PRIVACY POLICY — THE BESS ACADEMY
Last updated: January 29, 2026
This Privacy Policy governs the processing of personal data provided by users on the website https://thebessacademy.com (hereinafter, “the Website”), owned by Exergía y Formación S.L.U.
1. IDENTITY OF THE DATA CONTROLLER
Controller: Exergía y Formación S.L.U.
CIF: B24977472
Address: C/ Málaga 39, Pinto, 28320, Madrid, Spain
Contact email: hola@thebessacademy.com
Website: https://thebessacademy.com
2. PERSONAL DATA COLLECTED
Depending on your use of the Website, we may collect:
2.1. Browsing data
- IP address
- Cookies and technical data
- Browser and device identifiers
(See Cookie Policy)
2.2. Student registration data
- First and last name
- Password (stored encrypted)
- Country and preferences
2.3. Purchase data
- First and last name
- Billing address
- Country / state / postal code
- ID/Tax ID (if required for invoice)
- Tax information
- Order history
2.4. Course access data (TutorLMS)
- Course progress
- Lessons completed
- Activity times
- Quiz and test results
- Certificates generated
2.5. Payment data
Card data is NOT stored at The BESS Academy.
Payments are processed by third parties:
- Stripe Payments Europe, Ltd.
- PayPal (if enabled)
These providers comply with PCI-DSS.
2.6. Data for commercial communications
- Subscription preferences
- Newsletter activity (opens, clicks)
Through MailerLite, acting as Data Processor.
3. PURPOSE OF PROCESSING
Your data will be used for:
3.1. User and account management
- Creating and managing your Academy account
- Granting access to courses
- Password recovery
3.2. Purchase processing
- Invoicing
- Issuing receipts
- Payment management
- Anti-fraud control
3.3. Provision of educational services
- Progress tracking
- Training activities (tests, quizzes)
- Issuing certificates
- Student support
3.4. Communications
- Sending information about the purchased course
- Sending service-related communications
- Sending newsletters if the user voluntarily subscribes
(No marketing will be sent without consent.)
3.5. Legal compliance
- Tax obligations
- Accounting obligations
- Responding to authority requests
4. LAWFUL BASIS FOR PROCESSING
Data is processed based on:
4.1. Contract performance
To grant you access to the purchased course or service.
4.2. User consent
To send newsletters or non-mandatory training materials.
4.3. Legal obligation
To comply with tax and accounting regulations.
4.4. Legitimate interest
Service improvement, website security, fraud prevention.
5. DATA RECIPIENTS
Your data may be shared with:
5.1. Technology providers
- Stripe (payments)
- WooCommerce (order management)
- TutorLMS (course management)
- MailerLite (newsletter)
- Hostinger (site hosting)
Always under Data Processing Agreements.
5.2. Public Administrations
Only when there is a legal obligation (Tax Authority, etc.).
We never sell or transfer your data to third parties for commercial purposes.
6. DATA RETENTION
6.1. Purchase data
15 years (tax obligation in Spain).
6.2. Student account
Until the user requests its deletion.
6.3. Newsletter data
Until voluntary unsubscription.
6.4. Browsing data
According to the Cookie Policy.
7. USER RIGHTS
You can exercise the following rights free of charge:
- Access
- Rectification
- Erasure
- Data portability
- Restriction of processing
- Objection
- Withdrawal of consent
By sending an email to:
hola@thebessacademy.com
You must provide your name, email, and the right you wish to exercise.
8. SECURITY
Technical and organizational measures are applied:
- SSL encryption
- Secure storage
- Restricted access
- Encrypted passwords
- Backup systems
9. MINORS
Educational services are not managed for minors.
Data of individuals under 18 years of age is not deliberately collected.
10. MODIFICATIONS
This Policy may be updated when necessary.
Registered users will be notified.
