Privacy policy
Last updated: 20 August 2026.
1. Data controller
- Controller: Asociación Uniting Souls
- Tax ID (NIF): G01863752
- Address: Rambla Francesc Macià, 18, 7.º B, 08226 Terrassa (Barcelona), Spain
- Privacy contact email: hola@asociacionunitingsouls.com
- Telephone: 653 022 042
2. Applicable principles
The Association will process data lawfully, fairly and transparently; only for specified purposes; limiting data to what is necessary; keeping it up to date; retaining it only for as long as strictly necessary; and applying appropriate security and confidentiality measures.
3. Processing activities
| Processing activity | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Contact | Name, email, phone, interest and message. | Responding to enquiries and managing requests. | Pre-contractual steps, legitimate interest in handling enquiries or consent, as the case may be. | During handling and for the subsequent legal periods. |
| Newsletter | Email and preferences. | Sending news, events and content. | Consent. | Until consent is withdrawn; blocked during legal periods. |
| Members and memberships | Identification, contact details, membership type, payments, access and communications. | Processing admission, the membership relationship and associated benefits. | Membership/contractual relationship, legal obligation and consent for optional purposes. | For the duration of the relationship and the applicable legal, tax and liability periods. |
| Supporters | Identification, contact details and request. | Managing free participation and requested information. | Consent or steps requested by the individual. | While participating or until unsubscribing; legal periods. |
| Volunteering | Identification, contact details, availability, training and necessary documentation. | Selecting, onboarding and managing volunteers. | Pre-contractual steps, volunteer agreement and legal obligations. | During the programme and legal periods. |
| Events and courses | Registration, attendance, payment, needs communicated and image if authorised. | Organisation, safety, invoicing and certification. | Contract, legal obligation, vital interest where applicable and consent for images or other optional purposes. | During the activity and the tax/legal periods. |
| Professional directory | Profile, credentials, speciality and professional contact details. | Assessing applications and publishing authorised profiles. | Contractual/membership relationship and consent for optional data or publication where applicable. | During participation and until withdrawal or cancellation. |
| Circle Community | Account, profile, activity and shared content. | Providing the community, courses, groups and support. | Performance of the relationship and, where applicable, consent. | While the account exists and in accordance with legal periods and the platform’s settings. |
| Invoicing and payments | Identification, address, transaction and tax data; full card details are handled by the payment gateway. | Collecting payments, invoicing, preventing fraud and meeting obligations. | Contract and legal obligation. | Applicable tax, accounting and prevention periods. |
| Website security | IP address, technical logs, device and security events. | Ensuring operation and security and preventing abuse. | Legitimate interest and security obligations. | A limited period according to security needs. |
4. Mandatory data and accuracy
Fields marked as mandatory are necessary to manage the request or provide the service. Users guarantee that the data provided is accurate, complete and up to date and must report any relevant changes.
5. Electronic communications
The Association will send promotional communications only where there is a valid legal basis. Each communication will offer a simple, free way to unsubscribe. Withdrawing consent does not affect the lawfulness of prior processing.
6. Recipients and processors
Data may be processed by providers needed to deliver the services, such as web hosting, email, forms, community management, payments, accounting, support, videoconferencing, security, distribution of communications and consented analytics (including Hostinger as hosting provider, Circle as community platform, and ThriveCart with Stripe as the payment gateway for memberships). These providers will act, according to their role, as data processors or independent controllers.
Data may also be disclosed to public authorities, courts, financial institutions, insurers or other recipients where there is a legal obligation, or where necessary to perform a relationship or defend rights.
7. International transfers
Where a provider processes data outside the European Economic Area or allows access from third countries —as may be the case with Circle and other US providers—, the Association will apply a mechanism recognised by law, such as an adequacy decision, standard contractual clauses or another valid safeguard, and will provide additional information where necessary.
8. Rights
Data subjects may request access to their data, rectification, erasure, restriction, objection and portability where applicable, as well as withdraw their consent and not be subject to decisions based solely on automated processing with legal or similarly significant effects where applicable.
To exercise these rights, you may write to hola@asociacionunitingsouls.com or to the postal address indicated, identifying your request and providing only the information necessary to verify your identity. If you consider that the processing does not comply with the law, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos): www.aepd.es.
9. Minors
The services are not generally aimed at minors unless an activity expressly states otherwise. In Spain, where processing is based on consent, minors under the age of 14 require the authorisation of the person holding parental authority or guardianship. Activities involving minors will be subject to specific information and measures.
10. Images and testimonials
Identifiable images, videos or testimonials will be published on an appropriate legal basis and, where applicable, with specific authorisation. Refusing to authorise promotional uses will not affect access to an activity where the image is not necessary to provide it.
11. Security and breaches
The Association applies technical and organisational measures appropriate to the risk. If a security breach occurs, it will act in accordance with the law and notify the supervisory authority and the affected individuals where required.
12. Updates
This Policy may be updated due to legal, technical or organisational changes. The date of the latest review will appear at the top and, where the change is significant, it will be communicated by appropriate means.