TEREIKO PRIVACY POLICY

The company responsible for processing your data under this Privacy Policy is TEREIKO (hereinafter, TEREIKO).

TEREIKO, with registered office at Avinguda de Salou, 79 Reus, Tarragona, Spain 43205, tax ID B888703269, and contact email contact@tereiko.com, processes personal data to carry out some of its activities.

In this data processing, we always comply with the applicable regulations in force: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR) and Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).

1.Privacy statement

At TEREIKO, we are fully aware of the importance of how users’ personal data is processed. For this reason, we are committed to ensuring its protection, confidentiality, and security, in accordance with the principles of proactive responsibility, transparency, and respect for individual rights.

This Privacy Policy aims to provide clear and accessible information about which personal data we collect through any websites, mobile applications, or digital services operated by TEREIKO, whether currently available or developed in the future, the purposes for which we use it, the legal basis for processing, and the rights that data subjects may exercise.

We commit to processing only the personal data strictly necessary for the specific and legitimate purposes described in this policy and to adopting all appropriate technical and organizational measures to prevent unauthorized access, loss, or misuse.

2.Categories of personal data processed

The data we may process, depending on the corresponding purpose, includes the following categories of personal data:

  • Personal data voluntarily provided by the user through available channels, such as forms or emails.
  • Identification data: name, surname, ID/NIE or equivalent document, for example.
  • Contact data: phone number, email address, or postal address, for example.

Special categories of personal data are not collected or processed, except in cases provided by law and with the express consent of the data subject.

3.Purpose of processing personal data

The personal data provided by users through the website will be processed by TEREIKO for the following purposes, depending on the services or functionalities they interact with:

a) Platform access and use management: Processing enables access and use of the platform by students, professionals, and employees. TEREIKO does not impose a general minimum‑age requirement; age conditions depend on the Client. If the Client allows minors to use the platform, the Client is responsible for complying with all legal obligations for the processing of minors’ data. TEREIKO will not verify users’ ages and will process data only according to the Client’s documented instructions.

b) Provision of training services: Processing allows the creation and management of courses for adult students, professionals, and employees; the use of training materials; and the execution of activities, assessments, and analytics related to online and in-person training. In specific cases, external tools such as Zoom, Microsoft Teams, Google Meet, or SCORM-based systems may be required to deliver training or organize sessions.

c) Gamification: Processing is carried out to manage points, rankings, and participation metrics. If the advanced option is activated, processing may include assigning URT/USBC tokens through a connection with an independent external provider.

d) Internal communication functions: Processing is carried out to enable messages, comments, and other interactions between trainers and participants within the platform.

e) Payment management: Processing includes the data necessary to process payments through external payment service providers, such as Stripe.

f) User support and assistance: Processing is carried out to manage inquiries, resolve issues, and provide technical assistance related to platform use.

g) Sending commercial communications: Processing is carried out to send TEREIKO commercial communications related to its services, news, or training content, provided the user has consented or has not unsubscribed. The user may revoke such consent or unsubscribe at any time through the mechanisms provided.

h) AI-based functionalities: Processing may involve the use of data by external Artificial Intelligence (AI) providers, such as OpenAI, Anthropic, or ElevenLabs, to generate recommendations, summaries, translations, or other automated functions. In some cases, the processed information may be used by these providers to improve their AI models, in accordance with their own policies and applicable regulations.

i) Compliance with legal obligations: Processing and data retention are carried out when necessary to comply with legal obligations or requirements from competent authorities.

4.Retention periods for personal data

Personal data will be retained for as long as necessary to provide the services and, once the relationship has ended, for the periods required to comply with applicable legal obligations or to address potential liabilities arising from the processing.

5.Legal bases

The processing of your personal data will be carried out based on the following legal grounds that make it lawful:

  • Performance of services requested by the user or application of pre-contractual measures: Processing is necessary to manage access and use of the Tereiko platform, administer corporate accounts, provide contracted services (training, analytics, gamification features), process subscriptions and payments, and respond to information or support requests made before or during the contractual relationship. When TEREIKO processes data on behalf of its clients as a Data Processor, the applicable legal basis will be determined by each client in their capacity as Data Controller.
  • Consent of the data subject: Certain processing activities are based on the user’s free, specific, informed, and unequivocal consent. This consent is required for purposes such as the use of non-technical cookies and participation in optional features, including advanced gamification based on tokens or integration with external wallet providers. The user may withdraw consent at any time.
  • Compliance with legal obligations: Processing may be necessary to comply with legal obligations applicable to TEREIKO. In these cases, the organization is legally required to retain personal information for specific periods.
  • Legitimate interest: Processing is necessary to ensure platform security, prevent unauthorized access, improve functionality through internal analytics, maintain operational communications with client company administrators, and ensure essential technical traceability to provide adequate support, always respecting users’ rights and freedoms.

6.Relationship between processing purposes and legal bases when TEREIKO acts as data controller.

a) Purpose: Platform access and use management
Legal Basis: Performance of the contract (terms of use accepted by the user).

b) Purpose: Provision of training services
Legal Basis: Performance of the contract (terms of use accepted by the user).

c) Purpose: Gamification
Legal Basis: Performance of the contract. For advanced features with tokens or external wallets: consent.

d) Purpose: Internal communication functions
Legal Basis: Performance of the contract (terms of use accepted by the user).

e) Purpose: Payment management
Legal Basis: Performance of the contract (terms of use accepted by the user).

f) Purpose: User support and assistance
Legal Basis: Performance of the contract (terms of use accepted by the user).

g) Purpose: Sending commercial communications
Legal Basis: User consent.

h) Purpose: AI-based functionalities
Legal Basis: Performance of the contract (terms of use accepted by the user) or legitimate interest.

i) Purpose: Compliance with legal obligations
Legal Basis: Compliance with legal obligation.

Additionally, when TEREIKO processes personal data on behalf of its clients as a Data Processor, such processing will be governed by the provisions set out in ANNEX I – Conditions applicable to data processing on behalf of the Controller, which forms an integral part of this Privacy Policy.

7.Principles applied to personal data processing

In processing your personal data, TEREIKO will follow these principles, in accordance with the requirements of the GDPR and LOPDGDD:

  • Lawfulness, fairness, and transparency: Data is processed lawfully, fairly, and transparently. Users are always informed in advance about the purposes of processing, and consent is obtained when necessary.
  • Purpose limitation: Data is collected for specific, explicit, and legitimate purposes and is not further processed in a way incompatible with those purposes.
  • Data minimization: Only personal data strictly necessary for the intended purposes is processed.
  • Accuracy: Data is kept accurate and up to date, with measures taken to correct or delete inaccurate data without delay.
  • Storage limitation: Data is retained only for as long as necessary to fulfil the purposes of processing and, where applicable, for the legally required periods.
  • Integrity and confidentiality: Data is processed securely, ensuring protection against unauthorized access, loss, or alteration through appropriate technical and organizational measures.
  • Accountability: TEREIKO, as the data controller, commits to complying with these principles and can demonstrate compliance through effective measures.

8.Data transfer or communication of personal data and international transfers

Personal data may be shared with service providers that support TEREIKO (such as hosting, platform maintenance, analytics, payments, technical support or artificial intelligence), always acting as data processors and following our instructions.

All TEREIKO servers and service providers are located within the European Economic Area (EEA), so no international data transfers are carried out.

If this situation changes in the future (for example, if new providers outside the EEA are incorporated), TEREIKO will inform users and ensure that any transfer complies with GDPR requirements.

9.User responsibility

The user guarantees that the personal data they provide to TEREIKO is truthful, accurate, complete, and up to date.

The user will be liable for any false or inaccurate data provided through the website, as well as for any direct or indirect damages this may cause to TEREIKO and/or third parties.

10.User rights regarding personal data processing

The user has the following rights regarding the processing of their personal data by TEREIKO:

  • Right of access: Request confirmation of whether personal data concerning them is being processed and, if so, access it and obtain information about its processing.
  • Right of rectification: Request modification of their data if it is inaccurate or incomplete.
  • Right of erasure: Request deletion of their personal data when it is no longer necessary for the purposes for which it was collected.
  • Right to restriction of processing: In certain circumstances, request that the processing of their data be restricted.
  • Right to data portability: In specific cases, receive their personal data in a structured, commonly used, and machine-readable format and transmit it to another controller, or request that it be sent directly, where technically feasible.
  • Right to object: Object to the processing of their data for reasons related to their particular situation.
  • Right not to be subject to automated decisions: Not be subject to decisions based solely on automated processing, including profiling, that produce legal effects or significantly affect them.
  • Right to withdraw consent: For processing based on consent, withdraw it at any time. Withdrawal will not have retroactive effect and will not affect the lawfulness of prior processing.

11.How to exercise user rights

The user may exercise their rights by sending an explicit request via email to: contact@tereiko.com.

If the user believes that the processing of their personal data violates applicable data protection regulations or has not received a satisfactory response when exercising their rights, they have the right to file a complaint with the Spanish Data Protection Agency (www.aepd.es ), which will generally be the competent supervisory authority.

12.Security measures

TEREIKO commits to processing the user’s personal data with the utmost confidentiality, respecting the duty of secrecy at all times and acting in accordance with applicable data protection regulations. Therefore, it will adopt the necessary technical and organizational measures to ensure security and prevent alteration, loss, unauthorized processing, or access, considering the state of technology, the nature of the stored data, and the risks to which it may be exposed.

13.Changes to the Privacy Policy

TEREIKO reserves the right to modify this Privacy Policy. Any significant changes will be communicated through the website or other appropriate means.

14.Cookie processing

A cookie is a small file that is downloaded and stored on the user’s computer when accessing a website. Cookies allow the website to store and retrieve information about the user’s browsing habits or device and, depending on the information they contain and how the user uses their device, may enable recognition.

The user can prevent cookies from being generated by selecting the appropriate option in their browser settings. For more information, please read our Cookie Policy.

****

ANNEX I – Conditions applicable to data processing on behalf of the Controller

1. Purpose of the assignment

This Annex governs the conditions under which TEREIKO processes personal data on behalf of the Client in relation to the provision of services associated with the training platform.

Within this framework, TEREIKO will act as Data Processor under the terms set out in Article 28 of the GDPR, accessing only the data strictly necessary to execute the contracted functionalities. Processing will include, among other actions, user and access management, administration and delivery of training content, activation of gamification systems, generation of internal analytics, integration with external tools, and provision of technical support.

At all times, TEREIKO’s actions will be carried out exclusively in accordance with the documented instructions issued by the Client, who retains full control over the processing and determination of its purposes.

The Client may also issue an instruction authorising TEREIKO to use Client data to improve the technology and functionalities of the platform, including improvements that may benefit other clients. This processing is considered necessary for the proper performance of the service.

2. Nature, scope, and purpose of processing

The nature of the processing is limited to operations necessary for the proper functioning of the training platform and the provision of related services.

These operations include creating and managing educational content, facilitating interactions between trainers and participants, preparing reports and internal statistics, implementing progress mechanisms and gamified activities, as well as performing essential technical actions to ensure system availability, integrity, and continuity.

All these actions have the sole purpose of enabling the Client to manage its training processes effectively. Under no circumstances will the data be used by TEREIKO for its own purposes or for purposes other than those described herein.

3. Categories of data processed

The personal data processed by TEREIKO may include identifying information such as name, surname, corporate email, or internal user codes; professional data related to the position, department, or role assigned within the platform; data derived from the use of the platform, such as training progress, participation in activities, scores obtained, or activity logs; as well as data generated by integrated external tools, especially in videoconferencing contexts or equivalent systems.

Additionally, essential technical data for operation will be processed, such as IP addresses, logs, device identifiers, and connection metadata. In programs that require it, a wallet identifier or token associated with advanced gamification systems may be used.

However, TEREIKO will not process special categories of data unless there is an exceptional, express, and duly documented instruction from the Client.

4. Categories of data subjects

Processing carried out under this agreement may relate to the Client’s employees, authorised external collaborators, and users of the platform, as defined by the Client.

5. TEREIKO’s obligations as Data Processor

TEREIKO, in its capacity as Data Processor, assumes the following essential obligations regarding personal data processed on behalf of the Client:

a) Act in accordance with instructions: TEREIKO will process personal data exclusively following the Client’s documented instructions, without using it for its own purposes or for purposes other than those foreseen in the service provision.

b) Guarantee confidentiality: Authorised personnel accessing the data will be subject to professional secrecy obligations and will receive appropriate training in data protection, ensuring confidentiality during and after the assignment.

c) Apply appropriate security measures: TEREIKO will adopt technical and organisational measures in accordance with Article 32 of the GDPR, including reinforced access controls, encrypted communications, monitoring and incident detection, operation traceability, encrypted backups, environment segmentation, and periodic security audits or reviews.

d) Assist the Client: TEREIKO will cooperate with the Client in handling user rights requests, preparing impact assessments, identifying and analysing potential risks, and fulfilling obligations related to security incidents.

e) Notify incidents without delay: In the event of a security breach affecting personal data, TEREIKO will inform the Client without undue delay, providing the necessary information to assess its impact and take appropriate measures in accordance with the GDPR.

f) Facilitate audits or inspections: Where required by law, TEREIKO will allow the Client to carry out reasonable audits or reviews related to personal data processing.

g) Maintain processing records: TEREIKO will keep records of processing activities as required by applicable regulations.

6. Sub-processors

To ensure proper service delivery, TEREIKO may engage sub-processors when necessary, such as providers of cloud infrastructure, videoconferencing services, generative Artificial Intelligence (AI) tools, payment systems, storage services, content delivery, or technical support.

Currently, TEREIKO uses DigitalOcean as its cloud infrastructure provider. Any sub‑processor engaged by TEREIKO will be required to offer sufficient guarantees and to sign an agreement imposing obligations equivalent to those in this Annex. Where legally required, TEREIKO will inform the Client before adding or replacing a sub-processor. The Client may request an updated list of sub-processors and, where applicable, object to any of them.

7. International transfers

If the involvement of sub-processors or external integrations entails international data transfers, TEREIKO will ensure that such transfers comply with the requirements of Chapter V of the GDPR.

Valid mechanisms will be applied, such as Standard Contractual Clauses adopted by the European Commission, adequacy decisions, or other authorized instruments that guarantee a level of protection that is adequate and essentially equivalent to that of the EU.

8. Data handling upon service termination

Once the contractual relationship that legitimizes TEREIKO’s access to the data ends, TEREIKO will delete or return all personal data processed, strictly following the Client’s instructions and will carry out such deletion without undue delay and in accordance with its internal data retention and deletion procedures.

Where a legal obligation requires temporary retention of certain information, the data will remain blocked and accessible only to meet such obligations, without being used for any other purpose.

9. Liability

TEREIKO will only be liable for damages arising from processing carried out contrary to the Client’s instructions or the provisions of this Annex.

Conversely, the Client will assume responsibility when failing to comply with its duty of information, lacking an appropriate legal basis, issuing instructions contrary to regulations, or using the platform in a manner that violates applicable data protection provisions.

10. Duration

The obligations assumed by TEREIKO under this Annex will remain in force for as long as the services are provided and will continue to apply—particularly regarding confidentiality, security, and data deletion or return—even after the termination of the contractual relationship.