Privacy Policy
Last updated: June 18, 2026
This Privacy Policy describes how Cesar Ramos (hereinafter, the "Controller") processes the personal data of users of the website and application accessible from cervantes.training (the "Service"), in accordance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD).
For any matter relating to data protection, you may write to info@cervantes.training.
1. Data controller
Controller: Cesar Ramos. Address: 26/21 Bombery Street, Cannon Hill, QLD 4170, Australia. Website: cervantes.training. Contact email: info@cervantes.training.
2. Data we process
Registration and account data: name, email address, and password (stored in encrypted form using a hash). Date and version of acceptance of the Terms and of this Policy.
Service usage data: study progress, answers, mistakes, mock exams, statistics, and preferences (for example, language or settings). Much of this data may be stored locally on your device and, if you log in, synchronised with your account.
Technical data: IP address, device and browser identifiers, access dates and times, and data generated by cookies and similar technologies. If you enable push notifications, the subscription data necessary to send them.
3. Purposes and legal bases
To provide the Service, create and manage your account, and synchronise your progress (legal basis: performance of the contractual relationship arising from acceptance of the Terms).
To ensure security, prevent fraud and abuse, and maintain and improve the Service (legal basis: the Controller's legitimate interest).
To retain proof of acceptance of the Terms and of this Policy and to comply with legal obligations (legal basis: compliance with legal obligations and legitimate interest).
To send push notifications and use cookies or analytics tools that are not strictly necessary (legal basis: your consent, which you may withdraw at any time).
4. Data retention
The data will be retained for as long as the account is active and a relationship with the User exists. After the account is closed or a deletion request is made, the data will be erased or anonymised, unless it must be kept blocked during the periods legally required to address liabilities.
5. Recipients and data processors
We do not sell your personal data. To provide the Service we rely on suppliers acting as data processors, for example: hosting and infrastructure providers, database services, analytics and tag management tools (such as Google Tag Manager and the services activated through it), and push notification delivery services.
These suppliers only process the data in accordance with our instructions and applicable law. Likewise, we may disclose data where there is a legal obligation or where required by a competent authority.
6. International transfers
Some suppliers may process data outside the European Economic Area. In such case, these transfers are carried out with the appropriate safeguards provided for in the GDPR (for example, adequacy decisions or standard contractual clauses).
7. Cookies and similar technologies
The Service uses the browser's local storage for its operation (for example, to save your progress and preferences and to allow offline use) and may use cookies and similar technologies, including third-party ones for measurement and analytics purposes through tag managers.
Cookies and technologies that are not strictly necessary are only used with your consent. You can manage or revoke your preferences through your browser settings or through the mechanisms made available to you.
8. Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction of processing, and portability, as well as withdraw the consent given, by contacting info@cervantes.training. We may ask you to prove your identity.
If you consider that the processing of your data does not comply with the applicable regulations, you have the right to lodge a complaint with the competent supervisory authority. In Spain, the Spanish Data Protection Agency (AEPD, www.aepd.es).
9. Security
The Controller applies reasonable technical and organisational measures to protect personal data. However, no system is completely secure, so absolute security cannot be guaranteed. The User contributes to security by keeping their credentials confidential.
10. Minors
The Service is not directed at minors under fourteen (14) years of age, and they must not register or provide personal data. If we become aware that we have collected data from a minor under that age without the applicable consent, we will delete it.
11. Automated decisions and artificial intelligence
The content of the Service is generated and maintained with the help of artificial intelligence systems. These processes do not make automated decisions with legal or similarly significant effects on the User. As indicated in the Terms, the content may contain errors and must be verified against official sources.
12. Changes to this Policy
This Policy may be updated at any time. The version in force shall be the one published on the Service, with its date of update. We recommend that you review it periodically.