Privacy policy
Last updated: May 7, 2026
This policy explains how Rubén Benarroch Esayag, owner of rupgo.com, processes your personal data in compliance with Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 on the Protection of Personal Data and guarantee of digital rights (LOPDGDD) and Spanish Law 34/2002 on Information Society Services (LSSI-CE).
01Data controller
Controller: Rubén Benarroch Esayag
NIF (Spanish tax ID): 50905553K
Address: Calle Antonio Acuña 19, 28009 Madrid (Spain)
Email: rubenbenarroch@gmail.com
Phone: +34 652 111 007
For any matter related to data protection, you can contact the controller directly through the email indicated above.
02What personal data we collect
We process the following categories of data depending on how you interact with the site:
- Identification data: first name, last name, email, phone where applicable.
- Professional data: company name, role, team size, sector (in the private cohort form).
- Billing data: NIF (Spanish tax ID), postal address, amount paid and Stripe reference (for issuing a simplified or full invoice).
- Service usage data: progress in the workshop, forum messages, 1:1 booking dates, completed sessions.
- Technical and browsing data: approximate IP address, browser, operating system, pages visited, interaction events (CTA clicks). Collected via Vercel Analytics and Google Analytics.
03What we use your data for
We process the data exclusively for the following purposes:
- Processing your enrollment in the workshop, 1:1 session, audit or any contracted service, including payment management and invoice issuance.
- Granting you access to the student dashboard, managing your progress, answering questions in the forum and sending you the workshop content.
- Sending you operational communications related to the service (session reminders, recordings, materials).
- Responding to information requests (private cohort form, contacts by email).
- Complying with legal tax, accounting and data protection obligations.
- Analyzing the use of the site to improve content and experience (aggregated analytics, not personalized marketing).
04Legal basis for processing
| Processing | Legal basis (art. 6 GDPR) |
|---|---|
| Enrollment and service delivery | Performance of contract (art. 6.1.b) |
| Invoicing and tax obligations | Legal obligation (art. 6.1.c) — Spanish General Tax Law |
| Contact forms and business leads | Consent (art. 6.1.a) — upon submitting the form |
| Analytics and tracking cookies | Consent (art. 6.1.a) — cookie banner |
| Functional cookies (session) | Legitimate interest (art. 6.1.f) — essential for the service |
| Commercial communications | Consent (art. 6.1.a) — express opt-in |
05Retention periods
We retain your data only for the time necessary to fulfill the purposes for which it was collected and to meet the legal responsibilities that may arise, according to the following indicative periods:
| Type of data | Period |
|---|---|
| Data of paying students (billing) | 5 years (art. 66 Spanish General Tax Law) |
| Workshop progress data | While your account is active, up to 3 years from the last session |
| Private cohort leads (not converted) | 1 year from the last contact |
| Forum and community messages | While your account is active |
| Google Analytics data | 14 months (default configuration) |
| Vercel Analytics data | 30 days |
| Functional cookies (session) | 90 days or until logout |
Once the applicable period has expired, data is securely anonymized or deleted. You can request immediate removal at any time by exercising your rights (see below).
06Transfers to third parties (data processors)
To provide the service we use the following providers acting as data processors, all of them with a signed contract in accordance with art. 28 GDPR:
| Provider | Purpose | Location |
|---|---|---|
| Stripe Payments Europe Ltd. | Payment processing and billing | Ireland · USA |
| Resend | Sending transactional emails | USA |
| Vercel Inc. | Web hosting and analytics | USA · EU |
| Railway Corp. | PostgreSQL database | USA |
| Google LLC (Analytics 4) | Web usage analytics | USA |
| Google LLC (Calendar) | 1:1 booking management and video calls | USA |
| Telegram Messenger Inc. | Workshop group notifications | United Kingdom · Dubai |
We do not share your data with third parties for their own commercial purposes. Data is only shared with authorities when there is a legal obligation.
07International transfers
Some of the providers indicated above (Stripe, Resend, Vercel, Railway, Google) have infrastructure in the United States. In all cases the transfers are carried out with the safeguards required by the GDPR:
- Adherence to the EU-US Data Privacy Framework certified by the European Commission (adequacy decision of 10 July 2023), or
- Standard Contractual Clauses (SCC) approved by the European Commission when the provider has not adhered to the DPF.
08Your rights
In accordance with the GDPR and the LOPDGDD, you have the right to:
- Access: know what data of yours we process.
- Rectification: correct inaccurate or incomplete data.
- Erasure: delete your data when it is no longer necessary or you withdraw consent (“right to be forgotten”).
- Objection: object to processing on legitimate grounds.
- Restriction: request the restriction of processing in certain cases.
- Portability: receive your data in a structured format and transmit it to another controller.
- Withdrawal of consent: withdraw your consent at any time without affecting the lawfulness of prior processing.
- Not being subject to automated decisions: we do not apply automated profiling with legal effects.
To exercise any of these rights, write to us at rubenbenarroch@gmail.com indicating the right you are exercising and providing a copy of your ID or equivalent document to verify your identity. We will respond within a maximum period of one month.
If you consider that your rights have not been properly handled, you may file a claim with the AEPD (Spanish Data Protection Agency) (aepd.es), C/ Jorge Juan 6, 28001 Madrid.
09Security measures
We apply reasonable technical and organizational measures to protect your data, including: encryption in transit (HTTPS/TLS), database encryption at rest, access management based on least privilege, strong authentication for the admin panel, regular backups, and continuous review of providers and their security practices.
10Minors
The service is intended for adults. We do not knowingly collect data from minors under 14. If we detect that a minor has provided us with data without their guardians’ authorization, we will delete it as soon as possible.
11Changes to this policy
We may update this policy to reflect legal or service changes. The “Last updated” date at the beginning of the document indicates the current version. Substantial changes will be notified by email to users with an active account.