This Privacy Policy explains how JUDIT FERNÁNDEZ IRIZABAL, a sole trader operating under the Y.5 Perfect Skin brand, processes personal data relating to the website, purchases, accounts, customer support and the other services described below, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018.
During launch, Y.5 Perfect Skin's commercial offering and deliveries are limited to Spain. If other territories or new processing activities are enabled, this policy will be reviewed before activation.
Where a form displays a short privacy notice, this policy provides the additional or second-layer information.
1. Data controller
| Controller | JUDIT FERNÁNDEZ IRIZABAL |
|---|---|
| Trading status | Sole trader |
| Trading name | Y.5 Perfect Skin |
| Spanish tax ID (NIF) | 20188278-M |
| Address | Ruamayor 3, 39008 Santander, Cantabria, Spain |
| Privacy and rights | privacidad@y5perfectionskin.com |
| Website | www.y5perfectionskin.com |
This policy applies to processing carried out by Y.5 Perfect Skin through the website, customer accounts, checkout, one-off or recurring purchases, assisted orders, returns, enquiries, professional applications, reviews and any optional features that are active.
2. Data processed and sources
Y.5 Perfect Skin may process the following categories of data:
- Identification and contact data: first name, surname, email, telephone number and, where necessary, an identity or tax number.
- Account data: user identifier, authentication data managed by the provider, preferences and account status.
- Contract and purchase data: cart, products, amounts, discounts, orders, subscriptions, returns, incidents and transactional communications.
- Delivery and billing data: address, city, postcode, province, country and information needed to deliver or issue an invoice.
- Limited payment data: payment method, status, amount and references supplied by the payment gateway. Y.5 Perfect Skin does not receive or store the full card number or CVV.
- Professional data: company, tax or VAT number, business activity, role, professional address, B2B application, contract documents and related communications.
- Reviews: rating, title, comment, product or store reviewed and data needed to verify the purchase.
- Enquiries, returns, complaints and product incidents, including information about reactions or undesirable effects where needed to handle the communication.
- Technical and security data: IP address, date and time, route, device or browser, authentication events, errors, abusive attempts and security evidence.
- Preferences and consent: cookies, Analytics and, if enabled, marketing communications.
- Analytics data: pages, interactions, visit source, campaign and technical data, only after consent to Analytics.
Sources of data
Data may be obtained:
- directly from the data subject;
- from a purchaser who provides an address for another person;
- from the device or browser;
- from payment, authentication, delivery or security providers;
- from a company identifying an individual as its professional contact.
Address autocomplete with Google Places
Autocomplete will be voluntary. It will only be activated when selected by the user and may transmit to Google the text entered to search for an address and the technical data needed to provide the feature. Manual address entry will always remain available.
Flat or door details will not be sent to Google through autocomplete. The order confirmation page will not display or load a Google map and will not subsequently send the delivery address to Google for that purpose.
3. Purposes and legal bases
Each processing operation is limited to a defined purpose and relies on the legal basis shown below.
| Purpose | Legal basis |
|---|---|
| Create and manage accounts, authentication and preferences. | Performance of a contract or pre-contractual steps — Article 6(1)(b) GDPR. |
| Manage checkout, orders, payments, subscriptions, payment links, delivery, returns and after-sales support. | Performance of a contract — Article 6(1)(b) GDPR. |
| Send one manual reminder about an abandoned checkout if the feature is enabled and the individual voluntarily selects the specific authorisation. | Consent — Article 6(1)(a) GDPR. No reminder will be sent while the feature is inactive or without demonstrable authorisation. |
| Issue invoices and comply with accounting, tax and regulatory obligations. | Compliance with legal obligations — Article 6(1)(c) GDPR. |
| Answer enquiries. | Pre-contractual steps or performance of a contract where related to a purchase; legitimate interest in handling other voluntary enquiries — Articles 6(1)(b) and 6(1)(f) GDPR. |
| Manage B2B applications and relationships. | Pre-contractual steps, contract, legal obligations and, for company contacts, a duly assessed legitimate interest. |
| Prevent fraud, protect accounts and defend against abuse or claims. | Legitimate interest — Article 6(1)(f) GDPR— and legal obligations where applicable. |
| Verify and publish reviews. | Consent to publication — Article 6(1)(a) GDPR— and purchase verification to preserve the authenticity of the service. |
| Measure use of the website with Google Analytics 4. | Consent — Article 6(1)(a) GDPR— together with the rules applying to storage or access on a device. |
| Voluntarily provide address autocomplete through Google Places. | Consent arising from voluntary activation — Article 6(1)(a) GDPR. |
| Send newsletters or other promotional communications if the relevant feature is enabled. | Specific consent — Article 6(1)(a) GDPR. A general legitimate interest will not be used for these features. |
| Send transactional information about a specific order through WhatsApp where the feature is enabled and the individual expressly authorises it at checkout. | Consent — Article 6(1)(a) GDPR. It is optional, applies only to that order, excludes advertising and may be withdrawn without affecting emails necessary to perform the purchase. |
| Provide direct contact initiated voluntarily by the user through WhatsApp if the relevant button is enabled. | Pre-contractual steps or performance of a contract where the enquiry relates to a purchase; a duly assessed legitimate interest in handling other voluntary enquiries — Articles 6(1)(b) and 6(1)(f) GDPR. The link only pre-fills a greeting and does not send the enquiry until the user confirms it within WhatsApp. |
| Handle rights requests, official requests and claims. | Legal obligation and, where applicable, legitimate interest in proving how they were handled. |
| Manage product-safety incidents and cosmetovigilance obligations. | Compliance with legal obligations — Article 6(1)(c) GDPR. If health data is strictly necessary, additional information about the applicable Article 9 GDPR condition will be provided. |
Withdrawal of consent will not affect contractual or legally required processing or the lawfulness of processing carried out before withdrawal.
4. Retention, restriction and deletion
Data will only be kept for as long as necessary for each purpose. The following periods or criteria apply:
| Category | Period or criterion |
|---|---|
| Orders, payments, invoices, credit notes and commercial or tax documentation | Six years, without prejudice to any other legally required period. |
| Customer account | While active. Following a verified erasure request, data not subject to retention will enter a restricted technical quarantine of no more than 15 days before deletion or minimisation. During that period the user may sign in, view orders and tax documents, contact support, exercise rights and withdraw the request, but may not make new purchases or optional changes to profile, addresses or recurring orders. |
| Cart | 30 days after the last activity. |
| Abandoned checkout | 90 days where no order exists; recovery events will then be deleted and identifiers, payment references, basket, notes and navigation traces will be unlinked. Any fraud, claim or legal exception must be restricted, documented and time-limited. |
| Enquiries with no subsequent relationship | Until resolved and for no longer than 12 months. |
| Unsuccessful or abandoned B2B applications | 12 months after the last interaction; application-only documents will then be deleted and application data minimised unless a documented obligation or claim applies. Approved relationships follow a separate contractual rule. |
| Approved professional relationship | While active and subsequently for the applicable legal or claims periods. |
| Marketing communications | Until consent is withdrawn. Minimal evidence of withdrawal may be retained to prevent further messages. |
| WhatsApp order authorisation and messages | During order management. New messages will stop after withdrawal; necessary evidence may be kept under restriction for the applicable contractual, legal or claims periods. |
| Enquiries initiated through WhatsApp | Until resolved and for no longer than 12 months where no subsequent relationship arises, without prejudice to applicable contractual, legal or claims periods. |
| Google Analytics 4 | 14 months, without resetting the period following new activity. |
| Cookie preference | No longer than 24 months, unless changed or withdrawn earlier. |
| Ordinary security and application error logs | 90 days. Data connected to an incident may be restricted for the time needed to investigate it or defend claims. |
| Unpaid phone-order links | 30 days after expiry; the token and code will be invalidated and auxiliary data minimised. The related order or tax document follows its own retention rule. |
| Internal customer notes | No longer than 24 months, unless a documented contractual, legal or claims need applies. |
| Data-subject rights requests | Three years after closure, with restricted access. |
| Reviews | While published or until withdrawal; evidence needed to handle claims may be retained under restriction for the applicable period. |
| Cosmetovigilance | For the period required by product legislation and for the time needed for traceability and the defence of claims. |
Where data must be retained for a legal obligation or claim, it will be blocked or restricted and not used for other purposes. It will be deleted or anonymised when the applicable period ends.
Minimising an internal record does not mean that every copy or provider system becomes anonymous at that moment; each system follows its own rule and any exceptional retention must be limited and documented.
Providers acting as independent controllers may apply their own legally justified retention periods, which will be identified where applicable.
5. Recipients and providers
Y.5 Perfect Skin does not sell personal data. Access or disclosure will only be allowed where necessary to provide a requested service, comply with the law or protect legitimate rights.
The categories of recipients that may be involved are:
- infrastructure, hosting, database, storage and authentication;
- payment processing, invoicing, subscriptions and fraud prevention;
- transactional communications;
- logistics, carriers, tracking and returns;
- technical support, security and application error monitoring;
- Google Analytics, only after consent;
- Google Places, only where the user voluntarily activates autocomplete;
- WhatsApp, for expressly authorised transactional messages about an order or where the individual voluntarily opens the general contact channel and sends an enquiry;
- newsletter or cart-recovery providers, only if the relevant feature is enabled and the individual consents;
- professional advisers subject to confidentiality;
- public authorities, courts and regulators where legally required.
Conditional features will not disclose data while inactive. The provider list will be updated before a new feature is enabled or when a relevant provider changes.
6. International transfers
Some providers may process data outside the European Economic Area. Before allowing a transfer, Y.5 Perfect Skin will verify the country, receiving entity, its role and the applicable legal mechanism.
Where relevant, the transfer will rely on an adequacy decision or safeguards under Article 46 GDPR, such as Standard Contractual Clauses and any necessary supplementary measures. The EU-US Data Privacy Framework will only be relied on for an entity whose current certification has been verified.
Information about the applicable safeguards or how to obtain a copy may be requested from privacidad@y5perfectionskin.com.
7. Your rights
You may exercise the following rights:
- access to your personal data;
- rectification of inaccurate or incomplete data;
- erasure where applicable;
- restriction of processing;
- objection to processing;
- portability, where applicable;
- withdrawal of consent;
- not to be subject to a decision based solely on automated processing where it produces legal or similarly significant effects.
Requests may be sent to privacidad@y5perfectionskin.com or to the controller's postal address. Additional information to confirm identity will only be requested where necessary and proportionate.
Y.5 Perfect Skin will respond without undue delay and generally within one month. For complex or numerous requests, this period may be extended by a further two months, with notice being given within the first month.
Withdrawing consent will be as easy as giving it and will not affect the lawfulness of earlier processing.
You may also lodge a complaint with the Spanish Data Protection Agency.
8. Fraud prevention and automated decisions
Checkout and security systems may use automated rules and signals to detect fraud, abuse, unauthorised access or payment risk.
In its ordinary workflow, Y.5 Perfect Skin will not make decisions based solely on automated processing that produce legal or similarly significant effects on an individual. Relevant signals must be capable of human review.
If such a decision is introduced in the future, information about the logic involved, its significance, expected consequences and available safeguards—including the right to obtain human intervention and challenge the decision—will be provided before activation.
Payment providers may perform their own regulatory or security checks in accordance with their role and policy.
9. Minors, gift recipients and reviews
The services are not directed at children under 14, and Y.5 Perfect Skin does not intend knowingly to collect their data. If data is found to have been provided without a valid basis, steps will be taken to delete it. The age at which an individual may consent to data processing does not itself establish capacity to enter into a purchase; parental or guardian involvement or authorisation will be required where applicable.
If an individual supplies another person's details for delivery of an order or gift, only the necessary data may be provided and the purchaser must be authorised to do so. Y.5 Perfect Skin will use that data only to manage delivery, related incidents and legal obligations, and will provide the required information where applicable.
Public reviews will display only a chosen alias or the reviewer's first name and surname initial. The email address, order number and other data used to verify the purchase will not be public. Reviews may be moderated to remove unnecessary personal data, third-party data or unlawful content.
10. Security, confidentiality and breaches
Y.5 Perfect Skin implements appropriate technical and organisational measures to protect personal data against destruction, loss, alteration, unauthorised disclosure or access.
Measures are selected with regard to the state of the art, nature of the data, purposes and risks. They may include secure connections, access controls, restricted credential management, separation of public and server-only keys, data minimisation, incident logging, system updates and provider oversight.
Access is limited to people and providers who need it for their duties and are subject to confidentiality. No system can guarantee absolute security; this does not limit Y.5 Perfect Skin's legal responsibilities or individuals' rights.
In the event of a possible security breach, Y.5 Perfect Skin will take steps to contain it, investigate its causes, assess its consequences, document it and restore service. Where a risk to rights and freedoms is likely, the Spanish Data Protection Agency will be notified without undue delay and, where feasible, within 72 hours after becoming aware of it. Where a high risk is likely, affected individuals will also be informed without undue delay unless a legal exception applies.
Security or privacy communications may be sent to privacidad@y5perfectionskin.com.
11. Cookies and similar technologies
Y.5 Perfect Skin uses cookies and technologies such as localStorage and sessionStorage. Strictly necessary storage may be used without consent where essential to provide a requested service, for example authentication, cart operation, checkout security and idempotency, payment, shipping quotation and preservation of privacy preferences.
Google Analytics 4 will only be enabled after consent. Refusal will not prevent browsing, use of the cart or purchasing.
The consent preference will be stored for no longer than 24 months and requested again earlier where technologies, providers or purposes materially change.
Users may accept, reject or configure non-essential technologies through options presented at the same level and may later withdraw consent. Withdrawal will stop future collection without affecting processing lawfully carried out beforehand.
Google Ads, Meta or TikTok advertising or remarketing technologies will not be enabled at launch. Tracking associated with newsletters or cart recovery will also remain disabled while those features are inactive. Any future activation will require an inventory, updated documentation, consent configuration and prior verification.
Google Places is a separate optional feature and is not activated through general Analytics consent.
A detailed list of technologies, providers, purposes and durations is available in the Cookie Policy.
12. Effective date, changes and contact
This is version 1.3 of the Privacy Policy and it takes effect on 08-09-2026. It describes current processing and processing scheduled for imminent activation. Features expressly identified as future or conditional will remain inactive until the applicable information and technical requirements have been completed and, where required, the necessary consent has been obtained.
This policy is an information notice. Reading or acknowledging it does not, by itself, constitute consent to optional processing. Where consent is required, it will be requested separately for each purpose through an affirmative action.
Y.5 Perfect Skin will review this policy when its processing operations, purposes, providers, international transfers, methods for exercising rights or applicable rules change. Material changes will be communicated clearly and effectively and, where required by the nature of the change, sufficiently in advance through a prominent notice and, where an appropriate direct channel is available, a dedicated communication. Merely publishing a new version without notice will not be regarded as sufficient communication of a material change.
Before personal data is used for a new purpose, the relevant information will be provided. Where that purpose requires consent, processing will not begin until valid and specific consent has been obtained.
This policy is available in Spanish and English. Both versions describe the same processing operations, and no translation limits rights granted by applicable law.
Questions about this policy or the processing of personal data may be sent to privacidad@y5perfectionskin.com or by post to Y.5 Perfect Skin, Ruamayor 3, 39008 Santander, Cantabria, Spain.