GDPR Privacy Policy
1. Joint Data Controllers (GDPR Art. 26)
In accordance with Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR) and Spanish Organic Law 3/2018 (LOPDGDD), personal data processed on this platform is jointly co-managed by two data controllers:
• Neuro in Business, SL
• Neuroscience and Innovation at Work, SL
Registered Address: Carrer Creu Guixera 49 1-1, 08243 Manresa (Barcelona), Spain.
Data Protection Contact: privacy@whomby.com.
Pursuant to GDPR Article 26, the Joint Controllers have established an internal arrangement determining their respective compliance responsibilities. Users may contact the designated privacy email address as a central point of contact to exercise any data protection rights.
2. Lawful Bases for Processing (GDPR Art. 6)
We process your personal data under the following legitimate bases:
• Contractual Performance (Art. 6.1.b GDPR): Managing authentication, delivering learning paths, tracking progress, grading tests, and issuing verifiable completion badges.
• Legal Obligation (Art. 6.1.c GDPR): Maintaining purchase and invoice records for paid course enrollments in accordance with statutory accounting and tax regulations.
• Legitimate Interests (Art. 6.1.f GDPR): Safeguarding platform integrity, enforcing access allowlists, preventing fraud, and optimizing application performance.
• Consent (Art. 6.1.a GDPR): Serving non-essential analytics cookies and sending optional course updates.
3. Categories of Personal Data Collected
We collect and process the following categories of personal data:
• Identity & Account Data: Name, email address, profile photo (via Google Auth), and unique user identifier (UID).
• Educational Records: Course enrollments, lesson completion status, quiz and exam scores, accumulated learning time, and course feedback.
• Digital Credentials: Open Badges assertions, cryptographic recipient hashes (salted SHA-256), and verification metadata.
• Transaction Metadata: For paid courses, order identifiers, currency, payment amount, and PayPal payer email/ID (payment credentials are handled securely by PayPal and never stored on our servers).
• Technical Telemetry: Essential session cookies, timestamps, and aggregated performance metrics.
4. Third-Party Data Processors & Sub-processors
We partner with trusted service providers who process data on our behalf under active Data Processing Agreements (DPAs):
• Google Cloud / Firebase (EU Region): Authentication, Firestore database, file storage, and hosting infrastructure under an active DPA.
• Google Cloud Vertex AI / Gemini: Generative AI course assistance, translation, and pedagogical structuring.
• PayPal (Europe) S.à r.l. et Cie, S.C.A.: Secure payment processing and checkout validation.
• Cloudflare: Domain name system (DNS) resolution and domain configuration.
5. International Data Transfers & EU Hosting
All primary databases, authentication servers, and application instances are hosted within European Union (EU) data centers. Where technical sub-processors operate outside the European Economic Area (EEA), transfers are safeguarded through European Commission Standard Contractual Clauses (SCCs) and/or adherence to the EU-U.S. Data Privacy Framework (DPF).
6. Data Retention Schedule
Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected:
• User Profile & Learning History: Maintained for the lifetime of your account or until you request account erasure.
• Fiscal & Transaction Records: Retained for 5 years in compliance with Spanish tax and commercial legislation.
• Telemetry & Analytics: Stored in aggregated, anonymized format for a maximum of 14 months.
7. Your Rights under the GDPR (Articles 15–22)
Under European data protection law, you have the following enforceable rights:
• Right of Access (Art. 15): Request a copy of all personal data held about you.
• Right to Rectification (Art. 16): Correct inaccurate or incomplete information in your profile.
• Right to Erasure (Art. 17): Request the permanent deletion of your account and personal data ("Right to be Forgotten").
• Right to Restriction of Processing (Art. 18): Limit the scope of data processing under certain conditions.
• Right to Data Portability (Art. 20): Export your personal data and learning records in a structured JSON format.
• Right to Object (Art. 21): Object to processing based on legitimate interests.
You can exercise these rights directly through the GDPR tools in your User Profile or by emailing privacy@whomby.com. Requests are processed free of charge within 30 days.
8. Right to Lodge a Complaint
If you believe your data protection rights have not been respected, you have the right to lodge a formal complaint with the competent supervisory authority, specifically the Agencia Española de Protección de Datos (AEPD) at www.aepd.es, or the data protection authority in your EU member state of residence.