More information
We care about your privacy
At MUTUALIDAD GENERAL DE LA ABOGACÍA, MUTUALIDAD DE PREVISIÓN SOCIAL A PRIMA FIJA (hereinafter collectively and indistinctly referred to as “Mutualidad”, “we”, “our” or “us”), we consider the privacy of individuals to be important, both for visitors to our website https://www.mutualidad.com (hereinafter, the “website”) and for any other affected parties who provide us with information through it, whose data are processed by Mutualidad as part of the provision of services (hereinafter and jointly, “you” or the “user”, and in the plural, “you all” or the “users”). In this regard, Mutualidad undertakes to process your data in accordance with the applicable personal data protection regulations in force at all times. Specifically, Mutualidad will comply with the provisions of: REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC; Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights; and any other related regulations in force at any given time.
On this basis, Mutualidad informs you of its Privacy Policy, with the aim of making users aware of how their data are processed, as well as of the fundamental principles on personal data protection that it applies. Nevertheless, certain services that may be offered on the website in the future may contain specific terms of use with particular provisions regarding personal data protection, which shall prevail over this Privacy Policy.
In connection with the above, we encourage all users to read this Privacy Policy carefully in order to understand the rules and practices we have established to protect personal data and to better understand our relationships with third parties who may have access to such data.
In any case, the user is solely responsible for the information provided on the website, and if in the future Mutualidad wishes to use such information for purposes other than those mentioned, we will inform you of these new purposes and request your consent, where required.
Who is the data controller?
Contact details of the data controller: MUTUALIDAD GENERAL DE LA ABOGACÍA, MUTUALIDAD DE PREVISIÓN SOCIAL A PRIMA FIJA, with Tax ID No. V‑28/024149, registered address C/ Francisco Silvela, 106 – 28002 Madrid (Spain), and contact email buzon@mutualidad.com.
Data Protection Officer (DPO) contact details: proteccion.datos@mutualidad.com
For what purpose do we process your personal data and on what lawful basis?
For the purposes of this Privacy Policy, “personal data” means any information that identifies you or may be used to identify you, such as your name, address, telephone number or email address.
The personal data provided by users while browsing may be processed for the following purposes:
| Purpose | Lawful basis |
| To respond to any queries, requests or requests for information that users may submit, and to carry out any subsequent follow-up. | Consent given when sending us your query (Article 6(1)(a) GDPR) |
| In the online contracting process, the information will be used to identify the applicant unequivocally, assess the viability of the insurance contract based on the information provided and, where appropriate, manage its signature and, subsequently, the management of the contracted insurance. We remind you that all our contracts contain information on the processing of personal data linked to contract management. | Performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (Article 6(1)(b) GDPR) |
| If the user provides us with their CV, the data will be used to manage recruitment processes, analysing the suitability of the candidate who is the data subject for a specific job position and including them as a participant in a selection process for possible recruitment. | Performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (Article 6(1)(b) GDPR) |
| If the user provides us with their CV, the data will be used to manage recruitment processes, analysing the suitability of the candidate who is the data subject for a specific job position and including them as a participant in a selection process for possible recruitment. | Consent given when sending us your CV (Article 6(1)(a) GDPR) |
| Acceptance of promotions or participation in prize draws or competitions will require the processing of data for the purpose of managing participation, applying the promotion or delivering a prize. Prize draws or competitions will have their own legal terms and will be governed by the provisions set out therein. | Performance of a contract where the promotion is linked to it (Article 6(1)(b) GDPR) |
| Acceptance of promotions or participation in prize draws or competitions will require the processing of data for the purpose of managing participation, applying the promotion or delivering a prize. Prize draws or competitions will have their own legal terms and will be governed by the provisions set out therein. | Consent given when participating in a prize draw or requesting a promotion (Article 6(1)(a) GDPR) |
| To personalise and improve the Website’s tools and functionalities, as well as to ensure its technical operation. | Legitimate interest, consisting of analysing data for statistical purposes and system monitoring, and ensuring service continuity (Article 6(1)(f) GDPR) |
| Where the user has given consent, to keep them informed by sending the Mutualidad newsletter or other communications by email and/or other electronic means, the content of which will mainly relate to our services, activities, projects, updates and new website features, including information on collaboration agreements entered into by Mutualidad and on the products and services offered as a result of them, as well as information on third-party activities, products or services, and relevant information on activities promoted by Fundación Mutualidad or other companies of the Mutualidad Group. | Consent given to authorise the sending of commercial communications (Article 6(1)(a) GDPR) |
| To target users through social media for advertising purposes in order to promote services related to those used and similar to those contracted. For this purpose, provided that the user has not previously objected to receiving commercial communications, Mutualidad may use their email address for list-based targeting on social media. Mutualidad will upload pre-existing lists of personal data (such as email addresses) of its Users who have not objected to receiving commercial communications so that the social media provider can compare them with the information on its platform. The social media provider will compare such data with the data of users already held on its platform, and matching users will be included in or excluded from Mutualidad’s target audience (that is, the group of people to whom the advertisement will be shown on the social media platform); Mutualidad will not, under any circumstances, have access to the personal information and data of users on that social network. | Mutualidad’s legitimate interest, namely its economic interest in obtaining greater advertising reach for its products and services through targeting on social media (Article 6(1)(f) GDPR). |
| We may use your data to send surveys or carry out other actions aimed at monitoring quality and assessing your level of satisfaction with your experience. | Legitimate interest, consisting of managing and improving the actions carried out by Mutualidad (Article 6(1)(f) GDPR) |
| To comply with our legal obligations. | Compliance with legal obligations (Article 6(1)(c) GDPR) |
When the user is a Mutualista and accesses their personal area through the website, we inform you that the data provided or collected may also be used for the following purposes:
| Purpose | Lawful basis |
| To enable the use or provision of the services available in the personal area, following user identification through registration. The private area allows you to consult details of the contracted products and their cover, as well as to contact the entity to request the contracting of new products, make extraordinary contributions to products already contracted, modify them, etc. | Consent given when registering in your personal area or making changes to your data (Article 6(1)(a) GDPR) |
| To enable the use or provision of the services available in the personal area, following user identification through registration. The private area allows you to consult details of the contracted products and their cover, as well as to contact the entity to request the contracting of new products, make extraordinary contributions to products already contracted, modify them, etc. | Performance of a contract to which the data subject is party where the customer contracts or manages the contracted products (Article 6(1)(b) GDPR) |
| To offer the micro-savings service, which allows users to link bank accounts or cards to a specific project and which involves: • Setting up and customising financial piggy banks • Setting savings rules • Managing periodic contributions and savings through rounding up purchases made • Applying gamification rules; penalties, savings with the favourite team • Allowing the user to make solidarity contributions • Displaying information relating to progress towards goals. |
Compliance with legal obligations (Article 6(1)(c) GDPR) |
| To offer the micro-savings service, which allows users to link bank accounts or cards to a specific project and which involves: • Setting up and customising financial piggy banks • Setting savings rules • Managing periodic contributions and savings through rounding up purchases made • Applying gamification rules; penalties, savings with the favourite team • Allowing the user to make solidarity contributions • Displaying information relating to progress towards goals. |
Performance of a contract to which the data subject is party where the customer contracts or manages the micro-savings service (Article 6(1)(b) GDPR) |
| To offer the financial planning service “My financial health”, which allows users to link bank accounts to a specific project and which involves: • Accessing information on the current financial situation with details of income and expenditure from the linked bank accounts • Analysing the information and applying algorithms to determine how long the user could live without income based on savings (safety net) • Analysing the information and applying algorithms to determine the user’s savings capacity according to their current level of income and expenditure • Generating reports on the financial situation, safety net and savings capacity • Offering financial advice based on the information obtained • Linking the data from “My financial health” with Mutualidad products that, based on the information obtained, may be of interest. |
Performance of a contract to which the data subject is party where the customer contracts or manages the financial planning service “My financial health” (Article 6(1)(b) GDPR) |
| To offer the financial planning service “My financial health”, which allows users to link bank accounts to a specific project and which involves: • Accessing information on the current financial situation with details of income and expenditure from the linked bank accounts • Analysing the information and applying algorithms to determine how long the user could live without income based on savings (safety net) • Analysing the information and applying algorithms to determine the user’s savings capacity according to their current level of income and expenditure • Generating reports on the financial situation, safety net and savings capacity • Offering financial advice based on the information obtained • Linking the data from “My financial health” with Mutualidad products that, based on the information obtained, may be of interest. |
Compliance with legal obligations (Article 6(1)(c) GDPR) |
| Where a contracting process or management activity is subject to Law 10/2010 on the prevention of money laundering, the information will be processed to verify the existence of risks and comply with the applicable due diligence obligations, as well as other obligations linked to the law. | Compliance with legal obligations (Article 6(1)(c) GDPR) |
| To respond to any queries or requests for information made by customers and to carry out any subsequent follow-up. | Performance of a contract to which the data subject is party or in order to comply with pre-contractual measures (Article 6(1)(b) GDPR) |
| To allow the user to directly manage the consents given in relation to profiling and commercial communications, as well as to access and modify their personal data. | Consent given when making changes to your data (Article 6(1)(a) GDPR) |
| To keep the user informed, through the information contained on the website itself, about Mutualidad’s products and services, activities, and updates and new features of the personal area. | Legitimate interest in keeping Mutualidad customers informed (Article 6(1)(f) GDPR) |
Additionally, when using the telephone contact channel, you should be aware that the data collected through the recording of calls to the telephone assistance numbers enabled for this purpose, or calls that may be made to you by Mutualidad or by any company authorised by it, may be used for the purpose of:
| Purpose | Lawful basis |
| To evidence the contracting. | Performance of a contract to which the data subject is party or in order to comply with pre-contractual measures (Article 6(1)(b) GDPR) |
| To improve the quality of technical and commercial support, handle possible complaints, and verify user satisfaction. | Legitimate interest, consisting of managing and improving the actions carried out by Mutualidad (Article 6(1)(f) GDPR) |
How long do we retain your personal data?
Mutualidad processes your personal data for the period necessary to fulfil the purposes set out in this Privacy Policy, as well as to retain your personal information in compliance with the provisions of the applicable laws and regulations.
The criteria we apply in this regard are determined by:
- The purpose of the data collected and the fulfilment of that purpose.
- Mandatory retention periods in accordance with contractual and regulatory requirements.
- Retention periods longer than those required by law where the conditions for extending the period are met.
At present, Mutualistas’ data will be retained for the maximum period established by the Anti-Money Laundering Law. In the event that the contract is not formalised, the data provided will be kept blocked for the period legally required to deal with any possible liabilities arising from the processing.
Please note that, once the data has been erased, it may remain blocked for the defence against possible claims during the statutory limitation period for legal actions.
Recipients
Depending on the purposes for which the personal information is collected, the following persons and entities may have access to such information, as applicable:
- Authorised personnel of Mutualidad or of the entities within its corporate group who, within the framework of the internal organisation and the provision of services linked to the contractual relationship, act on behalf of Mutualidad and under its instructions, as well as third-party providers acting as data processors, with whom the corresponding agreements have been entered into in accordance with Article 28 of the GDPR.
- Public administrations, regulatory authorities or other third parties in accordance with applicable laws.
- Other companies forming part of the Mutualidad Group, to the extent that such disclosure of data is provided for or authorised by the applicable regulations.
- Third parties providing services related to the insurance contract: reinsurers and loss adjusters.
- Third parties (service providers that process information as data processors, under Mutualidad’s instructions). All this only after taking the necessary measures to ensure that we can share such information in compliance with applicable data protection laws.
- Confirma Sistemas de Información, S.L., with tax ID no. B-86303757 and registered address at Avda. de la Industria, 18, Tres Cantos (28760) Madrid, for the purpose of detecting irregularities, preventing fraud and complying with our legal obligations regarding the prevention of money laundering and terrorist financing.
- Within the framework of the micro-savings and financial planning services, personal data related to linked bank accounts and cards may be sent and received through the provider MORPHEUS AIOLOS S.L. (Afterbanks). The services of this provider must be expressly authorised by the user.
We will not sell or disclose to third parties any information or personal data that you have provided on our website and that may identify you directly or indirectly.
What are your rights regarding your personal data?
Users may request the following rights:
-
Right to request access to personal data: you may ask Mutualidad whether it is processing your data, for what purpose and from what source and, if so, access such data.
-
Right to request rectification if the data is inaccurate, or to complete any data we hold that is incomplete.
-
Right to request the erasure of your data.
-
Right to request restriction of processing: in this case, we will only retain the data for the exercise or defence of legal claims.
-
Right to object to processing: Mutualidad will stop processing the personal data, except where it must continue to be processed for legitimate reasons or for the exercise or defence of possible legal claims.
-
Right to data portability: if the user wants their data to be processed by another controller, Mutualidad will facilitate the transfer of their data to the new controller.
-
Right not to be subject to a decision based solely on automated processing of your personal data.
If you have given consent for a specific purpose, you may withdraw it at any time, without this affecting the lawfulness of the processing based on consent before its withdrawal.
You may exercise the above rights by emailing proteccion.datos@mutualidad.com or by post to C/ Francisco Silvela, 106-28002, Madrid (Spain).
In any event, when the user exercises their right to erasure, all personal data linked to their account, as well as the information and content included in their profile, will be deleted.
You may use the templates and forms relating to the above rights by visiting the official website of the Spanish Data Protection Agency..
Complaint to the Supervisory Authority: If you consider that Mutualidad is processing your personal data improperly, you may lodge a complaint with the Spanish Data Protection Agency.
How have we obtained your personal data?
You provide us with your personal data through the forms available on our website, when applying to take out one of our products, or it is obtained from Confirma Sistemas de Información, S.L. when consulted in order to comply with our obligations under anti-money laundering regulations and to detect irregularities so as to prevent and avoid possible attempts at fraud.
If you have linked your banking data in order to use the micro-savings and/or financial planning service, the provider MORPHEUS AIOLOS S.L. (Afterbanks) will provide us with the data necessary for the provision of the service.
International transfer
Mutualidad, through its providers, carries out transfers of personal data outside the European Economic Area (EEA). Such transfers are carried out in compliance with the applicable data protection laws. In particular, the providers with whom Mutualidad works comply with one of the following requirements: i) the data processing is carried out in a territory that guarantees an adequate level of protection according to the European Commission; ii) the provider has adopted binding corporate rules; or iii) a standard contractual clauses agreement has been entered into with the provider. Regardless of where your personal data is collected or processed, Mutualidad ensures and guarantees that service providers maintain appropriate technical and organisational security measures to protect information about you.
Direct marketing
We will not use users’ personal data for direct marketing purposes without an appropriate lawful basis.
If at any time you decide that you no longer wish to receive commercial or promotional information from Mutualidad by any means, including through social media, you may, free of charge and without having to provide any justification, unsubscribe from direct marketing campaigns and object to the future processing of your personal data for such purposes by sending us an email at proteccion.datos@mutualidad.com or by using the unsubscribe procedure provided in any promotional message you receive from Mutualidad.
Please note that, even if you decide not to subscribe or you unsubscribe from promotional emails or newsletters, we may still need to contact you regarding important non-commercial information, such as troubleshooting, the detection and prevention of errors or, in general, in order to comply with the Legal Notice and/or the Website Terms and Conditions, as well as any communications necessary to comply with our legal obligations as a mutual association towards our members.
Automated decision-making
We will not use automated decision-making processes, including profiling, unless we have an appropriate lawful basis that allows us to do so.
In the context of entering into a contract, it is envisaged that the data will be cross-checked automatically against the database of Confirma Sistemas de Información, S.L.
Profiling will be carried out using the basic data provided and the data collected while browsing when the website is used. Data collection will be carried out in an automated manner and the processing will involve human intervention. Under no circumstances will sensitive data be used for profiling. The authorisation granted has no effect on the cookie settings that the user may configure while browsing the website, and these will be respected at all times.
The sole purpose of profiling is the personalisation of commercial communications, and it will have no other effect on your relationship with us. In relation to commercial communications, we remind you that all of them include the option to unsubscribe, so at any time, if you change your mind, you may exercise your right to object by using this option, in which case the profiling will cease to have effect.
How do we protect your personal data?
Mutualidad maintains security levels for the protection of your data appropriate to the different personal data processing activities it carries out and to the sensitivity of such data, and has established all technical means within its reach to prevent the loss, misuse, alteration, unauthorised access to and theft of the data that the user provides through the website.
In any event, Mutualidad will adopt appropriate technical and organisational measures, both when designing the data processing system and at the time of the processing itself, in order to preserve security and prevent unauthorised processing.
Confidentiality
The professionals working at Mutualidad who are involved in any way in the services provided to the user are committed not to disclose or make use of the information to which they have had access. In all cases, the information provided by the user will be considered confidential and may not be used for purposes other than those communicated. In this regard, we undertake not to disclose or reveal information, except where the user’s authorisation has been obtained or where disclosure is required under the applicable regulations.
Social Media
Mutualidad is present on some of the main social media platforms on the Internet, and acts as the data controller in relation to the data published by Mutualidad on them. Specifically, these are the following:
- Facebook https://www.facebook.com/MutualidadEs
- X https://x.com/Mutualidad_es
- YouTube https://www.youtube.com/@Mutualidad_es
- Instagram https://www.instagram.com/Mutualidad_es
- LinkedIn https://www.linkedin.com/company/mutualidad/
Mutualidad will process the data on each social media platform in accordance with the rules established for that purpose by each platform. Therefore, unless Mutualidad states otherwise, we may inform our followers on the relevant social media platform about our activities, events and other related matters, including customer support, through the channels made available by the platform for that purpose.
Special categories of personal data
We will not collect or process any particularly sensitive personal data or any personal data included within the special categories of personal data of users, unless we are legally authorised to do so or have the explicit consent of the data subject. Special categories of personal data refer to information relating to race or ethnic origin, political opinions, religious or philosophical beliefs or other beliefs of a similar nature, trade union membership, genetic data, biometric data for the sole purpose of identifying a natural person, data concerning health, sex life or sexual orientation.
Policy on children’s use
This website is not designed for or directed at persons under eighteen (18) years of age without the authorisation of their parents or legal guardian. In this regard, we do not knowingly collect information from such persons. In any event, if parents or legal representatives consider that their children have sent us personal data without their consent, please contact us by writing to proteccion.datos@mutualidad.com
Links to other websites
Mutualidad websites contain links to other websites that we consider may be potentially useful and informative for you. However, please note that we do not endorse or recommend the content or services of such websites, nor are we responsible for their privacy policies. We recommend that you take note of and read the privacy policies of all the websites you visit. Please remember that the provisions of this Privacy Policy apply only to the data collected and/or processed by Mutualidad.
Changes to and integrity of our Privacy Policy
We will only use your personal data as set out in the Privacy Policy in force at the time we collect your personal data. Mutualidad reserves the right to modify this Privacy Policy at any time by publishing such changes on our website, and we therefore recommend that you review it each time you access the website. If at any time we decide to use personal data in a manner different from that stated at the time of its collection, you will be informed appropriately. And, where necessary, at that time you will be given the option to authorise other uses or disclosures of the personal data that you provided to us before the modification of our Privacy Policy.
If any clause of this Privacy Policy is annulled or considered null and void, the remaining provisions shall not be affected and shall retain their full validity and effectiveness, in accordance with the regulations applicable at any given time.