🔐

Privacy and Data Protection

Clear information about the minimum data processed by this website and the measures used to protect it.

Essential information

Under the GDPR, files are not registered with the AEPD, but this website keeps an internal Record of Processing Activities and applies minimisation, pseudonymisation, access control and audit logging.

1. Controller

Controller: USO Trade Union Section - Diputación de Granada. Data protection contact and rights requests: uso@dipgra.cloud.

2. Data processed

The public area processes security logs, aggregated internal statistics, language/theme preferences, affiliation requests with opaque codes, and contact forms delivered by Telegram with consent without storing them in the database. The members area processes opaque member codes, authentication hashes, access categories, sessions and audit records. Union membership is a special category of data even when pseudonymised.

3. Purposes and legal bases

Purposes include information, union services, access management, protection of private documents, security, audit logging and legal compliance. Legal bases may include the membership relationship or user request, legitimate security interests, legal obligations and GDPR Article 9.2.d for legitimate activities of a trade union organisation with appropriate safeguards.

4. Members and private access

Member access will use an opaque code and hashed PIN. Account recovery will be manual through administration. If Google is enabled as a second option, it will not create users automatically and only a hashed technical identifier of the linked account will be stored.

5. Audit, logs and statistics

The website records access, errors, relevant actions and usage statistics for security, diagnosis and service improvement. Logs are limited to what is necessary, protected from unauthorised access and reviewed for security and internal analysis.

6. Cookies and local storage

No advertising cookies or third-party trackers are used. Technical session cookies may be used. Theme, language and read-state preferences are stored in the browser through localStorage.

7. Retention

Data is kept only for as long as necessary for each purpose. Logs and audit records will have internal retention periods. Member codes and accesses will be disabled when no longer needed.

8. Disclosures and processors

Data is not disclosed to third parties except under legal obligation or documented technical need. The scraper and internal processes publish through an internal API. External services such as Telegram or Google will only be used when configured and documented.

9. Rights

You may exercise access, rectification, erasure, objection, restriction and portability rights by writing to uso@dipgra.cloud. You may also complain to the Spanish Data Protection Agency.

10. Security and breaches

HTTPS, access control, peppered hashes, encryption or pseudonymisation where appropriate, separation between public and internal areas and audit logging are applied. If a breach creates risk for individuals, it will be documented and notified under the GDPR.

Legal sources

Last updated: May 2026 · Version 1.0