At SOMNIA, we treat your personal data with the same seriousness with which we prepare your orders. This policy explains what data we collect, why, on what legal basis, and how to exercise your rights, in accordance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD).
1. Data Controller
- Controller: SOMNIA — [COMPLETE: company name or first and last name]
- Tax ID / CIF: [COMPLETE]
- Address: Carrer de Sant Sebastià, 12580 Benicarló, Castellón, Spain
- Privacy Contact: info@somniapremium.com
2. Data We Process
- Identification and Contact: first and last name, email, phone.
- Shipping and Billing: postal address, city, postal code, country, Tax ID when you request an invoice.
- Order and Payment: purchased products, amounts, payment method, and the last four digits of the card. We do not have access to your full card number, which is processed directly by the payment gateway. If you choose cash on delivery, the carrier manages the cash collection and only informs us if the order was collected or rejected.
- Browsing: IP address, device, browser, pages visited, and cookie data (see Cookie Policy).
- Communications: the content of emails, forms, or messages you send us.
We do not collect or process special categories of data (health, biometrics, etc.). We ask that you do not include medical information in your communications with us.
3. Purposes and Legal Bases
| Purpose | Legal Basis (Art. 6 GDPR) |
|---|---|
| Manage your order, collection, shipping, and after-sales service | Contract performance |
| Issue invoices and comply with tax and accounting obligations | Legal obligation |
| Process returns, warranties, and claims | Contract and legal obligation |
| Send you news and offers by email | Consent, or legitimate interest if you are already a customer and it concerns similar products (Art. 21 LSSI) |
| Analyze site usage and improve the experience | Consent (analytical cookies) |
| Prevent fraud and ensure security | Legitimate interest |
4. Retention Periods
- Orders and Billing: 6 years from the last operation, in accordance with the Commercial Code and tax regulations.
- Customer Account: as long as you keep it active and, after its deletion, for the prescription periods of possible liabilities.
- Commercial Communications: until you withdraw your consent or unsubscribe.
- Browsing and Cookies: according to the Cookie Policy's deadlines, with a maximum of 24 months.
5. Recipients of Your Data
We only share your data with the necessary providers to provide you with the service, all bound by a data processing agreement (Art. 28 GDPR):
- Shopify Inc. / Shopify International Ltd. — e-commerce platform and hosting.
- Payment Gateways — credit card payment processing.
- Transport and Logistics Companies — order delivery and, where applicable, cash on delivery collection.
- Email and Marketing Providers — confirmations and, if you consent, commercial communications.
- Tax and Accounting Advisory — compliance with legal obligations.
- Public Administrations — when there is a legal obligation.
We do not sell or transfer your data to third parties for advertising purposes.
6. International Transfers
Some providers are located outside the European Economic Area, mainly in the United States. These transfers are covered by an adequacy decision of the European Commission or by standard contractual clauses, along with complementary security measures.
7. Your Rights
You can exercise your rights of access, rectification, erasure, restriction of processing, data portability, and objection at any time, withdraw your consent, and not be subject to automated decisions.
Write to info@somniapremium.com indicating the right you wish to exercise and attaching a document that proves your identity. We will respond within one month, extendable to two in complex cases. The exercise is free.
If you believe that we have not properly addressed your request, you can file a complaint with the Spanish Data Protection Agency: www.aepd.es, C/ Jorge Juan 6, 28001 Madrid.
8. Security
We apply appropriate technical and organizational measures: TLS encryption in all communications, access control, hosting with certified providers, and periodic review of our processes. In the event of a breach that poses a high risk to your rights, we will notify you and inform the AEPD within the legal deadlines.
9. Minors
Our services are aimed at individuals over 18 years of age. We do not intentionally collect data from minors; if we detect that we have done so, we will immediately delete it.
10. Changes to This Policy
We may update it to reflect legal or operational changes. If the changes are substantial, we will notify you by email.
Last updated: July 2026.