Privacy Policy

This Privacy Policy describes how GESEME 1996, S.L. (owner of the website), GESEME MÉDICOS, S.L., and GESEME ASISTENCIAL, S.L. (hereinafter, collectively “GESEME”) collect, process, and use the personal information of their clients and users. This is always carried out in accordance with our commitment to privacy and data security, and such data is collected exclusively for specific, explicit, and legitimate purposes. It may not be processed in a manner incompatible with these purposes and is handled in strict compliance with the applicable personal data protection regulations, particularly the General Data Protection Regulation (EU) 679/2016 (hereinafter GDPR) and the Spanish Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights (hereinafter LOPDGDD).

The Privacy Policy may be periodically updated to clarify or reflect new practices in managing user privacy or changes in legislation, case law, or regulatory interpretation by the Spanish Data Protection Agency or other relevant authorities. It will always be available for consultation at www.geseme.com.

Data Controller Identification:

The entities responsible for processing your data are:

GESEME 1996, S.L., GESEME MÉDICOS, S.L., and GESEME ASISTENCIAL, S.L. (“GESEME”) 
NIF: B61193124, B65659609, B65688889, respectively. 
Address: C/Aragó, 25 (08015) Barcelona 
Phone: +34 93 247 62 90 
Email: dpo@geseme.com 

How We Process Personal Data Electronically:

We process personal data in the following circumstances:

  • (i) When you visit our website;
  • (ii) When you interact, connect, or link with our website via social media tools, blogs, or other websites;
  • (iii) When you use our electronic communication services (e.g. by sending documentation, inquiries, or suggestions via email or contact forms)
  • (iv) When you send your resume to apply for a position.
  • (v) When you create a user account and access your client area;
Purposes of Data Processing:

GESEME processes personal data in accordance with the principles of the GDPR and LOPDGDD. Data is not used for purposes other than those described below: 

Client Data:

Client data is processed to deliver the contracted services and to manage tax, accounting, and administrative obligations related to the contractual relationship. 

We may also process client data based on our legitimate interest to inform them about news, services, or events via our newsletter. 

Clients may opt out of these communications at any time via the unsubscribe link in each newsletter or by contacting: dpo@geseme.com.

Website User Data:

Website browsing data is used solely for statistical and analytical purposes as outlined in our Cookie Policy. It may also be used to provide information about our business or to respond to inquiries or suggestions. 

Data we may collect includes IP address, city of access, operating system and browser, visited pages, and duration of visit.

Résumé Data:

We may process résumés sent to us via email or contact forms for the purpose of participating in current or future recruitment processes. We do not accept résumés submitted through other channels. 

If expressly authorized, we may share this data with other GESEME entities to include the candidate in other selection processes.

Contact Form Submissions:

We may process personal data sent through our website’s contact forms solely to respond to your inquiries, complaints, or suggestions. 

We will never process health data, nor use personal data for purposes beyond those stated, nor send marketing communications without the user’s prior consent or a valid legal basis. 

Mandatory fields in each form will be clearly marked. If incomplete or incorrect, we may be unable to process your inquiry and the submission will be deleted.

Emails Received:

We process personal data included in emails (e.g. documentation, inquiries, complaints) strictly to respond to the communication received, under the same limitations described above.

Social Media Interaction:

We may process data of social media users who interact with GESEME’s official profiles.

General clauses for social media

Content shared by GESEME on social media is for informational purposes only. We are not responsible for errors or damages from its use. You may update your data directly through your social platform. GESEME can only view or remove your follower status.

Platform-specific notes

Facebook

By clicking “Like,” you consent to GESEME accessing your personal data, publishing posts on your feed, and sending messages, in accordance with Facebook’s terms.

Twitter

By clicking “Follow,” you authorize GESEME to access your data, publish to your timeline, retweet your content, and send messages.

Linkedin

By clicking “Follow,” you allow GESEME to view your data, publish content to your feed, join discussions, and send messages.

Newsletter:

Website users may subscribe to our newsletter by completing the subscription form available at www.geseme.com. 

Subscriber data will be processed solely for the purpose of sending information about the activities of GESEME 1996, including updates, promotions, organized events, or discounts applicable to our products and services, based on the subscriber’s prior consent. 

Subscribers may unsubscribe from the newsletter at any time using the unsubscribe link provided at the bottom of each email or by writing to: dpo@geseme.com.

Who We Share Your Data With:

GESEME ensures the confidentiality of all personal data and will not disclose it to third parties without the user’s prior authorization and/or a valid legal basis. However, we may share data with the following recipients:

Client Companies:

GESEME may share employee data with client companies to which we provide services, in accordance with applicable labor, occupational Health & Safety, social security, and data protection laws, or as required by judicial rulings or legal obligations.

Service Providers

GESEME may outsource certain services to external providers who may access personal data. These providers may include, but are not limited to: affiliated companies, distributors, legal representatives, auditors, consultants, banks, cloud service providers, hosting servers, and other professional service providers. 

These providers act as data processors on behalf of GESEME and under a data processing agreement that limits the use of personal data solely to the purposes of the service provided and ensures compliance with applicable data protection laws.

Public Administration and Authorities:

We may disclose your data, as well as any other information we hold, to public authorities or administrative bodies when legally required to do so, and always in compliance with applicable regulations. Such disclosures are made only to fulfill legal obligations or to prevent service misuse or fraudulent activities.

International Data Transfers:

Your data may be processed in countries outside the European Union. In such cases, GESEME ensures that these countries provide an adequate and comparable level of data protection. 

If the transfer is related to the provision of services to GESEME, it will comply with Articles 44 and following of the GDPR and Article 33 of the LOPDGDD, including the signing of a data processing agreement. 

For transfers to the United States, our service providers comply with all personal data protection requirements under the EU–U.S. Privacy Shield framework. Click here for more information.

Exercising Your Rights:

You may exercise your rights of access, rectification, erasure, objection, portability, and restriction of processing, or revoke your consent when applicable, by sending a written request along with a copy of your ID or equivalent document and a description of the right you wish to exercise to: 

  • 📬 Postal mail: C/Aragó, 25 (08015) Barcelona 
  • 📧 Email: dpo@geseme.com 
Supervisory Authority:

If you believe your data protection rights have been violated, you may contact the Spanish Data Protection Agency (AEPD) at: www.aepd.es 

Data Retention:

Client and user data (including recorded calls): will be retained only as long as necessary to fulfill the purposes for which it was collected and to comply with legal obligations. Financial data will be retained in accordance with the Spanish General Tax Law (Law 58/2003). 

Inquiries and résumés: unless a longer retention period is legally justified, these will be stored for a maximum of one year from the date of receipt. 

Cookies, plugins, and browsing data: will be retained for a maximum of one year from the time of collection.

Social media data: will not be incorporated into GESEME’s databases and will be subject to the retention policies of the respective platforms.

Data Protection Officer Contact:

You may contact our Data Protection Officer (DPO) by email at: dpo@geseme.com.

User Responsibilities:

The user confirms that they are of legal age and have the knowledge and capacity to use the website www.geseme.com and its content. The user guarantees that the personal data provided in all forms is accurate and agrees to inform GESEME of any changes to ensure correct processing.

Security Measures:

GESEME has implemented the necessary security measures to ensure the safe and effective processing of personal data, preserving its confidentiality, integrity, and privacy. We comply with all regulatory security requirements and use appropriate technical means to prevent unauthorized access, alteration, loss, or misuse of data, according to the state of the art and the scope of GESEME’s control.

Applicable Regulations

If you would like more information about the regulations that govern and protect your rights, here are the key laws relevant to this policy: