SICA Privacy Policy
This English text is a courtesy translation. The binding version is the Spanish version; in case of discrepancy, the Spanish text prevails.
1. Data controller
The controller of the personal data processed through SICA is:
VISUALNACERT, S.L.
Tax ID (CIF): B98655889
C/ Mayor 41
46138 Rafelbuñol, Valencia, Spain.
Privacy e-mail and Data Protection Officer contact: privacy@visualnacert.com
This Policy describes how VisualNACert collects, uses, retains, shares and protects the personal data processed through SICA.
2. What SICA is
SICA is a technology platform for recording, managing, locating and analysing information related to incidents, phenomena and events that may affect farms, livestock holdings and the land.
SICA Campo is mainly intended for users to record declarations and information.
SICA Geo and SICA Analytics are environments restricted to users expressly authorised by the relevant organisations.
3. Personal data we may process
Depending on the features used, SICA may process the following categories of information.
Identification and contact data
- first name and surname;
- e-mail address;
- telephone number;
- organisation, association or cooperative;
- user profile or type.
Account and authentication data
- user identifier;
- access credentials stored using appropriate security mechanisms;
- authentication information;
- login records;
- codes or technical evidence associated with SMS authentication systems.
Farm and agricultural activity data
- farm;
- plot;
- SIGPAC reference;
- crop;
- species;
- livestock activity;
- area;
- agronomic information needed to contextualise an incident.
Incident data
- phenomenon or type of incident;
- description;
- date and time;
- estimated affected area;
- observed damage;
- declaration of absence of damage;
- remarks;
- information on pests or diseases;
- additional information provided by the user.
Location data
- coordinates;
- device location when the user enables that feature;
- plot location;
- geographic information associated with an incident.
Photographs and metadata
SICA may process photographs provided by the user and their associated metadata, including, where available:
- date;
- time;
- coordinates;
- location;
- technical file information.
Photographs are intended to document incidents and their main purpose is not to identify or photograph people.
However, a photograph may accidentally contain people or other identifiable elements.
Technical data
The following may also be processed:
- IP address;
- operating system;
- device type;
- application version;
- technical logs;
- errors;
- security logs;
- information needed to prevent fraudulent access or ensure the operation of SICA.
4. What we use the data for
VisualNACert may process personal data for the following purposes.
A. Creating and managing the account
Includes:
- registration;
- authentication;
- access recovery;
- profile management;
- permission control;
- user support.
B. Recording and managing incidents
Includes:
- receiving communications;
- locating incidents;
- linking them to plots;
- storing photographs;
- recording damage or absence of damage;
- classifying phenomena;
- monitoring;
- avoiding duplicates;
- validating or reviewing information.
C. Territorial representation and analysis of the information
Data may be used for:
- mapping;
- geographic analysis;
- identification of affected areas;
- temporal analysis;
- production of indicators;
- generation of statistics;
- pattern analysis.
D. Analysing climatic and agronomic phenomena
SICA may use the information to study, among other things:
- weather episodes;
- climatic phenomena;
- agricultural damage;
- pests;
- diseases;
- phytosanitary or biological risks;
- damage to crops or livestock;
- spatial and temporal evolution of phenomena.
E. Prevention, surveillance and early-warning systems
The information may be used to develop or improve methods intended to:
- identify trends;
- detect territorial concentrations;
- anticipate risks;
- carry out territorial surveillance;
- support early-warning systems;
- improve assessment and response capacity.
F. Research and statistical analysis
The information may be used for:
- technical or scientific research;
- agricultural studies;
- statistical analysis;
- historical studies;
- assessment of phenomena;
- knowledge generation.
Wherever possible, these activities will rely on aggregated, anonymised or pseudonymised information.
G. Planning and public policy
Results obtained through SICA may contribute to:
- territorial planning;
- agricultural planning;
- needs analysis;
- assessment of events;
- definition or evaluation of public policies;
- prioritisation of actions;
- knowledge of the situation of the sector.
H. Improving SICA
Data may be used, with appropriate safeguards, to:
- check the operation of the system;
- improve classifications;
- improve processes;
- develop new features related to the purposes of SICA;
- assess data quality;
- improve analytical methods;
- improve territorial or agronomic models.
Anonymised or pseudonymised information will be used whenever the purpose can be achieved without identifying users.
I. Security and fraud prevention
We may process information to:
- protect accounts;
- detect unauthorised access;
- investigate security incidents;
- prevent abusive use;
- maintain the integrity of SICA.
J. Compliance with legal obligations
VisualNACert may retain or disclose certain information where necessary to comply with legal obligations or valid requests from competent authorities.
5. Compatible further uses
VisualNACert may carry out further processing related to the above purposes where it is compatible with the purpose for which the data were originally collected.
To assess that compatibility the following will be taken into account, among other aspects:
- the relationship between the purposes;
- the context in which the data were collected;
- users' reasonable expectations;
- the nature of the information;
- the consequences the new processing may have for individuals;
- and the existing protective measures.
Where a new use is not compatible with the original purposes, VisualNACert must have another valid legal basis and provide the data subject with the additional information required by law.
The existence of this clause does not constitute a blanket authorisation to use personal data for any purpose.
6. Legal bases
The main applicable legal bases are:
Provision of the service
Account management, authentication, use of SICA Campo and provision of the requested features are based mainly on the need to perform the relationship with the user and provide the requested service.
Legitimate interest
VisualNACert may base certain processing on its legitimate interest where proportionate and where users' rights do not prevail.
Among others:
- security;
- fraud prevention;
- improving service quality;
- incident control;
- normalisation and removal of duplicates;
- technical analysis related to the purpose of SICA;
- creation of accounts requested by authorised organisations;
- production of certain aggregated analyses.
Consent
Consent will be requested where necessary, particularly for optional features requiring device permissions and where required by law.
The user may withdraw permissions from their device's operating system.
Withdrawal of consent does not affect the lawfulness of processing carried out beforehand.
Legal obligation
Certain processing may be necessary to meet legal obligations applicable to VisualNACert.
Research and statistics
Further processing for scientific, historical or statistical purposes will be carried out in accordance with applicable law and with the necessary safeguards, especially minimisation, pseudonymisation or anonymisation where appropriate.
VisualNACert will not, on its own, base processing on the exercise of public powers merely because a Public Administration uses SICA.
7. Geolocation
SICA may request permission to access the device's location.
Location will be used only for SICA-related features, mainly:
- helping to find or select a plot;
- attaching coordinates to an incident;
- georeferencing photographs;
- contextualising recorded information territorially.
SICA does not use geolocation to continuously track the user's movements.
The user can control and withdraw location permissions in their device settings.
VisualNACert recommends allowing location access only while the app is in use, where the operating system offers that option.
8. Photographs
Photographs provided will be used to document recorded incidents.
It is neither necessary nor advisable to photograph people when not required.
Where an image accidentally includes third parties' personal data, VisualNACert may take measures to limit its processing, hide it or delete it where clearly unnecessary or inappropriate.
Coordinates, date, time and other metadata associated with photographs may be used to verify and contextualise the incident.
9. Who can access the data
The user
Each user may access their own communications and the features enabled for their profile.
VisualNACert
Expressly authorised staff may access the information where necessary to:
- provide the service;
- provide support;
- ensure security;
- manage incidents;
- control data quality;
- pursue the purposes described in this Policy.
Authorised organisations
Public Administrations, cooperatives, associations or other organisations using SICA may have authorised users with access to SICA Geo, SICA Analytics or other restricted modules.
Access will be limited to the scope of information and level of detail corresponding to their authorisation.
Wherever the purpose can be achieved without identifying the user, aggregated or pseudonymised information will be provided where possible.
Where a recipient organisation subsequently processes personal data for purposes it determines independently, that organisation may become an independent controller of that processing and will be subject to its own data protection obligations.
10. Service providers
VisualNACert may use technology providers acting as processors where necessary to operate SICA.
These may include providers of:
- cloud hosting;
- infrastructure;
- communications;
- e-mail;
- SMS authentication;
- security;
- technical support.
These providers are bound by the contractual obligations required by data protection law.
11. Hosting and international transfers
SICA's main infrastructure is hosted on Amazon Web Services, Frankfurt region, Germany.
SICA is configured so that its operational data remain within the European Union or the European Economic Area.
Should an international transfer of personal data become necessary in the future, VisualNACert will only carry it out where an appropriate legal mechanism exists under the GDPR and will provide data subjects with the necessary information.
12. Retention periods
VisualNACert applies the following retention criteria, unless a legal obligation, claim or justified circumstance requires a different period.
Account data
Retained while the account remains active.
After cancellation, data needed to evidence the relationship and address potential liabilities may be kept duly blocked for a general maximum of five years, after which they will be deleted or anonymised, unless another legal period applies.
Incidents and data linked to the user
Incidents directly linked to an identified person may be kept for five years from their recording or from the last relevant action on them, unless additional retention is justified.
After that period, the direct link to the user will be removed where possible, retaining only the information needed for historical, territorial, scientific or statistical analysis through anonymisation or, where necessary, pseudonymisation and reinforced measures.
Photographs
Identifiable photographs will be kept while needed to document the incident and, as a general rule, for a maximum of five years.
After that period they will be deleted, unless a legal, scientific, technical or claims-defence reason justifies additional retention with appropriate safeguards.
Anonymised information
Information that has been effectively anonymised and no longer allows a person to be reasonably identified may be retained without a predetermined period for statistical, scientific, historical, agronomic or territorial purposes.
Security logs
Ordinary technical logs are kept, as a general rule, for up to 12 months.
They may be kept longer where related to a security incident, investigation, fraud or claim.
Obligations and claims
Where necessary, certain information may be blocked for the applicable statutory limitation periods.
13. Minors
Where processing is based on consent:
- users aged 14 or over may give their consent under the legally established terms;
- for children under 14, the consent of the holder of parental authority or guardianship must be recorded.
SICA may set up a specific procedure for these cases.
Information aimed at minors will be provided in clear and understandable language.
14. Automated decisions
SICA may use automated tools to classify, group, detect patterns or generate analyses.
SICA is not designed to make, solely by automated means, decisions that produce legal effects on the user or similarly significantly affect them.
Nor does SICA's information by itself constitute an administrative decision, recognition of a right, claim notification or decision on compensation.
15. Security
VisualNACert applies technical and organisational measures aimed at protecting data against:
- unauthorised access;
- loss;
- alteration;
- improper disclosure;
- destruction;
- unlawful use.
These measures include access controls, profile and permission management, authentication mechanisms, communications security, backups, monitoring and incident-management procedures.
No system can guarantee absolute security, so the measures will be reviewed and updated according to risk and technological developments.
16. Users' rights
Where applicable, the user may exercise the rights of:
- access;
- rectification;
- erasure;
- objection;
- restriction of processing;
- portability;
- withdrawal of consent.
Requests may be sent to: privacy@visualnacert.com
VisualNACert may request reasonable information to verify the identity of the requester where necessary.
The user may also lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos) if they consider that the processing of their data does not comply with the law.
17. Deleting an account
The user may request the cancellation of their account.
Deleting the account does not necessarily mean the immediate deletion of all information previously provided where:
- there is a legal retention obligation;
- it is needed to address potential claims;
- it forms part of information that has been anonymised;
- or another legal basis justifies its retention.
Where possible, the user's identity will be unlinked from historical information that must be kept.
18. Changes to this Policy
VisualNACert may update this Policy as a result of regulatory, technological, functional or data-processing changes.
Where changes are material, the user will be informed through SICA, e-mail or another appropriate means.
Where new processing requires consent, it will be requested expressly.
19. Contact
For any enquiry about the processing of personal data:
Data Protection Officer
VISUALNACERT, S.L.
privacy@visualnacert.com
C/ Mayor 41
46138 Rafelbuñol
Valencia, Spain.