This privacy policy describes how Protocol & Diplomacy Consultancy handles the personal data of users who access its website, Campus, newsletter and contact forms.
DATA CONTROLLER
PROTOCOL & DIPLOMACY CONSULTANCY S.L. (hereinafter, “Protocol & Diplomacy Consultancy”), with Tax Identification Number (CIF) B02779437 and registered office at Calle Villaescusa, 54 (Madrid), is responsible for processing the personal data collected through:
- the website pedrolsanchezconsultancy.com,
- the subdomain pedrolsanchezconsultancy.com,
- and ist associated forms (contact, newsletter subscription, course registration and purchase on the Campus).
Contact details of the data controller:
Email: info@pedrolsanchezconsultancy.com
This policy has been drafted in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and Spanish Organic Law 3/2018, on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), which regulate the protection of personal data and the rights of individuals in this area.
SCOPE OF APPLICATION
This privacy policy applies to the processing of personal data derived from:
- Contact forms on the corporate website.
- Newsletter subscriptions forms.
- Registration, access, and enrollment forms for courses/services on the online campus.
DATA WE PROCESS
Depending on the form or service you use, we may process the following categories of data:
- Identification data: name, surname.
- Contact information: email address, telephone number.
- Professional / entity data: entity or institution, type of organization (public and political sector, business and corporate sector, embassies and diplomatic schools, universities and business schools), position or role, country.
- Navigation and technical data: IP addresses, device identifiers, cookies or similar technologies (see corresponding cookie policy).
- Financial and transaction data (only on Campus, when applicable): data necessary for the management of payments, billing and accounting (e.g. billing data; bank or card details are managed through secure payment gateways, without Protocol & Diplomacy Consultancy storing the complete card numbers).
- Academic data related to the Campus: courses in which the user enrolls, progress in the courses, certifications obtained, interactions with the Campus.
In all cases, the data collected is strictly necessary for each purpose and is processed in a fair, transparent and limited manner to what is necessary, as required by the GDPR and LOPDGDD.
PURPOSES OF PROCESSING
4.1. Website contact forms
The data provided through the contact form will be processed to:
- Manage and respond to requests for information, inquiries, or proposals that you send us.
- Maintain communication to follow up on these requests and, where appropriate, initiate or maintain a professional or contractual relationship.
4.2. Newsletter subscription forms
The data provided in the subscription forms will be used to:
- Manage your registration as a subscriber to the Protocol & Diplomacy Consultancy Newsletter.
- Send you professional, informative, and commercial communications by electronic means related to: a) artículos, recursos y contenidos sobre protocolo, diplomacia, comunicación e imagen estratégica; b) articles, resources, and content on protocol, diplomacy, communication, and strategic image; c) news about training and consulting programs; invitations to events, conferences, or activities linked to our services.
These communications are sent in accordance with the GDPR, LOPDGDD, and Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE), which requires prior consent and clear information on the right of opposition and cancellation.
You can unsubscribe at any time via the link included in each email or by writing to info@pedrolsanchezconsultancy.com.
4.3. Registration and Use of the Online Campus
On the Campus (campus.pedrolsanchezconsultancy.com), your data will be processed for the following purposes:
- Manage your registration as a user and grant you access to your personal area.
- Manage the contracting of courses or training services, including the processing and issuance of invoices and payment receipts.
- Administer and monitor the academic progress of courses: registration, progress, completed activities, evaluations, certificates, or diplomas.
- Address technical or support inquiries related to the use of the Campus.
- Maintain a history of courses and certifications, when applicable.
- Send you communications related to the execution of the contracted service (class reminders, changes, important notices, etc.).
- If applicable, and only with your consent, send you additional informational or commercial communications about other related courses or services.
LEGAL BASIS FOR PROCESSING
The legal bases that legitimize the processing of your data are:
- Consent (Art. 6.1.a GDPR)
- By submitting the contact form after checking the box to accept the privacy policy.
- By subscribing to the Newsletter.
- By registering on the Campus and, where applicable, accepting additional marketing communications.
- Performance of a contract or pre-contractual measures (Art. 6.1.b GDPR)
- Management of enrollment in Campus courses and provision of training services.
- Management of your user account, access, and technical support related to the contracted services.
- Compliance with legal obligations (Art. 6.1.c GDPR)
- Tax and accounting obligations arising from the issuance of invoices, retention of accounting documentation, etc., in accordance with Spanish tax regulations.
- Legitimate interest (Art. 6.1.f GDPR)
- To maintain minimal follow-up communications with existing clients or users regarding similar services, always within reasonable expectations and respecting their right to object.
- To improve service quality, campus security, and fraud prevention.
RECIPIENTS AND PROCESSORS OF DATA
Generally, Protocol & Diplomacy Consultancy will not transfer your data to third parties without your consent, except where legally required.
Notwithstanding the foregoing, for the proper provision of services, the following may have access to your data:
- Website and Campus technology and hosting service providers.
- Email marketing and automation platforms (e.g., Brevo/Sendinblue or equivalent), used for managing newsletters and communications.
- Payment gateways and financial institutions for managing collections and payments.
- External advisors (tax, accounting, IT, legal), when necessary.
All of these act as data processors, with contracts that include the safeguards provided for in the GDPR (Article 28 et seq.).
If international data transfers are made (for example, to providers located outside the European Economic Area), they will be carried out with appropriate safeguards in accordance with the GDPR (adequacy decisions, standard contractual clauses or other valid mechanisms).
DATA RETENTION PERIODS
Data will be retained for the following periods:
- Contact form data: for the time necessary to address the inquiry or request and, where applicable, while a professional or contractual relationship exists arising from it, and subsequently blocked for the statutory limitation periods for any potential liabilities.
- Newsletter data: while your subscription remains active and you do not unsubscribe or object to the processing of your data.
- Campus data (registration, courses, billing): for the duration of the contractual relationship and, once it has ended, for the periods required by tax, commercial, and data protection regulations.
RIGHTS OF DATA SUBJECTS
You can exercise your rights at any time:
- Access: to know what personal data we process.
- Rectification: to correct inaccurate or incomplete data.
- Erasure (right to be forgotten): to request the deletion of your data when it is no longer necessary for the purposes described or when you withdraw your consent.
- Objection: to request that we stop processing your data in certain circumstances, for example, for sending marketing communications.
- Restriction of processing: to request that we restrict the processing of your data in certain cases.
- Portability: to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller where appropriate.
To exercise these rights, you can write to:
info@pedrolsanchezconsultancy.com Subject: “Data protection”
Indicating the right you wish to exercise and attaching, if necessary, a copy of a document proving your identity.
If you believe that your rights have not been properly addressed, you can file a complaint with the Spanish Data Protection Agency (AEPD), the competent supervisory authority in Spain (www.aepd.es).
DATA SECURITY
Protocol & Diplomacy Consultancy will implement appropriate technical and organizational measures to guarantee the confidentiality, integrity, and availability of the personal data processed, in compliance with the security principles of the GDPR and the LOPDGDD.
However, you should be aware that no security measure on the Internet is completely infallible.
MINORS
The services on the corporate website and the Campus are not specifically directed at minors. Should any of our services be contracted by individuals under 16 years of age, the consent of their parents or legal guardians will be required for the processing of their personal data, in accordance with the LOPDGDD.
LINKS TO THIRD-PARTY WEBSITES
The website and the Campus may include links to third-party websites (e.g., social media, external platforms, or third-party resources). Protocol & Diplomacy Consultancy is not responsible for the content or privacy policies of these sites, so we recommend that you carefully read their privacy policies before providing them with your personal data.
COOKIE POLICY
The use of cookies and similar technologies on the corporate website and the Campus is governed by a specific Cookie Policy document, accessible at all times from the website. We recommend that you review it for detailed information about which cookies we use, for what purpose, and how you can manage or disable them in your browser.
UPDATE TO THIS POLICY
Protocol & Diplomacy Consultancy may modify this privacy policy to adapt it to legislative changes, criteria from the supervisory authority, or modifications in its personal data processing practices.
In such cases, the corresponding update will be announced on the website, indicating the date of the last revision.
Date of last update: February 2025
