Privacy Policy
Last updated: 18 August 2026
1. INTRODUCTION AND PURPOSE
At Edena we are committed to protecting the privacy of all users and to being fully transparent about how we process personal data. This Privacy Policy describes the data processing practices of Edena Software S.L. in relation to the use of our educational platform and this website, in accordance with Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 of 5 December (LOPDGDD), and Spanish Law 34/2002 of 11 July (LSSI).
Edena is a comprehensive school management platform designed for educational institutions. As a platform that processes data in the school environment, we apply strict privacy and security safeguards.
2. DATA CONTROLLER
Company name: Edena Software S.L.
Tax ID (CIF/NIF): B27627462
Registered address: Barcelona, Spain
Email: [email protected]
Website: www.edena.es
3. DATA PROTECTION OFFICER (DPO)
Edena has appointed a Data Protection Officer to oversee compliance with data protection regulations. You may contact our DPO at any time at: [email protected].
4. USERS AND DATA PROCESSED
Edena processes data in two distinct environments:
A. Website users and leads (Edena as Controller)
Data: name, email address, phone number, name of the educational institution and browsing data (anonymised IP).
Purpose: responding to information requests, managing software demo requests and analysing website usage.
B. ERP platform users (Edena as Processor)
For data entered by educational institutions (administrators, teachers, families and students), the educational institution is the Data Controller and Edena acts strictly as Data Processor, following the institution's instructions under a contract signed for that purpose (Art. 28 GDPR).
Data managed internally: identification, academic, communication and billing data of the institution, and essential health data (allergies or special needs) entered under the responsibility of the school.
5. PURPOSES AND LEGAL BASIS
- Handling requests and demos: performance of pre-contractual measures (Art. 6.1.b GDPR).
- Sending commercial communications: express consent of the user (Art. 6.1.a GDPR), revocable at any time.
- Provision of the ERP service: performance of the contract with the educational institution (Art. 6.1.b GDPR).
- Platform improvement: legitimate interest in optimising the security and tools of the software (Art. 6.1.f GDPR).
6. PROCESSING OF MINORS' DATA
In compliance with Article 8 of the GDPR and Article 7 of the LOPDGDD, educational institutions, as Data Controllers, are responsible for obtaining the consent of parents or legal guardians for the processing of data of children under 14 before entering it into the platform. Edena never uses minors' data for any purpose other than the strict educational management of the client institution.
7. DATA RETENTION
- Request/contact data: retained for as long as necessary to handle the request and, if no contract is entered into, deleted within a maximum of 24 months.
- Client contractual data: retained for the duration of the contract and, after termination, for the statutory limitation periods (6 years under commercial/tax law).
- Browsing data/logs: maximum 12 months.
8. RECIPIENTS AND TRANSFERS
Edena does not sell or disclose personal data to third parties. Data is only shared with:
- Cloud infrastructure and data storage providers acting as data processors under strict GDPR-compliant contracts.
- Certified payment gateways (PCI-DSS) for payment management on the platform.
- Public authorities where there is a legal obligation.
The database, application hosting and the artificial intelligence providers that process educational centres' data are located in the European Union. Certain email, push notification and payment providers are based in the United States; those transfers rely on the European Commission's Standard Contractual Clauses or on the EU-US Data Privacy Framework, as detailed in the Data Processing Agreement.
9. DATA SUBJECT RIGHTS
Users may exercise their rights of access, rectification, erasure, objection, restriction and portability by sending an email to [email protected], duly proving their identity. If you believe your rights have not been properly addressed, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
10. SECURITY MEASURES AND STANDARDS
Edena applies technical and organisational measures to guarantee the security of information:
- Encryption of data in transit via SSL/TLS (HTTPS) protocols and data encrypted at rest.
- Restricted role-based access control (least privilege).
- Regular backups and data recovery systems.
- Certified infrastructure: our platform is hosted in data centres of leading providers whose infrastructure holds internationally recognised security certifications such as ISO/IEC 27001 and SOC 2 audits, guaranteeing the highest standards of availability and physical protection of information.
11. CHANGES TO THIS POLICY
We may update this Privacy Policy to adapt it to legislative changes or changes to the software. The "last updated" date will always reflect the current version.
