TU Privacy Policy

 Publication date: 03 june 2024. 

1. Our principles and the purpose of this Privacy Policy 

Telefónica Group companies are committed to respecting the privacy of Users and the secrecy and security of personal data, in accordance with the provisions of the applicable regulations. 

Your privacy and the security of your data are our priority. It is part of our DNA and is reflected in the principles that govern our Privacy Policy. 

Transparency 

We are 100% transparent with you about the data we collect and/or process about you and explain why we use it and for what purposes. We will not process your data in an unexpected, obscure or abusive way. 

Control 

You are the only one who can control how your data is used. We provide you with the tools so that you can decide at any time how you want us to handle your data, when and how you can access and update your personal information. 

Security 

We are concerned about guaranteeing the security, secrecy and confidentiality of your personal data and information. We have carried out the necessary analyses and risk assessments in accordance with the best security and privacy standards, with the aim of adopting the most demanding and robust security measures for your data in order to prevent its loss, alteration, misuse or unauthorised access. 

These principles are set out in detail in the following sections of our Privacy Policy, which we encourage you to read carefully. In it we inform you about everything necessary for you to maintain control over your data as a user of www.tu.com de Telefónica Innovación Digital S.L.U. (hereinafter, "Tu.com"), whether as a user of the website, a user of the services provided through this website, or when you interact with us in any way in relation to Tu.com (hereinafter, the "User" or "Users").   

However, certain Tu.com services may have their own Privacy Policy, such as the digital collections accessible through colecciones.tu.com, whose Privacy Policy is: https://colecciones.tu.com/es/policy. In these cases, it is these Privacy Policies that you should read to understand how your data is handled and how you can control it on these specific Tu.com services.   

Please also note that Tu.com is an online platform of services that are provided in accordance with the General Terms and Conditions available on Tu.com and in accordance with the Specific Terms and Conditions of each service (both hereinafter referred to as the "Terms of Services").   

As we have said, through this Privacy Policy, what we intend to do is to inform you about who we are and how we will process your data when we act as a provider of the services available on Tu.com. 

2. Who is the data controller? 

  • Company name: Telefónica Innovación Digital, S.L.U. (hereinafter, "Telefónica Innovación Digital" or "we" or "us"). 
  • Tax Registration number: B83188953 
  • Registered office: Distrito Telefónica, Ronda de la Comunicación, S/N, 28050 Madrid. 

If you have any queries, requests or complaints regarding the content of this Privacy Policy and our processing of your data, you can contact us by writing to info@tu.com  

We also inform you that we have a Data Protection Delegate who oversees compliance with data protection regulations at Telefónica, and whom you can contact for any questions, doubts, suggestions and/or complaints you may have when we process your data, by writing to DPO_telefonicasa@telefonica.com 

3. What data is processed, for what purpose and why do we process the data? 

Data we process about you 

As a Tu.com User, we process various personal data about you for the purposes and for the reasons explained below. 

The personal data we process about you is as follows: 

  • Basic, identifying, personal and/or professional contact data: name and surname, personal identification number, User name, email, telephone, and any other basic or identifying information completed in the user profile of the services, when there is an access registration for a specific service. 
  • Access credentials to the services you use Tu.com and identifiers assigned to the User, when there is an access record for a specific service. 
  • Statistical data on the use and interactions of the User with Tu.com and corresponding services. 
  • Data relating to the device and/or connection with which Tu.com is accessed: the IP address and other connection metadata, as well as information that we may have obtained through the use of cookies and similar technologies (SDKs, pixels, tags, beacons, etc.). 
  • Data on the services contracted on Tu.com, as well as invoicing data, where applicable according to the service contracted. 
  • Data relating to queries, support, complaints and/or suggestions. 
  • Data provided in surveys and User tests that we may conduct, in particular, information relating to satisfaction with Tu.com and related services. 

Origin and provenance of your data 

In general, we obtain this data either directly from you, when you complete the registration form in Tu.com services, make a query, complaint or suggestion, or you contact us by any means and provide us with the required or voluntary data, or we may generate or capture them automatically during registration, during the process of creating your User account or during the use of Tu.com and its services, according to the operational functioning and/or functionalities existing at any given time.  

In this case, all the information you provide as a User must be truthful and accurate. For these purposes, the User guarantees the authenticity of all data provided as a result of filling in the corresponding forms. The User shall be solely responsible for any false or inaccurate statements made, and for any damage caused to Telefónica or third parties as a result of the information provided. 

In the event of the provision of false data or data that does not correspond to the account holder, Telefónica reserves the right to cancel the User's account, suspend the contracted services and/or adopt the measures it deems appropriate for the best defense of its interests and rights, or those of affected third parties that may be affected as a result of the above. 

Telefónica reserves the right to verify the information provided by the User by any means that may be appropriate for the purposes of control and/or verification, depending on the state of the art at any given time and what is most appropriate for the protection of the interests and rights of the parties involved. 

If the User provides personal data of third parties through the functionalities of the Tu.com which, where applicable, are available in the services, said User shall be obliged to inform them of said processing as detailed in this Privacy Policy and that their data will be provided to Telefónica for these purposes, and shall be exclusively and fully liable in the event of any breach in this regard, and Telefónica shall be exempt from any liability in this regard.   

Purposes we pursue and reasons we have for processing your data 

The purposes for which we process your data as a User are as follows: 

  • Provision of the service and all available functionalities, operation, administration, support and maintenance of the tu.com website and the corresponding services: based on the execution of the Terms of Services applicable to those services that you use, we will process your data for the purpose of providing you with the corresponding service, allowing you to enjoy all the functionalities available at all times, operate and maintain it so that the service functions correctly and securely, or, where appropriate, withdraw or block your access to the service, which includes allowing us to check the requirements demanded of the user, their compliance with the Terms of Services, proceed with or facilitate the User's registration and, where appropriate, the updating of their data, send them communications by any means provided by them, or, where appropriate, the updating of their data, send them communications by any means provided by them, where appropriate, updating their data, sending them communications by any means provided relating to the service and the functionalities of the services (for example, communications about the launch of new functionalities or about the processes of registration and verification of the User's identity, among others), their access to and use of the services at any time, among other similar purposes in execution and compliance with all the points included in the Terms of Services, while they maintain their status as Users and do not request cancellation. 
  • Conducting surveys, user testing and other research activities: based on our legitimate interest to maintain and improve the quality of service and user experience of the Tu.com services, we may contact you to collect information regarding your satisfaction or opinion in relation to the service provided and its functionalities, provided that you have not objected to such legitimate interest.  
  • Maintenance of the activity and security, detection and prevention of information security breaches and possible breaches: based on our legitimate interest, as the owner and managers of Tu.com, in ensuring the availability and security of Tu.com for all users, and in accordance with the Terms of Service, legal notices and other relevant notices of use, as well as with the provisions of our Cookies Policy and the cybersecurity regulations applicable to Telefónica, we will process your data in order to maintain and manage the security of Tu.com, protect it against security incidents and malicious attacks that it may suffer and, in general, to enable free and continuous access to Tu.com in a secure manner by all Users. 
  • Internal management and response to claims, demands, complaints and litigation related to Tu.com: based on our legitimate interest associated with the right to effective judicial protection that protects us, we may process your data to manage, respond to and intervene as an interested party or similar in administrative or judicial proceedings, when they, in any way, are related to you or refer to you in the corresponding condition. 
  • Management of invoicing, accounting and taxation of Tu.com's collection services: based on compliance with the legal obligations imposed on us in terms of invoicing and accounting, we are obliged to process your data for the correct management of invoicing, accounting and taxation, which includes collecting or declaring your data in the invoices, in the accounting books that we keep or in the declarations that for tax purposes may be required by the applicable regulations in this area. 
  • Retention of data on transactions, identification of Users and other procedures derived from the regulations on the prevention of money laundering and terrorist financing: we have a legitimate interest in acting with due diligence and proactivity in compliance with the aforementioned regulations, so, depending on the service, we may process your data for the purposes of being able to identify you properly and keep them together with the history of the actions carried out, always with the aim of, where appropriate, being able to make this information available to the competent authorities that may require it.  
  • Prevention and investigation of fraud and/or illegal activities: based on our legitimate interest in preventing and investigating fraud within Tu.com, we may process personal data of users for the purpose of setting up alerts that indicate potential fraud and/or illegal activity for the purpose of further investigation. During this investigation process, we may process more personal data provided that it allows us to carry out a better investigation and assessment of the specific case, in order to make decisions regarding the establishment and implementation of control measures and mitigation of the risks detected at any given time.   
  • Compliance with applicable laws and regulations and response to requests and official requests made by the authorities: in general, as any information society service provider and data controller, various legal obligations apply to us, including obligations relating to consumer affairs, data protection and security, digital services and markets, as well as obligations to cooperate with the competent authorities, including law enforcement agencies. Based on the foregoing, we may need to process your data in order to comply with such obligations, for example, to respond to exercises of data protection rights that we receive, or to respond to legitimate requests or requests notified to us that require, for example, the provision of information about you. 
  • Attention and response to contracting requests, doubts, queries, suggestions and any other type of contact received: based on our legitimate interest in managing and providing an effective response to the request or other type of contact made by a user, as well as to the extent necessary for the execution of pre-contractual measures at the user's request, aimed at the acceptance of the Terms of Services or the signing of an agreement with Telefónica Innovación Digital to contract the services of Tu.com services, we may process the data of the person who contacts us in order to provide them with an effective response based on the contact they have made, deal with the suggestion to correct or improve the service in the sense proposed or, where appropriate, provide information on the commercial conditions of the services and enter into a contractual relationship for this purpose. 
  • Statistical analysis: based on our legitimate interest to measure the quality of Tu.com services, as well as to understand how it is used by Users, we may perform appropriate statistical analysis on usage data of the services in order to: (1) measure the quality of service and, in case of degradation, take the necessary measures to prevent and/or remedy such degradation; and (2) make better business decisions regarding the future evolution of Tu.com services or other products or services, as well as to make evolutionary improvements or corrections, if any, that need to be made to provide an adequate experience.   
  • Personalization and profiling: based on the legitimate interest of both Telefónica Innovación Digital and Tu.com Users in enjoying relevant services and experiences and receiving communications of interest to them, we may process your data to (1) personalize such services or experiences, as well as to (2) segment and personalize communications with you. For example, some functionalities may work differently and/or have particular features depending on the device you use. Similarly, if some services are only available to certain Users, we may target communications to them. Also based on the aforementioned legitimate interest, we may process your personal data for basic profiling in order to infer your preferences or interests in relation to current and future Tu.com services or experiences, and to better personalize your experiences and target communications. In general, the data that we may process for this purpose will be: basic and identifying data, interactions with Tu.com services, data from your devices and the purchases you make.  
  • Sending newsletters and other communications about our products and services: if you request us to do so and have subscribed to our newsletter, we will send you our newsletter at the appropriate intervals or we will contact you via the contact details you have provided us with in order to send you information about our Tu.com products and services. Likewise, in the event that you have contracted any of our Tu.com products and services, we may also send you communications about our own products and services similar to those contracted, on the basis of our legitimate interest in maintaining commercial contact and disseminating our products and services. 
  • Sending third party advertising: in the event that you expressly consent, through the corresponding form available in the subscription section of the services, we may send you advertising, offers, promotions and, in general, commercial communications from the partners of Tu.com with which Telefónica Innovación Digital has signed agreements for this purpose ("Tu.com Partners").   
  • Transfer of your data to Telefónica Group companies for advertising: if you expressly consent, by means of the corresponding form available in the subscription section of the services, we will share your contact data, as well as data relating to the Tu.com services that you use or have contracted, with Telefónica Group companies so that they can send you advertising about their products and services by any means.  
  • Transfer of your data to Telefónica Group companies for profiling and analytical purposes: if you expressly consent, through the corresponding form available in the subscription section of the services, we will share your basic and identifying data, interactions with Tu.com services, data from your devices and the contracts you make, with Telefónica Group companies so that they can combine this information with other information they already process about you, with the aim of creating commercial profiles based on your interests and preferences in order to: (1) segment communications and personalise the communications they send you, as well as (2) personalise the services and experiences they provide or offer you. These Telefónica Group companies may also process such data for statistical analysis and to obtain aggregated business intelligence.    
  • Anonymisation: we may anonymize your data collected and processed for the legitimate purposes set out above, such processing in relation to the anonymization process being considered compatible with each of the purposes for which it was originally collected and processed. The anonymization process will involve a whole set of technical and organizational measures to prevent the direct and indirect re-identification of your personal data.    

4. How long is the data retained? 

In general, we will retain your data for the time necessary to fulfil each purpose described in each processing activity and to determine any liability that may arise from that purpose and/or processing. 

 

Personal data associated with reported processing purposes 

 

 

Time limits or criteria for the retention of your personal data 

 

Provision of the service and all available functionalities, operation, administration, support and maintenance of Tu.com and related services. 

The data will be kept for the essential and necessary time to enable you to browse and use our website and services correctly as long as you do not unsubscribe as a User. 

Conducting surveys, user tests and other research activities. 

In general, we will be able to process your personal data for this purpose as long as you have not objected to the processing on the grounds of Telefónica Innovación Digital's legitimate interest. However, even if you have not objected to this processing, we will only keep the answers you give to surveys and user tests for a maximum period of 24 months after they have been carried out. 

Maintaining the activity and security of Tu.com, avoiding information security breaches and potential breaches. 

 

We will process your personal data for this purpose for as long as you have not objected to the processing on the basis of Telefónica's legitimate interests and provided that such objection is satisfied in view of the circumstances that you have communicated. However, even if you have not objected to this processing, we will only keep your data for this purpose for a maximum period of 48 months from the date of collection. 

Internal management and response to claims, demands, complaints and litigation related to Tu.com. 

 

 

 

 

For the time necessary for the possible purging of liabilities arising during the processing of the data, always in accordance with the applicable regulations, and may not be used for purposes other than these. 

Management of Tu.com's invoicing, accounting and taxation. 

 

 

As long as we are obliged to retain them in compliance with a tax obligation (general retention for 4 years, without prejudice to the provisions of the applicable tax legislation) and commercial obligation (retention for 6 years). 

Retention of data on transactions, identification of Users and other procedures derived from the regulations on the prevention of money laundering and the financing of terrorism. 

 

 

 

 

 

We will process your personal data for this purpose for as long as you have not objected to the processing on the basis of Telefónica's legitimate interests and provided that such objection is satisfied in view of the circumstances that you have communicated. However, even if you have not objected to this processing, we will only keep your data for this purpose for a maximum period of 48 months from the date of collection. 

Prevention and investigation of fraud and/or illegal activities. 

 

We will process your personal data for this purpose as long as you have not objected to the processing on the grounds of the legitimate interest of Telefónica Innovación Digital and as long as such objection is met in view of the circumstances that you communicate. However, even if you have not objected to this processing, we will only keep your data for this purpose for a maximum period of 48 months from its collection. 

Compliance with applicable regulations and attention to requirements and official letters from the authorities. 

 

For as long as we are obliged to keep them in compliance with a legal obligation. 

Attention and response to recruitment requests, doubts, queries, suggestions and any other type of contact received. 

 

 

For the time necessary to correctly deal with your requests and/or specific requests according to each case. If these requests consist of the execution, at your request, of pre-contractual measures or the signing of a contract with Telefónica Innovación Digital, your data will be kept for the time necessary to give due satisfaction to such pre-contractual measures or contractual relationship between the parties. 

Statistical analysis of Tu.com 

 

We will process your personal data for this purpose for as long as you have not objected to the processing on the basis of Telefónica's legitimate interests and provided that such objection is satisfied in view of the circumstances that you have communicated. However, even if you have not objected to this processing, we will only keep your data for this purpose for a maximum period of 48 months from the date of collection. 

Personalization and 

profiling 

 

We will process your personal data for this purpose for as long as you have not objected to the processing on the basis of Telefónica's legitimate interests and provided that such objection is satisfied in view of the circumstances that you have communicated. However, even if you have not objected to this processing, we will only keep your data for this purpose for a maximum period of 24 months from the date of collection. 

Sending newsletters and other communications about our products and services. 

 

We will process your personal data for this purpose for as long as (1) you have not objected to the processing on the grounds of Telefónica's legitimate interest and provided that such objection is considered in accordance with the circumstances that you communicate; and (2) with respect to the newsletter, until you unsubscribe from the newsletter. 

Third-party advertising 

 

We will process your personal data for these purposes when you expressly consent to this processing and as long as you have not withdrawn your consent. 

Transfer of your data to Telefónica Group companies for advertising purposes. 

Transfer of your data to Telefónica Group companies for profiling and analysis purposes. 

Anonymization 

 

We will process your personal data for the time strictly necessary to carry out the anonymization process. Once anonymized, this data will no longer be personal data. 

 

Once the aforementioned retention periods have expired, we will block your personal data during the period of limitation of legal actions and, once this period has expired, we will proceed to its definitive deletion in accordance with the applicable regulations, and/or its secure anonymization by Telefónica Innovación Digital.   

 5. Who is the recipient of the data, and are there any international transfers of data? 

Third parties who may access, receive and process your data 

In general, in order to provide the service and carry out the processing purposes described above, we may make use of authorized subcontractors acting on behalf of and in the name of Telefónica, as processors (e.g. internet service and software development providers, data hosting and technical support providers, e-mail providers, general service providers and providers of digital or physical security services, etc.) and contractually subject to our instructions, only to the extent strictly necessary for the provision of the services contracted with them and only for the period of time strictly necessary for that purpose. 

We will share your data with Telefónica Group companies when you have consented to the transfer of your data to them. For these purposes, the Telefónica Group companies to which we may transfer your data are:  

  • Telefónica, S.A.  
  • The following Operators of the Telefónica Group: Telefónica de España, S.A.; Telefónica Móviles España; Telefónica Soluciones de Informática y Comunicaciones de España, S.A.U, Telefónica Brasil, Ltda., Telefónica Germany GmbH & Co. OHG. 

In addition, if there is a legal obligation to do so, we may communicate your data to the competent public administrations in accordance with said obligation or legal requirement and, where appropriate, to other bodies such as the State Security Forces and Corps and judicial bodies. 

International transfers of your data 

Finally, you should be aware that when authorized subcontractors acting on behalf of Telefónica or when the aforementioned potential recipients are located or process your data outside the European Economic Area, we will be carrying out an international transfer of your data, in accordance with the provisions of data protection regulations.  

In general, we avoid making international transfers and your data are processed within the European Economic Area or in countries with an adequate level of data protection in accordance with the Applicable Data Protection Regulation, but sometimes we cannot avoid it or it is strictly necessary for you to benefit from the use of the Tu.com services and functionalities described in the Terms of Services. In addition, in the event that we do transfer your data internationally, we assure you that we will take the necessary organizational, technical and contractual measures to ensure the protection and security of your data, such as, for example, signing Binding Corporate Rules with the authorized subcontractor or third party transferee, Certifications and Standard Contractual Clauses approved by the competent authorities, as well as conducting impact assessments on the international transfer in question to assess the risk and adopt mitigation measures, encryption of data in transit or at rest, pseudonymization of the data subject to the international transfer, and/or other measures in addition or complementary to the above.   

  1. What rights do you have as a data subject? 

Your rights 

As a User, data protection regulations grant you certain rights over your data which, depending on how they apply, you may exercise against Telefónica. Below you will find details of these rights and how you can exercise them.  

We also inform you that on the website of the Spanish Data Protection Agency (www.aepd.es) you can find more information on the characteristics of these rights and download templates to exercise each of them, although it is not necessary to use any template to exercise a right before us. 

Right to withdraw consent 

It is your right to withdraw your consent to the processing of your data for the purposes that are legitimate on that basis, at any time and in an easy way.  

Right of access 

It is your right to ask us for details of the data we hold about you and how we process it, and to obtain a copy of it.  

Right of rectification 

It is your right to obtain the rectification of your inaccurate or erroneous data, as well as to complete incomplete data.  

Right of suppression 

It is your right to request deletion or suppression of your data and information in certain circumstances. However, please note that there are certain occasions when we are legally entitled to continue to retain and process your data, for example, to comply with a legal obligation to retain data.   

Right of limitation 

This is your right to restrict or limit the processing of your data in certain circumstances. For example, if you apply to have your data erased, but, instead of erasure, you would prefer that we block it and process it only for record-keeping purposes because you will need it later to make a complaint. Again, please note that there may be times when we are legally entitled to refuse your request for restriction.  

Right to object 

This is your right to object to our processing of your data for a specific purpose, in certain circumstances provided for by law and related to your personal situation. 

Right to portability 

It is your right to ask us to receive your personal data in a structured, commonly used, machine-readable and interoperable format and to transmit it to another data controller, provided that we process your data by automated means.   

Right not to be subject to automated individual decisions 

It is your right to ask us not to subject you, in certain circumstances, to a decision based solely on automated processing of your data, including profiling, which produces legal effects concerning you or similarly significantly affects you. 

Means of exercising them and deadlines for response 

In general, you may exercise these rights at any time and free of charge by contacting Telefónica at DPO_telefonicasa@telefonica.com 

Similarly, as a general rule, mechanisms for the automated cancellation of communications and other options for withdrawal of consent and opposition will be made available to the User. 

To this end, it is important to bear in mind that, when you exercise a right, in some cases you must clearly specify which right you are exercising and provide a copy of a document proving your identity. It should also be noted that some of the data processing is carried out by Telefónica in a way that does not require the direct identification of Users, without Telefónica being obliged to obtain and/or process additional information to verify said User for the purposes of allowing them to exercise their data protection rights.  

In the event that a User exercises a data protection right and, due to the reasons indicated, Telefónica is not in a position to identify the User in order to deal with the request, it will inform the User to that effect if possible. Said request will be suspended until the User provides additional information that allows him/her to be identified.    

Any exercise of rights will be answered within a maximum period of one month, which may be extended by two months if we reasonably require it, taking into account the complexity of the request and the number of requests. 

Finally, in the event that you do not agree with the way in which your data is handled by Telefónica, you have the right to lodge a complaint with the national supervisory authority, by contacting the Spanish Data Protection Agency (AEPD), whose contact details are as follows: 

Spanish Data Protection Agency 
C/ Jorge Juan, 6 - 28001 Madrid 

www.aepd.es 

We recommend that before filing any complaint or claim with the Spanish Data Protection Agency (AEPD), you contact our Data Protection Officer in order to analyse the specific situation and try, if necessary, to find an effective and amicable solution. Apart from the above, if you wish, you can also refer to the AEPD. 

6. Further processing of data and changes to the Privacy Policy 

Telefónica reserves the right to update this Privacy Policy at any time. Any such update will be made public by Telefónica, in any case, with the legally required notice prior to its entry into force.  

Furthermore, it will be communicated directly to the User in the event that it affects his or her rights or freedoms or when, for example, the inclusion of a new processing activity requires the User's consent or modifies the scope of the legitimate interest that enables the processing.