Legal notice
Privacy policy
Published on 3 August 2026
1. Data controller
- Identity: Ayuntamiento de Ciudad Rodrigo
- Tax ID (NIF/CIF): P3710700J
- Address: Plaza Mayor, 27, 37500 Ciudad Rodrigo (Salamanca), Spain
- Email: info@cislaestrella.com
- Data Protection Officer: available on the electronic headquarters of Ciudad Rodrigo Town Council
2. Applicable legislation
We process your data in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) and Law 34/2002 (LSSI-CE), applying the technical and organisational measures needed to guarantee the security of the information.
3. What data we collect
We collect only the minimum data necessary in each case:
- Contact form: full name, email address, telephone (optional), subject and message content.
- Registration for programmes and activities: the data expressly requested in each call.
- Browsing data: if you accept analytics cookies, aggregated and anonymised data about how the site is used.
We do not collect special categories of data (health, political opinions, religion, ethnic origin, etc.) and we do not process data of children under 14 without the consent of their guardians.
4. For what purpose
- To handle and respond to the enquiries you send us.
- To manage registration for and participation in the centre's programmes, courses, workshops and open calls.
- To send you information about the centre's activities, where you have expressly consented.
- To analyse site usage in aggregate form in order to improve its content.
- To comply with our legal obligations.
5. Legal basis
- Consent (art. 6.1.a GDPR): contact form, information communications and analytics cookies. You may withdraw it at any time.
- Performance of a contract or pre-contractual measures (art. 6.1.b GDPR): registration for and participation in programmes and activities.
- Compliance with a legal obligation (art. 6.1.c GDPR): accounting and tax obligations and the justification of public grants.
- Public interest (art. 6.1.e GDPR): dissemination of the social innovation centre's own activities.
6. How long we keep your data
We keep your data for as long as is strictly necessary to provide the service requested. It will then be blocked for the limitation periods of any applicable legal obligations (generally up to 6 years for accounting records and up to 4 years for tax obligations), after which it will be securely deleted.
Messages received through the contact form are kept for a maximum of 12 months from the last communication, unless they lead to a different type of relationship.
7. Recipients
We do not transfer your data to third parties except where legally required. The following may access it as data processors, under a signed processing agreement:
- Web hosting provider: Arsys Internet, S.L.U. (Spain, EU).
- Google Ireland Ltd. — Google Analytics, only if you accept analytics cookies.
- Anthropic PBC (United States) — automated translation service for the site's public content. Only text intended for publication is sent; never users' personal data.
International data transfers, where they occur, are covered by the standard contractual clauses approved by the European Commission or by adequacy decisions in force.
8. Your rights
You may exercise the following rights at any time:
- Access: find out what data of yours we process.
- Rectification: correct inaccurate or incomplete data.
- Erasure: ask us to delete your data.
- Objection: object to a specific processing operation.
- Restriction: ask us to restrict processing.
- Portability: receive your data in a structured, commonly used format.
- Withdrawal of consent at any time, without affecting the lawfulness of prior processing.
To exercise them, write to info@cislaestrella.com stating the right you wish to exercise and enclosing a copy of a document proving your identity. We will respond within a maximum of one month.
If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency: www.aepd.es, C/ Jorge Juan 6, 28001 Madrid.
9. Security
We apply appropriate technical and organisational measures to protect your data against unauthorised destruction, loss, alteration, disclosure or access: encrypted communications over HTTPS, access control with hashed passwords, regular backups and logging of operations carried out from the management panel.
10. Changes to this policy
We may update this policy to reflect legislative changes or new services. The version in force will always be the one published on this page, together with the date it was last updated.