Eterea Logo Eterea
Inicio Sobre Nosotros Disciplinas Certificaciones Contacto

Last updated: 14 August 2026

Privacy Policy

This policy explains what personal data we process on the www.eterea.art website and in the app.eterea.art booking app, for what purposes and on what lawful basis, who we share it with, how long we keep it, and how you can exercise your rights.

This is a courtesy translation. The Spanish version is the binding one in case of discrepancy.

← Back to home Leer en español

Contents

  1. Data controller
  2. Scope and applicable law
  3. Data, purposes and lawful bases
  4. Google user data
  5. Where the data comes from
  6. Recipients and processors
  7. International transfers
  8. Retention periods
  9. Your rights
  10. Automated decision-making
  11. Information security
  12. Minors
  13. Cookies and third-party resources
  14. Changes to this policy

1. Data controller

The controller of your personal data, and owner of this website for the purposes of Spanish Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE), is:

Legal entity name
Eterea
Tax ID (NIF / CIF)
Z0271987V
Registered address
C. Pedro Miguel Hernández Camacho, 41, 38760 Los Llanos, Santa Cruz de Tenerife (Spain)
Trading name
Eterea — Cultura del Movimiento
Data protection contact
eterea.palma@gmail.com
Websites
www.eterea.art (information site) and app.eterea.art (booking app)

We are not required to appoint a Data Protection Officer under Article 37 GDPR or Article 34 LOPDGDD. Enquiries are handled directly at the email address above.

2. Scope and applicable law

This policy covers two distinct services:

  • The information website (www.eterea.art), which presents the disciplines, the founder's training and the ways to get in touch. No registration is required.
  • The booking app (app.eterea.art), where members create an account, book classes, buy class credits and manage their subscription.

We process your data in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), with Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD) and, as regards electronic communications, with the LSSI-CE.

3. Data, purposes and lawful bases

We only process the data we need in order to provide the service. This is everything we collect and why:

Data Purpose Lawful basis
Name and email address Creating and authenticating your member account in the booking app Performance of a contract (Art. 6(1)(b) GDPR)
Email address, name and profile picture from your Google account (only if you choose "Sign in with Google") Authenticating you without a password and completing your member profile Performance of a contract (Art. 6(1)(b)) and your express choice of that sign-in method (Art. 6(1)(a))
Bookings, class attendance, purchased class credits, subscription status and member preferences Managing bookings, tracking available credits and organising each class group Performance of a contract (Art. 6(1)(b))
Stripe customer id and purchase and subscription records. We never see or store card numbers Charging class credits and subscription fees, issuing receipts and handling refunds Performance of a contract (Art. 6(1)(b)) and compliance with accounting and tax obligations (Art. 6(1)(c))
Email address Sending transactional email from reservas@eterea.art: booking confirmations and reminders, schedule changes, payment notices Performance of a contract (Art. 6(1)(b))
Email address Sending studio news, workshops and offers, only if you have expressly subscribed Your consent (Art. 6(1)(a) GDPR and Art. 21 LSSI-CE), withdrawable at any time
Technical data: IP address, access logs and security events Keeping the service available and preventing unauthorised access, fraud and abuse Our legitimate interest in the security of our systems (Art. 6(1)(f))
Whatever you tell us when you write to us by email, WhatsApp or Instagram Answering your enquiry and, where relevant, booking your first class Pre-contractual steps at your request (Art. 6(1)(b)) or our legitimate interest in replying (Art. 6(1)(f))

Health data

No health data is required in order to register, book a class or pay: you can use the service without giving us any.

There are two ways you may nonetheless choose to tell us. The personalised-routine order form in the app includes an optional "Injuries or limitations" field, and you may voluntarily tell us about an injury, a pregnancy or a physical limitation so that we can adapt the exercises. In both cases we process that information for that purpose only and on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you can withdraw at any time by writing to us.

Mandatory data

The fields marked as required in the app's forms are indispensable for creating your account and managing your bookings. Without them we cannot provide the service.

4. Google user data

"Sign in with Google" is an optional sign-in method for the booking app. You can equally register with an email address and a password.

When you choose it, Eterea requests only the following scopes from Google:

  • openid — the identifier of your Google account.
  • email — your email address.
  • profile — basic profile information: name and profile picture.

This data is used solely to create and authenticate your Eterea member account, to display your name in the app and to send you the transactional email related to your bookings.

Eterea does not request or receive access to Gmail, Google Drive, Google Calendar, Google Contacts or any other Google service. We do not read, write or store any content from your Google account beyond the three scopes listed above.

Eterea's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We do not sell this data or disclose it for advertising purposes.
  • We do not use it for advertising or for building profiles.
  • We do not use it to develop, improve or train generalised artificial intelligence models.
  • We do not allow humans to read it, except with your express consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised.
  • We do not transfer it to third parties other than the processors listed in section 6.

You can revoke Eterea's access to your Google account at any time at myaccount.google.com/permissions. Revoking access prevents future Google sign-ins but does not by itself delete your Eterea account: for that, exercise your right to erasure as described in section 9.

5. Where the data comes from

The data comes directly from you: you provide it when you register, book a class, buy class credits or write to us. The only exceptions are the basic profile information passed to us by Google if you choose to sign in with your Google account, and the data Stripe returns to us after a purchase: the customer id and the status of the transaction or subscription.

We do not buy data sets and we do not obtain your data from public sources or third parties.

6. Recipients and processors

We do not sell your data and we do not share it with third parties for advertising purposes. To operate, the app and the website rely on technology providers that act as processors on Eterea's behalf, under contracts compliant with Article 28 GDPR:

Provider What for What data Location
Clerk, Inc. Authentication and account management Name, email address and, if you use Google Sign-In, the email address, name and profile picture of the Google account USA
Convex, Inc. Application database Bookings, class attendance, purchased class credits, subscription status and preferences USA
Stripe Payments Europe, Ltd. (Stripe, Inc. group) Payment and subscription processing Card data, handled directly by Stripe; Eterea only keeps the customer id and the purchase record Ireland, with access from the USA
Resend, Inc. Transactional email delivery from reservas@eterea.art Name, email address and message content USA
Vercel, Inc. Hosting for the website and the app Technical connection data and access logs USA, with a global delivery network
Google Ireland Limited Google Sign-In (optional) and delivery of the website's web fonts Account identifier, email address and basic profile; IP address when the fonts are loaded Ireland, with access from the USA
SuperSaaS B.V. Booking widget linked from the information website Whatever you enter in its booking form Netherlands (EU)

In addition, your data may be disclosed to banks in order to process payments, to the Spanish Tax Agency and other public authorities where there is a legal obligation, and to our accountants for invoicing purposes.

7. International transfers

Some of the providers above (Clerk, Convex, Resend, Vercel and the US parent companies of Stripe and Google) are established in the United States or may access the data from there. Those transfers are covered by the Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR), supplemented by additional technical measures such as encryption in transit and at rest. Some of these providers are also self-certified under the EU-U.S. Data Privacy Framework, the subject of the European Commission's adequacy decision of 10 July 2023.

You may request a copy of the safeguards in place by writing to eterea.palma@gmail.com.

8. Retention periods

  • Member account and profile: for as long as the account is active. If you ask to close it, we delete the account and block the associated data.
  • Bookings and class attendance: for the duration of the relationship and thereafter until contractual claims become time-barred (5 years, Art. 1964 of the Spanish Civil Code).
  • Invoicing, payments and subscriptions: 6 years from the last entry (Art. 30 of the Spanish Commercial Code) and 4 years for tax purposes (Art. 66 of the General Tax Act).
  • Consent for marketing communications: until you withdraw it or unsubscribe.
  • Technical and security logs: 12 months at most.
  • Enquiries by email, WhatsApp or Instagram: one year from the last interaction, unless they lead to a contractual relationship.

Once those periods elapse, the data is securely deleted or irreversibly anonymised.

9. Your rights

The GDPR and the LOPDGDD grant you the following rights over your personal data:

  • Access: to know what data of yours we process and obtain a copy of it.
  • Rectification: to have inaccurate data corrected or incomplete data completed.
  • Erasure ("right to be forgotten"): to have your data deleted when it is no longer necessary.
  • Restriction of processing: to have us keep the data but stop using it while a claim is resolved.
  • Portability: to receive your data in a structured, commonly used format, or to have us send it to another controller.
  • Objection: to object to processing based on our legitimate interest, including objecting to marketing communications.
  • Withdrawal of consent at any time, without affecting the lawfulness of processing carried out beforehand.

How to exercise them

Write to eterea.palma@gmail.com with "Data protection" in the subject line, saying which right you wish to exercise. To verify your identity, send the request from the email address linked to your account or attach a copy of your identity document. Exercising these rights is free of charge.

We will reply within one month of receiving the request, extendable by two further months if the request is complex, in which case we will let you know.

Complaint to the supervisory authority

If you believe we have not handled your request properly, or that our processing breaches the rules, you can lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD):

Website
www.aepd.es
Postal address
C/ Jorge Juan, 6 — 28001 Madrid, Spain
Telephone
+34 901 100 099 / +34 91 266 35 17

Before complaining, feel free to come to us first: we will try to sort it out with you.

10. Automated decision-making

We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, and we do not build profiles for advertising purposes. The app applies simple automatic rules — such as deducting a credit when a booking is confirmed, or releasing a place when a booking is cancelled — which are the direct execution of the terms of service.

11. Information security

We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR): HTTPS/TLS encryption of traffic, access to the app's back office restricted to the studio staff who need it, passwords managed by our authentication provider (Eterea never stores your password in clear text), and card processing delegated to Stripe, a PCI-DSS Level 1 certified provider.

Should a security breach occur that poses a high risk to your rights, we will inform you without undue delay and notify the AEPD in accordance with Articles 33 and 34 GDPR.

12. Minors

Under Article 7 of the LOPDGDD, children under 14 years of age may not create an account themselves. For the children's classes, the account is created and managed by the parent or legal guardian, who accepts this policy and provides only the child's data strictly necessary for the booking.

If we find that an account for a child under 14 has been created without the authorisation of the holder of parental responsibility, we will delete it.

13. Cookies and third-party resources

The www.eterea.art website sets no first-party analytics or advertising cookies and uses no tracking or profiling tools.

The app.eterea.art booking app uses strictly necessary technical cookies only, managed by the authentication provider, to keep you signed in. Such cookies are exempt from the prior consent requirement under Article 22(2) LSSI-CE.

The website loads resources hosted by third parties — Google Fonts web fonts, Font Awesome icons and, where applicable, the SuperSaaS booking widget. When they load, your browser discloses your IP address and basic device information to those providers. You can prevent this by blocking those domains in your browser.

14. Changes to this policy

We may update this policy to reflect legal or technical changes, or changes in the services we use. The version in force will always be published at this same address, with the date of the last update in the header. If a change materially affects how we process your data, we will notify you by email before it takes effect.

Last updated: 14 August 2026.

Eterea Logo Eterea
Email
Política de Privacidad · Privacy Policy (EN)

© 2025 Eterea. Developed by Hugo Nguyen