Privacy Policy
Privacy Policy
PAEZ GRUPO ADUANERO, S.L.
Effective date: 11 September 2026
ㅤ
This Privacy Policy explains how PAEZ GRUPO ADUANERO, S.L. uses and protects personal information in connection with its UK website, customs services, private client area and internal customs management platform.
ㅤ
1. Who we are
PAEZ GRUPO ADUANERO, S.L. («Páez Aduanas», «we», «us» or «our») is the controller of the personal information described in this Policy unless a particular service agreement states otherwise.
• Company number / tax ID: ESB05440854
• Registered address: Paseo de los Robles, 2, Office 2.3, 04720 Aguadulce, Almería, Spain
• Telephone: +34 950 58 46 46
• Privacy contact: customs@paezaduanas.co.uk
Páez Aduanas is established in Spain and provides customs services to business customers in the United Kingdom. Where UK data protection law requires the appointment of a UK representative, the representative’s contact details will be made available in this Policy and through the relevant service information.
ㅤ
2. Scope
This Policy applies to the website paezaduanas.co.uk, enquiries, quotations, customs clearance and representation services, professional communications, the private client area and PAEZ ADUANAS ERP. The services are intended for companies, self-employed persons and professionals acting for business purposes.
ㅤ
3. Information we process
3.1 Contact, account and professional information
• Name, role, organisation, business address, email address, telephone number and signature.
• User account identifiers, access permissions, authentication events and technical support communications.
• EORI, tax, customs and professional registration identifiers where relevant.
3.2 Customs, commercial and transport information
• Information contained in commercial invoices, customs declarations, packing lists, transport documents, guarantees, certificates and supporting records.
• Details of importers, exporters, declarants, recipients, carriers and other supply-chain participants.
• Description, tariff classification, origin, quantity, value, weight, packaging, itinerary, loading and unloading locations, vehicle registration and shipment dates.
• Declaration references, MRNs, acceptance or rejection messages, controls, releases and other communications received from customs authorities.
The information mainly concerns organisations. Personal information may nevertheless be included where a party is a sole trader, a professional contact or an identifiable driver or representative. We do not intentionally request special category information for these purposes.
3.3 Website and technical information
• IP address, device and browser information, timestamps, pages viewed, security events and diagnostic logs.
• Cookie identifiers and consent preferences, as described in the Cookie Policy.
ㅤ
4. Purposes and lawful bases
| Purpose | Use | Lawful basis |
|---|---|---|
| Enquiries and quotations | To respond to requests and prepare proposals. | Steps requested before entering into a contract; legitimate interests in managing business enquiries. |
| Customs and professional services | To provide customs clearance, representation, shipment coordination, account administration and support. | Performance of a contract; legal obligations; legitimate interests in providing and administering business services. |
| HMRC and other authorities | To submit declarations and supporting information, receive outcomes, maintain audit records and comply with customs requirements. | Performance of a contract; legal obligations; legitimate interests in delivering accurate and secure customs services. |
| Private client area and ERP | To provide controlled access to documents, manage files, authenticate users, maintain security and investigate incidents. | Performance of a contract; legitimate interests in secure service delivery, fraud prevention and network and information security. |
| Document extraction assisted by AI | To extract and structure relevant information from documents, subject to human review, data minimisation and contractual safeguards. The tools are not used to make solely automated decisions producing legal or similarly significant effects. | Performance of a contract; legal obligations where relevant; legitimate interests in improving accuracy and efficiency, after assessing necessity and impact. |
| Legal, accounting and claims | To meet record-keeping duties and establish, exercise or defend legal claims. | Legal obligations; legitimate interests in compliance and legal defence. |
| Marketing | To send service updates or commercial communications where permitted. | Consent or legitimate interests, together with applicable electronic marketing rules. Unsubscription is available at any time. |
ㅤ
5. HMRC integration
PAEZ ADUANAS ERP is an internal platform used by Páez Aduanas. It communicates with HM Revenue & Customs through authorised interfaces, including services for Entry Summary Declarations and, when placed into production, the Customs Declaration Service. It may submit declaration, commercial, transport and supporting-document information and receive identifiers, acceptance or rejection messages, control notices and release status information.
Customers do not provide Páez Aduanas with their Government Gateway usernames or passwords and do not connect their own HMRC accounts to the platform. An authorised representative of Páez Aduanas authenticates directly on HMRC’s website. The platform stores the resulting application authorisation tokens in an encrypted production database solely to maintain the authorised HMRC connection.
ㅤ
6. AI-assisted document processing
We may use enterprise-grade artificial intelligence services to assist with reading, extracting and structuring information contained in customs and commercial documents. Only information reasonably necessary for the relevant task is submitted. Appropriate contractual, confidentiality, security and international-transfer safeguards are required, and customer information must not be used by the provider to train general-purpose models. Outputs are subject to appropriate human review before they are used for customs work. We do not use this process to make solely automated decisions that have legal or similarly significant effects on individuals.
ㅤ
7. Sources of information
• Directly from the individual or business customer.
• From the organisation represented by the individual.
• From importers, exporters, recipients, carriers, agents and other supply-chain participants.
• From HMRC, SOIVRE and other customs, tax or inspection authorities.
• From professional advisers, service providers and lawful public sources.
ㅤ
8. Recipients and service-provider categories
Where necessary and proportionate, information may be disclosed to:
• Customs, tax, border, inspection and law-enforcement authorities.
• Importers, exporters, recipients, carriers, freight forwarders, warehouse operators and other parties involved in the shipment or customs procedure.
• Cloud hosting, storage, backup, email, productivity and infrastructure providers.
• Software development, maintenance, cybersecurity and technical support providers.
• Enterprise document-processing and artificial-intelligence service providers.
• PDF and document-format processing providers.
• Billing, accounting, banking, insurance, audit and professional-advisory providers.
• Courts, regulators and other recipients where disclosure is required by law or necessary for legal claims.
Providers acting on our behalf are required to process information only for documented purposes, maintain confidentiality and security, assist with data protection obligations and delete or return information as required.
ㅤ
9. International transfers
Our core platform and backups are hosted in the European Union. Some service providers or their support teams may process or access information from other countries. Before making a restricted transfer, we use a legally recognised mechanism, such as applicable UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved contractual clauses, or another lawful safeguard, together with the required transfer assessment and supplementary measures where appropriate.
ㅤ
10. Retention
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including applicable customs, tax, accounting, security and limitation periods. We apply a documented retention schedule and periodic review. In particular:
• Enquiries and unsuccessful quotations are normally retained for up to 24 months after the last meaningful contact.
• Customer, customs and transaction records are retained for the statutory period applicable to the relevant declaration or service and, where necessary, for the establishment, exercise or defence of claims.
• HMRC messages and supporting documents form part of the relevant customs file and follow the same retention rule.
• Application, access and security logs are retained for a proportionate period, normally between 6 and 24 months depending on their purpose, unless required for an incident, investigation or legal claim.
• Temporary document downloads are deleted after a short operational period.
• Backups follow defined rotation and deletion cycles. Exceptional archival copies require a documented legal or incident-response justification.
• Marketing preferences are retained until withdrawal or objection. A minimal suppression record may be retained to ensure that the preference continues to be respected.
At the end of the applicable period, information is securely deleted or irreversibly anonymised unless further retention is required by law.
ㅤ
11. Security
We use risk-based technical and organisational measures, including encryption in transit and at rest, role-based access, password hashing, multifactor authentication for privileged access, controlled support access, logging and monitoring, backup and recovery, vulnerability and patch management, incident response and supplier oversight. Sessions and authentication attempts are subject to proportionate expiry, rate-limiting and revocation controls.
Development and testing must use synthetic or anonymised information wherever possible. Where reproducing an incident requires personal information, access is restricted to the minimum necessary dataset, the need is documented, protective controls are applied and the data is deleted promptly after testing.
ㅤ
12. Your rights
Subject to applicable conditions and exemptions, individuals may request access, correction, erasure, restriction, objection and portability, withdraw consent where relied upon, object to direct marketing and obtain information about safeguards used for international transfers. Requests may be sent to customs@paezaduanas.co.uk. We may request proportionate information to verify identity and will not routinely retain copies of identity documents unless necessary.
ㅤ
13. Complaints
Please contact us first so that we can investigate. You may also complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint/ or, where relevant, to the Spanish Data Protection Agency at aepd.es.
ㅤ
14. Cookies and changes
Information about cookies and similar technologies is available in our Cookie Policy. We may update this Policy to reflect changes in law, services, suppliers or technology. The current version and effective date will always appear on this page.
