Last Updated: April 1, 2026
English Driving School (Juan Jesús Gil Lamela, NIF: 78967382X) is committed to protecting your privacy and complying with GDPR (EU Regulation 2016/679) and the Spanish Organic Law 3/2018 on Personal Data Protection and Digital Rights Guarantee.
1. Data Controller
Identity: Juan Jesús Gil Lamela
NIF: 78967382X
Address: Av. Petunias Nº13, San Pedro Alcántara, 29670 Málaga, Spain
Email: info@englishdrivingschool.com
2. Information We Collect
We collect and process the following personal data:
- Identity data: Name, surname, DNI/NIE
- Contact data: Email address
- Account data: Login credentials (password is not stored in plain text)
- Payment data: Processed securely by Redsys (bank card) or PayPal. We do not store card details or bank account numbers.
- Usage data: Test scores, study progress, session history
- Technical data: IP address, browser type, device information
3. Purpose and Legal Basis for Processing
3.1 Service Provision (Contractual Necessity)
To create and manage your account, provide access to study materials, track your progress, and deliver the services you have purchased.
3.2 Communication (Legitimate Interest)
To send important service updates (e.g. payment confirmation, password recovery) and respond to your inquiries.
3.3 Legal Compliance
To retain payment and billing records as required by Spanish tax law.
4. Data Retention
- Active accounts: While your account remains active
- Inactive accounts: 2 years after last login
- Payment records: 6 years (legal tax obligation under Spanish law)
5. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right to access: Request a copy of your data
- Right to rectification: Correct inaccurate data
- Right to erasure ("Right to be forgotten"): Request deletion of your data
- Right to restrict processing: Limit how we use your data
- Right to data portability: Receive your data in a structured format
- Right to object: Object to processing based on legitimate interests
To exercise these rights, email info@englishdrivingschool.com with the subject "Data Protection Request". We respond within 30 days.
6. Data Security
- SSL/TLS encryption for all data transmission
- Passwords are not stored in plain text
- Access to personal data is restricted to authorised personnel only
- Servers located within the European Union
7. Third-Party Processors
We use the following third-party services that may process your data as part of providing our service:
- Redsys (bank card payments): Your card details are entered directly on Redsys's secure payment page. We never see or store your card data. Redsys is operated by Sistema de Tarjetas y Medios de Pago, S.A. and complies with PCI-DSS standards.
- PayPal: If you choose to pay via PayPal, your payment is processed directly by PayPal (Europe) S.à r.l. et Cie, S.C.A. We do not receive or store your PayPal credentials.
- Gmail (SMTP): We use Google's email infrastructure to send transactional emails such as password recovery and payment confirmation. Only your email address and name are used for this purpose.
All processors are GDPR-compliant.
8. Cookies
We use a single essential cookie on this platform:
eds_plan (Session Cookie)
This cookie is set when you log in to your account. It stores your user ID and subscription plan in a cryptographically signed format (HMAC-SHA256). It is used solely to maintain your authenticated session and control access to features included in your plan. It does not track your browsing behaviour or share data with third parties.
This cookie is strictly necessary for the service to function and cannot be disabled while you are logged in. It expires after 30 days or when you log out.
We do not use analytics cookies, advertising cookies, or any third-party tracking technologies.
9. International Transfers
Your data is stored on servers located within the European Economic Area (EEA). We do not transfer your personal data outside the EEA.
10. Complaints
If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD):
Website: www.aepd.es
Address: C/ Jorge Juan, 6, 28001 Madrid, Spain
11. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be posted on this page with an updated revision date. Significant changes will be notified via email.
12. Mobile Application
When you use the English Driving School mobile app (iOS / Android) we also process:
- Your login credentials (DNI/NIE, password) through the same account as the web service.
- Device identifier used solely to register the device for push notifications and to tie in-app purchase receipts to your account.
- Subscription status received from Apple App Store or Google Play after a successful purchase (product ID, transaction ID, start/expiry dates). We do not receive your payment card details — these are handled exclusively by Apple or Google.
13. In-App Purchases
Subscriptions purchased inside the mobile app are processed by Apple App Store or Google Play. Their own privacy policies apply to the payment transaction:
- Apple: www.apple.com/legal/privacy
- Google: policies.google.com/privacy
Your purchase receipt is validated against Apple/Google servers and stored on our servers to unlock the premium features of your account. You may delete your account at any time from Account → Delete Account, which also removes your subscription status from our database (the subscription itself must be cancelled through Apple or Google).
14. Contact
Email: info@englishdrivingschool.com
Address: Av. Petunias Nº13, San Pedro Alcántara, 29670 Málaga, Spain