Back to home

Privacy Policy

This policy governs the processing of personal data collected through this website in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD). We respect your privacy and are committed to protecting your personal data.

Last updated: June 2026

Data controller

The data controller is Asociación Cultural de Hindú Bengalís de la India en Madrid, a non-profit cultural association based in Madrid, Spain.

Name: Asociación Cultural de Hindú Bengalís de la India en Madrid · Tax ID (NIF): [to be completed] · Registered address: [to be completed], Madrid, Spain.

If you have any questions about this policy or how we handle your data, contact us at contact@utsavmadrid.es.

Data we process, purposes and legal basis

Contact, membership and community forms: when you submit a form on utsavmadrid.es, we process the details you provide, such as your name, email address, phone number, area of interest and message, in order to respond to your request and manage community participation. The form submission is handled through Google Forms. Legal basis: your consent (Art. 6.1.a GDPR) and, where applicable, steps prior to or performance of a membership or event participation relationship (Art. 6.1.b GDPR). Retention: until your request has been handled and, thereafter, for up to one year unless a longer period is required for legal, accounting or organisational purposes.

Event registration and participation (for example, Durga Puja or Poila Boishakh): name, email address, phone number and, where applicable, details relating to tickets, membership or donations. Legal basis: performance of the relationship with the participant and your consent (Art. 6.1.b and 6.1.a GDPR). Retention: for the duration of the event and the period required to meet applicable legal, tax and accounting obligations.

Updates and information about activities: when you ask to receive information, we process your email address to send you news about our events. Legal basis: your consent (Art. 6.1.a GDPR). Retention: until you ask to stop receiving these communications.

Website browsing: when you visit utsavmadrid.es, limited technical data such as IP address, browser information, device information, requested pages and timestamps may be processed by our hosting, security and delivery providers to serve the website securely and reliably. Legal basis: our legitimate interest in operating a secure website (Art. 6.1.f GDPR). See our Cookie Policy for details.

Recipients and data processors

We do not sell or share your data with third parties for commercial purposes. Your data may only be disclosed to public authorities where there is a legal obligation to do so.

To run the website we rely on providers that act as data processors or independent service providers: Cloudflare, Inc., for hosting, delivery, DNS, security and related technical services for utsavmadrid.es; GitHub, Inc., for storing and managing the site's source content; Google LLC, for Google Forms used to receive membership and community requests, Gmail used to receive and respond to messages, and Google Fonts used to load website typography. These providers may involve international data transfers covered by appropriate safeguards, such as the EU-US Data Privacy Framework or standard contractual clauses.

Data retention

We keep your personal data only for as long as necessary to fulfil the purposes described above and, thereafter, for the periods required by applicable law. You may ask us to delete your data at any time.

Your rights

You may exercise at any time your rights of access, rectification, erasure, portability, restriction and objection to the processing of your data, as well as withdraw your consent without affecting the lawfulness of processing carried out beforehand.

To exercise these rights, contact us at contact@utsavmadrid.es. You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es).

Security

We apply reasonable technical and organisational measures to protect your data, including HTTPS encryption for communications, restricted access to systems, and the principle of data minimisation.

Minors

We do not knowingly collect data from children under 14. If we become aware that such data has been provided to us, we will delete it.

Changes to this policy

This policy may be updated. We will publish the current version on this same page, indicating the date of the last update.