Privacy
Privacy notice and GDPR commitments
Last updated: September 10, 2026
Who is responsible for your data
BCN Student Concierge (the “controller”) determines how and why your personal data is processed. Contact for all data-protection matters, including exercising the rights below: [email protected].
What we collect, and why
Identity and civil-status data (passport number, NIE, names, gender, birth details, nationality, marital status, parents' given names), your Spanish address, contact details, and scans of your passport, university acceptance letter and lease.
Legal basis: performance of a contract with you (GDPR Art. 6(1)(b)). We collect this data because Spanish residency forms require it — not because we want it. We do not collect health data, biometric templates, or any special-category data under Art. 9 beyond what appears on the face of the documents you upload.
How your data is protected
Your questionnaire answers (passport number, names, date and place of birth, address) and every document you upload are encrypted at rest with AES-256-GCM, each under its own key. Those keys are themselves encrypted under a master key that is kept separately from the database and its backups — so a copy of the database or of a backup decrypts nothing on its own, and one compromised record never exposes another.
All traffic is served over TLS 1.3 only, with HTTP Strict Transport Security. Payment card details are handled entirely by Stripe and never reach our servers.
An honest limitation: this is strong encryption at rest, but it is not end-to-end encryption. Our systems can decrypt your documents, because our staff must review them and our software must read your data to populate your forms. Any service telling you it holds your passport under end-to-end encryption while also filling in your paperwork is describing something that cannot be true.
How long we keep it — the 30-day rule
Passport scans, uploaded documents and identity data are permanently deleted 30 days after your service completes. This runs as an automated job, not a manual promise: expired files are purged without anyone deciding to do it, and the deletion is irreversible.
Two things survive that purge, and only these: a record that the file existed and was deleted, and invoice data. Spanish commercial and tax law (Código de Comercio Art. 30; Ley General Tributaria) requires invoice records to be kept for several years, and that obligation overrides erasure requests for those specific records under GDPR Art. 17(3)(b). An invoice holds the payer's name, billing address and, for a business, its tax ID — stored encrypted — plus the amounts. It never includes your passport number or document scans.
You may request deletion earlier than 30 days at any time.
If someone authorises your address
When the flat is not in your name, the person who holds it (the owner or the main tenant) authorises your Padrón registration on the City of Barcelona's official form. You type the signer's name and ID number so we can fill in the form for you. We use those details once, to produce the PDF, and do not store them.
The signed form, a copy of the signer's ID and the lease that you then upload are needed by the city to register you. We hold them encrypted, like your own documents, use them only to prepare your Padrón file, and delete them with the rest of your file 30 days after your service completes. Please let the signer know you are sharing these documents with us for that purpose.
Who else sees your data
Stripe (payment processing, Ireland/USA under the EU-US Data Privacy Framework); Resend (delivery of our emails, such as your sign-in links); and the EU-based provider of our server — each under a data processing agreement. We do not sell your data, we do not share it with advertisers, and we do not transfer it outside the EEA except as stated here.
Public authorities receive only what you submit to them yourself, in your own name, at your appointment.
Your rights
You may request access to your data, correction of inaccuracies, erasure, restriction of processing, portability in a machine-readable format, and you may object to processing. Where processing rests on consent, you may withdraw it at any time — though withdrawing consent to hold your documents will usually mean we cannot complete the service.
We respond within one month. If you are unsatisfied, you may complain to the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, or at aepd.es.
Breach notification
If a breach occurs that is likely to result in a risk to your rights, we notify the AEPD within 72 hours and inform you directly without undue delay. We will tell you what was accessed, not a vague reassurance.
Cookies
This site sets no advertising or analytics cookies and runs no third-party trackers. The only cookies are strictly necessary ones: a sign-in cookie that keeps you in your file for up to 24 hours, and the cookies Stripe sets for fraud prevention during checkout. There is no consent banner because there is nothing to consent to.