This English version is provided for convenience only. If it differs from the Spanish version, the Spanish version prevails.
1. Parties and purpose
In accordance with article 28 of the GDPR, this document governs how Uelta SLU (the “Processor”) processes personal data on behalf of the Customer (the “Controller”) when providing the Uelta service. It forms part of the terms of service and lasts as long as they do.
2. Nature of the processing and data
- Purpose: managing bookings, online and till sales, customers, signed documents, team and venue operations.
- Operations: collection, recording, storage, consultation, modification, sending the emails configured by the Controller, and erasure.
- Data subjects: the Controller’s customers and participants (including minors whose data is provided by their guardians) and the Controller’s employees.
- Types of data: identification and contact details, bookings and purchases, signed documents and consents, and any other data the Controller requests in its forms. The Controller must not collect special categories of data through the platform unless it has a legal basis to do so and informs the Processor.
3. Processor’s obligations
- Process the data only on the Controller’s documented instructions, including those given when configuring the platform.
- Ensure that the persons authorised to process the data are bound by a confidentiality commitment.
- Apply the technical and organisational measures of article 32 of the GDPR: HTTPS encryption, hashed passwords, encrypted credentials, access control by role and by venue, and backups.
- Assist the Controller in responding to data subjects’ rights and, where applicable, in impact assessments and prior consultations.
- Notify the Controller, without undue delay and at most within 48 hours, of any personal data breach of which it becomes aware, with the information available.
- Make available to the Controller the information necessary to demonstrate compliance and allow reasonable audits.
- Inform the Controller immediately if it considers that an instruction infringes data protection regulations.
4. Sub-processors
The Controller gives the Processor general authorisation to use the following sub-processors, with which it has contracts offering the same guarantees:
- Hostinger International Ltd.: server hosting and email delivery. Server location: Union Europea.
- Google Ireland Limited: only if the Customer or its users use “Sign in with Google”.
If the Processor wishes to add or replace a sub-processor, it will give 30 days’ notice and the Controller may object on reasonable grounds.
5. Controller’s obligations
The Controller warrants that it has a legal basis for the data it processes, that it has informed data subjects as the law requires, and that it correctly configures its legal texts and forms.
6. End of the engagement
When the service ends, the Processor will allow the Controller to export its data for 30 days and will then delete it together with its copies, except for data it must keep by law.