Internal Information System (I.I.S.)

01

What is it?

It is the channel provided by GILMAR to informants so they can report breaches or infringements that have occurred or are occurring within a work-related or professional context.

02

Breaches or infringements that can be reported through the I.I.S.

Breaches or infringements related to the following matters may be reported:

  • European Union law in relation to public procurement and awarding of contracts; services, products and financial markets; prevention of money laundering and terrorist financing; safety and compliance of products marketed in the EU; transport safety; environmental protection; protection against radiation and nuclear safety; food and feed safety, animal safety and welfare; public health; consumer protection; protection of privacy and personal data, as well as security in networks and information systems.
  • Criminal law.
  • Administrative law, where the infringement is classified as serious or very serious.
  • Prevention of Money Laundering and Terrorist Financing.
  • GILMAR internal policies and rules.
  • Employment matters related to safety, health, harassment and equality at work.
  • Data protection.
03

Who the GILMAR Internal Information System is intended for

The Internal Information System is intended for public employees, employees, self-employed persons, shareholders, members of the management, administration or supervisory body (including non-executive members), volunteers, interns and trainees, candidates, former employees and any other person working for or under the supervision and direction of contractors and subcontractors or any other third party who maintains a relationship with GILMAR within a work-related or professional context. When using the GILMAR Internal Information System, these persons will be considered Informants.

04

Guarantees of the GILMAR Internal Information System

  • Accessibility: breaches can be reported in different ways, including the option to report anonymously or with identification, at the Informant’s choice.
  • Confidentiality and data protection: confidentiality will be maintained at all times.
  • Effectiveness: all Informant reports received through GILMAR’s IIS will be handled so that the organisation is the first to be made aware of them.
  • Objectivity and impartiality: reports will always be handled objectively and impartially, regardless of who makes the report and/or who it concerns, without privileges or differences.
  • Presumption of innocence: the presumption of innocence, the right of defence and the safeguarding of the right to honour of the parties affected by the report are guaranteed.
  • No retaliation: GILMAR prohibits and guarantees that no retaliation may be taken against Informants acting in good faith.
  • Transparency: information will be provided to the Informant upon request, as well as to the affected person(s) regarding the status of the investigation.
05

Rights of the informant

  • Not to suffer retaliation for reporting, or for the facts reported, when acting in good faith.
  • To receive acknowledgement of receipt of the report within a period not exceeding seven calendar days from receipt.
  • To receive a response regarding investigative actions within a maximum period of three months, extendable by a further three months depending on the complexity of the investigation.
  • To request further information.
  • To request to be informed — or not to be further informed — about the status of the procedure.
  • To submit the report in the modality they choose, either identified or anonymously.
  • To have their rights regarding personal data protection respected.
  • To have all guarantees of the Internal Information System respected.
06

Rights of the person affected by the report

  • To be informed about the progress of the investigation.
  • To be informed of the facts attributed to them in the report in an understandable manner.
  • To appear as many times as they wish, upon written request, during the investigation; to provide information; to make statements; or to request investigative steps within the legally permitted limits.
  • To be accompanied by a lawyer and/or workers’ representative.
  • To have their personal data protection rights respected.
07

Channels to report breaches

Each type of breach is handled through a different channel:

  • Breaches related to data protection must be reported to the data protection channel: gdpr@gilmar.es.
  • Breaches related to employment matters and harassment/equality must be reported to the Human Resources channel: rrhh@gilmar.es.
  • Breaches related to the Prevention of Money Laundering and Terrorist Financing must be reported via the AML channel: prevencionblanqueo@gilmar.es.
  • All other breaches must be reported via the compliance channel: manuel.orduna@gilmar.es.
08

Ways to submit a report

The GILMAR Internal Information System allows Informants to submit reports through five different modalities:

  • In-person meeting: at the GILMAR headquarters located at Calle Goya 47, 6th floor, 28001, Madrid.
  • Online (Teams): by requesting it via email to manuel.orduna@gilmar.es.
  • Telephone: 630 966 022.
  • Post: Calle Goya 47, 6th floor, 28001, Madrid.
  • Email: to the addresses specified above.
09

Personal data protection rights

The GILMAR Internal Information System complies with data protection legislation. Both the identity of the informant and the person affected by the reported information will be protected and, in any case, kept confidential. The same applies to any personal data included in the report and throughout the investigation. Access to identity and personal data contained in the GILMAR Internal Information System will be limited to the following persons, within the scope of their duties and responsibilities:

  • The Head of the Internal Information System and whoever manages it.
  • Head of Human Resources.
  • Head of Data Protection Security.
  • Data processors, where the system or part of it is outsourced.

Nevertheless, processing of data by persons other than those listed above, or even disclosure to third parties, shall be lawful where necessary to adopt corrective measures within the entity or to process sanctioning or criminal proceedings, where applicable.
Specific information regarding the processing of personal data within the Internal Information System is as follows:
Data Controller: CONSULTING INMOBILIARIO GILMAR, S.A., Tax ID A-28894194, with registered address at Calle Goya 47, 6th floor, 28001, Madrid.

Purpose and legal basis: personal data are processed to manage reports submitted by informants and, where appropriate, to investigate facts that may indicate breaches or infringements of (i) EU law, (ii) criminal or administrative law (serious or very serious infringements), (iii) GILMAR’s AML/CTF prevention system, (iv) breaches of GILMAR internal regulations, (v) matters relating to safety, health, harassment and equality at work, and (vi) data protection. The legal basis is the legal obligation arising from Articles 6(1)(c) of Regulation (EU) 2016/679 and Article 8 of Organic Law 3/2018 of 5 December, as well as Article 11 of Organic Law 7/2021 of 26 May and Article 10 of Law 2/2023 of 20 February.

Recipients: your data will not be transferred except where required by law, and will be sent as appropriate to State Security Forces and Corps, the Administration of Justice and/or the competent Public Administration.

Retention period: reports, personal data and other information provided by the informant will be kept for a maximum period of three months, unless the investigation is extended for a further three months, totalling six months. Where the purpose of retention is to evidence the operation of the Internal Information System, blocking will be applied as provided for in Organic Law 3/2018. In the case of anonymous reports, these will be recorded only in anonymised form.

Data subject rights: the informant may exercise rights of access, erasure, rectification, objection, restriction of processing, data portability, and the right to withdraw consent by contacting the Data Protection Security Officer at gdpr@gilmar.es. They may also lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).

You can consult further data protection information in GILMAR’s Privacy Policy: https://www.gilmar.es/en/privacy-policy/.

10

External Reporting Channel of the Independent Whistleblower Protection Authority (I.W.P.A.)

The Informant may also submit a report directly to the Independent Whistleblower Protection Authority (I.W.P.A.), the authority responsible for managing the External Reporting Channel. Regardless of whether the authority has been established in Madrid, you may use the reporting channel provided by the Community of Madrid, called the “Whistleblower Channel”, accessible via: https://comunidad.madrid/transparencia/canal-delinformante.

The Informant may also contact State Security Forces and Corps (National Police, Guardia Civil, Municipal Police, etc.) or the competent judicial authority.

Private area

Your account information