PRIVACY POLICY
This Privacy Policy explains how your personal data is collected, used, stored, and protected when you visit this website, purchase courses, enroll in coaching programs, attend talks or workshops, or otherwise interact with this business.
This policy has been prepared in accordance with EU Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (GDPR), as applied in Spain through Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).
By using this website or engaging with any of the services offered, you agree to the practices described in this Privacy Policy.
1. Data Controller
In accordance with Article 13 of the GDPR, the data controller responsible for processing your personal data is:
CYPHERIAN OFFICIAL
Address: Avenida de los Arces 1, 28042 Madrid, Spain
Email: info@cypherianofficial.com
Website: https://cypherianofficial.com
For any questions or requests relating to how your personal data is handled, please contact us at the email address above.
2. Personal Data We Collect
We may collect and process the following categories of personal data:
2.1 Information you provide directly
- Name and email address when you subscribe to our mailing list or newsletter
- Name, email address, billing address, and payment details when purchasing a course or program
- Name, job title, and company name when registering for a corporate training session, workshop, or talk
- Any information you share when submitting a contact form, booking a discovery call, or communicating with us by email
- Survey or feedback responses if you choose to participate voluntarily
2.2 Information collected automatically
- IP address and browser type when you visit the website
- Pages visited, time spent on site, and referring URLs, collected via analytics tools
- Cookie data (see Section 7 on Cookies below)
We do not process special categories of personal data (sensitive data) as defined in Article 9 of the GDPR.
3. Purposes and Legal Basis for Processing
Your personal data is processed for the following purposes, each supported by the legal basis indicated:
- Performance of a contract: to deliver the coaching, training, or online courses you have purchased or requested (Art. 6.1.b GDPR)
- Performance of a contract: to process payments and send you order confirmations and invoices (Art. 6.1.b GDPR)
- Legitimate interests: to manage and respond to your enquiries and communications (Art. 6.1.f GDPR)
- Consent: to send you marketing emails, newsletters, and updates about our services, where you have given your explicit consent (Art. 6.1.a GDPR). You may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal
- Legal obligation: to comply with applicable accounting, tax, and legal obligations under Spanish law (Art. 6.1.c GDPR)
Your data will not be used for purposes other than those described above without informing you in advance.
4. Recipients of Your Data
We do not sell, transfer, or rent your personal data to third parties. We may share your data with the following trusted service providers, solely for the purpose of delivering the services you have requested:
- Payment processors (e.g. Stripe or PayPal) to handle transactions securely
- Email marketing platforms (e.g. Mailchimp, MailerLite, or similar) to manage communications
- Online course hosting platforms (e.g. Teachable, Kajabi, Thinkific, or similar)
- Website hosting and analytics providers
All third-party providers are bound by contractual obligations and are only permitted to process your data in accordance with our instructions and for the purposes set out in this policy. Where any such provider is located outside the European Economic Area, we ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR.
We may also disclose your data where required to do so by law, court order, or a competent regulatory authority.
5. Data Retention
Your personal data will be retained for the following periods:
- Purchase and transaction records: for a minimum of 5 years, in accordance with Spanish tax and accounting obligations (General Tax Law 58/2003 and the Spanish Commercial Code)
- Marketing and newsletter subscriber data: until you withdraw your consent or request deletion
- Enquiry and correspondence data: for a maximum of 2 years from the last contact, unless an ongoing contractual relationship exists
- Website analytics data: in line with the retention policy of the analytics tool used, typically up to 26 months
Once data is no longer required and no legal retention obligation applies, it will be securely deleted or anonymized.
6. International Data Transfers
Some of our third-party service providers may be based outside the European Economic Area (EEA). In such cases, we ensure that your personal data is transferred only to countries that provide an adequate level of protection, or under appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, in accordance with Articles 44–49 of the GDPR.
7. Cookies
This website uses cookies and similar tracking technologies. Cookies are small text files stored on your device when you visit a web page. We may use the following types of cookies:
- Technical or essential cookies: necessary for the website to function correctly; these do not require your consent
- Analytics cookies: allow us to understand how users interact with the website in order to improve it (e.g. Google Analytics)
- Preference cookies: enable the website to remember your browsing preferences
- Advertising or marketing cookies: used to measure the effectiveness of advertising campaigns, where applicable
In accordance with Law 34/2002 of 11 July on Information Society Services and Electronic Commerce (LSSI-CE), and the guidelines of the Spanish Data Protection Agency (AEPD), we will request your consent before placing any non-essential cookies. You can manage or withdraw your cookie consent at any time via the cookie settings panel on this website or through your browser settings.
For further information, please see our Cookie Policy [link].
8. Your Rights
Under the GDPR and the LOPDGDD, you have the following rights in relation to your personal data:
- Right of access: to request confirmation of whether we process your data and to obtain a copy of it
- Right to rectification: to request correction of inaccurate or incomplete data
- Right to erasure (‘right to be forgotten’): to request deletion of your data where, among other grounds, it is no longer necessary for the purpose for which it was collected
- Right to restriction of processing: to request that we limit the use of your data in certain circumstances
- Right to data portability: to receive your data in a structured, commonly used, machine-readable format
- Right to object: to object to processing based on legitimate interests or carried out for direct marketing purposes
- Right to withdraw consent: where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing
- Right not to be subject to automated decisions: including profiling, except in cases permitted by applicable law
To exercise any of these rights, please send a written request to the email address listed in Section 1, enclosing a copy of your identity document. We will respond within one month, which may be extended by a further two months in cases of particular complexity.
If you believe your data protection rights have not been respected, you have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Espanola de Proteccion de Datos — AEPD), the supervisory authority in Spain, via their website: www.aepd.es.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, alteration, or disclosure, in accordance with Article 32 of the GDPR. These measures include encrypted connections (SSL/TLS), PCI-DSS certified payment processing, and restricted access to personal data.
However, no internet-based transmission system is entirely secure. While we take all reasonable steps to protect your data, we cannot guarantee the absolute security of information transmitted to or from this website.
10. Links to Third-Party Websites
This website may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites. We encourage you to review the privacy policies of any external websites you visit.
11. Minors
Our services are intended for individuals aged 14 and over. In accordance with Article 7 of the LOPDGDD, the processing of personal data of children under the age of 14 requires the consent of a parent or legal guardian. We do not knowingly collect data from children under 14. If you become aware that a minor has provided us with their personal data without the appropriate consent, please contact us and we will take steps to delete it promptly.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we do, we will update the ‘Last updated’ date at the top of this page. We encourage you to review this policy periodically to stay informed about how we protect your personal data.
13. Contact
If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact us at:
CYPHERIAN OFFICIAL
Email: info@cypherianofficial.com
Website: https://cypherianofficial.com
