Last updated: September 14, 2026
Legal Notice · Privacy Policy · Terms of Service · Cookie Policy · DPA
This Data Processing Agreement ("DPA") is entered into under Article 28 of the EU General Data Protection Regulation 2016/679 (GDPR) between the Customer ("Controller") and Gabriel Labrada Cary, trade name "alinaflow", NIF Y9661599A, Carrer d'Estruc, 9, 08002 Barcelona, Spain ("Processor"). It forms part of and is incorporated into the Terms of Service. Where they conflict on data protection, this DPA prevails.
The Processor provides the alinaflow platform to the Controller. In doing so, the Processor processes personal data on behalf of and under the documented instructions of the Controller. The Controller determines the purposes and means of the processing and warrants that it has a lawful basis for it, including, where the data concerns minors, any parental consent required.
The processing consists of the operations necessary to provide the Service (storage, organization, retrieval, transmission, and analysis). It lasts for the term of the Terms of Service and until data is deleted or returned as set out below.
Data subjects: the Controller's students, families/guardians, staff, instructors, and contacts.
Personal data: identification and contact details, enrollment and attendance records, communications, and billing and payment history. The Controller must not enter special categories of data (e.g. health) unless strictly necessary and lawful.
The Processor shall: (a) process personal data only on the Controller's documented instructions, including for transfers, unless required by law; (b) ensure persons authorized to process the data are bound by confidentiality; (c) implement the technical and organizational security measures required by Article 32; (d) respect the conditions for engaging sub-processors below; (e) assist the Controller, taking into account the nature of the processing, in responding to data-subject rights requests; (f) assist the Controller with its obligations under Articles 32–36 (security, breach notification, impact assessments); (g) at the Controller's choice, delete or return all personal data at the end of the services and delete existing copies, save where retention is required by law; and (h) make available the information necessary to demonstrate compliance and allow for and contribute to audits.
The Controller grants general authorization for the Processor to engage the sub-processors below. The Processor imposes data-protection obligations on them equivalent to this DPA and remains liable for their performance. We will inform Controllers of intended changes and give them the opportunity to object.
Personal data is hosted on AWS infrastructure in the United States, and some sub-processors are outside the EEA. Transfers of EEA personal data outside the EEA are protected by the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework, as applicable.
The Processor applies appropriate measures under Article 32, including encryption of data in transit and at rest, logical tenant isolation, access controls, logging, and monitoring.
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and provide the information reasonably needed for the Controller to meet its notification obligations.
On termination, the Controller may export its data for 30 days, after which the Processor deletes it and existing copies, except records that must be retained by law.
This DPA is governed by Spanish law and the GDPR. Disputes are subject to the courts of Barcelona (Spain), except where mandatory law provides otherwise.
For a countersigned copy of this DPA or any data-protection question, contact hello@alinaflow.com.