Data Protection Policy

PERSONAL DATA PROTECTION

This is the data protection policy of EUMES Girona S.L. It is based on the principles of the Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016 (General Data Protection Regulation) and of the Organic Law 3/2018, of 5 December, on the protection of personal data and guarantee of digital rights (LOPDGDD).

Controller of personal data processing

EUMES Girona S.L. (hereinafter EUMES)

CIF B55134449

Carrer Galligants, 6 17007, Girona

972 241 010, eumes@eumes.cat.

Data Protection Officer

The Data Protection Officer (DPO) oversees compliance with our data protection policy, ensuring that personal data are handled appropriately and that individuals’ rights are protected. Among their duties is to address any questions, suggestions, complaints or claims from the persons whose data are processed. The Data Protection Officer can be contacted in writing at our postal address and telephone number, or directly by email at protecciodades@eumes.cat.

Purposes of the processing of personal data

EUMES processes personal data for various purposes, primarily to provide teaching services, send information about activities and services, and maintain commercial relationships with our suppliers.

Academic management. EUMES processes students’ data to provide them with educational services. The data provided and those resulting from teaching activity form the basis for assessment. Students’ data are also used for administrative management, to send information of interest and to process and issue certificates or diplomas.

Contact. We process data to respond to enquiries from people who use the contact forms on our website. They are used solely for that purpose.

Information about activities and services. With the explicit authorisation of each student, once their studies are completed we use their contact details to send information about our services and activities.

Management of our suppliers’ data. We record and process the data of suppliers from whom we obtain services or goods. We process only the data necessary to maintain the commercial relationship, we use them solely for that purpose and for the normal uses inherent to that type of relationship.

Other channels for obtaining data. We obtain data through in-person interactions and other channels such as receiving emails or via our social media profiles. In all cases the data are used only for the explicit purposes that justify their collection and processing.

User experience analysis. We use behaviour analysis tools (such as Microsoft Clarity) to visualise how users interact with the website (clicks, mouse movements, time on page). This information is used exclusively to optimise the design and functionality of our site.

Collection of personal data

In the previous section we referred to some of the sources of the data we process. In most cases the data come directly from the data subjects, and we obtain them mainly via the forms provided for that purpose. In training activities organised in agreement with other institutions, the data may come from the co-organising institution.

Legal basis for the processing of personal data

The data processing activities we carry out have different legal bases, depending on the nature of each processing operation.

For the provision of educational services. Once admitted, our students receive educational services from EUMES. The processing of their data begins with the consent of the data subject, and is carried out in fulfilment of a contractual relationship (provision of services) and in compliance with legal obligations.

In fulfilment of a pre-contractual relationship. This is the case for the data of people interested in EUMES’s educational offer with whom we establish initial contact. For other reasons but with a similar legal basis, we process data of potential clients or suppliers with whom we have prior relations before formalising a contractual relationship.

In fulfilment of a contractual relationship. This is the case for relationships with our suppliers and all actions and uses of data that these commercial relations entail.

In compliance with legal obligations. In compliance with tax regulations we disclose data to the tax authorities. It would also be in compliance with legal obligations that we would disclose data to judicial bodies or to law enforcement agencies if required.

On the basis of consent. When we send information about our activities or services we use contact details with the explicit consent of the recipient.

Disclosure of personal data

As a general rule we only disclose data to comply with legal obligations. In the preceding sections we explained disclosures of students’ data, necessary to enable the provision of educational services, and of our clients’ and suppliers’ data, in the conduct of economic and commercial relations.

For the recognition of completed studies and issuance of diplomas students’ data are disclosed to university institutions. In compliance with legal requirements they are disclosed to insurance entities, and to banking entities for payment purposes. For the placement of internships they are disclosed to host companies or institutions. This is done with the student’s consent.

Data transfers outside the European Union (international transfers) are carried out when required by the international mobility of students.

Data transfers outside the European Union are made as a result of the use of technological services provided by suppliers located in the United States (such as Microsoft Corporation). These transfers are made under the protection of the Standard Contractual Clauses approved by the European Commission, ensuring that the provider applies security and privacy levels equivalent to those in Europe.

Access to personal data by other companies and institutions

EUMES assigns teaching to specialists in the subjects included in the curricula and teaching plans. Instructors receive information about their obligations under data protection law and formalise their commitment to process data appropriately.

On the other hand, EUMES obtains services from private companies that provide experience and specialisation. On some occasions these external companies must access personal data. We only contract services from companies that guarantee compliance with data protection regulations. At the time of contracting, these companies’ confidentiality obligations are formalised and their performance is monitored. For example, certain data may reside on servers contracted from specialised companies or must be processed by firms that provide IT support.

Likewise, the website uses third-party analytics services such as Microsoft Advertising and Microsoft Clarity. Microsoft may collect or receive personal data from your interaction with the website to provide statistical reports and for its own commercial and advertising purposes. You can consult how Microsoft uses these data in its Privacy Statement.

Retention period for personal data

The retention period for data is determined by the specific purpose of each processing operation. They are also kept to respond to possible requests from public authorities or judicial bodies. Consequently we retain data for the time necessary to preserve their legal or informational value and to demonstrate EUMES’s compliance with obligations, but not for a period longer than necessary for the purposes of the processing. In the case of information that certifies students’ completed training, the data are retained permanently to preserve those students’ rights.

In certain cases, such as data appearing in accounting documentation and invoicing, fiscal regulations require retention until the liabilities in these matters expire.

In the case of data processed solely on the basis of the data subject’s consent, they are retained until that person withdraws their consent.

Regulations governing the retention of public records, and the opinions of qualification committees, are a determining reference when deciding on the retention or deletion of data related to the provision of services of public interest.

Data collected through Microsoft Clarity cookies have a retention period of 12 months.

Rights of individuals regarding personal data

As provided by the General Data Protection Regulation, persons whose data we process have the following rights:

To know if their data are processed. Anyone has, first of all, the right to know whether we process their data, regardless of whether there has been a prior relationship.

To be informed at the time of collection. When personal data are obtained from the data subject directly, at the moment of providing them they must receive clear information about the purposes for which they will be used, who will be the data controller and the main aspects arising from that processing.

To access them. A broad right that includes knowing precisely which personal data are being processed, the purpose for which they are processed, the disclosures to other parties that will be made (if any) or the right to obtain a copy or to know the expected retention period.

To request rectification. This is the right to have inaccurate data we process corrected.

To request erasure. In certain circumstances there is the right to request deletion of data when, among other reasons, they are no longer necessary for the purposes for which they were collected and justified.

To request restriction of processing. Also in certain circumstances there is the right to request restriction of data processing. In that case they will cease to be processed and will only be retained for the exercise or defence of claims, in accordance with the General Data Protection Regulation.

Right to portability. In cases provided for by the regulations, there is the right to obtain one’s own personal data in a structured, commonly used, machine-readable format, and to transmit them to another data controller if the data subject so decides.

To object to processing. A person may object for reasons related to their particular situation, in which case their data will cease to be processed to the extent that it may cause them harm, except for legitimate reasons or the exercise or defence of claims.

Not to receive information. We immediately comply with requests to stop receiving information about our activities and services, when such mailings were based solely on the recipient’s consent.

Exercise and defence of rights

The rights we have just listed may be exercised by submitting a request to EUMES at the postal address or the other contact details indicated at the heading.

If a satisfactory response has not been obtained in the exercise of rights, it is possible to file a complaint with the Spanish Data Protection Agency, using the forms or other channels accessible from its website (www.agpd.es).

In all cases, whether to file complaints, request clarifications or send suggestions, you can contact the Data Protection Officer by email at protecciodades@eumes.cat.

Would you like more information?

Write to us and let’s talk!

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.