Holding a card?Check it →
ValidPass

Privacy policy

Draft pending legal review. This document has yet to be reviewed by a lawyer and may change.

This policy explains what personal data we process when you visit validpass.app, when you write to us and when your association subscribes to ValidPass; what we use it for; and what rights you have. The data of each association’s members is a separate case: we process it on the association’s behalf (section 8).

1. Who the controller is

  • Controller: Treserras Multimèdia SL
  • Tax ID (NIF): B66358680
  • Registered address: Mas el Garet Nou s/n, 08550 Els Hostalets de Balenyà (Barcelona)
  • Data protection email: info@validpass.app

We have not appointed a data protection officer, as we are not required to. For any question about your data, email us at the address above.

2. What data we process and why

When you write to us

  • Data: your name, email address, phone number if you give it to us, your association and whatever you tell us, whether you write by email, through a form on the website or with a query from the board area.
  • Why: to reply to you and, if you ask, to prepare a proposal.
  • Legal basis: taking steps at your request before entering into a contract (Article 6(1)(b) of the General Data Protection Regulation, GDPR) or our legitimate interest in answering the queries we receive (Article 6(1)(f)).
  • How long: up to one year after the last communication, if the association does not become a customer. Queries sent from the board area are kept for as long as the association has the service.

When the association signs up and uses the service

  • Association details: name, tax ID, sector, approximate number of members, ValidPass address, phone number and email address. The phone number appears on the card pages so that anyone checking a card can call the board.
  • Details of the person subscribing: full name, position on the board, email address and phone number.
  • Record of acceptances: who accepted the terms of service and the data processing agreement, when and which version; the declaration that they could contract on the association’s behalf; and the request to start the service straight away.
  • Why: to create and manage the account, provide and support the service, notify you of renewals, invoices and changes to the service, and be able to prove what was accepted.
  • Legal basis: the contract with the association (Article 6(1)(b) GDPR). For the data of the people who represent it or act as its contacts, our legitimate interest in maintaining the relationship with the association (Article 6(1)(f) GDPR and Article 19 of the Spanish Data Protection Act, Organic Law 3/2018, LOPDGDD).
  • How long: for as long as the association has the service. After that, we keep the data blocked (unused) only for as long as liabilities may arise from it, and then delete it.

Billing and payments

  • Data: legal name, tax ID, billing address and email, contact person, invoices (number, date, period and amounts) and payments (date, amount and payment method). If you pay by bank transfer, the bank tells us who made it and from which account.
  • When direct debit and card payments become available, card or account details will be handled by Stripe; we will only see a reference, such as the last digits.
  • Why: to issue and collect invoices and to meet our tax and accounting obligations.
  • Legal basis: the contract (Article 6(1)(b) GDPR) and our legal tax and commercial obligations (Article 6(1)(c)).
  • How long: invoices and accounting records, 6 years (Spanish Commercial Code, Article 30), or longer if tax rules require it.

Board members who use the board area

  • Data: name, email address, role (administrator or manager), preferred language, password (which we only store as a cryptographic fingerprint, never as you type it), sessions and failed sign-in attempts.
  • Why: to give you personal access, protect it (limits on attempts, closing sessions) and, once email is in place, send you service notices.
  • Legal basis: the contract with the association and our legitimate interest in giving secure access to the people the association designates (Article 6(1)(b) and (f) GDPR).
  • How long: for as long as the association has the service. When someone leaves the board, the association removes their access, but their name remains in the association’s activity log for 3 years, as a record of who made each change. We process that log on the association’s behalf (section 8).

Website technical logs

  • Data: when you visit any page on validpass.app, your browser sends, as with any website, your IP address, the date and time, the page requested and the type of browser.
  • Why: to serve the pages, protect the website from abuse and attacks (for example, by limiting the number of attempts) and find and fix errors.
  • Legal basis: our legitimate interest in keeping the website secure and working (Article 6(1)(f) GDPR).
  • How long: request and error logs, 7 days at most. To limit attempts, we do not store the IP address but a cryptographic fingerprint of it, and expired counters are deleted every day.

3. Who we share data with

We do not sell data or give it to anyone to use for their own purposes. Only the following have access to it:

  • Cloudflare, Inc., as processor: hosting, network, security, database and technical logs. ValidPass’s databases are in the European Union.
  • Stripe, once direct debit and card payments become available: payment collection. The entity involved is Stripe Payments Europe, Ltd. (Ireland), which acts as an independent controller for fraud prevention and its own legal obligations.
  • The email service, once it is in place: to send the service’s emails (confirmations, access links, notices and invoices). We will name it here before we use it.
  • The banks involved in payments, and the Spanish Tax Agency, other authorities or the courts when the law requires it.
  • Our advisers (accountants, lawyers), when necessary and under a duty of confidentiality.

4. International transfers

Cloudflare and Stripe are US companies or have group companies there. ValidPass’s databases are in the European Union, but Cloudflare’s network serves each visit from the nearest data centre, which may be outside the EU, and these companies’ staff may access the data for support or security purposes. When data leaves the European Economic Area, it is protected by:

  • the EU-US Data Privacy Framework, under which both companies are certified; and
  • the standard contractual clauses approved by the European Commission, included in their data processing agreements.

You can read Cloudflare’s data processing agreement and the list of certified companies.

5. Your rights

You can ask us at any time for:

  • access: to know what data of yours we hold;
  • rectification: to correct it if it is inaccurate;
  • erasure: to delete it when it is no longer needed or there is no reason to keep it;
  • objection: to stop processing it on the basis of our legitimate interest, on grounds relating to your situation;
  • restriction: to keep it without using it, for example while a complaint is being resolved;
  • portability: to receive the data you have given us in a commonly used format, so that you can take it elsewhere.

Email us at info@validpass.app, or write to us at Mas el Garet Nou s/n, 08550 Els Hostalets de Balenyà (Barcelona), saying which right you want to exercise. If we have reasonable doubts about who you are, we may ask you for some information to check. It is free of charge, and we will reply within one month at most (in complex cases, this can be extended by two more months, and we will tell you).

If you think we have not handled your data properly, you can lodge a complaint with the Spanish Data Protection Agency (aepd.es). We would be grateful if you told us first, so that we can try to sort it out.

6. No profiling or advertising

We do not take automated decisions that affect you or build profiles, and we do not use the data for advertising. If we ever want to send you marketing communications, we will do so with your consent or, if you are already a customer, about services of ours similar to those you have, and you will be able to opt out in every message (LSSI-CE, Article 21).

7. Security

We protect the data with encrypted connections, databases in the EU, passwords stored as cryptographic fingerprints, limits on attempts and access by our staff with two-factor authentication, recorded in the association’s activity log; and members’ DNI numbers are not stored in full. No system is infallible: if there were ever a security breach affecting you, we would inform you as the law requires.

8. The data of associations’ members

  • Controller: each association is the controller of its members’ data. Treserras Multimèdia SL processes it on the association’s behalf, as processor (Article 28 GDPR): only to provide the service and on the association’s instructions.
  • The contract: the terms are set out in the data processing agreement, which a board administrator accepts in the association’s account (board area → Account → Data protection). Administrators can read it in the board area.
  • What appears on the card page: the name, the member number, the last three digits and the letter of the DNI, the authorised areas, the licence plates and whether the member’s fee is paid. This is what anyone needs to check the card. The manual check asks for the full DNI, which is compared with a cryptographic fingerprint and is not stored.
  • If you check a card: the check is logged for the association (which card, how it was checked, the result, the country and the time), without your IP address. It is kept for 13 months; after that, only daily totals remain.
  • If you are a member: to exercise your rights, contact your association. If you write to us, we will pass your request on to the association and help it to respond.

9. Changes to this policy

If we change this policy, we will say so on this page. If the change is significant, we will notify the boards before it applies.