Privacy policy
Privacy policy – ONA US
Last updated: Monday, June 30, 2025
This Privacy Policy describes how ONA Corp, S.L.U. ("Secretos del Agua”, we", "us", or "our") collects, uses, and discloses your personal information when you visit, use our Website, or make a purchase from www.secretosdelagua.us (the "Website") or otherwise communicate with us regarding the Website. For purposes of this Privacy Policy, "you" and "your" means you as the user of the Website, whether you are a customer, website visitor, or another individual whose information we have collected pursuant to this Privacy Policy.
Please read this Privacy Policy carefully. By using and accessing any of the Website, you agree to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree to this Privacy Policy, please do not use or access any of the Website.
1. Scope and Purpose
This Privacy Policy applies to users who access or interact with our Website, including customers, visitors, and others who use the Website. It outlines our practices concerning the collection, use, disclosure, and protection of your personal information.
2. Processing Principles
ONA Corp, S.L.U. are committed to processing your personal information in accordance with applicable U.S. and international data protection laws. This includes principles such as consent, contractual necessity, legal obligation, legitimate interest, lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability. ONA Corp, S.L.U. implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk involved.
3. Changes to This Privacy Policy
We may update this Privacy Policy from time to time, including to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will post the revised Privacy Policy on the Website, update the "Last updated" date and take any other steps required by applicable law.
4. How ONA Corp, S.L.U. Collects and Use Your Personal Information
ONA Corp, S.L.U., for the use of its Website, collects and has collected over the past 12 months personal information about you from a variety of sources, as set out below, as for example the email service. The information that we collect and use varies depending on how you interact with us.
In addition to the specific uses set out below, we may use information we collect about you to communicate with you, provide or improve or improve the Website, comply with any applicable legal obligations, enforce any applicable terms and conditions, and to protect or defend the Website, our rights, and the rights of our users or others.
5. What Personal Information ONA Corp, S.L.U. Collects
The types of personal information we obtain about you depends on how you interact with our Website. When we use the term "personal information", we are referring to information that identifies, relates to, describes or can be associated with you. The following sections describe the categories and specific types of personal information we collect.
6. Information s Collect Directly from You
Information that you directly submit to us through our Website may include:
- Contact details including your name, address, phone number, and email.
- Order information including your name, billing address, shipping address, payment confirmation, email address, and phone number.
- Account information including your username, password, security questions and other information used for account security purposes.
- Customer support information including the information you choose to include in communications with us, for example, when sending a message through the Website.
Some features of the Website may require you to directly provide us with certain information about yourself. You may elect not to provide this information, but doing so may prevent you from using or accessing these features.
7. Information ONA Corp, S.L.U. Collects about Your Usage
We may also automatically collect certain information about your interaction with the Website ("Usage Data"). To do this, we may use cookies, pixels and similar technologies ("Cookies"). Usage Data may include information about how you access and use our Website and your account, including device information, browser information, information about your network connection, your IP address and other information regarding your interaction with the Website.
8. Third-Party Data Provided by You
If you provide us with personal data relating to third parties, you confirm that you have informed such individuals of the content of this Privacy Policy and, where necessary, have obtained their prior consent. ONA Corp, S.L.U. is not responsible for unauthorized disclosures of third-party data by users. We may carry out checks and apply due diligence measures as required by applicable data protection regulations.
9. Information ONA Corp, S.L.U. Obtains from Third Parties
Finally, we may obtain information about you from third parties, including from vendors and service providers who may collect information on our behalf, such as:
- Companies who support our Website and its function, such as Shopify.
- Our payment processors, who collect payment information (e.g., bank account, credit or debit card information, billing address) to process your payment in order to fulfill your orders and provide you with products you have requested, in order to perform our contract with you.
- When you visit our Website, open or click on emails we send you, or interact with our Website, its functionalities or advertisements, we, or third parties we work with, may automatically collect certain information using online tracking technologies such as pixels, web beacons, software developer kits, third-party libraries, and cookies.
Any information we obtain from third parties will be treated in accordance with this Privacy Policy. Also see the section below, Third Party Websites and Links.
10. Cross-Device Tracking
ONA Corp, S.L.U. may use technologies to recognize you across different devices and platforms, allowing us and our partners to deliver seamless user experience and consistent marketing communications.
11. How ONA Corp, S.L.U. Use Your Personal Information
- Providing Products. We use your personal information to provide you with the Website in order to perform our contract with you, including to process your payments, fulfill your orders, to send notifications to you related to your account, purchases, returns, exchanges or other transactions, to create, maintain and otherwise manage your account, to arrange for shipping, facilitate any returns and exchanges and other features and functionalities related to your account. We may also enhance your shopping experience by enabling Shopify to match your account with other Shopify services that you may choose to use. In this case, Shopify will process your information as set forth in its Privacy Policy and Consumer Privacy Policy.
- Marketing and Advertising. ONA Corp, S.L.U. may use cookies, pixels, and similar technologies to personalize your experience and show you relevant advertisements based on your online behavior across websites and online. This includes profiling based on your interactions with our Website, email campaigns, and advertisements. You may opt out of such processing by using the “Do Not Sell or Share My Personal Information / Target Ads” link at the bottom of our Website or by enabling the Global Privacy Control (GPC) signal in your browser.
- Security and Fraud Prevention. We use your personal information to detect, investigate or take action regarding possible fraudulent, illegal or malicious activity. If you choose to use the Website and register an account, you are responsible for keeping your account credentials safe. We highly recommend that you do not share your username, password, or other access details with anyone else. If you believe your account has been compromised, please contact us immediately.
- Communicating with You and Website Improvement. We use your personal information to provide you with customer support and improve our Website. This is in our legitimate interests in order to be responsive to you, to provide an effective use of the Website to you, and to maintain our business relationship with you.
· Loyalty Program and Financial Incentives. ONA Corp, S.L.U., may offer discounts, promotional codes, or exclusive offers to users who participate in our loyalty programs. Participation in these programs may require you to provide personal information such as your name, email address, and purchase history. You may opt out at any time, but doing so may result in the loss of associated benefits. The value of personal information collected through such programs is reasonably related to the value of the benefit provided to you.
12. International Data Transfers
If ONA Corp, S.L.U. transfers personal data outside of your country (e.g., from the EU to the U.S.), such transfers are safeguarded using appropriate mechanisms such as Standard Contractual Clauses (SCCs).
13. Cookies
Like many websites, we use Cookies on our Site. For specific information about the Cookies that we use related to powering our store with Shopify, see https://www.shopify.com/legal/cookies. We use Cookies to power and improve our Website (including to remember your actions and preferences), to run analytics and better understand user interaction with the Website (in our legitimate interests to administer, improve and optimize the Website). We may also permit third parties and services providers to use Cookies on our Website to better tailor the products and advertising on our Website and other websites.
Most browsers automatically accept Cookies by default, but you can choose to set your browser to remove or reject Cookies through your browser controls. Please keep in mind that removing or blocking Cookies can negatively impact your user experience and may cause some of the Website, including certain features and general functionality, to work incorrectly or no longer be available. Additionally, blocking Cookies may not completely prevent how we share information with third parties such as our advertising partners.
Our Website also recognizes the Global Privacy Control (GPC) signal, which enables you to opt-out of certain uses or disclosures of your information. If you notify us of your preference through GPC, we will treat such signal as a valid request to opt out of sharing / targeted advertising for the associated browser or device, and, if we are able to associate the device sending the signal to a Shopify account, we will apply the opt out request to the account as well. To learn more about Global Privacy Control, you can visit https://globalprivacycontrol.org/. Other than the Global Privacy Control, we do not recognize other “Do Not Track” signals that may be sent from your web browser or device.
14. How We Disclose Personal Information
In certain circumstances, we may disclose your personal information to third parties for contract fulfillment purposes, legitimate purposes and other reasons subject to this Privacy Policy. Such circumstances may include:
- With vendors or other third parties who perform services on our behalf (e.g., IT management, payment processing, data analytics, customer support, cloud storage, fulfillment and shipping).
- With business and marketing partners to provide services and advertise to you. Our business and marketing partners will use your information in accordance with their own privacy notices.
- When you direct, request us or otherwise consent to our disclosure of certain information to third parties, such as to ship you products or through your use of social media widgets or login integrations, with your consent.
- With our affiliates or otherwise within our corporate group, in our legitimate interests to run a successful business.
- In connection with a business transaction such as a merger or bankruptcy, to comply with any applicable legal obligations (including to respond to subpoenas, search warrants and similar requests), to enforce any applicable terms and conditions, and to protect or defend the Website, our rights, and the rights of our users or others.
We have in the past 12 months disclosed the following categories of personal information and sensitive personal information about users for the purposes set out above in "How we Collect and Use your Personal Information" and "How we Disclose Personal Information":
|
Category |
Categories of Recipients |
|
|
We do not use or disclose sensitive personal information without your consent or for the purposes of inferring characteristics about you.
We have “sold” and “shared” (as those terms are defined in applicable law) personal information over the preceding 12 months for the purpose of engaging in advertising and marketing activities, as follows.
|
Category of Personal Information |
Categories of Recipients |
|
Identifiers such as name, e-mail address and phone number |
Business and marketing partners |
|
Commercial information such as records of products purchased |
Business and marketing partners |
|
Usage Data |
Business and marketing partners |
15. Third Party Websites and Links
Our Website may provide links to websites or other online platforms operated by third parties. If you follow links to websites not affiliated or controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of such websites, including the accuracy, completeness, or reliability of information found on these websites. Information you provide on public or semi-public venues, including information you share on third-party social networking platforms may also be viewable by other users of the Website and/or users of those third-party platforms without limitation as to its use by us or by a third party. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators, except as disclosed on the Website.
16. Children's Data
The Website are not intended to be used by children, and we do not knowingly collect any personal information about children. If we become aware that we have inadvertently received personal data from a child, we will delete the information as soon as possible. If you are the parent or guardian of a child who has provided us with their personal information, you may contact us using the contact details set out below to request that it be deleted.
As of the Effective Date of this Privacy Policy, we do not have actual knowledge that we “share” or “sell” (as those terms are defined in applicable law) personal information of individuals under legal age.
17. Detailed incident report
We may process limited health-related data that you voluntarily provide to us, such as skin conditions, allergies, or reactions in the context of consultations, diagnostic tools, or customer service interactions. All information of that nature should be referred to the Detailed incident report and will be kept for as long as required by law. That information will also be shared in accordance with any legal obligations.
We may collect such data (e.g., skin allergies, reactions, treatments) to improve product safety and customer experience, and within the legal limits. Where required, your consent will be obtained prior to collecting or using this information. These information should be shared on the Detailed incident report page of the Website, or on the medium and format that we might legally be required to and communicate to you.
18. Security
Please be aware that no security measures are perfect or impenetrable, and we cannot guarantee “perfect security.” In addition, any information you send to us may not be secure while in transit. We recommend that you do not use insecure channels to communicate sensitive or confidential information to us.
For the purposes of this Privacy Policy, Sensitive Personal Information includes, but is not limited to, personal data that reveals or relates to:
- Government-issued identifiers (e.g., Social Security number, driver’s license or passport number);
- Financial account details in combination with access to credentials (e.g., bank account number with login);
- Precise geolocation data (within a radius of 1,850 feet);
- Racial or ethnic origin, religious or philosophical beliefs, or union membership;
- Contents of consumer communications (e.g., email, messages) where ONA is not the intended recipient;
- Genetic, biometric, or health-related data (e.g., skin conditions, allergies, medical reactions);
- Sexual orientation, sex life, or gender identity;
- Personal information collected from a known child under the age of 13.
This list is illustrative and not exhaustive. We treat any information as sensitive where its misuse could reasonably lead to significant harm to the individual or where applicable law designates it as such.
We do not use or disclose Sensitive Personal Information for purposes beyond those authorized under applicable state privacy laws, including the California Consumer Privacy Act (as amended by the CPRA). Where legally required, we will obtain your explicit consent prior to processing any such information and provide you with the ability to limit its use and disclosure pursuant to your rights under state law.
19. Retention of Your Information
We implement appropriate technical and organizational measures to protect your personal data from unauthorized access, use, or disclosure. Please note that no security measures are entirely foolproof, and we cannot guarantee “perfect security.” Avoid sending sensitive information over unsecured channels.
How long we retain your personal information depends on several factors, including whether we need the information to:
- Maintain your account or relationship with us;
- Provide access and the functionalities of the Website;
- Comply with applicable legal obligations;
- Resolve disputes; and
- Enforce our agreements and policies.
In addition, we apply the following data governance and retention practices:
- Data Classification: We categorize personal information based on its sensitivity, purpose, and regulatory impact to determine the appropriate retention period and protection measures.
- Purpose Limitation Mechanisms: We only retain personal information for the specific, explicit, and legitimate purposes for which it was collected. Once the original purpose has been fulfilled, data is either deleted or deidentified unless a legal obligation justifies continued storage.
- Data Minimization: We retain only the minimum amount of personal data necessary to fulfill the stated purpose. Redundant, outdated, or unnecessary data is regularly reviewed and securely deleted.
- Retention Schedule Management: We maintain documented retention schedules that define how long each category of personal data is retained. For example:
- Order and transaction data is typically retained for 7 years to comply with tax, accounting, and fraud-prevention requirements.
- Marketing preference data is retained until you withdraw your consent or unsubscribe.
- Inactive user accounts may be deactivated and deleted after 24 months of inactivity, subject to legal exceptions.
We may retain deidentified or aggregated data indefinitely for statistical, research, or product improvement purposes, provided it cannot be used to reidentify individuals.
20. Your Rights
Depending on where you live, you may have some or all of the rights listed below in relation to your personal information. However, these rights are not absolute, these may apply only in certain circumstances and, in certain cases, we may decline your request as permitted by law.
- Right to Access / Know: You may have a right to request access to personal information that we hold about you, including details relating to the ways in which we use and share your information.
- Right to Delete: You may have a right to request that we delete personal information we maintain about you.
- Right to Correct: You may have a right to request that we correct the inaccurate personal information we maintain about you.
- Right of Portability: You may have a right to receive a copy of the personal information we hold about you and to request that we transfer it to a third party, in certain circumstances and with certain exceptions.
- Restriction of Processing: You may have the right to ask us to stop or restrict our processing of personal information.
- Withdrawal of Consent: Where we rely on consent to process your personal information, you may have the right to withdraw this consent.
- Appeal: You may have a right to appeal our decision if we decline to process your request. You can do so by replying directly to our denial.
- Managing Communication Preferences: We may send you promotional emails, and you may opt out of receiving these at any time by using the unsubscribe option displayed in our emails to you. If you opt out, we may still send you non-promotional emails, such as those about your account or orders that you have made.
· Right to Appeal. If we deny your privacy rights request, you may have the right to appeal that decision by contacting us at [email] with the subject “Privacy Appeal Request.” We will review your appeal in accordance with applicable state laws and respond within the legal timeframe.
You may exercise any of these rights where indicated on our Website or by contacting us using the contact details provided below.
We will not discriminate against you for exercising any of these rights. We may need to collect information from you to verify your identity, such as your email address or account information, before providing a substantive response to the request. In accordance with applicable laws, you may designate an authorized agent to make requests on your behalf to exercise your rights. Before accepting such a request from an agent, we will require that the agent provide proof you have authorized them to act on your behalf, and we may need you to verify your identity directly with us. We will respond to your request in a timely manner as required under applicable law.
21. International Users
Please note that we may transfer, store and process your personal information outside the country you live in. Your personal information is also processed by staff and third party service providers and partners in these countries.
If we transfer your personal information out of Europe, we will rely on recognized transfer mechanisms like the European Commission's Standard Contractual Clauses, or any equivalent contracts issued by the relevant competent authority of the UK, as relevant, unless the data transfer is to a country that has been determined to provide an adequate level of protection.
22. Contact
If you have complaints about how we process your personal information, any questions about our privacy practices or want to exercise your rights, please contact us through phone or email at pvalladolid@secretosdelagua.com or contact us at Avenida de la Victoria, 134, 28023, Madrid, ES.
If you are not satisfied with our response to your complaint, depending on where you live you may have the right to appeal our decision by contacting us using the contact details set out below, or lodge your complaint with your local data protection authority.