How we comply with the GDPR.
Bedel answers residents, families and staff of halls of residence and student accommodation on WhatsApp. Here, in plain terms, is how we protect their data and how we comply with Regulation (EU) 2016/679 (GDPR) and Spain's LOPDGDD. No promises the system doesn't keep.
- Data hosted in the European Union (Ireland / Dublin).
- Encryption in transit (TLS); application-level encryption (AES-256-GCM) for reports, allergy notes and credentials.
- Data Processing Agreement (DPA, Art. 28) ready to sign.
- A real right to erasure, and data export.
- Declared sub-processors, with Standard Contractual Clauses where they apply.
- Breach notification in less than 72 hours (Art. 33).
- An encrypted, confidential reporting channel (Spanish Act 3/2022).
- An AI disclosure, and the option to escalate to a person at the centre.
1Controller and processor (Art. 28)
The controller of the data is the centre (the hall of residence or student accommodation). Bedel acts as processor on its behalf, processing the data only in accordance with its documented instructions.
Processor: Miguel Gamboa Sánchez (trading as Bedel), NIF 47402408Y, Abegondo (A Coruña), Spain. The relationship is formalised through a Data Processing Agreement (DPA) under Art. 28 GDPR.
2What data we process, and on what basis
Data subjects: residents, their family members and the centre's staff. Data: identifying details (name, phone number, email, room, year of study), the content of the WhatsApp conversations, incidents, dining-hall bookings and feedback.
Lawful basis: performance of the contract between the resident and the centre (Art. 6(1)(b)) and the centre's legitimate interest in looking after and protecting its residents.
Special categories (Art. 9): health data (allergens and diets for medical reasons) and the content of the reporting channel. Art. 9 prohibits processing these except in specific cases, so here the basis is the person's explicit consent (Art. 9(2)(a)), which the centre obtains and keeps; without it, the data should not be recorded. It is stored with restricted access — only the person themselves and whoever on the team needs it for the dining hall — and it is excluded from the internal improvement analysis, which is carried out on de-identified data. On top of that, both the content of the reporting channel and the notes on the allergy record — where the clinical detail sits — carry application-level encryption (AES-256-GCM): if someone reached the database, they still could not read them.
3Your rights, and how to exercise them
You can exercise the rights of access, rectification, erasure, objection, restriction and portability. Write to the centre or to miguel@bedel.es; we answer within 30 days at most. If you believe they are not being respected, you can complain to the Agencia Española de Protección de Datos, the Spanish data protection authority (aepd.es).
The right to erasure is real: exercising it genuinely deletes the record, the conversations, the messages and the phone number; the centre's maintenance history is kept, already anonymised. The centre can also export the data in an open format.
4Security measures (Art. 32)
- Encryption at rest (AES-256-GCM): of the reporting channel, of the notes on the allergy record and of the messaging credentials. For reports it is fail-closed: without the key, the system does not store them. For allergies it deliberately is not — stopping the kitchen from recording an allergy would be more dangerous than storing it.
- Encryption in transit (TLS): on all communications; private documents are shared through links that expire.
- Message authenticity: every incoming message is validated against its cryptographic signature; unsigned ones are rejected.
- Isolation per centre: access control at database level (RLS) and by role; each centre sees only its own data.
- Anti-impersonation checks: residents are verified with a one-time code, rate-limited against brute force.
- Audit trail: accesses to the reporting channel and verification attempts are logged.
5Processing by artificial intelligence
To understand and draft the answers we use a language model from a specialist provider, which acts as a sub-processor and does not train its models on the messages we send it, and we process the minimum content necessary. The content of the reporting channel is handled through a separate encrypted channel and does not go through the AI.
The first time Bedel replies in a conversation, it discloses that it is an automated assistant. Anyone can write HUMANO to speak to a person. Bedel does not take decisions with legal effect on a solely automated basis (Art. 22): the case is passed to a person at the centre.
6Sub-processors
We rely on a small number of providers, all with the same guarantees. We give notice in advance of any change.
| Provider | Function | Location | Safeguard |
|---|---|---|---|
| Database and storage | Centre data, authentication and files | European Union (Ireland) | — |
| WhatsApp messaging | WhatsApp Business Cloud API (Meta Platforms Ireland) | European Union (Ireland) | — |
| Application hosting | Running the dashboard and the functions | European Union (Dublin) | — |
| Artificial intelligence model | Generating the assistant's replies | United States | SCCs · no training |
| Transactional email | Operational alerts by email | United States | SCCs |
7International transfers
Most of the data is processed in the European Union. Transfers to the United States (the AI model and transactional email) rely on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) and on supplementary measures post-Schrems II: encryption, no training of the model and minimisation of the data sent.
8Retention and the reporting channel
Data is kept for as long as the relationship with the centre lasts and for the periods the law requires; it is deleted on request (right to erasure).
The reporting channel (Spanish Act 3/2022) allows anonymous submissions; the account is stored encrypted and the alert to Management states only the category, never the content. It has its own retention period (1 to 10 years, as the centre sets it), after which the system destroys it automatically.
9Security breaches
In the event of a personal data breach, we notify the centre without undue delay and in less than 72 hours (Art. 33), with the information it needs to meet its own obligations.
For the binding legal detail — DPA, record of processing activities (ROPA), transfers — see the legal documentation and the privacy policy, both in Spanish. Data protection questions? miguel@bedel.es or half an hour with the person who built it.