Skip to content
This is a machine translation. The version that binds the university is the Spanish one. Read it in Spanish.

Privacy Policy

Universidad Católica Digital de Guadalupe · Toledo, Spain

This page explains what data about you we process, why we process it, how long we keep it, and what you may require of us. It is written to be understandable; if anything is not clear, write to us and we will correct it.

The controller’s identifying information—NIF, registered address, registration details, and contact address for data protection matters—is provided below. Everything else in this document derives from the platform’s own operation and is accurate.

Who processes your data

  • Controller: Universidad Católica Digital de Guadalupe.
  • Promoted by: Private association of the faithful “Gaudium de veritate (the joy of truth).”
  • Registered office: Toledo, Spain.
  • NIF: R4500511C
  • Address: Calle Río Cabriel, 1, 45007 Toledo
  • Contact for data protection: info@iacampus.es

That address handles everything related to your data. We have not appointed a data protection officer (DPO): Article 37 of the GDPR requires one for public authorities and for those that systematically process data on a large scale or special categories of data, and that is not our case. If that ever changes, we will appoint one and state it here.

What data we process and why

When What Why Legal basis
You request information Name, email, telephone number, and Your message To respond to you and tell you how that study is progressing Your consent (Art. 6.1.a GDPR)
You enroll Enrolment and payment data To provide you with the educational service Performance of the contract (Art. 6.1.b)
You study Progress, exercises, assignments, conversations with assistants To teach you and be able to certify what you have done Contract and legal obligation (Art. 6.1.b and 6.1.c)
You apply for a scholarship What you tell us about your circumstances and the country you declare To decide on your application Your consent
You request a correction Your submission and the context of the correction For a person to review it Legal obligation and your consent

You declare the country associated with a scholarship application yourself. We never infer it from your IP address: geolocating means making an inference about a person, and it also fails. The browser also has access to geolocation, the camera, and the microphone denied across the entire platform.

How long we keep it

  • Conversations with assistants: 36 months, after which they are automatically deleted. The same applies to what you write in the summaries, responsiones, and help ladder.
  • If you requested information and never enrolled: 24 months.
  • Academic record (enrolments, grades, degrees): it is retained. This is not our decision: there is a legal obligation to retain it, and Art. 17.3.b of the GDPR excludes from the right to erasure anything that must be retained by law. Nor do we anonymize it, because an anonymous academic record certifies nothing.
  • Record of what an AI decided about you (what it corrected and with which model): it is retained separately from the conversation, because the European Artificial Intelligence Act requires that it be possible to reconstruct it.

Unenrolling does not mean deleting everything, and it is worth knowing this beforehand: when you unenroll, the pedagogical interaction is deleted and your access is closed, but the academic record remains for the reasons stated above.

Who else sees your data

To operate, the platform relies on providers acting on our behalf and only for the purposes assigned to them:

  • Artificial intelligence models (OpenAI, DeepSeek, Anthropic, and Gemini—by Google): they receive the text necessary to respond or correct. The purposes for which AI is used, what it decides, and what it does not decide are set out in the AI use policy.
  • Google Cloud Text-to-Speech: converts text into speech.
  • OVHcloud (European Union): stores class videos and backup copies.
  • Hostinger (European Union): is the server on which the platform runs, so it hosts the database containing everything described here.
  • buzondecorreo.com: delivers the email we send to you and hosts the admissions mailbox, so if you write to us, your message passes through it.

And two things that are NOT providers, so that the list does not mislead in the other direction. The automation that handles the admissions mailbox and registers information requests (n8n) is our software running on that same server: it is not a third party, and your message does not leave that server. And there is not yet a payment gateway: when there is one, it will be identified here before any payment is charged.

There are international transfers, because some of those AI providers are in the United States. They are covered by adequacy decisions and the European Commission’s standard contractual clauses.

We do not sell or disclose your data to anyone else, and we do not use third-party analytics: visits to the showcase site are counted in-house, without an IP address, cookie, or identifier of any kind. The only information stored consists of three daily counters:

  • how many times each page has been viewed;
  • the site from which the visitor arrived—only the site’s name, never the complete address, because a search address would contain what you wrote;
  • and how many times the website assistant was used, without information about who used it or what it was used for.

We do not know who you are when you browse the website.

Cookies

We use three, and all three are technical—the kind that the law does not require consent for:

  • idioma: remembers which language you prefer to read in.
  • session: keeps your session within the campus, and also stores the code that protects the public forms—the login form, the registration form, the password-recovery form, and the information-request form. That is why it may appear before you have an account: without it, those forms could not be submitted securely.
  • no_contar: only if you request it by visiting any page with ?no_contar=1. It prevents your visits from being included in the showcase-site count. It lasts one year and stores nothing other than a “1.”

That is why you will not see a cookie banner: there is nothing requiring consent.

What we store in your browser

In addition to cookies, the campus remembers a few preferences about how you view pages on your own device—and not on our servers. They do not leave your browser, we do not receive them, and they do not identify anyone:

  • uca-modo-lectura: whether you prefer a light or sepia background.
  • campusSidebarCollapsed: whether you have the side menu collapsed.
  • avatares_aviso: whether you have already closed a notice on the digital professors’ screen.

You can delete them from your browser whenever you wish; the only consequence is that you will see the pages again as they appear by default.

Automated decisions

No decision affecting you is made automatically. AI makes a proposal—a correction, a grade, or a learning path—and a person always validates it before it counts. Publishing a lesson, formally assigning a grade, and issuing a degree require the intervention of an instructor or the administration. This is what keeps the platform outside Article 22 of the GDPR, and it is explained in detail in the AI use policy.

If you believe an automated correction is unfair, you may challenge it: a person will review it, and we will respond to you in writing within 10 business days.

Your rights

At any time, you may ask us to access your data, rectify it, erase it, restrict its processing, object to it, and take it elsewhere (data portability). If you gave us your consent, you may withdraw it whenever you wish, without affecting what was done up to that point.

There is no need to request access: if you have an account, your user menu contains a “Download my data” option that immediately provides you with a file containing everything we store about you—your academic record and your activity on the campus—ready for you to read or take elsewhere. It also states what is not included and why: your account keys, which are not data that informs you about anything, and the identifier of the person who wrote to you, because your right of access cannot affect the rights of other people.

There is no need to request erasure, either: the same menu contains an “Unenroll me” option that closes your access and deletes what we are not required to retain. Before asking you, it shows you what will be retained and what will be deleted, with the numbers in front of you. What is not deleted is your academic record—your enrolments, grades, and the degrees we have issued to you—and this is not our decision: Article 17.3.b of the GDPR excludes from the right to erasure what must be retained by legal obligation. Nor do we anonymize it, because an anonymous academic record certifies nothing: anonymizing it would be destroying it under another name. If you have no academic record—an account that never reached enrolment—it is deleted in its entirety.

The other rights—rectification, restriction, objection, and portability—are requested at the address above and handled within one month.

If you believe we have not handled this properly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es). We would like you to tell us first, but you are under no obligation to do so.

Changes to this policy

If we change anything that affects you, we will state it here and—when appropriate—write to you about it. The version you are reading is the one currently in force.

Return to the summary

Edit the texts