Legal
Privacy policy
Last updated: July 2026.
This policy describes how Tarraco App Lab, S.L.U. processes the personal data of the users of this website, in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and Spanish Organic Law 3/2018, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
1. Data controller
- Company name: Tarraco App Lab, S.L.U.
- Tax ID (CIF): (in the process of incorporation)
- Registered address: C/ Pau Claris, 2 - 43005 Tarragona, Spain.
- Contact telephone: (+34) 877 64 12 52
- Privacy and GDPR rights contact: privacidad@tarracoapplab.com
2. What data we process
- Contact data: the data you provide when filling in forms or writing to us (name, email address, phone number and the content of your message).
- Account data: if you access the private client portal, your email address and the technical authentication data; if you sign in with a third-party provider, the basic data from your profile.
- Technical data: IP address, session identifiers and logs necessary for security and operation.
3. Purposes and legal basis
- Handling your request and providing the contracted service — performance of a contract or pre-contractual measures.
- Security and abuse prevention — legitimate interest.
- Analytics and commercial communications — consent (which you can withdraw at any time).
- Applicable legal obligations — legal obligation.
4. Specific processing on the platform
Private client portal
Access to the portal is granted through a single-use code sent to the client’s email address. The code is held temporarily (fifteen minutes) and then destroyed. No passwords are stored.
Learner data provided by the centre
Where a centre, academy or organisation engages GestCampus and enrols its learners (first name, surname, identity document, email address, enrolments, progress, grades and certificates), the centre acts as data controller and GestCampus acts as data processor under the terms of the Data Processing Agreement (DPA), which applies mandatorily. GestCampus does not use that data for its own purposes and does not disclose it to third parties.
Training activity records
The platform records learner progress (logins, connection time, completed activities and assessment results) because it is essential in order to evidence completion of the training to the centre and, where applicable, to the funding body. These records are made available to the responsible centre, not to third parties.
Nature of the service
Training content and issued certificates are the responsibility of the centre delivering them. Where the platform incorporates AI-assisted features, their output is indicative and must be reviewed before use.
5. Recipients and data processors
To deliver the service we rely on the following providers (data processors), with whom the guarantees required by the GDPR are in place:
| Provider | Purpose | Location |
|---|---|---|
| Netlify, Inc. | Hosting of the website and receipt of form submissions. | USA |
| Brevo (Sendinblue SAS) | Delivery of the access emails for the private client portal. | France (EU) |
6. International transfers
Some providers are located outside the European Economic Area (mainly the USA). These transfers are covered by the Standard Contractual Clauses (SCCs) approved by the European Commission and by supplementary measures. You can request information about these safeguards by writing to privacidad@tarracoapplab.com.
7. Retention
Data will be retained for as long as necessary to fulfil the stated purposes, to meet legal obligations or to resolve incidents and claims. Indicative retention periods by type of data:
- Portal access codes: fifteen minutes; automatically destroyed after use or expiry.
- Client account: for as long as the contractual relationship lasts; closing the account entails cascade deletion of the associated data.
- Learner data provided by the centre: for as long as the centre keeps the service engaged. On termination it is returned or deleted at the centre’s choice, within a maximum of 90 calendar days, except for retention the centre itself must comply with under its own regulations.
- Training activity records and certificates: for as long as the centre needs them to evidence completion and, where applicable, for the period required by the body funding the training.
- Contact form data: for as long as necessary to handle the enquiry and, where applicable, to respond to subsequent claims.
- Accounting and invoicing data: in accordance with applicable tax and commercial legislation (generally 6 years).
- Server technical logs: limited retention, 30 days by default on Netlify.
8. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to privacidad@tarracoapplab.com. You may also withdraw your consent at any time and lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) if you consider that your request has not been addressed.
9. Security
We apply the following technical and organisational measures appropriate to the risk of the processing, in accordance with Art. 32 GDPR:
- Encryption in transit: TLS 1.2 / 1.3 mandatory on all communications. HSTS enabled. Cookies with Secure and SameSite=Lax flags.
- Encryption at rest: AES-256 on the database and file storage.
- Access control: passwordless access via a single-use code expiring after fifteen minutes. Strict separation of each centre’s data. Administrative access with multi-factor authentication and least-privilege principle.
- Secrets management: credentials and keys kept out of the codebase, in the provider’s encrypted environment variables.
- Backups: automatic backups with retention according to the provider’s policy.
- Staff confidentiality: personnel with access to systems sign a perpetual confidentiality undertaking and receive periodic data protection training.
- Activity logging: server technical logs with limited retention (30 days by default on Netlify).
- Analysis and testing: continuous review of dependencies (lockfiles, vulnerability alerts) and penetration testing whenever a critical component is introduced.
Reporting of security breaches
In the event of a personal data breach that may pose a risk to the rights and freedoms of data subjects, we will act in accordance with Articles 33 and 34 GDPR:
- Notification to the AEPD: within a maximum of 72 hours of becoming aware of the breach, stating the nature of the breach, the categories and approximate number of data subjects, the measures taken and the likely consequences.
- Communication to data subjects: where the breach is likely to result in a high risk, individual notification by email without undue delay.
- Notice to the responsible centre: where the breach affects learner data, the centre will be notified within a maximum of 48 hours so that it can meet its own notification obligations.
- Internal record: every breach, whether or not notifiable, is recorded together with its analysis and the corrective measures adopted.
Users who detect or suspect a security incident can report it by writing to privacidad@tarracoapplab.com with the subject «Security breach».
Data Processing Agreement (DPA)
Where a centre uses GestCampus to process personal data of third parties (its learners, teaching staff or employees), the centre acts as data controller and GestCampus acts as data processor under the terms of the Data Processing Agreement (DPA), which forms an integral part of the service terms and is deemed accepted upon using the platform for those purposes.
Data of a specially sensitive nature
Do not request or send specially sensitive data (racial origin, health, beliefs, trade union membership, etc.) unless strictly necessary and supported by an appropriate legal basis. If such data is sent by mistake, contact us immediately so that it can be deleted.
10. Changes to this policy
We may update this policy to reflect legal or service changes. The current version will always be published on this page.
This English version is provided for information purposes. In the event of any discrepancy, the Spanish version shall prevail.