Privacy policy
This policy sets out what personal data the association operating under the SkillHeart name processes when someone visits this website, for what purpose and on what legal basis, who else is involved and what rights the data subject holds. It is drafted in accordance with Regulation (EU) 2016/679 and Spanish Organic Law 3/2018, and describes only what this site does.
Draft pending legal review. What it describes is how this site actually works, checked against the code that serves it, but the wording has not yet been reviewed by a legal professional. It is published so that it can be read, not as a final version.
Last reviewed: Aug 1, 2026.
Data controller
Legal name: Asociación para el Desarrollo del Talento Tecnológico y la Empleabilidad Digital, operating publicly under the SkillHeart name.
Legal form: non-profit association of national scope, entered in Spain's National Registry of Associations under number 633639 by resolution of 20 July 2026.
Registered office: C/ Metge Josep Darder, 21, 1.º B, 07008 Palma, Illes Balears (Spain). Email: admin@skillheart.org. Website: skillheart.org.
The association has not appointed a data protection officer, as none of the circumstances listed in Article 37 of Regulation (EU) 2016/679 apply. Requests on this matter are handled at the email address above.
Scope
This policy applies to skillheart.org, to its four language versions and to the subdomains the association operates directly.
It does not apply to third-party sites linked from here, which are governed by their own policies, nor to the association's profiles on platforms it does not run, where the provider is also involved in the processing.
This site offers no user registration, no private area, no newsletter and no data collection forms. Providing personal data is not a condition for reading any of its content.
Categories of data processed
Technical connection data: IP address, browser type and version, operating system, preferred language, date and time of the request and the resource requested. Any web server receives these in order to respond.
Usage data: page views, a closed set of named events describing specific actions, and the performance metrics of the page itself. By default they are not tied to any persistent identifier.
Diagnostic data: the technical information accompanying a malfunction, scrubbed of values that could identify a person before it is sent.
Consent records: the decision taken on cookies and similar technologies, its date, the version of this policy in force at the time and the jurisdiction applied.
Contact data: whatever a person voluntarily includes in an email addressed to the association.
Donation data: what is needed to process a contribution, handled by the payment service provider once that channel is open. The association never sees or stores the card number.
No special categories of data within the meaning of Article 9 of Regulation (EU) 2016/679 are processed.
Purposes and legal bases
Providing the service and keeping it available and secure: the association's legitimate interest in operating its website and protecting it against abuse (Article 6(1)(f)).
Remembering functional preferences such as the chosen language: storage strictly necessary to provide a service explicitly requested, exempt from the consent requirement under Article 22(2) of Spanish Law 34/2002.
Measuring use of the site without persistent identifiers: legitimate interest in understanding, in aggregate, which content is useful (Article 6(1)(f)).
Measuring use by means of an identifier stored on the device: the data subject's consent (Article 6(1)(a)), which may be withdrawn at any time.
Detecting and fixing malfunctions: legitimate interest in keeping the site operational and correcting its defects (Article 6(1)(f)).
Evidencing the decision taken on cookies: compliance with the obligation to demonstrate consent imposed by Article 7(1) of the Regulation (Article 6(1)(c)).
Responding to correspondence received: legitimate interest in replying to whoever writes to the association (Article 6(1)(f)).
Administering donations and meeting the accounting and tax obligations arising from them: performance of the relationship with the donor and compliance with legal obligations (Articles 6(1)(b) and 6(1)(c)).
For the processing based on legitimate interest, the association has assessed that it is limited to low-impact data, that its object is how the site performs rather than who the visitor is, and that it can be objected to on the terms set out in the section on rights.
Usage measurement
Measurement is carried out with PostHog, on its European Union infrastructure. The default configuration runs without cookies: instead of storing an identifier on the device, the provider derives a temporary one on its own servers from a salt that rotates daily, so it does not persist from one day to the next.
That configuration is deliberately narrow. No individual profiles are built, no sessions are recorded, no heatmaps are generated and interaction is not captured automatically. What is recorded is page views, a closed set of named events such as opening a programme card or copying the contact address, and the performance metrics of the page.
Measurement requests are served from our own domain rather than sent directly to the provider. The reason is not to conceal the processing, which this policy declares, but that a blocker withholding part of the traffic skews the rest and leaves the figures meaningless.
If measurement is accepted in the cookie notice, the provider may additionally store an identifier on the device, which is what allows a returning visit to be told apart from a new one. If it is declined, measurement continues without cookies and nothing is stored on the device.
Error reporting
Malfunctions are reported to the association through Sentry, processed in its European region. The report contains the failure, where it comes from in the code and the technical context needed to reproduce it.
Only exceptions are sent. Sessions are not recorded and browsing is not traced from the browser, and reports are scrubbed before leaving the device, so values that could identify a person are removed rather than travelling with the report.
This is not usage measurement and therefore falls outside the cookie notice: it rests on the legitimate interest in keeping the service operational and stores nothing on the device.
Consent records
When someone accepts, declines or adjusts their preferences in the cookie notice, the association keeps the decision itself: what was chosen, on what date, under which version of this policy and with which jurisdiction applied.
These records live in the association's own database, on its own server in the European Union, and they are append-only: a later change adds a new entry instead of overwriting the previous one, so the full history of decisions can be reconstructed.
Their purpose is to evidence consent, an obligation Article 7(1) of the Regulation places on the controller. Without a record there is no proof, neither for the association nor for the person who decided.
Cookies and device storage
Language: keeps the chosen language so it does not have to be resolved again on the next visit. Technical and necessary.
Consent: keeps the decision taken in the notice so the question is not repeated on every page. Technical and necessary.
Measurement: set only if measurement is accepted. Placed by PostHog, it distinguishes a returning visit from a new one.
Editorial preview: set only for the association's team while unpublished content is being reviewed.
The first two are exempt from the consent requirement under Article 22(2) of Spanish Law 34/2002, being strictly necessary to provide the service requested. The third does require consent, which is what the notice is for.
Processors and recipients
Hosting: Hetzner Online GmbH, in data centres located in Germany. The site, the database and the consent records live there.
Content management: Sanity, which stores and serves the articles and their images. Design assets are additionally served from a content delivery network.
Usage measurement: PostHog, on its European Union infrastructure.
Error reporting: Sentry, in its European region.
Payments: Stripe, once the donation channel is open.
A processing agreement on the terms of Article 28 of the Regulation is in place with each provider. Data may also be disclosed to public authorities where the law requires it.
The association does not sell personal data, does not share it for advertising purposes, and this site carries no advertising pixels or tags.
International data transfers
The data this site processes is stored in the European Union. Several of the providers listed above are companies established in the United States, so occasional access from that country, for technical support for instance, amounts to an international transfer.
Those transfers rely on the standard contractual clauses approved by the European Commission and, where the provider is certified, on the EU-US Data Privacy Framework, whose adequacy was recognised by Implementing Decision (EU) 2023/1795.
Information on the safeguards applied to a specific provider can be requested at the contact address in this policy.
Retention periods
Technical connection data: as long as needed to serve the request and, in server logs, for a short period devoted to security and diagnostics.
Usage data: the analytics provider's default retention period. It is not tied to an identifiable person, so there is no profile to retrieve.
Error reports: as long as needed to diagnose and fix the incident, within the provider's retention period.
Consent records: for as long as the decision may need to be evidenced and, in any event, for the limitation period of any claims that could arise from it.
Correspondence: as long as needed to deal with the matter raised and to evidence how it was handled.
Donation data: the periods imposed by applicable law, in particular the six years under Article 30 of the Spanish Commercial Code and the four-year tax limitation period under Article 66 of Law 58/2003.
Security measures
The site is served entirely over an encrypted connection, so data is encrypted in transit. Access to the systems is restricted to the people who need it for their role and takes place with individual authentication.
The design reduces exposure rather than guarding it: measurement works without persistent identifiers, error reports are scrubbed at source, and this site has no forms that collect data.
Consent records are append-only, so no decision can be altered without leaving a trace.
Should a personal data breach occur, the association will notify the Spanish Data Protection Agency within the seventy-two hours provided for in Article 33 of the Regulation and, where the breach entails a high risk, the individuals affected.
Minors
This site is not specifically directed at people under fourteen and does not deliberately collect their data. Under Article 7 of Spanish Organic Law 3/2018, processing based on the consent of a person below that age requires the authorisation of the holder of parental responsibility or guardianship.
Should the association become aware that it has processed the data of a person under fourteen without that authorisation, it will delete it without delay.
Automated decisions and profiling
Through this site the association takes no decisions based solely on automated processing that produce legal effects or significantly affect a person, and it builds no profiles for that purpose.
Usage measurement is aggregate and does not evaluate personal characteristics.
Rights of data subjects
Any person may request access to their personal data, its rectification and its erasure, the restriction of its processing, its portability and object to the processing, on the terms of Articles 15 to 22 of Regulation (EU) 2016/679.
Requests should be sent to admin@skillheart.org. The association will reply within one month of receipt, extendable by two further months where the request is complex, and may ask for the additional information needed to confirm the identity of the person making it.
Consent to measurement may be changed or withdrawn at any time from the cookie preferences link in the footer of every page. Withdrawing it is as straightforward as giving it and does not affect the lawfulness of earlier processing.
A complaint may be lodged with the Spanish Data Protection Agency (calle Jorge Juan 6, 28001 Madrid, www.aepd.es), in particular if the association's reply is not satisfactory.
One practical consequence is worth stating in advance: because default measurement uses no persistent identifiers, simply browsing this site leaves no data tied to an identifiable person, so an erasure request covering only that browsing will usually have nothing to act on. It will where correspondence or a donation exists.
Updates to this policy
This policy is reviewed whenever what the site does or which providers are involved changes. The date of the last review appears at the start of the document and determines the version in force.
Substantial changes will be announced on the site itself and, where they affect the scope of consent, the cookie decision will be requested again.
Earlier versions can be requested at the contact address.
Contact and complaints
For any question about this policy, including the exercise of the rights listed above, the contact address is admin@skillheart.org.
Requests concerning those rights are handled within the one-month period stated above. All other correspondence is answered, as a rule, within three working days at most.
