Privacy Policy
1Data controller
Throughout this document, “Aula” refers to that entity acting as data controller.
- General contact: hola@aulaapp.es
- Data protection and exercise of rights: privacidad@aulaapp.es
2Legal framework
This policy is governed by Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), and by Ley Orgánica 3/2018 of 5 December on the Protection of Personal Data and guarantee of digital rights (LOPDGDD).
It covers both the aulaapp.es website and the Aula app for iPad, iPhone and Mac. Sections 4.A and 4.B set out which processing applies to each.
3General principle: what we do not process
Before setting out the processing in detail, one point should be stated plainly.
Aula has no access, under any circumstance, to the student data, family data, marks or observations that a teacher enters in the app. There are no Aula servers on which that data resides.
That information is stored exclusively:
- On the teacher’s device (iPad, iPhone or Mac), encrypted and protected by Face ID.
- Optionally, if the teacher turns on sync, in the teacher’s own personal iCloud account, managed entirely by Apple, encrypted in transit and at rest.
Under this arrangement it is the teacher, and where applicable the school, who decides what data to enter about their students and for what purpose, acting as controller of that processing. Aula acts solely as the maker of the software, and at no point intervenes in that data.
4.AData processed on the website
| Purpose | Data processed | Legal basis | Retention |
|---|---|---|---|
| Answering enquiries sent to hola@aulaapp.es or privacidad@aulaapp.es | Name, email address and the content of the message | Legitimate interest in answering the enquiry, or pre-contractual measures | For as long as needed to resolve the enquiry and, afterwards, the statutory limitation period for liability |
The website uses no cookies, no sign-up forms and no analytics or third-party scripts. The only processing of personal data that takes place through the website is what follows from direct contact by email.
4.BData processed inside the app
Inside the app, and solely in relation to the teacher’s account as a customer (never the student data the teacher enters), data is processed through two providers.
RevenueCat, Inc. (subscription management)
- Purpose
- Managing subscriptions and in-app purchases.
- Data processed
- Strictly what is needed to identify the customer and their subscription (for example, account identifier and subscription status).
- Legal basis
- Performance of the subscription contract.
- Location
- United States.
- Safeguards
- RevenueCat publishes its data processing agreement (DPA) at revenuecat.com/dpa. That DPA incorporates the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) as the safeguard for data transfers from the EEA to the United States, together with the UK addendum (UK IDTA) and an equivalent clause for Switzerland. RevenueCat holds SOC 2 Type II certification. Its list of sub-processors (Annex 3 of the DPA) is located mostly in the US; it includes OpenAI OpCo, LLC and Anthropic, PBC, described as AI providers for “product features requiring automated analysis or content generation”.
PostHog Inc. (app usage analytics, optional)
- Purpose
- Analysing app feature usage in aggregate (for example, how often a given feature is used), in order to improve the product.
- Data processed
- User actions inside the app, identified by individual pseudonymous identifiers. Under no circumstances does it include data entered by the teacher about their students, nor marks or personal content created by the teacher.
- Activation
- This processing is optional and is only switched on if the teacher gives explicit consent, which can be withdrawn at any time from the app settings.
- Legal basis
- The teacher’s consent (Art. 6(1)(a) GDPR).
- Location
- PostHog is a US company, but we use its European cloud infrastructure, with data hosted in Germany.
- Safeguards
- The data processing agreement (DPA) is signed on request at posthog.com/dpa. PostHog publishes its list of sub-processors at posthog.com/subprocessors.
5International transfers
As set out in section 4.B, RevenueCat processes data in the United States, relying on the European Commission’s Standard Contractual Clauses as the safeguard for the transfer. All other processing described in this policy takes place within the European Union (PostHog, with data hosted in Germany) or involves no data leaving the teacher’s own device or iCloud account.
6Recipients
- RevenueCat, Inc., for subscription management.
- PostHog Inc., for usage analytics, only if the teacher gives consent.
- Apple Inc., to the extent that the teacher turns on iCloud sync, with Apple acting under its own terms in respect of that data.
Data is not disclosed to third parties for commercial or advertising purposes.
7Retention periods
- Email contact data: for as long as needed to deal with the enquiry and, afterwards, for the statutory limitation period for liability.
- Customer account data (RevenueCat): for as long as the contractual relationship is active and, afterwards, the applicable statutory commercial and tax periods.
- Analytics data (PostHog): 1 calendar year.
- Student data entered in the app: not applicable to Aula, which has no access to it. Its retention depends solely on the teacher’s own decisions and, where applicable, on the rules of the school or the relevant education authority.
8Rights of data subjects
Anyone has the right to exercise the following rights over the data Aula processes as controller (contact data and customer account data):
- Access to their personal data.
- Rectification of inaccurate data.
- Erasure (the “right to be forgotten”).
- Restriction of processing.
- Objection to processing.
- Data portability.
These rights can be exercised by writing to privacidad@aulaapp.es. Anyone also has the right to lodge a complaint with the Agencia Española de Protección de Datos (AEPD), the Spanish data protection authority, if they consider that the processing does not comply with applicable law (aepd.es).
For any request relating to student data entered in the app, and given that Aula has no access to it, that request must be addressed directly to the teacher or to the relevant school, who are the ones who control and can act on that information.
9Data security
- Student data entered in the app is encrypted natively on iOS and protected by Face ID; it never leaves the device except by the teacher’s explicit decision to turn on iCloud, whose security is managed by Apple.
- The providers RevenueCat and PostHog apply their own security measures, set out in their respective data processing agreements.
10Minors
The app is intended for teachers of legal age. The student data they enter in the app never reaches Aula, so Aula processes no data relating to minors at any point. Responsibility for that data lies entirely with the teacher and, where applicable, with the school.
11Changes to this policy
Aula may amend this Privacy Policy to reflect legislative developments or changes to the providers or features of the service. Any substantial change will be communicated through the website or through the app itself.
12Contact
For any question about this Privacy Policy, you can write to privacidad@aulaapp.es.