Skip to content

Compliance

Summary for town clerks, comptrollers and DPOs. The full dossier (DPA, sub-processors, security measures) is delivered with the contract.

  • Minimization: only what the service needs — name, birth date, monitor-relevant medical information, allergies, support needs and image-rights consent.
  • Access: the legal guardian (their children only) and authorized municipal staff. Monitors get the printed session list, not system access.
  • Legal basis: exercise of public powers / delivery of the municipal service (art. 6.1.e GDPR); image consent is captured and traced separately.
  • Private EU-jurisdiction bucket, encrypted at rest, accessed only through signed links by authorized staff.
  • Per-season retention: deleted when the season closes (period configurable per your ordinance).
  • The town is the data controller; EnaJoin the processor (art. 28 GDPR).
  • Standard DPA ready to sign: categories, listed sub-processors (EU hosting), rights assistance, 24-hour incident notification, deletion on termination.
  • No transfers outside the EU.
  • We store no card data: payment happens at the town bank’s Redsys TPV (SAQ-A scope). Only order references, amounts and statuses.
  • ENS básica controls: EU hosting, role-based access, staff 2FA, daily backups, audit logging.
  • Functional audit: every request timestamped to the millisecond; every discount review attributed with author and reason. Allocation order is exportable and verifiable.
  • Citizen pages follow UNE-EN 301 549 / WCAG 2.1 AA. A product accessibility statement is available to link from the municipal website.

Machine translations always carry a visible indicator (“machine translated”) until staff review them. No automated decisions are made about people.