Annex: Data Processing Agreement (DPA)
Last updated: 15 May 2026
This page is a translation provided for convenience only. In case of any discrepancy, the Spanish version prevails and is the only legally binding version.
1. Identification of the parties
This Data Processing Agreement (hereinafter, "DPA") governs the processing of personal data carried out by:
- The Client, as Data Controller
- Maladeta Studio S.L., with Tax ID B02697837, registered office at Plaça Naua, 1, Planta 2, Módulo 8, 25538 Casau (Lleida), Spain, owner of the Lueira software (hereinafter, "Lueira"), as Data Processor
within the framework of the use of the Lueira management software.
2. Purpose
This agreement governs the processing of personal data carried out by Lueira on behalf of the Client for the provision of the services contracted through its platform, in accordance with article 28 of Regulation (EU) 2016/679 (GDPR) and article 33 of Organic Law 3/2018 (LOPDGDD).
Lueira will only process personal data following the Client's documented instructions, and will not use it for its own purposes or purposes other than those established in this agreement.
3. Nature and purpose of processing
Lueira will process personal data exclusively to provide the services included in the contracted subscription, which include:
- Management of customers, students and participants
- Management of bookings, activities and calendar
- Billing, payments and financial control
- Rental and inventory management
- Digital check-in and collection of electronically signed forms
- Communications with service users
- Document management with electronic signature (eIDAS)
- Automated management of bookings and enquiries via the artificial intelligence assistant integrated with WhatsApp (hereinafter, "AI Assistant"), when the Client enables this feature
Lueira will not use the data processed on behalf of the Client to train its own artificial intelligence models or for any analysis, marketing or product development purpose beyond the provision of the contracted service.
4. Types of data and categories of data subjects
Types of data that may be processed:
- Identification data: name, surname, ID document number
- Contact data: email address, phone number, postal address
- Transaction and billing data: purchase history, amounts, payment references
- Bank data: account number (IBAN), holder and bank, when entered by the Client into the platform to manage collections or payments
- Service usage data: activity logs, bookings, attendance
- Communication content: messages exchanged through the WhatsApp AI Assistant, when this feature is enabled by the Client
- Electronic signatures collected through digital check-in forms
- Any other data the Client enters into the platform in the course of its activity
Categories of data subjects:
- The Client's end customers (people who book activities, rentals or services managed with Lueira)
- Students and activity participants
- Employees, instructors and Client staff with access to the platform
- Any other person whose data the Client decides to manage through the platform
Special categories of data (article 9 GDPR):
This agreement does not generally provide for the processing of specially protected data (health, ethnic origin, biometric data, etc.). If the Client needs to process such data through the platform, it must notify Lueira in advance and ensure it has the appropriate legal basis. Lueira will not be responsible for the processing of special category data entered by the Client without such prior notice.
4 bis. Data of minors
The parties acknowledge that the Lueira platform may be used by the Client to manage the data of students, participants or end customers who are minors, especially in the context of sports schools, camps or active tourism activities aimed at minors.
In these cases:
- The Client, as Data Controller, is solely responsible for obtaining the informed consent of parents or legal guardians when required under applicable law. In Spain, article 7 of the LOPDGDD establishes that minors under 14 require the consent of their legal representative for their data to be processed.
- The Client guarantees that it has the appropriate legal basis before entering data of minors into the platform, and that forms, communications and documents directed at minors or their legal representatives comply with applicable regulations.
- Lueira, as Data Processor, will not use the data of minors for any purpose of its own beyond the provision of the contracted service, and will apply the same security measures to it as to the rest of the personal data processed.
- The Client's breach of the obligations set out in this clause releases Lueira from any liability arising from such breach.
5. Lueira's obligations as Data Processor
Lueira undertakes to:
a) Process personal data solely in accordance with the Client's documented instructions, as set out in these Terms and in this DPA, unless required to act otherwise under EU or Member State law, in which case it will inform the Client of that legal requirement, unless applicable law prohibits such information for reasons of public interest.
b) Not transfer, disclose or allow access to personal data to third parties without the Client's prior authorization, except to the sub-processors listed in section 7 of this agreement.
c) Not use the Client's personal data for its own purposes, including the development or training of artificial intelligence models.
d) Ensure that persons authorized to process personal data have committed to respecting confidentiality or are subject to a legal duty of confidentiality.
e) Apply the technical and organizational security measures set out in section 6 of this agreement.
f) Assist the Client in complying with data subject rights requests (access, rectification, deletion, objection, portability, restriction), responding to requests received directly by Lueira within a maximum of 5 business days and redirecting the data subject to the Client where appropriate.
g) Help the Client ensure compliance with obligations relating to security, data breach notification, impact assessment and prior consultation.
h) Make available to the Client all information necessary to demonstrate compliance with the obligations set out in article 28 of the GDPR.
i) Notify the Client, without undue delay and in any case within the maximum period set out in section 10, of any security breach affecting personal data processed under this agreement.
6. Security measures
Lueira implements the following technical and organizational security measures to protect personal data:
- Encryption of data in transit via HTTPS/TLS
- Encryption of sensitive data at rest (in particular, bank data and passwords)
- Role-based access control, with secure authentication
- User and permission management under the principle of least privilege
- Regular backups stored within the EEA
- Cloud infrastructure hosted entirely within the European Economic Area
- Security incident management procedures
- Regular staff training on data protection matters
Lueira will review and update these measures periodically to keep them up to date with the state of the art. The Client acknowledges that no system is completely infallible and that Lueira will adopt measures that are reasonable and proportionate to the risk of processing.
7. Sub-processors
By accepting these Terms, the Client authorizes Lueira to engage the following sub-processors to provide the service. Lueira guarantees that these sub-processors offer sufficient guarantees in accordance with the GDPR and has entered into the corresponding data processing agreements with them:
| Sub-processor | Service provided | Data location | Transfer safeguard |
|---|---|---|---|
| [PENDING — cloud provider] | Infrastructure, hosting and database | EEA | Within the EEA |
| [PENDING — payment gateway] | Card payment processing | [PENDING] | [PENDING] |
| [PENDING — transactional email service] | Sending notifications and confirmations | [PENDING] | [PENDING] |
| Meta Platforms Ireland Ltd (WhatsApp Business API) | AI Assistant conversational channel | USA | Standard Contractual Clauses (Commission Decision 2021/914) |
| Zoho Corporation (Zoho EU) | Contact forms and lead management (lueira.com website) | EU | Within the EEA |
Lueira will notify the Client at least 30 days in advance of any planned change to the list of sub-processors (addition or replacement of a sub-processor), giving the Client the opportunity to object to such change. In case of justified objection, the parties will negotiate an alternative solution in good faith. If no agreement can be reached, the Client may terminate the contract without penalty.
The up-to-date list of sub-processors will always be available at /en/legal/terms/dpa/ or may be requested at any time from rgpd@maladetastudio.com.
8. International data transfers
When processing involves the transfer of personal data outside the European Economic Area (EEA), Lueira will ensure that such transfers have appropriate safeguards in accordance with Chapter V of the GDPR, including:
- Standard Contractual Clauses approved by the European Commission (Decision 2021/914)
- European Commission adequacy decisions in force at the time of the transfer
The international transfers currently identified are detailed in the sub-processor table in section 7. The Client acknowledges and accepts the transfers described in that table upon entering into this agreement.
9. Data subject rights
Lueira will assist the Client in handling data subject rights under the GDPR:
- Right of access (art. 15)
- Right to rectification (art. 16)
- Right to erasure (art. 17)
- Right to object (art. 21)
- Right to portability (art. 20)
- Right to restriction of processing (art. 18)
The Client is ultimately responsible for handling rights requests received from data subjects. When Lueira receives a request directly from a data subject, it will forward it to the Client within 5 business days so that the Client can respond within the maximum 1-month period established by the GDPR.
10. Security breach notification
Lueira will notify the Client of any security breach affecting personal data processed under this agreement without undue delay and, in any case, within a maximum of 72 hours of becoming aware of it.
The notification will include, to the extent possible:
- Description of the nature of the breach
- Categories and approximate number of data subjects and records affected
- Likely impact and consequences of the breach
- Measures taken or proposed to remedy the situation
The Client, as Data Controller, is responsible for assessing whether the breach must be notified to the Spanish Data Protection Agency (deadline: 72 hours from becoming aware of it) and/or to the affected data subjects, in accordance with articles 33 and 34 of the GDPR.
11. Duration and termination
This agreement will remain in force for as long as the contractual relationship between the Client and Lueira lasts.
Upon termination of the service, and within a maximum of 30 days from the date of account cancellation:
- Lueira will securely delete the Client's active data from the platform, or return it in an exportable format (CSV or equivalent) if the Client requests it before cancellation.
- The Client will be provided, upon request, with written confirmation of the deletion carried out.
Notwithstanding the above, Lueira may retain certain data in blocked form when required to do so by applicable legal regulations (tax, accounting or other obligations), for the legally established periods and without using it for any other purpose. Once those periods have elapsed, it will proceed to their permanent deletion.
12. Audits and inspections
The Client may verify Lueira's compliance with the obligations set out in this agreement through any of the following mechanisms:
a) Requesting documented information on the security measures and procedures applied, which Lueira will respond to within a maximum of 15 business days.
b) Audits carried out by the Client or by an external auditor appointed by the Client, subject to prior agreement with Lueira on the scope, date and conditions of the audit, and provided they do not disproportionately interfere with the operation of the service. Audit costs will be borne by the Client.
c) Reviewing security certifications or independent audit reports that Lueira makes available to the Client.
Audit requests must be made at least 30 days in advance to rgpd@maladetastudio.com.
12 bis. Data Protection Impact Assessment (DPIA)
When the type of processing envisaged, particularly due to the use of new technologies or the processing of bank data, data of minors, or automated decisions via the AI Assistant, may pose a high risk to the rights and freedoms of data subjects, the Client, as Data Controller, must carry out a Data Protection Impact Assessment (DPIA) in accordance with article 35 of the GDPR.
Lueira will cooperate with the Client in carrying out this assessment, providing reasonably necessary information about the processing carried out on the Client's behalf and the security measures applied.
12 ter. Records of processing activities
In accordance with article 30.2 of the GDPR, Lueira, as Data Processor, maintains a record of the categories of processing activities carried out on behalf of the Data Controllers who use the platform. This record includes the information provided for in article 30.2 of the GDPR and is available to the competent supervisory authority (AEPD) when required.
13. Liability
Each party will be liable for damages arising from a breach of its respective data protection obligations set out in this agreement and in applicable regulations.
Lueira will not be liable for breaches arising from incorrect, incomplete or unlawful instructions provided by the Client, or for processing carried out by the Client outside the scope of the contracted service.
14. Integration with the Terms
This DPA forms an integral part of Lueira's Terms and Conditions.
Acceptance of those Terms during the registration process implies acceptance of this Data Processing Agreement.
In the event of a conflict between the provisions of the Terms and Conditions and the provisions of this DPA regarding data protection, the provisions of this DPA will prevail.