English
Documentation for your legal adviser.
You can send this page as it is to the centre's adviser or to its board. It is written so that the security committee can sign off the decision without having to call us.
Who is who in the processing
- Controller: the centre (student accommodation or hall of residence) that contracts the service.
- Processor: Bedel IA, acting exclusively under the controller's documented instructions and under the signed DPA.
- Authorised sub-processors: database and authentication (EU), AI model (US, under SCCs), transactional email, Meta (WhatsApp Business Cloud API). An up-to-date list is in the DPA.
- Supervisory authority: the Agencia Española de Protección de Datos (AEPD), Spain's data protection authority. Complaints at aepd.es.
Lawful bases
- Resident data: performance of the centre's contract with the resident (GDPR Art. 6(1)(b)) + explicit consent for health data (allergens, Art. 9(2)(a)).
- Family data: the centre's legitimate interest in maintaining lines of contact + consent for non-essential communications.
- Staff data: performance of the employment or services contract (Art. 6(1)(b)).
- Confidential reports: compliance with a legal obligation — Act 3/2022 on University Coexistence (Art. 6(1)(c)).
Security measures
- TLS 1.2+ encryption in transit and AES-256 at rest (infrastructure in the EU).
- WhatsApp Business tokens encrypted with AES-256-GCM, with keys not accessible by the application.
- Isolation per organisation through Row Level Security (RLS) — no client can query another's data.
- 2FA available for staff (recommended; not mandatory by default).
- Auditable logs (audit_log + ticket_events), immutable and exportable to CSV/PDF.
- Breach notification to the AEPD in less than 72 hours, under GDPR Art. 33.
- Automatic daily encrypted backups with 30 days' retention.
International transfers
The AI model provider processes data in the United States. The transfer relies on the standard contractual clauses (SCCs) approved by the European Commission (Decision 2021/914) plus supplementary measures post-Schrems II: encryption in transit, a contractual policy of no training on client data, and payload minimisation: what is sent is the resident's message and the minimum context needed to answer them — their name, room and, when the query requires it, their allergens or diet — with no more data than necessary.
If the centre requires it, we can limit processing exclusively to non-identifying data (prior anonymisation) or use a model hosted in the EU (subject to technical feasibility).
Retention and portability
- Active messages: kept for the term of the contract + 6 months after termination (for claims and audits).
- Resolved tickets: 24 months; after that period the identifying data is anonymised.
- Health data (allergens): the term of the resident's contract with the centre.
- Audit logs: 5 years (AEPD / ENS / university account audits).
- Portability: CSV/JSON export available at any time from the centre's dashboard (endpoint
/api/export). After the contract ends you have 90 days to download all the data before certified deletion.
Data subjects' rights
Any resident, family member or member of staff can exercise their rights of access, rectification, erasure, restriction, portability and objection, and the right not to be subject to automated decisions (known in Spain by the acronym ARSULIPO). The first point of contact is always the centre, as controller. We, as processor, assist in exercising the right within 30 days.
Sector-specific compliance
- RD 126/2015 + EU Regulation 1169/2011: information on the 14 EU allergens in the centre's dining hall, cross-checked automatically against the resident's allergen record.
- Act 3/2022 on University Coexistence: an integrated confidential reporting channel, with urgent escalation to the management body.
- Crea y Crece Act + RD 238/2026: B2B electronic invoicing from 2027 (on the roadmap).
- Spain's National Security Framework (ENS): BASIC-level self-assessment available for public centres. MEDIUM categorisation on the roadmap.
- Meta policy, January 2026: the chatbot explicitly declares that it is an AI on first contact, offers a direct route to a human (the word "HUMANO") and respects the user's opt-out.
Does the board need something more specific?
We also sign a specific NDA, a DPIA (data protection impact assessment) if you process sensitive data at scale, and an employment contract if someone at the centre acts as system administrator.
Let's talk