Privacy Policy
Toty is a brand of the Cantabria Labs Group, which operates in Spain under the name INDUSTRIAL FARMACÉUTICA CANTABRIA, SA
Company name: INDUSTRIAL FARMACEUTICA CANTABRIA, SA
Main office: Calle Arequipa, nº1, 5th floor, 28043 Madrid (Spain).
Registered Office : Solía Neighborhood, 30. La Cocha de Villaescusa, 39690-Cantabria (Spain)
Contact email: contact@toty.com
Registry: Company registered in the Commercial Registry of Cantabria: Book 22 of Companies, Folio 105, Page 1151, 1st Entry
NIF: A-39000914
No personal data is collected from users through this website without their knowledge.
This website may contain links to third-party websites whose privacy policies are separate from those of toty . When you access these websites, you can decide whether to accept their privacy and cookie policies. Generally speaking, if you browse the internet, you can accept or reject third-party cookies from your browser's settings.
Basic information on data protection
Below, we inform you about toty 's data protection policy.
Data controller
Any personal data collected directly from the data subject will be treated confidentially and will be incorporated into the corresponding processing activity of toty .
Purpose
The purpose of data processing corresponds to each of the processing activities carried out by Toty . See each processing activity for more information.
Legitimation
Your data is processed to comply with Toty 's legal obligations, to fulfill contracts, and when the purpose of the processing requires your consent, which must be given through a clear affirmative action. You can consult the legal basis for each of Toty's processing activities by consulting each processing activity.
Data retention
The personal data provided will be retained for the time necessary to fulfill the purpose for which it was collected and to determine any potential liabilities that may arise from that purpose. See each processing activity for more information.
Data communication
You can consult the recipients for each processing activity carried out by toty .
Rights of interested parties
To request access, rectification, deletion or limitation of the processing of personal data or to oppose the processing, if the requirements established in the General Data Protection Regulation are met, as well as in Organic Law 3/2018, of December 5, on the Protection of Personal Data and guarantee of digital rights, you can send a letter to the data controller, in this case, Industrial Farmacéutica Cantabria, SA (Grupo Cantabria Labs), addressing it to Grupo Cantabria Labs (Legal Area), C/Arequipa, 1, 5th floor, 28043 - Madrid or to lopd@cantabrialabs.es
The updated list of processing activities carried out by Toty is as follows:
1.- SENDING COMMERCIAL AND PROMOTIONAL COMMUNICATIONS
Purpose of the treatment :
which includes:
•Sending marketing communications;
•Invitations to events;
•Product routine tests that can help you select the products that best suit your needs;
•Sending product samples;
•Processing and resolution of draws called by toty ;
•Registration and participation in activities promoting and disseminating TOTY .
Legal Basis:
Article 6.1. a) and f) of the GDPR: Consent or execution of the contract.
Likewise, you may revoke your consent to receive commercial communications at any time, through the link or button provided in each of the communications, or by communicating your wish to revoke such consent by contacting Grupo Cantabria Labs, C/Arequipa, 1, 5th floor, 28043 - Madrid or at lopd@cantabrialabs.es
Collective :
Participants, attendees and those interested in Toty products.
Categories of personal data :
Email, first and last name, ID/Tax ID, address, signature, phone number, age range, skincare habits, lifestyle, hobbies, and any questions related to your skin, which will help you find the most suitable products for your needs. Raffle participants: photograph, if applicable. Attendees at events organized by toty : voice and image.
Category of recipients :
Service providers with access to data:
Advertising, marketing, digital media, and social media agencies to help us deliver advertising, marketing, and campaigns, to analyze their effectiveness, and to manage your contact and inquiries;
Postal/delivery services for product/sample delivery;
That help us provide IT services, such as maintenance and support for our databases, as well as for our software and applications that may contain your data;
Third parties that help us provide digital services such as store locator, web analytics, and search engines.
Raffle participants: The winners' first and last names will be available on Toty 's social media channels. Those attending events organized by Toty: The video generated will be published on Toty 's social media channels.
Deletion period:
The personal data of those interested in receiving information about toty products and activities will be kept in the system indefinitely unless the interested party requests its deletion. Participants' personal data will be retained during the prize award process. Videos generated at events organized by toty will be retained indefinitely as long as they remain valid as promotional activities for toty products.
International transfers:
No international transfers of data are planned.
2.- ATTEND AND MANAGE QUERIES ABOUT POSSIBLE ADVERSE EVENTS REGARDING OUR PRODUCTS (HEREINAFTER, "SURVEILLANCE"), WHICH INCLUDES: COSMETICS (COSMETOVIGILANCE) AND FOOD SUPPLEMENTS (MARKET SURVEILLANCE)
Purpose of the treatment :
Surveillance, which includes:
•Investigate the adverse event;
• Contact you to obtain further information about the reported adverse event;
• Compare the information on the adverse event with information on other adverse events received by Toty to comprehensively analyze the safety of its products;
• Submit mandatory reports to national or regional regulatory bodies so that they can comprehensively analyze the safety of Toty products.
Legal Basis :
Toty processes personal data relevant for Surveillance purposes, including special categories of personal data, for the purposes of:
– investigate the adverse event;
– comply with legal obligations arising from applicable laws and regulations on Surveillance and its legitimate interests for Surveillance purposes, considering that
– Surveillance legislation has been enacted for reasons of substantial public interest in the field of public health.
Collective :
Users of our products and
Notifiers (citizens, users, professionals, such as beauty professionals, as well as health professionals in Pharmacy, Medicine, Nursing, Dentistry, etc.)
Categories of personal data :
In compliance with our Oversight obligations, we may share or disclose personal data:
- within the Cantabria Labs Group, to analyse and process a reported adverse event;
– with the competent regulatory bodies, in relation to suspected adverse events;
– with third-party service providers of the Cantabria Labs Group, such as security database providers, call center operators, and, if you have reported your suspected adverse reaction to our sales representatives, the relevant sales network services company. We maintain appropriate data protection safeguards with those service providers with whom the Cantabria Labs Group shares personal data and who perform services or tasks on our behalf;
– with other pharmaceutical companies that maintain marketing, distribution, or other licensing agreements with the Cantabria Labs Group, if the Oversight obligations relating to a Toty product require such sharing of safety information. Please note that we maintain appropriate data protection safeguards with those business partners with whom the Toty Group shares personal data and who perform services or tasks on our behalf;
– with a third party in the event of the sale, assignment or transfer of a particular Toty product, in which case we would require the transferee or beneficiary of the transfer to handle the personal data in question in accordance with applicable data protection legislation;
– when publishing information about adverse events (e.g., clinical case studies or summaries). In these cases, we will remove any identifiers from the publication to maintain your confidentiality.
Category of recipients :
In compliance with our Oversight obligations, we may share or disclose personal data:
- within the Cantabria Labs Group, to analyse and process a reported adverse event;
– with the competent regulatory bodies, in relation to suspected adverse events;
– with third-party service providers of the Cantabria Labs Group, such as security database providers, call center operators, and, if you have reported your suspected adverse reaction to our sales representatives, the relevant sales network services company. We maintain appropriate data protection safeguards with those service providers with whom the Cantabria Labs Group shares personal data and who perform services or tasks on our behalf;
– with other pharmaceutical companies that maintain marketing, distribution, or other licensing agreements with the Cantabria Labs Group, if the Oversight obligations relating to a Toty product require such sharing of safety information. Please note that we maintain appropriate data protection safeguards with those business partners with whom the Cantabria Labs Group shares personal data and who perform services or tasks on our behalf;
– with a third party in the event of the sale, assignment or transfer of a particular Toty product, in which case we would require the transferee or beneficiary of the transfer to handle the personal data in question in accordance with applicable data protection legislation;
– when publishing information about adverse events (e.g., clinical case studies or summaries). In these cases, we will remove any identifiers from the publication to maintain your confidentiality.
Deletion period:
We will use and store your personal data in accordance with legally mandated requirements for the retention and reporting of Surveillance information. These requirements oblige us to archive Surveillance information, which may include personal data, at least throughout the product's life cycle and until 10 years have elapsed since the product in question ceases to be marketed.
International transfers:
Toty hosts its Surveillance databases in Spain. However, we may need to transfer your personal data to other members of the Cantabria Labs Group or to external business partners and regulatory bodies. These may be located in countries for which the European Commission has not determined that an adequate level of data protection is guaranteed (hereinafter "third countries"). Whenever we need to transfer your personal data for Surveillance purposes to an external business partner located in a third country, we will apply standard data protection clauses adopted by the European Commission as adequate safeguards.
3.- INTERNAL SYSTEM OF INFORMATION AND DEFENSE OF THE INFORMANT
Purpose of the treatment:
Management of the procedure referred to in Article 9 of Law 2/2023.
Legal Basis:
GDPR: 6.1.c) Processing necessary for compliance with a legal obligation applicable to the data controller.
Law 2/2023, of February 20, regulating the protection of persons who report regulatory violations and combating corruption.
Collective :
Reporting persons, affected persons, and third parties whose personal data are necessary for the management of the procedure referred to in Article 9 of Law 2/2023.
Categories of personal data :
Name and surname, ID/Tax ID, address, phone number, and signature. Other information: as provided in the report.
Category of recipients :
Grupo Cantabria Labs' Compliance Body, composed of luis.salgado@cantabrialabs.es and blanca.riveradealvarado@cantabrialabs.es , is the internal body of Grupo Cantabria Labs responsible for the investigation. Your data may be shared with external advisors, as well as internally within the various areas of Grupo Cantabria Labs involved in the investigation of your case, in accordance with our policies.
Deletion period:
They will be retained for the time necessary to fulfill the purpose for which they were collected and to determine any potential liabilities that may arise from said purpose and the processing of the data.
International transfers :
No international transfers of data are planned.
4.- STAFF SELECTION
Purpose of the treatment :
Staff selection.
Legal Basis :
GDPR: 6.1.b) Processing necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Collective :
Candidates presented for job positions.
Categories of personal data :
Name and surname, ID, address, email and telephone number.
Special categories of data:
health data (disabilities).
Personal characteristics data :
Sex, age, date and place of birth and family data.
Academic and professional data :
Qualifications, training and professional experience.
Detailed employment and career data.
Category of recipients:
Talent and People Department of Grupo Cantabria Labs. Third parties that help us provide IT services, such as platform providers, hosting services, maintenance, and support for our databases, as well as for our software (for example, through the Bizneo application, talent management software at Grupo Cantabria Labs) and applications that may contain your data.
Deletion period :
The data provided will be kept for a period of twenty-four (24) months, provided that you do not request its deletion beforehand and without prejudice to its conservation while the legal obligations applicable to toty persist.
International transfers :
No international transfers of data are planned.
5.- CUSTOMER SERVICE
Purpose of the treatment:
Customer service, which includes: Managing customer relationships, sales visits from our sales team, product deliveries, promotional samples, and corresponding invoicing.
Legal Basis :
Article 6.1. b) of the GDPR: The legitimate basis for this processing is the execution of the (pre)contractual relationship we maintain with our customers, or, where applicable (for example, in the very early stages of our relationship), our legitimate interest in developing a business relationship.
Collective :
Clients: pharmacies, clinics, wholesalers.
Categories of personal data :
Identification details of the client's individual representative: First and last name; National ID/Tax Identification Number; Postal address; Telephone number; Signature. Economic and financial details: Bank details; Billing information.
Category of recipients :
Postal/delivery services; Third parties that help us provide IT services, such as platform providers, hosting services, maintenance, and support for our databases, as well as our software and applications that may contain your data.
Deletion period :
The data will be retained for as long as the contractual legal relationship between the parties persists, without prejudice to its retention while legal obligations affecting Grupo Cantabria Labs persist: commercial data will be retained for 6 years, as established by the Commercial Code.
International transfers :
No international transfers of data are planned.
6.- CLAIMS
Purpose of the treatment :
Complaints, which includes: Addressing and managing your complaints, queries, and requests that you make through the enabled contact channels, such as telephone, email, social media, forms on the Grupo Cantabria Labs website or applications, and any other channel enabled for this purpose.
Legal Basis :
Legitimate interest: To respond to your requests and questions regarding our products.
Collective:
Information collected through surveys about product-related issues and usage; and information collected when you contact us with questions.
Categories of personal data :
First and last name; Phone number; Email address; and Other information you share with us about yourself in relation to your inquiry.
Category of recipients :
Third parties that help us provide IT services, such as platform providers, hosting services, maintenance, and support for our databases, as well as our software and applications that may contain your data.
Deletion period:
They will be retained for the time necessary to fulfill the purpose for which they were collected and to determine any potential liabilities that may arise from said purpose and the processing of the data.
International transfers :
No international transfers of data are planned.
7.- PROFILE PREPARATION
Purpose of the treatment :
Profiling, which includes: Improving our websites/apps; Monitoring and improving our apps and devices; Analyzing your wellness characteristics and recommending appropriate products and routines; Providing you with product and routine recommendations.
Legal Basis: Legitimate interest: To ensure our websites/apps remain secure, to help us better understand your needs and expectations and therefore improve our services, products, and brands.
Collective :
Through the use of Grupo Cantabria Labs applications or devices.
Categories of personal data :
First and last name; Gender; Email address; Phone number; Date of birth or age range; Photo; Wellness data, including skin tone, skin/hair type, etc.; Personal description or preferences; Social media profile (where you use social login or share this personal information with us).
Category of recipients:
Third parties who help us provide IT services, such as platform providers, hosting services, maintenance, and support for our databases, as well as for our software and applications that may contain your data; advertising, marketing, digital media, and social media agencies to help us deliver advertising, marketing, and campaigns, analyze their effectiveness, and manage your contacts and inquiries.
Deletion period :
The personal data of users of our websites/applications will be kept in the system indefinitely unless the user requests its deletion.
International transfers :
No international transfers of data are planned.
8.- ALLOW THE OPERATION OF OUR WEBSITE/APPLICATIONS THROUGH TECHNICAL AND FUNCTIONAL COOKIES
Purpose of the treatment :
Enabling our website/apps to function through technical and functional cookies, including: Proper display of content; Creating and remembering your login; Customizing the interface, such as language; Parameters attached to your device, including screen resolution, etc.; Improving our websites/apps; Ensuring the website or app is safe and secure; Preventing visitors from being saved twice.
Legal Basis:
Legitimate interest: To ensure that we provide you with websites/apps that function properly and to continually improve cookies that (i) are essential to the operation of our websites/apps (ii) are used to keep our websites/apps secure.
Collective :
Information collected by cookies or similar technologies as part of your browsing experience on the Cantabria Labs website/applications.
For information about specific cookies hosted on a particular website or application, please refer to the cookie settings center and the Cookie Policy for that website.
Categories of personal data :
Data related to your use of applications or websites; Data related to the website you came from; Login details; Pages you visited; Videos you watched; Ads you clicked on; Products you searched for; and Length of your visit. Technical information: IP address; Browser information; Device information.
Category of recipients :
Third parties that help us provide IT services, such as platform providers, hosting services, maintenance, and support for our databases, as well as our software and applications that may contain your data.
Deletion period :
The personal data of users of our websites/applications will be retained in the system indefinitely unless the user requests its deletion.
International transfers :
No international transfers of data are planned.
9.- INSERTION OF ADVERTISING BASED ON BEHAVIOR
Purpose of the treatment :
Behavioral advertising, which includes: Showing you online ads for products that may be of interest to you based on your past behavior. Showing you ads and content on social media platforms. Sending you recommendations, marketing, or content based on your profile and interests.
Legal Basis :
Consent
Collective :
Information collected by cookies or similar technologies as part of your browsing experience on the Grupo Cantabria Labs website/applications.
For information about specific cookies placed on a particular website or application, please refer to the cookie settings center and the Cookie Policy for that website.
Categories of personal data :
Data related to your use of applications or websites; Data related to the website you came from; Login details; Pages you visited; Videos you watched; Ads you clicked on; Products you searched for; and Length of your visit. Technical information: IP address; Browser information; Device information.
Category of recipients :
When we use Google advertising services on our websites or apps, your data may be collected by Google. If you'd like to learn more about Google's use of your personal data in this context, please refer to the Google Privacy Policy, which covers these advertising services and the corresponding data processing. Third parties that help us provide IT services, such as platform providers, hosting services, maintenance, and support for our databases, as well as our software and apps, may contain data about you.
Deletion period :
The personal data of users of our websites/applications will be retained in the system indefinitely unless the user requests its deletion.
International transfers :
No international transfers of data are planned.
10.- CREATION OF STATISTICS
Purpose of the treatment :
Statistics collection, including: Understanding user reactions to our advertising campaigns. To improve our campaigns. To understand how you found our websites/apps.
Legal Basis :
Legitimate interest: To help us better understand our users' needs and expectations and therefore improve our services, products, and brands.
Collective :
Information collected when you are asked questions via surveys about brands, products, and their use; through your use of Grupo Cantabria Labs applications or devices; user-generated content submitted to any of our social platforms; registration or subscription to games, promotions, offers, or surveys; subscription to newsletters and commercial communications; account creation and management; and information collected through cookies or similar technologies as part of your browsing experience on Grupo Cantabria Labs websites and applications.
For information about specific Cookies placed on a particular website or application, please refer to the cookie settings center and the Cookie Policy for that website.
Categories of personal data :
First and last name or alias; Gender; Email address; Phone number; Photo; Date of birth or age range; ID, username, and password; Wellness data, including skin tone, skin/hair type, etc.; Personal description or preferences; Social media profile (when you use social login or share this personal information); Other information you share with us about yourself (e.g., by contacting us, or by providing your own content such as photos or reviews, or by asking questions via the chat function available on some websites/apps, or by participating in a contest, game, or survey); Data relating to your use of the apps or websites; Data relating to the website you came from; Registration details; Pages you visited; Videos you watched; Ads you clicked on; Products you searched for; Length of your visit. Technical information: IP address; Browser information; Device information.
Category of recipients :
Third parties that help us provide IT services, such as platform providers, hosting services, maintenance, and support for our databases, as well as our software and applications that may contain your data.
Deletion period :
The personal data of users of our websites/applications will be kept in the system indefinitely unless the user requests its deletion.
International transfers :
No international transfers of data are planned.
Last modified: September 16, 2025