ROPA
Record of Processing Activities (ROPA)
A record in accordance with Article 30 of Regulation (EU) 2016/679 (GDPR). Owner: Miguel Gamboa Sánchez (trading as Bedel), NIF 47402408Y, Abegondo (A Coruña), Spain. Contact: miguel@bedel.es.
Last updated: 23 July 2026.
This is a courtesy translation. The legally binding version of this document is the Spanish original, and it is the one that prevails in the event of any discrepancy. You can read it at the Spanish version of this page.
A) As Processor (on behalf of each centre)
Bedel processes this data on behalf of the centre (student accommodation or hall of residence), which is the Controller. See the data processing agreement (DPA).
- Activity: a WhatsApp assistant for residents, families and the centre's staff (incidents, bookings, alerts, surveys and the confidential reporting channel).
- Categories of data subjects: residents, family members and the centre's staff.
- Categories of data: identifying data (name, phone, email, room, year of study), the content of the WhatsApp messages, incidents and feedback. Special categories (Art. 9) — only if the centre expressly enables them: health data (allergies, intolerances and medically prescribed diets), switched off by default in every centre; and the content of reports (which may include harassment or mental health), only if the centre contracts the channel. In a centre that enables neither, no special category data is processed.
- Purpose: providing the centre's support and management service.
- Lawful basis: whichever the Controller centre determines (typically performance of a contract or legitimate interests; for special categories, the reinforced Art. 9 basis the centre provides).
- Recipients / sub-processors: database and authentication (EU), AI model providers (US), transactional email (US), Meta Platforms Ireland Ltd. (WhatsApp, EU), application hosting (EU), code repository and version control (US), corporate email (EU) and encrypted backup storage (EU). The identity of each provider is set out in the contract's Sub-processor Annex and is provided on request.
- International transfers: the AI model providers, the transactional email provider and the code repository, all in the US, covered by standard contractual clauses (SCCs) and supplementary measures. The reporting channel makes no international transfer whatsoever: the AI model takes no part in any of its stages.
- Retention period: for the term of the contract; deletion within 90 days of its end (unless a legal obligation applies). Reports are kept for the period each centre sets (1–10 years) and are destroyed automatically on expiry.
- Security measures (Art. 32): encryption in transit (TLS) and at rest, data isolation per centre (access control by organisation), specific encryption of reports and of the Meta credentials, and auditable access logs.
B) As Controller (Bedel's own data)
B.1 Commercial contacts and demo requests
- Data subjects: people requesting information or a demo.
- Data: name, job title, organisation, email, phone and the message they send.
- Purpose: handling the request and the commercial contact.
- Lawful basis: the data subject's consent and/or legitimate interests (Art. 6(1)(a)/(f)).
- Recipients: database (EU), where the request is logged; transactional email provider (US); Google Ireland Ltd. (Google Calendar, if the calendar is used for booking).
- Retention: for as long as there is commercial interest; deletion on request.
B.2 The website's interactive demo
- Data: IP address, the text the visitor enters and the generated response.
- Purpose: showing the demonstration and preventing abuse of the service.
- Lawful basis: legitimate interests (Art. 6(1)(f)).
- Recipients: database (EU) and AI model providers (US).
B.3 Staff access and dashboard telemetry
- Data: email, name and role of the dashboard's users; dashboard usage events (pseudonymised, with no personal content).
- Purpose: giving access to the dashboard and improving the product.
- Lawful basis: performance of the contract and legitimate interests.
- Recipients: database (EU).
Rights
Data subjects can exercise their rights of access, rectification, erasure, objection, restriction and portability by writing to miguel@bedel.es, and can complain to the Agencia Española de Protección de Datos (AEPD), Spain's data protection authority. For data processed as Processor, the exercise of rights is channelled through the Controller centre.