Legal Information & Policies

Review the legal terms, data privacy practices, and cookie policies governing HoiPoi Learning.

Last Updated: September 4, 2026
Legal Entity & Data Protection Info
Joint Controllers (Art. 26 GDPR)Neuro in Business, SL & Neuroscience and Innovation at Work, SL
Registered OfficeCarrer Creu Guixera 49 1-1, 08243 Manresa (Barcelona), Spain
Privacy Point of Contactprivacy@whomby.com

GDPR Privacy Policy

1. Joint Data Controllers (GDPR Art. 26)

In accordance with Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR) and Spanish Organic Law 3/2018 (LOPDGDD), personal data processed on this platform is jointly co-managed by two data controllers: • Neuro in Business, SLNeuroscience and Innovation at Work, SL Registered Address: Carrer Creu Guixera 49 1-1, 08243 Manresa (Barcelona), Spain. Data Protection Contact: privacy@whomby.com. Pursuant to GDPR Article 26, the Joint Controllers have established an internal arrangement determining their respective compliance responsibilities. Users may contact the designated privacy email address as a central point of contact to exercise any data protection rights.

2. Lawful Bases for Processing (GDPR Art. 6)

We process your personal data under the following legitimate bases: • Contractual Performance (Art. 6.1.b GDPR): Managing authentication, delivering learning paths, tracking progress, grading tests, and issuing verifiable completion badges. • Legal Obligation (Art. 6.1.c GDPR): Maintaining purchase and invoice records for paid course enrollments in accordance with statutory accounting and tax regulations. • Legitimate Interests (Art. 6.1.f GDPR): Safeguarding platform integrity, enforcing access allowlists, preventing fraud, and optimizing application performance. • Consent (Art. 6.1.a GDPR): Serving non-essential analytics cookies and sending optional course updates.

3. Categories of Personal Data Collected

We collect and process the following categories of personal data: • Identity & Account Data: Name, email address, profile photo (via Google Auth), and unique user identifier (UID). • Educational Records: Course enrollments, lesson completion status, quiz and exam scores, accumulated learning time, and course feedback. • Digital Credentials: Open Badges assertions, cryptographic recipient hashes (salted SHA-256), and verification metadata. • Transaction Metadata: For paid courses, order identifiers, currency, payment amount, and PayPal payer email/ID (payment credentials are handled securely by PayPal and never stored on our servers). • Technical Telemetry: Essential session cookies, timestamps, and aggregated performance metrics.

4. Third-Party Data Processors & Sub-processors

We partner with trusted service providers who process data on our behalf under active Data Processing Agreements (DPAs): • Google Cloud / Firebase (EU Region): Authentication, Firestore database, file storage, and hosting infrastructure under an active DPA. • Google Cloud Vertex AI / Gemini: Generative AI course assistance, translation, and pedagogical structuring. • PayPal (Europe) S.à r.l. et Cie, S.C.A.: Secure payment processing and checkout validation. • Cloudflare: Domain name system (DNS) resolution and domain configuration.

5. International Data Transfers & EU Hosting

All primary databases, authentication servers, and application instances are hosted within European Union (EU) data centers. Where technical sub-processors operate outside the European Economic Area (EEA), transfers are safeguarded through European Commission Standard Contractual Clauses (SCCs) and/or adherence to the EU-U.S. Data Privacy Framework (DPF).

6. Data Retention Schedule

Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected: • User Profile & Learning History: Maintained for the lifetime of your account or until you request account erasure. • Fiscal & Transaction Records: Retained for 5 years in compliance with Spanish tax and commercial legislation. • Telemetry & Analytics: Stored in aggregated, anonymized format for a maximum of 14 months.

7. Your Rights under the GDPR (Articles 15–22)

Under European data protection law, you have the following enforceable rights: • Right of Access (Art. 15): Request a copy of all personal data held about you. • Right to Rectification (Art. 16): Correct inaccurate or incomplete information in your profile. • Right to Erasure (Art. 17): Request the permanent deletion of your account and personal data ("Right to be Forgotten"). • Right to Restriction of Processing (Art. 18): Limit the scope of data processing under certain conditions. • Right to Data Portability (Art. 20): Export your personal data and learning records in a structured JSON format. • Right to Object (Art. 21): Object to processing based on legitimate interests. You can exercise these rights directly through the GDPR tools in your User Profile or by emailing privacy@whomby.com. Requests are processed free of charge within 30 days.

8. Right to Lodge a Complaint

If you believe your data protection rights have not been respected, you have the right to lodge a formal complaint with the competent supervisory authority, specifically the Agencia Española de Protección de Datos (AEPD) at www.aepd.es, or the data protection authority in your EU member state of residence.
HoiPoi Learning - Whomby Test