletter subscription, contact form).

Placing orders on the Website.

Sending communications to Robust by email, WhatsApp or phone.

Interaction with the Website through cookies (in accordance with the Cookie Policy).

Robust does not collect personal data from external sources, social networks or intermediaries without the User's consent.

 

5. CATEGORIES OF DATA

The categories of personal data processed by Robust are as follows:

Identifying data: name, surname, Tax ID (where applicable), postal address, email, phone.

Commercial data: order history, products purchased, shipping preferences, customer service communications.

Financial data: payment data is handled directly by the payment gateway (Shopify Payments or other authorised providers). Robust does not store or have access to full credit card data.

Browsing data: IP address, cookie identifiers, browsing behaviour, device and browser used (see Cookie Policy).

Robust does not process special categories of data (racial or ethnic origin, political opinions, religious beliefs, health data, sexual orientation, etc.).

6. RECIPIENTS OF THE DATA (assignments and processors)

To properly provide its services, Robust relies on external providers acting as processors or, where appropriate, as independent controllers. These providers access certain personal data exclusively to provide the contracted service and are bound by the security and confidentiality measures required by law.

The main providers and recipients are:

Provider

Service provided

Location / International transfer

Shopify International Limited

E-commerce platform hosting the Website and processing orders.

Ireland (EU); Shopify Inc. (Canada) and sub-processors in the USA. Transfers covered by Standard Contractual Clauses (SCC) and/or the EU-US Data Privacy Framework (DPF).

Shopify Payments / Stripe (or other configured payment gateway)

Payment processing.

Ireland (EU) / USA (DPF + SCC).

Google Ireland Limited / Google LLC

Google Analytics (GA4) services.

Ireland (EU) / USA (DPF + SCC).

Meta Platforms Ireland Limited / Meta Platforms, Inc.

Meta Pixel (Facebook/Instagram Ads) and WhatsApp Business.

Ireland (EU) / USA (DPF + SCC).

Transport companies (Correos Express, FedEx or other logistics carriers)

Order delivery.

EU (mainly Spain).

Tax and accounting consultancy

Accounting and tax management of the company.

Spain (EU).

Public authorities, law enforcement bodies, judges and courts

Only where there is a legal obligation.

Spain (EU).

Robust does not transfer, sell or rent personal data to third parties for purposes other than those indicated in this Policy.

 

7. INTERNATIONAL TRANSFERS OF DATA

Some of the providers indicated in the previous section are established outside the European Economic Area (EEA), mainly in the United States.

Where international data transfers occur, Robust ensures that they are covered by the appropriate safeguards provided for in Chapter V of the GDPR, in particular:

EU-US Data Privacy Framework (DPF) — Adequacy decision of the European Commission of 10 July 2023 — for providers certified under that framework.

Standard Contractual Clauses (SCC) approved by the European Commission, supplemented with the necessary technical and organisational measures.

Users may request a copy of the applicable safeguards by sending an email to info@robust-europe.com.

 

8. USER RIGHTS

In accordance with the GDPR and the LOPDGDD, the User has the following rights in relation to their personal data:

Right

Description

Access (Art. 15 GDPR)

Knowing what personal data we process about you and obtaining a copy thereof.

Rectification (Art. 16 GDPR)

Requesting the correction of inaccurate or incomplete data.

Erasure / "right to be forgotten" (Art. 17 GDPR)

Requesting the deletion of your data when no longer necessary, when you have withdrawn consent or in other legally established circumstances.

Restriction of processing (Art. 18 GDPR)

Requesting that we restrict the processing of your data in certain circumstances.

Portability (Art. 20 GDPR)

Receiving your data in a structured, commonly used and machine-readable format, and transmitting it to another controller.

Objection (Art. 21 GDPR)

Objecting to the processing of your data based on legitimate interest or for marketing purposes.

Not to be subject to automated decisions (Art. 22 GDPR)

Not being subject to decisions based solely on automated processing, including profiling, that produce legal effects or significantly affect you. Robust does not carry out automated decision-making of this kind.

Withdraw consent (Art. 7.3 GDPR)

Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

 

9. HOW TO EXERCISE YOUR RIGHTS

To exercise any of the above rights, you can send a written request to:

Email: info@robust-europe.com

Postal address: ROBUST EUROPE, S.L. — Calle Espiño 120, 15405 Ferrol, A Coruña, Spain

Your request must include:

Your name and surname.

A copy of your identity document (to verify your identity and avoid impersonation).

The right you wish to exercise and, where applicable, the specific details of the request.

Robust will respond to your request within a maximum of one month from receipt, extendable by a further two months for particularly complex requests, in which case we will inform you within the initial one-month period.

The exercise of these rights is free of charge, except in the cases provided for in Art. 12.5 GDPR (manifestly unfounded or excessive requests).

 

10. COMPLAINT TO THE SUPERVISORY AUTHORITY

If you consider that the processing of your personal data is not in line with current regulations, or that your rights request has not been properly handled, you have the right to lodge a complaint with the competent supervisory authority:

Spanish Data Protection Agency (AEPD)

C/ Jorge Juan, 6 — 28001 Madrid (Spain)

Phone: +34 901 100 099 / +34 912 663 517

Website: https://www.aepd.es

However, we recommend that you contact us first to try to resolve any issue before approaching the AEPD.

 

11. SECURITY OF THE DATA

Robust has adopted the technical and organisational measures necessary to guarantee the security, integrity and confidentiality of the personal data processed, taking into account the state of the art, the costs of application, the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of natural persons, in accordance with Article 32 of the GDPR.

These measures include, among others:

Encryption of communications (HTTPS/TLS) on the Website.

Access control and authentication of authorised users.

Selection of providers with sufficient guarantees regarding data protection.

Conclusion of data processing agreements (Art. 28 GDPR) with all providers who access personal data.

Training and awareness of personnel in data protection matters.

However, no security measure can guarantee absolute protection. In the event of a security breach affecting personal data and posing a risk to the rights and freedoms of the User, Robust will notify the AEPD within a maximum of 72 hours and, where appropriate, also the affected User.

 

12. MINORS

The Website and Robust's services are aimed at persons of legal age (18 years or older). Robust does not intentionally collect personal data of minors without the consent of their legal representatives.

If Robust becomes aware of having collected data from a minor without appropriate consent, it will proceed to delete it immediately.

 

13. AMENDMENTS TO THE PRIVACY POLICY

Robust reserves the right to amend this Privacy Policy at any time to adapt it to legislative or case-law changes or to changes in the operation of the business.

Amendments will be published on the Website and will enter into force from the date of publication. In the case of substantial amendments, Robust will inform registered Users via the email address provided.

We recommend that you review this Policy periodically to be aware of the current version.

Privacy Policy prepared in accordance with Regulation (EU) 2016/679 (GDPR), Organic Law 3/2018 (LOPDGDD — Spanish Data Protection Act), Law 34/2002 (LSSI-CE) and the guidelines published by the Spanish Data Protection Agency (AEPD).