Version 2026-10
Data processing agreement
Article 28 of Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
Parties
Controller: the association that signs up for the service, with tax ID (NIF) [tax ID] and registered address at [address] (hereinafter “the Association”).
Processor: Treserras Multimèdia SL, with tax ID (NIF) B66358680 and registered address at Mas el Garet Nou s/n, 08550 Els Hostalets de Balenyà (Barcelona), which provides the ValidPass service (validpass.app) (hereinafter “the Processor”).
1. Subject matter
The Processor processes, on behalf of the Association, the personal data necessary to provide the ValidPass service: management of members, fees and permits, issuing of cards with a QR code, and public checking of cards (the card page that opens when a card is scanned or through the manual check).
2. Duration
This agreement remains in force for as long as the Association subscribes to the service. When it ends, the Processor will make all the data available to the Association in a structured, commonly used format and will delete it within 30 days, except for any data that the law requires to be retained.
3. Nature and purpose of the processing
Hosting, storage, consultation, alteration and erasure of the data by the board; publication on the card page of the data necessary to check the card; backups; and logging of checks and of activity for the security of the service.
4. Types of data and data subjects
- Members: first name and surnames, member number, DNI or NIE (not stored in full: only the last digits and a cryptographic fingerprint for the manual check), town, length of membership, vehicle licence plates, fees and permits and, if the board enters them, phone number, email address and postal address.
- Board members: name, email address and a log of their activity in the back office.
- People who check a card: an aggregated log of checks, without the IP address in clear text.
5. Obligations of the Processor
- To process the data only in order to provide the service and on the documented instructions of the Association (this agreement and the board's use of the back office).
- To ensure that the persons authorised to process the data have committed themselves to confidentiality.
- To implement appropriate security measures (Article 32 of the GDPR), such as: encrypted connections; board access with a personal password and a limit on attempts; support access by the Processor with two-factor authentication, recorded in the Association's activity log; the DNI is not stored in clear text; and backups.
- Not to engage any other processor without the Association's authorisation. The Association authorises Cloudflare, Inc. (hosting and network), with the databases in the European Union and the safeguards of its data processing agreement and of the standard contractual clauses. The Processor will give 30 days' notice of any change, and the Association may object to it.
- To assist the Association in responding to requests from data subjects exercising their rights (access, rectification, erasure, objection, restriction and portability). The back office makes it possible to export all the data and to erase the personal data of a member who has left.
- To notify the Association, without undue delay and within 48 hours at the latest, of any personal data breach of which it becomes aware.
- To assist the Association, where necessary, with data protection impact assessments and with consultations with the supervisory authority.
- To delete or return the data when the service ends, as set out in clause 2.
- To make available to the Association all the information necessary to demonstrate compliance with these obligations.
- To access the Association's back office only to provide it with support or on its instructions; each access is recorded in its activity log.
6. Obligations of the Association
- To have a lawful basis for processing members' data and to inform them of the processing, including the fact that the card has a public card page showing the name, the masked DNI, the permits and the licence plates.
- To keep the data accurate and up to date, and to give the Processor any instructions that may be necessary.
- To safeguard access to the back office: each board member with their own email address and password.
7. Acceptance
The person who signs up the association accepts it on the association’s behalf in the sign-up form (or a board administrator does, in Account → Data protection). We record who, when, which version and the exact text.