Privacy Policy
Last updated: 8 September 2026
This Privacy Policy explains how Inner Spark Center S.L. (“Simple AI Studio”, “we”, “us”, or “our”) collects, uses, and protects personal data obtained through our website (simpleaistudio.com), contact channels, and professional training programmes, including the Solar AI Bootcamp.
We process personal data in compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation, “GDPR”, Articles 13 and 14) and the Spanish Organic Law 3/2018 on Data Protection and Guarantee of Digital Rights (“LOPDGDD”).
1. Data Controller
The entity responsible for the processing of your personal data is:
Inner Spark Center S.L.
Carrer de Floridablanca 68, Coworking Local 9F, 08015 Barcelona, Spain
VAT ID / NIF: ESB70984208
Contact and data protection email: [email protected]
2. Principles of Data Processing
We process your personal data in accordance with the fundamental principles established in Article 5 of the GDPR:
- Lawfulness, fairness, and transparency: Data is processed on valid legal grounds and with complete clarity toward the user.
- Purpose limitation: Data is collected only for specified, explicit, and legitimate professional purposes.
- Data minimisation: We collect only the data that is strictly necessary for the intended purpose.
- Accuracy: We take reasonable steps to keep personal data accurate and up to date.
- Storage limitation: Data is kept only for the time necessary to fulfill the purpose of collection or comply with statutory retention periods.
- Integrity and confidentiality: Data is protected by appropriate technical and organizational measures against unauthorized access, loss, or alteration.
3. Data Collected, Purposes, and Legal Bases
We collect and process personal data across distinct interactions:
3.1. Contact, Application, and Inquiry Forms
When you submit an application for the Bootcamp, request information, or contact us through our website forms, we collect:
- Your full name, company name, professional email address, and telephone number.
- Information regarding your business activity, including your active installation territory and current operational workflow.
- The content of your message, inquiry, or responses to application questionnaires.
- Technical navigation parameters (such as campaign identifiers or UTM parameters in the link you followed), used exclusively to determine which content or channel prompted an enquiry, without identifying you before you submit the form.
Purposes: Answering inquiries, evaluating bootcamp applications, qualifying installation territories to prevent geographic and commercial conflicts among cohort participants, and arranging introductory onboarding calls.
Legal bases: Article 6(1)(b) GDPR (taking steps prior to entering into a contract at the request of the data subject) and Article 6(1)(f) GDPR (our legitimate interest in managing cohort composition, preventing territorial overlap, and responding effectively to prospective clients).
3.2. Direct Online Checkout, Registration, and Billing (Stripe)
When you enrol and purchase access to a bootcamp, workshop, or service via our checkout flow, we collect:
- Company billing information: legal entity name, registered address, tax identification number (NIF, CIF, or VAT ID), billing contact name, and billing email.
- Payment details and transaction records: transaction identifiers, payment timestamps, and payment status. Credit card numbers and sensitive banking credentials are handled directly and securely by Stripe. We never store or access complete card numbers on our servers.
Purposes: Executing the training agreement, processing payment transactions, delivering confirmation receipts, issuing statutory tax invoices, maintaining corporate accounting records, and fulfilling tax compliance obligations.
Legal bases: Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(c) GDPR (compliance with statutory legal, accounting, and tax obligations).
3.3. Live Bootcamp Cohort Participation and Video Recordings
During live interactive sessions of the Solar AI Bootcamp:
- We process your video image, audio voice stream, display name in the virtual meeting room, verbal contributions, questions, and any chat messages or shared screens.
- Session recordings: Live group sessions are recorded to provide replay access in the private student workspace, exclusively for registered members of the same cohort.
Purposes: Educational delivery, facilitating practical implementation between live sessions, and providing an asynchronous learning resource for cohort participants who could not attend live or wish to review technical demonstrations.
Legal bases: Article 6(1)(b) GDPR (performance of the training agreement) and Article 6(1)(f) GDPR (our legitimate interest and the cohort members’ shared interest in having access to review session materials). In addition, your voluntary activation of webcam or microphone during a session constitutes consent under Article 6(1)(a) GDPR.
Visual privacy controls: Every participant retains full control over their camera and microphone. You may turn off your webcam and microphone at any time and interact exclusively via the text chat.
Mandatory confidentiality guideline: Participants must not share confidential customer records, sensitive personal data, or third-party proprietary trade secrets during live sessions without prior anonymization or formal authorization.
3.4. Student Workspace and Implementation Support
When you log in to the student platform, download automation templates, and exchange messages through designated support channels, we process your login credentials, session timestamps, exercise submissions, and workflow questions.
Purpose: Providing access to course materials and delivering technical mentoring on qualifying workflows.
Legal basis: Article 6(1)(b) GDPR (performance of a contract).
4. Third-Party Processors and Service Providers
We rely on trusted third-party service providers who act as data processors (encargados del tratamiento) and process personal data exclusively on our instructions under formal data processing agreements:
- Stripe (Stripe Payments Europe, Ltd. and Stripe, Inc.): Payment processing, payment authentication, fraud prevention, and billing management.
- Cloudflare (Cloudflare, Inc.): Website hosting, Content Delivery Network (CDN), DNS resolution, web application firewall, and network security.
- PostHog (PostHog, Inc.): Privacy-friendly product and website analytics, configured without invasive tracking cookies or based on consent.
- Email delivery and workspace (Google Workspace by Google Ireland Limited, and AgentMail): Corporate email communications, calendar scheduling, and transactional notifications.
- Private video hosting and LMS platform: Secure hosting and restricted video streaming of session replays, accessible only to authenticated students.
International data transfers: Where service providers process personal data outside the European Economic Area (EEA), transfers are safeguarded by European Commission Standard Contractual Clauses (SCCs), adequacy decisions, or participation in recognized frameworks such as the EU-US Data Privacy Framework.
5. Data Retention Periods
We retain personal data only for the period necessary to achieve the purposes outlined in this policy, or to satisfy legal, tax, and regulatory requirements:
- Invoicing and tax data: 5 years, in accordance with statutory requirements under Spanish tax law (Ley General Tributaria).
- Bootcamp student workspace and session recordings: 12 months from the date of purchase, corresponding to the guaranteed access period defined in our terms of service.
- General inquiries and prospective lead data: Up to 2 years from the last contact, or until the data subject requests deletion or objects to processing.
- Technical and security connection logs: Up to 12 months for security auditing, anomaly detection, and fraud prevention.
6. Your Rights as a Data Subject
Under Articles 15 to 22 of the GDPR and Spanish LOPDGDD, you have the right to exercise the following rights regarding your personal data:
- Right of access: Obtain confirmation as to whether your personal data is being processed, and access the specific information held.
- Right to rectification: Request the correction of inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”): Request the deletion of your personal data when it is no longer necessary for the purposes for which it was collected, subject to statutory retention obligations.
- Right to restriction of processing: Request that processing be suspended under circumstances provided by law, such as while accuracy is verified.
- Right to data portability: Receive your personal data in a structured, commonly used, and machine-readable format, or request its transfer to another data controller where technically feasible.
- Right to object: Object at any time to the processing of your data based on legitimate interests.
- Right to withdraw consent: Withdraw any previously granted consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
How to exercise your rights: You can exercise your rights free of charge by sending an email to [email protected], stating your full name, the specific right you wish to exercise, and providing proof of identity if necessary to verify your request. We will reply within one calendar month.
Right to lodge a complaint: If you believe that our processing of your personal data violates data protection regulations, you have the right to lodge a complaint with the competent supervisory authority:
Agencia Española de Protección de Datos (AEPD)
Carrer de Jorge Juan 6, 28001 Madrid, Spain
Website: www.aepd.es
You may also contact the supervisory authority in your European Union Member State of habitual residence or workplace.
7. Data Security
We have established appropriate technical and organizational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include HTTPS/TLS transport encryption, strict authentication controls, least-privilege administrative access, and encrypted backups.
8. Minors
Our website, services, and training programmes are intended exclusively for business professionals and adults over 18 years of age. We do not knowingly collect or solicit personal data from minors.
9. Updates to this Policy
We may update this Privacy Policy periodically to reflect operational changes, technical enhancements, or new legal obligations. The latest version will always be published on this page with an updated revision date.
If you have questions regarding this Privacy Policy, please write to us at [email protected].