PRIVACY POLICY
I. PRIVACY POLICY AND DATA PROTECTION
In compliance with current legislation, Inbound Students (hereinafter, also the Website) commits to adopting the necessary technical and organisational measures, appropriate to the level of risk of the data collected.
Laws incorporated into this privacy policy
This privacy policy complies with current Spanish and European regulations on the protection of personal data online. Specifically, it adheres to the following rules:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR).
- Organic Law 3/2018 of 5 December on the Protection of Personal Data and guarantee of digital rights (LOPD-GDD).
- Royal Decree 1720/2007 of 21 December approving the Regulation implementing Organic Law 15/1999 of 13 December on the Protection of Personal Data (RDLOPD).
- Law 34/2002 of 11 July on Information Society Services and Electronic Commerce (LSSI-CE).
Identity of the data controller
The data controller for personal data collected through Inbound Students is: Iolanda Carbone, ID number: Y5653918A (hereinafter, the Data Controller). Contact details:
- Address: Campo de la Estrella 7, L, 6B, 28050 Madrid
- Phone: +34 625 78 19 00
- Email: info@inboundstudents.com
Personal Data Register
In compliance with the GDPR and LOPD-GDD, we inform you that personal data collected by Inbound Students through the forms on its pages will be incorporated into and processed in our records in order to facilitate, streamline and fulfil the commitments established between Inbound Students and the User, or to maintain the relationship established through the forms completed by the User, or to handle requests or enquiries. In accordance with the GDPR and LOPD-GDD, and unless the exception provided for in Article 30(5) of the GDPR applies, a record of processing activities is maintained specifying, by purpose, the processing activities carried out and the other circumstances established in the GDPR.
Principles applicable to the processing of personal data
The processing of the User’s personal data shall be subject to the following principles set out in Article 5 of the GDPR and Articles 4 et seq. of Organic Law 3/2018:
- Principle of lawfulness, fairness and transparency: the User’s consent will always be required following fully transparent information about the purposes for which personal data is collected.
- Principle of purpose limitation: personal data will be collected for specified, explicit and legitimate purposes.
- Principle of data minimisation: only the personal data strictly necessary in relation to the purposes for which it is processed will be collected.
- Principle of accuracy: personal data must be accurate and kept up to date.
- Principle of storage limitation: personal data will only be kept in a form that allows identification of the User for as long as necessary for the purposes of processing.
- Principle of integrity and confidentiality: personal data will be processed in a manner that ensures its security and confidentiality.
- Principle of accountability: the Data Controller shall be responsible for ensuring compliance with all of the above principles.
Categories of personal data
The categories of data processed by Inbound Students are identification data only. Under no circumstances are special categories of personal data processed within the meaning of Article 9 of the GDPR.
Legal basis for the processing of personal data
The legal basis for processing personal data is consent. Inbound Students commits to obtaining the User’s express and verifiable consent for the processing of their personal data for one or more specific purposes.
The User has the right to withdraw consent at any time. Withdrawing consent shall be as easy as giving it. As a general rule, withdrawing consent will not affect the use of the Website.
Where the User must or may provide their data through forms to make enquiries, request information, or for reasons related to the content of the Website, the User will be informed where completion of any field is mandatory, as it may be essential for the correct execution of the requested operation.
Purposes of personal data processing
Personal data is collected and managed by Inbound Students in order to facilitate, streamline and fulfil the commitments established between the Website and the User, or to maintain the relationship established through the forms completed by the User, or to handle requests or enquiries.
Data may also be used for commercial personalisation, operational and statistical purposes, and activities inherent to Inbound Students’ business, as well as for data extraction, storage and marketing studies to tailor the content offered to the User and to improve the quality, performance and navigation of the Website.
At the time personal data is collected, the User will be informed of the specific purpose or purposes for which their personal data will be used.
Personal data retention periods
Personal data will only be retained for the minimum time necessary for the purposes of processing and, in any case, only for the following period: 18 months, or until the User requests its deletion.
At the time personal data is collected, the User will be informed of the period for which their personal data will be retained or, where this is not possible, the criteria used to determine this period.
Recipients of personal data
The User’s personal data will be shared with the following recipients:
- HubSpot, Inc., with registered address at 25 First Street, Cambridge, MA 02141, United States.
- Google LLC, with registered address at 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States.
- ASISA (Asistencia Sanitaria Interprovincial de Seguros, S.A.U.), with registered address at Calle Julián Camarillo, 43, 28037 Madrid, Spain.
- Sanitas, S.A. de Seguros, with registered address at Calle Ribera del Loira, 52, 28042 Madrid, Spain.
- Unión Madrileña de Seguros y Reaseguros, S.A., with registered address at Calle Orense, 4, 28020 Madrid, Spain.
- Telecommunications operators (SIM): depending on the operator contracted by the User.
- DROMO, S.A., with registered address at Rue Madame de Staël 5, 1201 Geneva, Switzerland.
Where the Data Controller intends to transfer personal data to a third country or international organisation, the User will be informed at the time of data collection of the intended destination and of the existence or absence of an adequacy decision by the European Commission.
Personal data of minors
In accordance with Articles 8 of the GDPR and 7 of Organic Law 3/2018, only users aged 14 and over may lawfully provide consent for the processing of their personal data by Inbound Students. For users under 14, parental or guardian consent is required, and processing will only be considered lawful to the extent that such consent has been granted.
Confidentiality and security of personal data
Inbound Students commits to adopting the necessary technical and organisational measures appropriate to the level of risk of the data collected, in order to ensure the security of personal data and prevent its accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.
The Website uses an SSL (Secure Socket Layer) certificate, ensuring that personal data is transmitted securely and confidentially, as all data transmitted between the server and the User is fully encrypted.
However, as Inbound Students cannot guarantee the absolute security of the internet or the complete absence of unauthorised access, the Data Controller commits to notifying the User without undue delay when a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons. As defined in Article 4 of the GDPR, a personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
Personal data will be treated as confidential by the Data Controller, who commits to informing and ensuring through legal or contractual obligations that such confidentiality is upheld by its employees, associates, and any person to whom the information is made accessible.
Rights arising from the processing of personal data
The User has the following rights under the GDPR and Organic Law 3/2018, which may be exercised against the Data Controller:
- Right of access: the right to obtain confirmation of whether Inbound Students is processing personal data and, if so, to obtain information about the specific data and the processing carried out or being carried out, including information about the origin of such data and the recipients of any communications made or intended.
- Right to rectification: the right to have inaccurate or incomplete personal data corrected.
- Right to erasure (“right to be forgotten”): the right, where not precluded by current legislation, to obtain the erasure of personal data when it is no longer necessary for the purposes for which it was collected or processed; when the User withdraws consent and no other legal basis applies; when the User objects to processing and there is no other legitimate reason to continue; when the data has been unlawfully processed; when erasure is required by a legal obligation; or when the data was obtained in connection with the direct provision of information society services to a child under 14.
- Right to restriction of processing: the right to restrict the processing of personal data where the User contests the accuracy of the data; processing is unlawful; the Data Controller no longer needs the data but the User requires it for the establishment, exercise or defence of legal claims; or where the User has objected to processing.
- Right to data portability: where processing is carried out by automated means, the right to receive personal data in a structured, commonly used and machine-readable format, and to transmit it to another controller. Where technically feasible, the Data Controller will transmit the data directly to the other controller.
- Right to object: the right to object to the processing of personal data by Inbound Students.
- Right not to be subject to automated decision-making: the right not to be subject to a decision based solely on automated processing, including profiling, except where permitted by applicable legislation.
To exercise these rights, the User may send a written request to the Data Controller referencing “GDPR – https://inboundstudents.com/“, including:
- Full name and a copy of the User’s ID. Where representation is permitted, identification of the representative and supporting documentation are also required.
- The specific request and its grounds, or the information to which access is sought.
- Address for notifications.
- Date and signature.
- Any supporting documents.
Requests may be sent to:
- Postal address: Campo de la Estrella 7, L, 6B, 28050 Madrid
- Email: info@inboundstudents.com
Links to third-party websites
The Website may include hyperlinks to third-party websites not operated by Inbound Students. Those websites have their own privacy policies, and their owners are solely responsible for their own files and privacy practices.
Complaints to the supervisory authority
If the User believes there is a problem or breach of applicable regulations regarding the processing of their personal data, they have the right to seek effective judicial protection and to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged breach. In Spain, the supervisory authority is the Spanish Data Protection Agency (https://www.aepd.es/).
II. ACCEPTANCE AND CHANGES TO THIS PRIVACY POLICY
The User must have read and agreed to the data protection terms set out in this Privacy Policy, and must consent to the processing of their personal data, in order for the Data Controller to proceed with such processing in the manner, for the periods and for the purposes indicated. Use of the Website implies acceptance of its Privacy Policy.
Inbound Students reserves the right to amend its Privacy Policy at its own discretion or in response to legislative, jurisprudential or regulatory changes issued by the Spanish Data Protection Agency. Changes or updates to this Privacy Policy will not be explicitly notified to the User. Users are advised to review this page periodically to stay informed of the latest changes.
This Privacy Policy was updated to comply with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR), and with Organic Law 3/2018 of 5 December on the Protection of Personal Data and guarantee of digital rights.
