Privacy Policy

Last updated: 22 May 2026

1. Who We Are

This website (thespanishprogram.com) and the learning platform (learn.thespanishprogram.com) are operated by:

Fernando Pérez Cos
NIF: 13774598J
Barrio Cotillo, 4, Aés
39670 Puente Viesgo, Cantabria, Spain
Email: fernando@thespanishprogram.com

Fernando Pérez Cos is the data controller responsible for your personal data.

2. What Data We Collect

2.1 Data you provide directly

  • Account data: your name and email address, provided when you register, take the free level test, or make a purchase.
  • Billing data: your billing name and address. We do not store card numbers — payment card data is processed and held securely by PayPal (PCI DSS Level 1 certified).
  • Learning activity: written exercises, forum posts, quiz answers, and progress records that you create within the Moodle learning platform.

2.2 Data collected automatically

  • Analytics data: pages visited, time on site, device type, and approximate geographic location (country/city level), collected via Google Analytics 4.
  • Cookies: session cookies necessary for the platform to function, and analytics cookies (only with your prior consent). See our Cookie Policy for full details.

3. How and Why We Use Your Data

Purpose Data used Legal basis (GDPR)
Delivering the course and learning platform Account data, learning activity Contract performance — Art. 6.1(b)
Processing payments and issuing invoices Billing data Contract performance — Art. 6.1(b); Legal obligation — Art. 6.1(c)
Sending transactional emails (enrolment confirmations, password resets, level test results) Email address Contract performance — Art. 6.1(b)
Sending marketing emails and course updates (only if you opted in) Email address, level information Consent — Art. 6.1(a)
Improving the platform and course content Aggregated analytics and learning data Legitimate interest — Art. 6.1(f)
Complying with tax and accounting obligations Billing and transaction records Legal obligation — Art. 6.1(c)

4. AI-Generated Feedback

Written exercises and forum posts submitted through the learning platform are processed by Google’s Gemini AI API to generate personalised language feedback. This processing is subject to Google’s data processing terms. Your exercise submissions are not used to train AI models. All AI feedback is supervised by the course instructor, Fernando Pérez Cos.

5. Third-Party Service Providers

We share data with the following providers only to the extent necessary to deliver the service:

Provider Purpose Location Safeguard
PayPal Payment processing USA / EU Standard Contractual Clauses; PCI DSS Level 1
Brevo (formerly Sendinblue) Email delivery and marketing automation France (EU) EU-based; GDPR-compliant DPA in place
Google Analytics 4 Website analytics USA Standard Contractual Clauses; IP anonymisation enabled
Google Gemini API AI-generated exercise feedback USA Standard Contractual Clauses; data processing agreement in place
Hostinger Web and platform hosting (VPS) EU EU-based data centre; GDPR-compliant DPA in place

We do not sell your personal data to any third party. We do not share your data with any party not listed above without your explicit consent.

6. Data Retention

  • Account and learning data: retained for 3 years after your last activity on the platform, then permanently deleted or anonymised.
  • Billing and invoicing records: retained for 7 years in accordance with Spanish tax law (Ley General Tributaria).
  • Marketing consent records: retained until you withdraw consent or for 3 years of inactivity, whichever comes first.

7. Your Rights

Under the GDPR — and, for users in the United Kingdom, the UK GDPR — you have the following rights:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: ask us to correct inaccurate or incomplete data.
  • Erasure (“right to be forgotten”): request deletion of your personal data, subject to our legal retention obligations.
  • Data portability: receive your data in a structured, commonly used, machine-readable format.
  • Restriction of processing: ask us to limit how we use your data in certain circumstances.
  • Object to processing: object to processing based on legitimate interest, including for direct marketing.
  • Withdraw consent: where processing is based on your consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, email fernando@thespanishprogram.com. We will respond within 30 days.

8. Supervisory Authorities

If you are in Spain or the EU and believe we have not handled your data correctly, you have the right to lodge a complaint with the Agencia Española de Protección de Datos (AEPD): www.aepd.es.

If you are in the United Kingdom, you may contact the Information Commissioner’s Office (ICO): ico.org.uk.

9. Children’s Privacy

The Spanish Program is designed for adults aged 18 and over. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us immediately and we will delete it.

10. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss or disclosure, including SSL encryption, server-level security, and access controls on the learning platform.

11. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated by email to registered users and by a prominent notice on this page. The date at the top of this page indicates when it was last updated.

12. Contact

For any questions about this Privacy Policy or how we handle your data, contact:
Fernando Pérez Cos
Email: fernando@thespanishprogram.com
Post: Barrio Cotillo 4, Aés, 39670 Puente Viesgo, Cantabria, Spain

Scroll to Top