hank Logo

hank

Data Protection Policy

Last updated: October 1st, 2025

Language: This privacy policy is also available in Spanish / Esta política de privacidad también está disponible en español

Controller Information

Data Controller:

hank.parts S. L.

NIF: B23862170

Calle Callejoncillo 4

11130 Chiclana de la Frontera, Cádiz, Spain

(hereinafter referred to as "we", "our" or "the Controller")

Data Protection Contact: help@support.hank.parts

Age Requirement

Our Service is only available to users who are at least 18 years of age.

While GDPR allows individuals aged 13 and above to provide valid consent for data processing, depending on the country of residence, our Service requires, as an internal policy, to be at least 18 years of age. Therefore, we do not knowingly collect personal data from individuals under 18.

If you are under 18, do not use our Service or provide any personal data. If we detect that we have collected personal data from someone under 18, we will delete that information immediately and, where appropriate, deactivate the associated account.

Data We Collect

We may collect and process the following data:

1) In case of contacting us:

  • Identifying and contact data
  • Data you voluntarily provide in communications you send us

2) In case of creating an account and using our Services:

  • Account and contact data: email address, username and password.
  • Profile images: avatar photos you upload to your profile (if applicable)
  • Content images: photos you upload for part requests and offers.
  • User-generated content: part requests, offers, comments and other platform interactions
  • Conversations and interactions carried out through communication tools such as chats, forums or comments.

The following data is also automatically collected:

  • Technical data: IP address, browser type, device information.
  • Usage data: logs of your activity on our platform

Legal Basis for Processing

We process your data for specific purposes under the following legal bases (Article 6 GDPR):

1) In case of contacting us:

The personal data identified in the previous section will be processed to answer your requests and follow up on them.

The legal basis is user consent, granted when you voluntarily contact us through the means available to you.

2) In case of creating an account and using our Services:

The personal data identified in the previous section will be processed for:

2.a) User registration and account management, which includes:

  • Create and manage the user account,
  • Provide the Service, in accordance with the Terms of Use,
  • Send service communications necessary for account operation (confirmations, technical notices, changes in conditions, etc.),
  • Manage inquiries, requests or incidents submitted by users through contact channels.

Legal basis: Contract performance or application of pre-contractual measures at the request of the data subject (art. 6.1.b GDPR).

In the case of voluntarily provided personal data (for example, profile images), their provision will be based on user consent (Art. 6.1.a GDPR)

2.b) Allow technical and operational use of the Platform, ensure its security and prevent fraudulent uses.

Legal basis: Legitimate interest of the Controller in ensuring service security (art. 6.1.f GDPR).

2.c) Analyze, in aggregate and anonymized form, service usage to improve its operation and user experience.

Legal basis: Legitimate interest of the Controller in improving and maintaining service quality (art. 6.1.f GDPR).

2.d) Comply with legal obligations imposed on the Controller, including keeping certain information for legal periods, responding to requests from competent authorities, etc.

Legal basis: Compliance with a legal obligation applicable to the data controller (art. 6.1.c GDPR).

Regarding purposes based on our legitimate interests, we have assessed that these interests do not override your fundamental rights and freedoms. If you wish to obtain more information about such assessments, you can request it by writing to help@support.hank.parts.

Mandatory vs. Optional Data

All personal data requested as mandatory will be indicated with an asterisk (*) or equivalent sign. Failure to provide such data (such as contact data) will prevent continuation of the corresponding process (such as creating a user account), since without such information it is not possible to provide the Services offered through the Platform.

Fields not marked as mandatory are requested to improve user experience (for example, profile image) and, therefore, may be completed voluntarily, and their absence will not prevent you from using the Platform, although it may reduce functionality or user experience.

Data Retention

We retain your personal data according to specific retention periods based on data type and legal requirements:

1) Contact with the Controller

Data provided through inquiries, forms or support communications will be kept as long as necessary to address the request or resolve the incident, and subsequently for the statute of limitations period for possible liabilities.

Indicative period: 3 years from resolution of the inquiry.

2) Creating an account and using our Services

Data will be kept while the account remains active.

If the user requests account cancellation, associated personal data will be permanently deleted, except for those that must be kept blocked during legally established periods to address possible liabilities or requests from authorities.

Notwithstanding the above, you can request restoration of your account within the sixty (60) day window through help@support.hank.parts. During this period, personal data associated with the account will remain blocked and will not be visible to other users or used for any purpose other than possible account restoration at the user's own request.

Indicative period: until cancellation request + 60 days recovery + up to 5 years blocked from cancellation request.

Technical, usage or connection data will be kept as long as necessary to ensure operation, security and service improvement, and will subsequently be anonymized or deleted.

Indicative period: session and usage data, up to 180 days from collection; afterwards, only aggregated or anonymized information.

Recipients of your personal data

User personal data will not be communicated to third parties, except in the following cases:

1) Between Platform users:

Certain user profile information (such as username, profile image, approximate location or published part descriptions) may be visible to other registered users, solely to allow interaction, communication or part exchange within the functional framework of the Service.

2) Service providers necessary for Service operation:

Data may be processed by service providers (data processors) who need to access your data to provide their services (for example, technological, web hosting, maintenance, IT support, electronic communications or other services). Such providers act under contracts that guarantee confidentiality, security and GDPR compliance.

3) Compliance with legal obligations and authority requests:

The Controller may communicate your personal data when necessary to comply with legal obligations (for example, tax, security or information retention under LSSI), or when required by administrative, judicial or police authorities in the exercise of their powers.

4) In case of a corporate transaction:

In case of a merger, acquisition, sale of all or part of its assets or any other type of corporate transaction involving a third party, we may share, disclose or transfer user data to the successor entity (even during the pre-transaction phase).

We also inform you that this Privacy Policy only refers to the collection, processing and use of information (relating to personal data) by the Controller. Access to third-party websites that you may access through links from the Platform have their own privacy policies over which we have no control. Therefore, before providing them with any personal information, we recommend that you read their Privacy Policies.

International Data Transfers

Your data is stored and processed primarily within the European Economic Area (EEA).

However, some of our service providers are located in countries outside the European Economic Area ("EEA").

The location of these companies outside the EEA implies the existence of an international transfer of your personal data, which could mean a lower degree of protection than that provided for in European regulations. However, service providers located outside the EEA have a valid mechanism for making international transfers: (i) either they are in a country or territory that has been declared to have an adequate level of protection by the European Commission, in the case of US companies they may be certified under the EU-U.S. Data Privacy Framework Decision (Data Privacy Framework or DPF); or (ii) they have signed the corresponding standard contractual clauses approved by the European Commission ("SCC"), an agreement signed between both entities by which the non-EU company guarantees that it applies European data protection standards.

Therefore, the use of these providers does not result in a lower degree of protection of your personal data than would result from using providers located in the European Union.

You can request copies of the safeguards through help@support.hank.parts.

Your GDPR Rights

The rights that correspond to you as a data subject are as follows:

i. Right to withdraw consent

You can revoke your consent in relation to all processing based on it at any time. However, withdrawal of consent will not affect the lawfulness of processing based on consent prior to its withdrawal.

ii. Right of access

You have the right to know what data is being processed, if applicable and, if so, obtain a copy of it, as well as obtain information regarding:

  • the origin and recipients of the data;
  • the purposes for which it is processed;
  • whether there is an automated decision-making process, including profiling;
  • the data retention period; and
  • the rights provided by regulations.

iii. Right of rectification

You have the right to obtain rectification of your personal data or to complete it when it is incomplete.

iv. Right of erasure

You have the right to request erasure of your personal data if it is no longer necessary for the purpose for which it was collected or, where appropriate, if we are no longer authorized to process it.

v. Right to data portability

You have the right to request data portability in the case of processing of your data that is based on your consent or on the performance of a contract, provided that the processing has been carried out by automated means. In case of exercising this right, you will receive your personal data in a structured format, commonly used and readable by any electronic device. However, you can also request, when possible, that your data be transmitted directly to another company.

vi. Right to restriction of processing of your personal data

You have the right to restriction of processing of your data in the following cases:

  • When you have requested rectification of your personal data during the period in which we verify their accuracy.
  • When you consider that we are not authorized to process your data. In that case, you can request that we restrict their use instead of requesting their erasure.
  • When you consider that it is no longer necessary for us to continue processing your data and you want us to keep them for the purposes of exercising or defending claims.
  • In cases where there is processing based on our legitimate interest and you have exercised your right to object to it, you can ask us to restrict the use of your data during verification of the prevalence of such interests over yours.

vii. Right to object

You have the right to object at any time to processing of your personal data based on our legitimate interest, including profiling.

How to Exercise Your Rights

You can exercise the rights that the law guarantees you in relation to the processing of your personal data by contacting us at the following addresses:

  • help@support.hank.parts
  • Postal mail: hank.parts S. L., Calle Callejoncillo 4, 11130 Chiclana de la Frontera, Cádiz, Spain
  • We will respond to your request within one month (extendable to two months for complex requests)

Right to Complain

If you are not satisfied with our response, you have the right to file a complaint with the competent data protection authority. In the case of Spain:

Spanish Data Protection Agency (AEPD)

C/ Jorge Juan, 6, 28001 Madrid

Tel: 901 100 099 / 912 663 517

Website: www.aepd.es

Electronic office: sedeaepd.gob.es

Rights of Deceased Persons (Spanish Law)

Under Spanish data protection law (LOPDGDD Article 3), the following persons may exercise rights over the data of a deceased user:

  • Persons designated by the deceased for this purpose
  • Heirs or legal representatives
  • Family members

To exercise these rights, contact through help@support.hank.parts with appropriate documentation proving your relationship with the deceased.

Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure or destruction. These include encryption, access controls and regular security assessments.

Cookies and Similar Technologies

We use strictly necessary cookies essential for website operation. These cookies do not require consent as they are essential for service provision under Article 5(3) of the GDPR ePrivacy Directive.

Essential Cookies We Use:

  • Authentication (Hanko JWT): Maintains your login session and identity (expires after 14 days or when you log out)
  • CDN Session (Bunny.net): Optimizes content delivery and caching (expires after session ends)
  • Language preference (i18n): Remembers your language selection (persists until changed)

We do not use marketing, analytics or tracking cookies. If we add such cookies in the future, we will request your explicit consent before placing them.

For more information about cookies and how to manage them, visit: www.aboutcookies.org

Changes to this Policy

We may update this policy from time to time. If we make significant changes, we will notify you through our website or by email.

Contact

If you have questions about our data processing, contact us through help@support.hank.parts.

Our goal is to acknowledge all data protection inquiries within 72 hours and provide a substantive response within the legal period of one month.

Version History

  • October 1st, 2025: Current version