PRIVACY POLICY

Privacy Policy. Protection of Personal Data under the GDPR

Investigación Tecnología y Educación Nuevos Medios, S.L., in application of current regulations regarding the protection of personal data, informs that the personal data collected through the forms on the website: https://itenlearning.com/ are included in the automated files specific to users of the services of Investigación Tecnología y Educación Nuevos Medios, S.L.

The collection and automated processing of personal data aims to maintain the commercial relationship and to perform tasks related to information, training, advice, and other activities inherent to Investigación Tecnología y Educación Nuevos Medios, S.L.

These data will only be shared with entities necessary solely to fulfill the purpose described above.

Investigación Tecnología y Educación Nuevos Medios, S.L. takes the necessary measures to guarantee the security, integrity, and confidentiality of the data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and the free movement of such data, repealing the previous LOPD, and the new Organic Law 3/2018, of December 5, on Data Protection and Guarantee of Digital Rights (LOPDGDD).

The user may at any time exercise the rights of access, opposition, rectification, cancellation, limitation, and portability recognized in the aforementioned Regulation (EU). These rights can be exercised by the user via email at: itenlearning@itenlearning.com or at the address: Avd. De Dolores 11, C.P. 03203 – Elche (Alicante), for which we may request documentation proving their identity if necessary.

Data Protection Officer Contact Information: GRUPO ATICO34 SL LOPD-GDD@ATICO34.COM

The user declares that all data provided by them is true and correct and commits to keeping it updated, communicating any changes to Investigación Tecnología y Educación Nuevos Medios, S.L.

Purpose of the processing of personal data:

For what purpose will we process your personal data?

At Investigación Tecnología y Educación Nuevos Medios, S.L., we will process your personal data collected through the website: https://itenlearning.com/ for the following purposes:

  1. To comply with the company’s commercial, labor, corporate, and accounting obligations.
  2. To provide services according to the specific needs of clients in order to fulfill the contracts signed.
  3. For security or fraud prevention purposes.
  4. To provide the information requested by the user through any of the contact channels available on the website.

The fields in these records are mandatory; it is impossible to carry out the purposes expressed without providing this data.

How long are the personal data collected retained?

The personal data provided will be retained as long as the commercial relationship exists or until the user requests its deletion, and during the period during which legal liabilities may arise from the services provided. Likewise, we will retain your data as long as you do not object to the processing.

Legal Basis

The processing of your data is carried out on the following legal bases that legitimize it:

  • Performance of a contract or adoption of pre-contractual measures for managing the provision of the service, including administrative management.
  • Compliance with legal obligations to fulfill the legal, fiscal, accounting, or administrative obligations applicable to Tecnología y Educación Nuevos Medios, S.L.
  • For the use of non-essential cookies, prior, free, informed, and explicit consent from the user will be requested. The user may revoke this consent at any time.
  • Legitimate interest to address the request and/or inquiry submitted through any of the enabled contact channels, as well as for fraud prevention and website security.

Source of Data and Method of Collection

The personal data we process has been provided directly by you. If you provide data belonging to other people, you guarantee that you have their express consent and have informed them of the contents of this Policy. Likewise, you release us from any liability arising from the failure to comply with this obligation.

Recipients and International Data Transfers

As a general rule, data will not be disclosed to additional third parties, except in the following cases:

  • Where required by law, when disclosure is mandated by applicable legislation (Tax Authorities, State Security Forces and Corps, judicial bodies, or other competent authorities).
  • To service providers acting as data processors in accordance with Article 28 of the GDPR, with whom the corresponding Data Processing Agreements have been executed to ensure compliance with applicable data protection legislation.

In this regard, we inform you that, as a result of the cloud computing services provided by Google, data may be transferred to service providers located outside the European Economic Area, specifically to Google LLC, located at 1600 Amphitheatre Parkway, Mountain View, California 94043 (USA), which provides website hosting services. We further inform you that Google LLC is certified under the EU-US Data Privacy Framework (information available at: https://www.dataprivacyframework.gov/s/participant-search ) and also relies on Standard Contractual Clauses adopted by the European Commission.

However, we inform you that the servers on which we deploy the technological infrastructure of our online software are located in Google Cloud (Belgium, Europe).

We also use OVH services for the hosting and management of our servers. The service is contracted with OVH Hispano, S.L., located at C/ Alcalá 21, 5th Floor, 28014 Madrid (Spain), a subsidiary of OVH SAS (2 rue Kellermann, 59100 Roubaix, France), the parent company of the OVHcloud Group. When contracting the service, we selected that our data be hosted in data centres located within the European Union.

However, please note that OVHcloud may use, for certain support, maintenance, or remote administration tasks, subprocessors belonging to the OVHcloud Group that are located outside the European Economic Area (EEA). For such transfers, OVH SAS and its subsidiaries have entered into the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as an appropriate safeguard pursuant to Article 46 of the GDPR, supplemented, where appropriate, by additional technical and organisational measures.

You may consult the updated list of OVHcloud subprocessors, as well as further information regarding the location of its data centres and the applicable safeguards, at: https://www.ovhcloud.com/es/personal-data-protection/ and https://www.ovhcloud.com/es/personal-data-protection/subprocessors/

Accuracy of Personal Data

If you do not provide your data or provide it incorrectly or incompletely, we will not be able to process your request, making it impossible to provide the requested information or carry out the contracted services.

The data subject guarantees that the provided data is truthful, accurate, complete, and up-to-date. You will inform us of any changes to the provided data through the channels indicated in the header of this policy.

Data Collected by Users of the Services

If the user uploads files containing personal data to shared hosting servers, Investigación Tecnología y Educación Nuevos Medios, S.L. is not responsible for the user’s non-compliance with the GDPR.

Intellectual Property Rights https://itenlearning.com/

Investigación Tecnología y Educación Nuevos Medios, S.L. owns all copyright, intellectual and industrial property, know-how, and all other rights related to the content of the website https://itenlearning.com/ and its offered services, as well as the software required for implementation and related information.

Reproduction, publication, and/or non-strictly private use of the content, in whole or in part, is not permitted without prior written consent.

Intellectual Property of Software

Users must respect third-party programs made available by Investigación Tecnología y Educación Nuevos Medios, S.L., even if they are free or publicly available.

Investigación Tecnología y Educación Nuevos Medios, S.L. holds the exploitation and intellectual property rights of the software.

Users acquire no rights or licenses through the contracted service over the software necessary for service provision, nor over technical information for monitoring the service, except for the rights and licenses necessary to fulfill the contracted services, and only for their duration.

For any actions beyond contract fulfillment, users must obtain written authorization from Investigación Tecnología y Educación Nuevos Medios, S.L., and are prohibited from accessing, modifying, or viewing server configurations, structures, and files, assuming civil and criminal liability for any incidents resulting from negligent or malicious actions.

Intellectual Property of Hosted Content

Use contrary to intellectual property laws regarding services provided by Investigación Tecnología y Educación Nuevos Medios, S.L. is prohibited, particularly:

  1. Use that violates Spanish law or infringes third-party rights.
  2. Publication or transmission of content deemed violent, obscene, abusive, illegal, racist, xenophobic, or defamatory.
  3. Use of cracks, program serial numbers, or any content violating third-party intellectual property rights.
  4. Collection or use of personal data from other users without express consent or in violation of EU Regulation 2016/679 (GDPR).
  5. Use of domain email servers for unsolicited mass emailing.

Users are fully responsible for their website content, transmitted or stored information, hyperlinks, third-party claims, and legal actions regarding intellectual property, third-party rights, and child protection. 

Users are also responsible for compliance with applicable laws, online service regulations, e-commerce rules, copyright, public order, and universal Internet usage principles.

Users will indemnify Investigación Tecnología y Educación Nuevos Medios, S.L. for expenses arising from legal claims attributable to the user, including fees and legal defense costs, even if a judicial decision is not final.

Protection of Hosted Information

Investigación Tecnología y Educación Nuevos Medios, S.L. performs backups of the content hosted on its servers; however, it is not responsible for the loss or accidental deletion of data by users. Likewise, it does not guarantee the full restoration of data deleted by users, as such data may have been removed and/or modified during the period since the last backup.

The services offered, except for specific backup services, do not include the restoration of content stored in the backups performed by Investigation Technology and Education New Media, S.L., when such loss is attributable to the user. In such cases, a fee will be determined according to the complexity and volume of the recovery, always subject to prior acceptance by the user.

Restoration of deleted data is only included in the service price when content loss is due to causes attributable to Investigation Technology and Education New Media, S.L.

Commercial Communications

In accordance with the LSSI, Investigación Tecnología y Educación Nuevos Medios, S.L. will not send advertising or promotional communications by email or any equivalent electronic communication means unless previously requested or expressly authorized by the recipients.

For users with whom there is a prior contractual relationship, Investigación Tecnología y Educación Nuevos Medios, S.L. is authorized to send commercial communications regarding products or services similar to those initially contracted by the client.

In all cases, the user may request not to receive further commercial information, once their identity has been verified, through Customer Service channels.

Data Processing by Investigación Tecnología y Educación Nuevos Medios, S.L. as Data Processor

The personal data managed through the systems and services of Investigación Tecnología y Educación Nuevos Medios, S.L. shall be processed by this same entity in its capacity as data processor. The main terms and conditions governing this processing are detailed below.

In order to provide the contracted services, Investigación Tecnología y Educación Nuevos Medios, S.L. shall process personal data on behalf of the client, within the framework of the processing activities under the client’s responsibility, in accordance with the provisions of Article 28 of Regulation (EU) 2016/679 (GDPR).

This agreement authorises Investigación Tecnología y Educación Nuevos Medios, S.L., as data processor, to process, on behalf of the client (data controller), the personal data necessary to provide any of the services contracted by the client.

In this regard, the data for which the client is responsible and to which Investigación Tecnología y Educación Nuevos Medios, S.L. may have access for the provision of these services are as follows:

  • Categories of data subjects: Any category of data subjects that the data controller considers necessary for the proper provision of the service.
  • Types of data: Any category of personal data that the data controller considers necessary for the proper provision of the service.

The processing of this data will mainly involve the collection of data provided by the client, its recording, storage, access and structuring, as well as its destruction once the service has ended. Once destroyed, the data processor, at the request of the data controller, shall certify its destruction in writing and provide the corresponding certificate. In any event, Investigación Tecnología y Educación Nuevos Medios, S.L. may retain a copy, duly blocked, for as long as there remains a possibility that liabilities arising from the service provided may arise.

Investigación Tecnología y Educación Nuevos Medios, S.L. shall only access and process the data in order to fulfil the obligations arising from the contractual relationship, and shall always follow the documented instructions of the client. If any instruction could violate the GDPR or any other applicable data protection legislation, Investigación Tecnología y Educación Nuevos Medios, S.L. shall immediately notify the data controller.

Investigación Tecnología y Educación Nuevos Medios, S.L. and its personnel, duly trained in data protection, are obliged to:

  • Maintain the confidentiality of the information processed and not disclose it to third parties except with the express authorisation of the client or in legally established cases. If an international transfer were required by legal obligation, the client shall be informed in advance, unless legally prohibited.
  • Implement the necessary measures to ensure the confidentiality, integrity, availability and resilience of the systems, restore access to the data in the event of incidents, assess the effectiveness of the measures implemented and, where appropriate, apply techniques such as pseudonymisation and encryption.
  • Maintain an up-to-date record of the processing activities carried out by Investigación Tecnología y Educación Nuevos Medios, S.L. on behalf of the data controller.
  • Cooperate in managing requests for access, rectification, erasure, objection, data portability, restriction of processing and automated decision-making.
  • Notify the client of any personal data breach within a maximum period of 36 hours, so as to enable the client to notify, where applicable, the supervisory authority or the data subjects.
  • Assist the client, where appropriate, in carrying out data protection impact assessments and prior consultations with the supervisory authority.
  • Provide the client with all information necessary to demonstrate compliance with its data protection obligations and allow the client or its authorised auditor to carry out inspections or audits.

For the contracted service, Investigación Tecnología y Educación Nuevos Medios, S.L., in addition to the auxiliary services necessary for the normal operation of the data processor’s services, shall subcontract the following services, which may involve international transfers of data:

  • Web hosting and cloud computing services, provided by Google LLC, with registered office at 1600 Amphitheatre Parkway, Mountain View, California 94043 (USA). In this regard, we inform you that Google LLC is certified under the EU-US Data Privacy Framework (Information available at: https://www.dataprivacyframework.gov/s/participant-search) and also has Standard Contractual Clauses adopted by the European Commission. In particular, the following Google services are used:
    • Google Workspace
    • Google Cloud Platform (GCP)
    • Google Cloud Domains
    • Google Play Store
  • Elastic Cloud: provides us with the deployment and management of our technologies in the cloud. Elastic Cloud works with certain support and infrastructure subprocessors to provide its services. The following list shows the external or internal subprocessors with which they work. In addition, they may transfer data outside national borders. To this end, they implement appropriate safeguards to help protect data when it is processed by their subprocessors, including entering into data processing agreements and approved transfer mechanisms (such as SCCs), as well as implementing supplementary measures. They also have robust processes in place to review the privacy and security controls of all subprocessors that have access to customers’ personal data. Information available at: https://www.elastic.co/es/trust/faq#security
  • Project management tool for the generation of technical documentation, provided by Atlassian Pty Ltd (JIRA). Due to the use of the JIRA tool, data may be transferred outside the European Economic Area, both to companies within the Atlassian group and to third parties with which it collaborates for the proper provision of the service (the list of subprocessors can be consulted at https://www.atlassian.com/es/legal/sub-processors#atlassian-group-sub-processors). In this regard, we inform you that Atlassian is certified under the EU-US Data Privacy Framework and has Standard Contractual Clauses adopted by the European Commission for international transfers of data carried out both to companies within the Atlassian group and to the corresponding subprocessors (information available at https://www.atlassian.com/es/legal/privacy-policy#how-we-transfer-information-we-collect-internationally). In addition, Atlassian has adopted additional technical measures to ensure adequate protection (you can consult the technical and organisational security measures at https://www.atlassian.com/legal/security-measures#program-management).
  • As a result of the use of the HubSpot CRM solution, your data may be transferred to service providers located outside the European Economic Area, specifically to HubSpot, Inc., whose registered office is at Two Canal Park, Cambridge, MA 02141, USA, for the provision of the HubSpot CRM solution for customer management. In this regard, we inform you that HubSpot is certified under the EU-US Data Privacy Framework (Adequacy Decision of 10 July 2023) and also has Standard Contractual Clauses adopted by the European Commission (Information available at: https://legal.hubspot.com/es/dpa).
  • Mailgun Technologies, Inc. for the sending, receipt and tracking of transactional emails, a provider based in the United States that offers a cloud-based transactional email platform.

This service makes it possible to integrate, through an application programming interface (API), the automated sending of emails from our applications and systems, as well as the receipt and monitoring of such messages to verify their delivery, opening or possible incidents. The processing of data by Mailgun is governed by a data processing agreement (Data Processing Addendum – DPA). In the event of international transfers of data outside the European Economic Area, the appropriate safeguards provided for in Regulation (EU) 2016/679 shall apply, such as certification under the EU–U.S. Data Privacy Framework and/or the execution of Standard Contractual Clauses approved by the European Commission. (Further information is available at: https://www.mailgun.com/es/legal/politica-privacidad/)

  • OVH (OVHcloud), for the hosting and management of our servers. The service is contracted with OVH Hispano, S.L., with registered office at C/ Alcalá 21, 5th floor, 28014 Madrid (Spain), a subsidiary of OVH SAS (2 rue Kellermann, 59100 Roubaix, France), the parent company of the OVHcloud group. When contracting the service, we have selected that our data be hosted in data centres located within the European Union. However, we inform you that OVHcloud may, for certain support, maintenance or remote administration tasks, engage subprocessors belonging to the OVHcloud group located outside the European Economic Area (EEA). For such transfers, OVH SAS and its subsidiaries have entered into the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as an appropriate safeguard pursuant to Article 46 of the GDPR, supplemented, where applicable, by additional technical and organisational measures. You can consult the updated list of OVHcloud subprocessors, as well as further information regarding the location of data centres and the applicable safeguards, at: https://www.ovhcloud.com/es/personal-data-protection/ and https://www.ovhcloud.com/es/personal-data-protection/subprocessors/

In the event of new subcontracting arrangements, the client shall be informed in advance, with a minimum of 10 days’ notice, specifying the tasks to be outsourced and the identity of the subcontractor. If the client does not raise any objections within this period, authorisation shall be deemed to have been granted.

Any subcontractor, who shall also be considered a data processor, shall likewise be obliged to comply with the obligations established in this document for the data processor and with the instructions issued by the client (in its capacity as data controller). It shall be the responsibility of the initial data processor to regulate the new relationship so that it is subject to the same conditions (instructions, obligations, security measures, etc.) and the same formal requirements regarding the proper processing of personal data and the safeguarding of the rights of the data subjects. In the event of non-compliance by the subprocessor, the initial data processor shall remain fully liable to the data controller for the fulfilment of its obligations.

Additionally, it shall be the responsibility of the client, as data controller:

  • Provide the data processor with the data necessary for the provision of the service.
  • Where applicable, carry out a data protection impact assessment regarding the processing activities to be carried out by the data processor.
  • Carry out prior consultations as necessary.
  • Ensure compliance with the GDPR by the data processor before and throughout the entire processing period.
  • Supervise the processing, including carrying out inspections and audits.

Confidentiality and Data Security

At Investigación Tecnología y Educación Nuevos Medios, S.L., we value and protect the information you entrust to us. Aware of the importance of privacy and the confidentiality of personal data, we have implemented technical and organizational measures aimed at preserving the security, availability, integrity, and resilience of our systems and processing services. These measures have been designed to provide a level of protection in line with the risks associated with handling personal information. However, it is important to note that no security measure on the Internet is completely infallible; therefore, although we continuously work to protect your data, we cannot guarantee the absolute absence of unauthorized access, cyberattacks, loss, or information leaks.

Privacy Policy Updates

Privacy Policy updated in August 2025. We may modify this policy due to legal, judicial, or commercial changes, always publishing the current version at the same address.