1. Data controller
The controller of your personal data, and owner of this website for the purposes of Spanish Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE), is:
- Legal entity name
- Eterea
- Tax ID (NIF / CIF)
- Z0271987V
- Registered address
- C. Pedro Miguel Hernández Camacho, 41, 38760 Los Llanos, Santa Cruz de Tenerife (Spain)
- Trading name
- Eterea — Cultura del Movimiento
- Data protection contact
- eterea.palma@gmail.com
- Websites
- www.eterea.art (information site) and app.eterea.art (booking app)
We are not required to appoint a Data Protection Officer under Article 37 GDPR or Article 34 LOPDGDD. Enquiries are handled directly at the email address above.
2. Scope and applicable law
This policy covers two distinct services:
- The information website (www.eterea.art), which presents the disciplines, the founder's training and the ways to get in touch. No registration is required.
- The booking app (app.eterea.art), where members create an account, book classes, buy class credits and manage their subscription.
We process your data in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), with Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD) and, as regards electronic communications, with the LSSI-CE.
3. Data, purposes and lawful bases
We only process the data we need in order to provide the service. This is everything we collect and why:
| Data | Purpose | Lawful basis |
|---|---|---|
| Name and email address | Creating and authenticating your member account in the booking app | Performance of a contract (Art. 6(1)(b) GDPR) |
| Email address, name and profile picture from your Google account (only if you choose "Sign in with Google") | Authenticating you without a password and completing your member profile | Performance of a contract (Art. 6(1)(b)) and your express choice of that sign-in method (Art. 6(1)(a)) |
| Bookings, class attendance, purchased class credits, subscription status and member preferences | Managing bookings, tracking available credits and organising each class group | Performance of a contract (Art. 6(1)(b)) |
| Stripe customer id and purchase and subscription records. We never see or store card numbers | Charging class credits and subscription fees, issuing receipts and handling refunds | Performance of a contract (Art. 6(1)(b)) and compliance with accounting and tax obligations (Art. 6(1)(c)) |
| Email address | Sending transactional email from reservas@eterea.art: booking confirmations and reminders, schedule changes, payment notices | Performance of a contract (Art. 6(1)(b)) |
| Email address | Sending studio news, workshops and offers, only if you have expressly subscribed | Your consent (Art. 6(1)(a) GDPR and Art. 21 LSSI-CE), withdrawable at any time |
| Technical data: IP address, access logs and security events | Keeping the service available and preventing unauthorised access, fraud and abuse | Our legitimate interest in the security of our systems (Art. 6(1)(f)) |
| Whatever you tell us when you write to us by email, WhatsApp or Instagram | Answering your enquiry and, where relevant, booking your first class | Pre-contractual steps at your request (Art. 6(1)(b)) or our legitimate interest in replying (Art. 6(1)(f)) |
Health data
No health data is required in order to register, book a class or pay: you can use the service without giving us any.
There are two ways you may nonetheless choose to tell us. The personalised-routine order form in the app includes an optional "Injuries or limitations" field, and you may voluntarily tell us about an injury, a pregnancy or a physical limitation so that we can adapt the exercises. In both cases we process that information for that purpose only and on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you can withdraw at any time by writing to us.
Mandatory data
The fields marked as required in the app's forms are indispensable for creating your account and managing your bookings. Without them we cannot provide the service.
4. Google user data
"Sign in with Google" is an optional sign-in method for the booking app. You can equally register with an email address and a password.
When you choose it, Eterea requests only the following scopes from Google:
openid— the identifier of your Google account.email— your email address.-
profile— basic profile information: name and profile picture.
This data is used solely to create and authenticate your Eterea member account, to display your name in the app and to send you the transactional email related to your bookings.
Eterea does not request or receive access to Gmail, Google Drive, Google Calendar, Google Contacts or any other Google service. We do not read, write or store any content from your Google account beyond the three scopes listed above.
Eterea's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We do not sell this data or disclose it for advertising purposes.
- We do not use it for advertising or for building profiles.
- We do not use it to develop, improve or train generalised artificial intelligence models.
- We do not allow humans to read it, except with your express consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised.
- We do not transfer it to third parties other than the processors listed in section 6.
You can revoke Eterea's access to your Google account at any time at myaccount.google.com/permissions. Revoking access prevents future Google sign-ins but does not by itself delete your Eterea account: for that, exercise your right to erasure as described in section 9.
5. Where the data comes from
The data comes directly from you: you provide it when you register, book a class, buy class credits or write to us. The only exceptions are the basic profile information passed to us by Google if you choose to sign in with your Google account, and the data Stripe returns to us after a purchase: the customer id and the status of the transaction or subscription.
We do not buy data sets and we do not obtain your data from public sources or third parties.
6. Recipients and processors
We do not sell your data and we do not share it with third parties for advertising purposes. To operate, the app and the website rely on technology providers that act as processors on Eterea's behalf, under contracts compliant with Article 28 GDPR:
| Provider | What for | What data | Location |
|---|---|---|---|
| Clerk, Inc. | Authentication and account management | Name, email address and, if you use Google Sign-In, the email address, name and profile picture of the Google account | USA |
| Convex, Inc. | Application database | Bookings, class attendance, purchased class credits, subscription status and preferences | USA |
| Stripe Payments Europe, Ltd. (Stripe, Inc. group) | Payment and subscription processing | Card data, handled directly by Stripe; Eterea only keeps the customer id and the purchase record | Ireland, with access from the USA |
| Resend, Inc. | Transactional email delivery from reservas@eterea.art | Name, email address and message content | USA |
| Vercel, Inc. | Hosting for the website and the app | Technical connection data and access logs | USA, with a global delivery network |
| Google Ireland Limited | Google Sign-In (optional) and delivery of the website's web fonts | Account identifier, email address and basic profile; IP address when the fonts are loaded | Ireland, with access from the USA |
| SuperSaaS B.V. | Booking widget linked from the information website | Whatever you enter in its booking form | Netherlands (EU) |
In addition, your data may be disclosed to banks in order to process payments, to the Spanish Tax Agency and other public authorities where there is a legal obligation, and to our accountants for invoicing purposes.
7. International transfers
Some of the providers above (Clerk, Convex, Resend, Vercel and the US parent companies of Stripe and Google) are established in the United States or may access the data from there. Those transfers are covered by the Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR), supplemented by additional technical measures such as encryption in transit and at rest. Some of these providers are also self-certified under the EU-U.S. Data Privacy Framework, the subject of the European Commission's adequacy decision of 10 July 2023.
You may request a copy of the safeguards in place by writing to eterea.palma@gmail.com.
8. Retention periods
- Member account and profile: for as long as the account is active. If you ask to close it, we delete the account and block the associated data.
- Bookings and class attendance: for the duration of the relationship and thereafter until contractual claims become time-barred (5 years, Art. 1964 of the Spanish Civil Code).
- Invoicing, payments and subscriptions: 6 years from the last entry (Art. 30 of the Spanish Commercial Code) and 4 years for tax purposes (Art. 66 of the General Tax Act).
- Consent for marketing communications: until you withdraw it or unsubscribe.
- Technical and security logs: 12 months at most.
- Enquiries by email, WhatsApp or Instagram: one year from the last interaction, unless they lead to a contractual relationship.
Once those periods elapse, the data is securely deleted or irreversibly anonymised.
9. Your rights
The GDPR and the LOPDGDD grant you the following rights over your personal data:
- Access: to know what data of yours we process and obtain a copy of it.
- Rectification: to have inaccurate data corrected or incomplete data completed.
- Erasure ("right to be forgotten"): to have your data deleted when it is no longer necessary.
- Restriction of processing: to have us keep the data but stop using it while a claim is resolved.
- Portability: to receive your data in a structured, commonly used format, or to have us send it to another controller.
- Objection: to object to processing based on our legitimate interest, including objecting to marketing communications.
- Withdrawal of consent at any time, without affecting the lawfulness of processing carried out beforehand.
How to exercise them
Write to eterea.palma@gmail.com with "Data protection" in the subject line, saying which right you wish to exercise. To verify your identity, send the request from the email address linked to your account or attach a copy of your identity document. Exercising these rights is free of charge.
We will reply within one month of receiving the request, extendable by two further months if the request is complex, in which case we will let you know.
Complaint to the supervisory authority
If you believe we have not handled your request properly, or that our processing breaches the rules, you can lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD):
- Website
- www.aepd.es
- Postal address
- C/ Jorge Juan, 6 — 28001 Madrid, Spain
- Telephone
- +34 901 100 099 / +34 91 266 35 17
Before complaining, feel free to come to us first: we will try to sort it out with you.
10. Automated decision-making
We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, and we do not build profiles for advertising purposes. The app applies simple automatic rules — such as deducting a credit when a booking is confirmed, or releasing a place when a booking is cancelled — which are the direct execution of the terms of service.
11. Information security
We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR): HTTPS/TLS encryption of traffic, access to the app's back office restricted to the studio staff who need it, passwords managed by our authentication provider (Eterea never stores your password in clear text), and card processing delegated to Stripe, a PCI-DSS Level 1 certified provider.
Should a security breach occur that poses a high risk to your rights, we will inform you without undue delay and notify the AEPD in accordance with Articles 33 and 34 GDPR.
12. Minors
Under Article 7 of the LOPDGDD, children under 14 years of age may not create an account themselves. For the children's classes, the account is created and managed by the parent or legal guardian, who accepts this policy and provides only the child's data strictly necessary for the booking.
If we find that an account for a child under 14 has been created without the authorisation of the holder of parental responsibility, we will delete it.
13. Cookies and third-party resources
The www.eterea.art website sets no first-party analytics or advertising cookies and uses no tracking or profiling tools.
The app.eterea.art booking app uses strictly necessary technical cookies only, managed by the authentication provider, to keep you signed in. Such cookies are exempt from the prior consent requirement under Article 22(2) LSSI-CE.
The website loads resources hosted by third parties — Google Fonts web fonts, Font Awesome icons and, where applicable, the SuperSaaS booking widget. When they load, your browser discloses your IP address and basic device information to those providers. You can prevent this by blocking those domains in your browser.
14. Changes to this policy
We may update this policy to reflect legal or technical changes, or changes in the services we use. The version in force will always be published at this same address, with the date of the last update in the header. If a change materially affects how we process your data, we will notify you by email before it takes effect.
Last updated: 14 August 2026.