← Volver al inicio

Política de Privacidad

Última actualización: agosto de 2026 · Solutions Institute

La presente política de privacidad cumple con el Reglamento (UE) 2016/679 (RGPD), la Ley Orgánica 3/2018 (LOPDGDD) y demás normativa vigente. Los datos personales se tratan de forma lícita, leal y transparente, con las medidas de seguridad técnicas y organizativas apropiadas.

Cancelación de citas

Las sesiones, clases o programas ya reservados pueden cancelarse o aplazarse de forma gratuita hasta 24 horas antes de la cita acordada.

En caso de cancelación posterior o incomparecencia, la cita se facturará íntegramente y no podrá recuperarse.

Aviso legal

En cumplimiento de la normativa aplicable, se informa de los siguientes datos del titular:

Esther Butenschoen
Solutions Institute
Calpe, España
esther@solutions.institute

Responsable del contenido: Esther Butenschoen, Calpe, España

I. Responsable del tratamiento

IdentidadEsther Butenschoen: Solutions Institute
CIF / NIF[CIF / NIF]
DomicilioCalpe, España
Teléfono-
E-mailesther@solutions.institute
Sitio webSolutions Institute

Ejercicio de derechos: esther@solutions.institute (o por correo postal a la dirección indicada, adjuntando copia de NIF/NIE/Pasaporte).

II. Finalidades, bases jurídicas y plazos de conservación

Para cada tratamiento de datos se indica la finalidad, la base jurídica que lo legitima y el plazo de conservación:

1. Formulario de contacto

Finalidad: Atender consultas y solicitudes de información.

Base jurídica: Consentimiento del interesado (art. 6.1.a RGPD).

Conservación: Hasta que se resuelva la consulta; después, hasta 3 años para acreditar el cumplimiento de nuestras obligaciones.

Datos tratados: Nombre, email, teléfono (si se facilita), contenido del mensaje.

2. Gestión de reservas y pedidos

Finalidad: Gestión, ejecución y seguimiento de reservas, pedidos y membresías.

Base jurídica: Ejecución de contrato (art. 6.1.b RGPD).

Conservación: Durante la relación contractual y, una vez finalizada, durante 6 años por obligación fiscal (Ley General Tributaria).

Datos tratados: Nombre, email, teléfono, datos de la reserva/pedido, historial de transacciones.

3. Procesamiento de pagos (Stripe)

Finalidad: Tramitar el cobro de reservas, pedidos y membresías.

Base jurídica: Ejecución de contrato (art. 6.1.b RGPD).

Conservación: Los datos de pago no son almacenados por el Titular. Son tratados directamente por el proveedor de pago (Stripe) como encargado del tratamiento, sujeto a su propia política de privacidad.

Datos tratados: Nombre del titular, datos de la tarjeta/cuenta (gestionados exclusivamente por la pasarela de pago), importe, referencia de transacción.

4. Comunicaciones comerciales y newsletter (SendGrid)

Finalidad: Envío de comunicaciones comerciales, promociones y novedades.

Base jurídica: Consentimiento expreso del interesado (art. 6.1.a RGPD y art. 21 LSSI-CE).

Conservación: Hasta que el usuario retire su consentimiento. La retirada del consentimiento no afectará a la licitud del tratamiento previo.

Datos tratados: Email, nombre (si se facilita), preferencias de comunicación.

III. Destinatarios y transferencias internacionales

Con carácter general, los datos no serán cedidos a terceros salvo obligación legal. No obstante, para la prestación del servicio se utilizan los siguientes proveedores que actúan como encargados del tratamiento:

HerramientaProveedorPaísDatos transferidosGarantía
StripeStripe, Inc.EE.UU.Datos de pago, nombre del titular, referencia de transacciónCláusulas contractuales tipo UE (art. 46 RGPD)
SendGrid (Twilio)Twilio Inc.EE.UU.Email, nombre (emails transaccionales y de confirmación)Cláusulas contractuales tipo UE (art. 46 RGPD)
Google Tag ManagerGoogle LLCEE.UU.IP (gestión de etiquetas; no recoge datos propios)Cláusulas contractuales tipo UE (art. 46 RGPD)
Meta Pixel (previsto)Meta Platforms, Inc.EE.UU.IP, comportamiento de navegación, conversiones (pendiente de activación; requiere consentimiento previo)Cláusulas contractuales tipo UE (art. 46 RGPD)

Las transferencias a países fuera del Espacio Económico Europeo (EEE) se realizan amparadas en cláusulas contractuales tipo aprobadas por la Comisión Europea (art. 46 RGPD) o en la decisión de adecuación correspondiente.

IV. Derechos

Le informamos de que puede ejercer los siguientes derechos sobre sus datos personales:

Derecho de acceso
Derecho a obtener confirmación de si se están tratando datos personales que le conciernen y, en su caso, acceso a los mismos y a la información prevista en el RGPD.
Derecho de rectificación
Derecho a solicitar la rectificación de datos inexactos o la completitud de datos incompletos.
Derecho de supresión
Derecho a solicitar la supresión de sus datos cuando ya no sean necesarios para la finalidad por la que fueron recabados, salvo obligación legal de conservación.
Derecho a la limitación
Derecho a solicitar la limitación del tratamiento en los supuestos previstos en el RGPD.
Derecho a retirar el consentimiento
Derecho a retirar el consentimiento en cualquier momento, sin efectos retroactivos cuando el tratamiento se base en el consentimiento.
Derecho a la portabilidad
Derecho a recibir sus datos en formato estructurado y a transmitirlos a otro responsable cuando el tratamiento se base en el consentimiento o en un contrato y se efectúe por medios automatizados.
Derecho de oposición
Derecho a oponerse al tratamiento basado en interés legítimo, salvo motivos legítimos imperiosos que prevalezcan.
Derecho a presentar una reclamación
Si considera que tratamos sus datos de forma incorrecta, puede reclamar ante la Agencia Española de Protección de Datos (AEPD): C/ Jorge Juan, 6, 28001 Madrid. www.aepd.es

Ejercicio de derechos: Puede ejercer los derechos que le asisten mediante escrito a la dirección postal o correo electrónico indicados al inicio de este documento, adjuntando copia de su NIF/NIE/Pasaporte o documento análogo que acredite su identidad.

V. Seguridad y notificación de brechas

El Titular adopta las medidas técnicas y organizativas necesarias para garantizar la seguridad de los datos personales y evitar su alteración, pérdida, tratamiento o acceso no autorizado.

En caso de producirse una violación de seguridad que suponga un riesgo para los derechos y libertades de los interesados, el Titular lo notificará a la AEPD en el plazo máximo de 72 horas desde que tenga conocimiento de ella, conforme al art. 33 RGPD. Si la brecha supone un alto riesgo para los afectados, también se les notificará directamente.

VI. Transferencias internacionales de datos

El Responsable utiliza los siguientes proveedores externos con sede fuera del Espacio Económico Europeo (EEE), todos ellos actuando como encargados del tratamiento bajo cláusulas contractuales tipo aprobadas por la Comisión Europea (art. 46 RGPD):

  • Stripe, Inc. (EE.UU.): procesamiento de pagos. Certificado PCI-DSS nivel 1. Política: stripe.com/privacy-center/legal
  • Twilio Inc. / SendGrid (EE.UU.): envío de emails transaccionales y de confirmación. Política: twilio.com/legal/privacy
  • Google LLC / Google Tag Manager (EE.UU.): gestión de etiquetas web. Política: policies.google.com/privacy
  • Meta Platforms, Inc. / Meta Pixel (EE.UU.): pendiente de activación. Cuando se active, recogerá datos de comportamiento y conversiones con fines publicitarios, con consentimiento previo del usuario. Política: facebook.com/privacy/policy

VII. Decisiones automatizadas y elaboración de perfiles

El Responsable no realiza decisiones automatizadas ni elaboración de perfiles con efectos jurídicos o significativos para el Usuario (RGPD art. 22).

VIII. Modificaciones

El Responsable podrá actualizar esta Política de Privacidad para adaptarla a cambios legales o en los tratamientos realizados. La versión publicada en el Sitio Web con su fecha de actualización será siempre la versión vigente.

Privacy Policy

Last updated: August 2026 · Solutions Institute

This privacy policy complies with Regulation (EU) 2016/679 (GDPR), Organic Law 3/2018 (LOPDGDD) and other applicable legislation. Personal data is processed lawfully, fairly and transparently, with appropriate technical and organisational security measures.

Appointment cancellations

Booked sessions, lessons or programmes may be cancelled or rescheduled free of charge up to 24 hours before the agreed appointment.

In the event of a later cancellation or a no-show, the appointment will be charged in full and cannot be made up.

Legal notice

In accordance with applicable law, the following details of the owner are provided:

Esther Butenschoen
Solutions Institute
Calpe, Spain
esther@solutions.institute

Responsible for content: Esther Butenschoen, Calpe, Spain

I. Data controller

IdentityEsther Butenschoen: Solutions Institute
Tax ID (CIF / NIF)[CIF / NIF]
AddressCalpe, Spain
Phone-
Emailesther@solutions.institute
WebsiteSolutions Institute

Exercising your rights: esther@solutions.institute (or by post to the address indicated above, attaching a copy of your ID/NIE/Passport).

II. Purposes, legal bases and retention periods

For each processing activity, the purpose, legal basis and retention period are indicated below:

1. Contact form

Purpose: To respond to enquiries and information requests.

Legal basis: Data subject consent (Art. 6.1.a GDPR).

Retention: Until the enquiry is resolved; thereafter, up to 3 years to demonstrate compliance with our obligations.

Data processed: Name, email, phone (if provided), message content.

2. Bookings and orders management

Purpose: Management, execution and follow-up of bookings, orders and memberships.

Legal basis: Performance of a contract (Art. 6.1.b GDPR).

Retention: For the duration of the contractual relationship and, once ended, for 6 years due to tax obligations (Spanish General Tax Law).

Data processed: Name, email, phone, booking/order details, transaction history.

3. Payment processing (Stripe)

Purpose: To process payment for bookings, orders and memberships.

Legal basis: Performance of a contract (Art. 6.1.b GDPR).

Retention: Payment data is not stored by the Controller. It is processed directly by the payment provider (Stripe) as a data processor, subject to its own privacy policy.

Data processed: Cardholder name, card/account data (handled exclusively by the payment gateway), amount, transaction reference.

4. Commercial communications and newsletter (SendGrid)

Purpose: Sending commercial communications, promotions and news.

Legal basis: Express consent of the data subject (Art. 6.1.a GDPR and Art. 21 LSSI-CE).

Retention: Until the user withdraws consent. Withdrawal does not affect the lawfulness of prior processing.

Data processed: Email, name (if provided), communication preferences.

III. Recipients and international transfers

As a general rule, data will not be disclosed to third parties except where required by law. However, the following providers acting as data processors are used to deliver the service:

ToolProviderCountryData transferredSafeguard
StripeStripe, Inc.USAPayment data, cardholder name, transaction referenceEU Standard Contractual Clauses (Art. 46 GDPR)
SendGrid (Twilio)Twilio Inc.USAEmail, name (transactional and confirmation emails)EU Standard Contractual Clauses (Art. 46 GDPR)
Google Tag ManagerGoogle LLCUSAIP (tag management; does not collect data itself)EU Standard Contractual Clauses (Art. 46 GDPR)
Meta Pixel (planned)Meta Platforms, Inc.USAIP, browsing behaviour, conversions (pending activation; requires prior consent)EU Standard Contractual Clauses (Art. 46 GDPR)

Transfers to countries outside the European Economic Area (EEA) are carried out under EU Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR) or the relevant adequacy decision.

IV. Your rights

You may exercise the following rights regarding your personal data:

Right of access
Right to obtain confirmation as to whether personal data concerning you is being processed and, where that is the case, access to the data and the information provided for in the GDPR.
Right to rectification
Right to request correction of inaccurate data or completion of incomplete data.
Right to erasure
Right to request deletion of your data when it is no longer necessary for the purpose for which it was collected, unless legal obligations require retention.
Right to restriction
Right to request restriction of processing in the cases provided for in the GDPR.
Right to withdraw consent
Right to withdraw consent at any time, without retroactive effect where processing is based on consent.
Right to data portability
Right to receive your data in a structured format and to transmit it to another controller where processing is based on consent or contract and carried out by automated means.
Right to object
Right to object to processing based on legitimate interest, unless compelling legitimate grounds override your interests.
Right to lodge a complaint
If you believe we are processing your data incorrectly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD): C/ Jorge Juan, 6, 28001 Madrid. www.aepd.es

Exercising your rights: You may exercise your rights by writing to the postal or email address indicated at the beginning of this document, attaching a copy of your ID/NIE/Passport or equivalent proof of identity.

V. Security and breach notification

The Controller adopts the technical and organisational measures necessary to ensure the security of personal data and prevent unauthorised alteration, loss, processing or access.

In the event of a security breach that poses a risk to the rights and freedoms of data subjects, the Controller will notify the AEPD within 72 hours of becoming aware of it, in accordance with Art. 33 GDPR. If the breach poses a high risk to those affected, they will also be notified directly.

VI. International data transfers

The Controller uses the following external providers based outside the European Economic Area (EEA), all acting as data processors under EU Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR):

VII. Automated decisions and profiling

The Controller does not carry out automated decision-making or profiling with legal or similarly significant effects for the User (GDPR Art. 22).

VIII. Changes

The Controller may update this Privacy Policy to reflect legal changes or changes in processing activities. The version published on the Website with its update date will always be the current version.

Datenschutz

Letzte Aktualisierung: August 2026 · Solutions Institute

Die vorliegende Datenschutzerklärung entspricht der Verordnung (EU) 2016/679 (DSGVO), dem spanischen Organic Law 3/2018 (LOPDGDD) und der übrigen geltenden Rechtslage. Personenbezogene Daten werden rechtmäßig, fair und transparent verarbeitet, mit angemessenen technischen und organisatorischen Sicherheitsmaßnahmen.

Terminabsagen

Bereits gebuchte Sitzungen, Unterrichtsstunden oder Programme können bis spätestens 24 Stunden vor dem vereinbarten Termin kostenfrei abgesagt oder verschoben werden.

Bei einer späteren Absage oder Nichterscheinen wird der Termin voll berechnet und kann nicht nachgeholt werden.

Impressum

In Erfüllung der geltenden Vorschriften werden die folgenden Angaben zum Verantwortlichen mitgeteilt:

Esther Butenschoen
Solutions Institute
Calpe, Spanien
esther@solutions.institute

Verantwortlich für den Inhalt: Esther Butenschoen, Calpe, Spanien

I. Verantwortlicher

IdentitätEsther Butenschoen: Solutions Institute
CIF / NIF[CIF / NIF]
AnschriftCalpe, Spanien
Telefon-
E-Mailesther@solutions.institute
WebsiteSolutions Institute

Ausübung der Rechte: esther@solutions.institute (oder per Post an die oben angegebene Anschrift, mit Kopie von Ausweis/NIE/Reisepass).

II. Zwecke, Rechtsgrundlagen und Speicherdauern

Für jede Verarbeitung werden Zweck, Rechtsgrundlage und Speicherdauer angegeben:

1. Kontaktformular

Zweck: Beantwortung von Anfragen.

Rechtsgrundlage: Einwilligung der betroffenen Person (Art. 6 Abs. 1 lit. a DSGVO).

Speicherung: Bis zur Klärung der Anfrage; danach bis zu 3 Jahre zum Nachweis unserer Pflichten.

Verarbeitete Daten: Name, E-Mail, Telefon (falls angegeben), Inhalt der Nachricht.

2. Buchungen und Bestellungen

Zweck: Verwaltung, Durchführung und Nachverfolgung von Buchungen, Bestellungen und Mitgliedschaften.

Rechtsgrundlage: Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).

Speicherung: Für die Dauer der Vertragsbeziehung und danach 6 Jahre aufgrund steuerlicher Pflichten.

Verarbeitete Daten: Name, E-Mail, Telefon, Buchungs-/Bestelldaten, Transaktionshistorie.

3. Zahlungsabwicklung (Stripe)

Zweck: Abwicklung der Zahlung für Buchungen, Bestellungen und Mitgliedschaften.

Rechtsgrundlage: Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).

Speicherung: Zahlungsdaten werden vom Verantwortlichen nicht gespeichert. Sie werden direkt vom Zahlungsdienstleister (Stripe) als Auftragsverarbeiter verarbeitet.

Verarbeitete Daten: Name des Karteninhabers, Karten-/Kontodaten (ausschließlich über das Zahlungsportal), Betrag, Transaktionsreferenz.

4. Werbung und Newsletter (SendGrid)

Zweck: Versand von Informationen, Angeboten und Neuigkeiten.

Rechtsgrundlage: Ausdrückliche Einwilligung (Art. 6 Abs. 1 lit. a DSGVO und Art. 21 LSSI-CE).

Speicherung: Bis zum Widerruf der Einwilligung. Der Widerruf berührt nicht die Rechtmäßigkeit der vorherigen Verarbeitung.

Verarbeitete Daten: E-Mail, Name (falls angegeben), Kommunikationspräferenzen.

III. Empfänger und internationale Übermittlungen

Daten werden grundsätzlich nicht an Dritte weitergegeben, außer bei gesetzlicher Pflicht. Zur Leistungserbringung werden folgende Auftragsverarbeiter eingesetzt:

ToolAnbieterLandÜbermittelte DatenGarantie
StripeStripe, Inc.USAZahlungsdaten, Name, TransaktionsreferenzEU-Standardvertragsklauseln (Art. 46 DSGVO)
SendGrid (Twilio)Twilio Inc.USAE-Mail, Name (transaktionale E-Mails)EU-Standardvertragsklauseln (Art. 46 DSGVO)
Google Tag ManagerGoogle LLCUSAIP (Tag-Verwaltung)EU-Standardvertragsklauseln (Art. 46 DSGVO)
Meta Pixel (geplant)Meta Platforms, Inc.USAIP, Nutzungsverhalten, Conversions (noch nicht aktiv; nur mit Einwilligung)EU-Standardvertragsklauseln (Art. 46 DSGVO)

Übermittlungen in Länder außerhalb des EWR erfolgen auf Grundlage der von der Europäischen Kommission genehmigten Standardvertragsklauseln (Art. 46 DSGVO) oder eines Angemessenheitsbeschlusses.

IV. Ihre Rechte

Sie können folgende Rechte in Bezug auf Ihre personenbezogenen Daten ausüben:

Auskunftsrecht
Recht auf Bestätigung, ob Sie betreffende personenbezogene Daten verarbeitet werden, und auf Auskunft über diese Daten.
Recht auf Berichtigung
Recht, unrichtige Daten berichtigen oder unvollständige Daten vervollständigen zu lassen.
Recht auf Löschung
Recht auf Löschung, wenn die Daten für den ursprünglichen Zweck nicht mehr erforderlich sind, soweit keine gesetzliche Aufbewahrungspflicht besteht.
Recht auf Einschränkung
Recht, die Einschränkung der Verarbeitung in den von der DSGVO vorgesehenen Fällen zu verlangen.
Widerruf der Einwilligung
Recht, eine Einwilligung jederzeit zu widerrufen, ohne dass die Rechtmäßigkeit der bis dahin erfolgten Verarbeitung berührt wird.
Recht auf Datenübertragbarkeit
Recht, Ihre Daten in einem strukturierten Format zu erhalten und an einen anderen Verantwortlichen zu übermitteln, wenn die Verarbeitung auf Einwilligung oder Vertrag beruht und automatisiert erfolgt.
Widerspruchsrecht
Recht, einer Verarbeitung auf Grundlage berechtigter Interessen zu widersprechen, sofern keine überwiegenden zwingenden Gründe vorliegen.
Beschwerderecht
Wenn Sie der Ansicht sind, dass wir Ihre Daten unrichtig verarbeiten, können Sie sich an die spanische Datenschutzbehörde (AEPD) wenden: C/ Jorge Juan, 6, 28001 Madrid. www.aepd.es

Ausübung der Rechte: Schriftlich an die zu Beginn dieses Dokuments angegebene Post- oder E-Mail-Adresse, mit Kopie von Ausweis/NIE/Reisepass oder einem gleichwertigen Identitätsnachweis.

V. Sicherheit und Meldung von Verletzungen

Der Verantwortliche trifft die erforderlichen technischen und organisatorischen Maßnahmen, um die Sicherheit der personenbezogenen Daten zu gewährleisten und unbefugte Veränderung, Verlust, Verarbeitung oder Zugriff zu verhindern.

Bei einer Sicherheitsverletzung, die ein Risiko für die Rechte und Freiheiten betroffener Personen darstellt, benachrichtigt der Verantwortliche die AEPD innerhalb von 72 Stunden nach Kenntniserlangung gemäß Art. 33 DSGVO. Bei hohem Risiko werden die Betroffenen zusätzlich direkt informiert.

VI. Internationale Datenübermittlungen

Der Verantwortliche setzt folgende externe Anbieter mit Sitz außerhalb des EWR ein, die als Auftragsverarbeiter unter EU-Standardvertragsklauseln tätig sind:

VII. Automatisierte Entscheidungen und Profiling

Der Verantwortliche trifft keine automatisierten Entscheidungen und erstellt kein Profiling mit rechtlicher oder ähnlich erheblicher Wirkung für die Nutzerin oder den Nutzer (Art. 22 DSGVO).

VIII. Änderungen

Der Verantwortliche kann diese Datenschutzerklärung anpassen, um rechtliche Änderungen oder Änderungen der Verarbeitung abzubilden. Maßgeblich ist stets die auf der Website veröffentlichte Fassung mit ihrem Aktualisierungsdatum.