Privacy Policy
Privacy Policy
Last updated: July 2026
At ENEB, the protection of personal data is a priority. This Privacy Policy describes how the Student's personal data is processed in compliance with Regulation (EU) 2016/679 of 27 April (GDPR) and Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
Data Controller
The controller responsible for the processing of personal data is:
| Controller | Escuela de Negocios Europea de Barcelona, S.L.U. (ENEB) |
|---|---|
| Tax ID (N.I.F.) | B-66412644 |
| Registered address | Avda. Europa 24, 28108 Alcobendas (Madrid) |
| academy@eneb.com | |
| Data Protection Officer | datos@namenciseducation.com |
Escuela de Negocios Europea de Barcelona, S.L.U. is part of the NAMENCIS Group. The Student may contact the Group's Data Protection Officer for any question relating to the processing of their data at datos@namenciseducation.com.
Data We Process
We process the categories of data provided by the Student that are necessary for the purposes described in this Policy:
- Identification and contact data: first and last name, identity document, postal address, email address and telephone number.
- Academic and enrolment management data: programme enrolled in, academic record, grades, qualifications and, where applicable, documentation evidencing prior qualifications.
- Financial and billing data: payment data and, where applicable, data relating to any financing arrangement.
- Browsing data: data arising from use of the website, as set out in the Cookie Policy.
The Student guarantees the accuracy of the data provided and undertakes to notify any changes thereto. Where the Student provides data belonging to third parties, the Student must have previously informed them and obtained their consent.
Purposes and Legal Bases for Processing
Data is processed for the following purposes, on the legal bases indicated:
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Management of enrolment and the academic record, and provision of the educational service | Performance of a contract [Art. 6(1)(b)] |
| Invoicing, collections management and compliance with legal, accounting and tax obligations | Legal obligation [Art. 6(1)(c)] |
| Issuance and registration of qualifications and certifications, including their communication to partner universities | Performance of a contract and legal obligation [Art. 6(1)(b) and (c)] |
| Handling of enquiries, incidents and complaints | Legitimate interest / performance of a contract [Art. 6(1)(f) and (b)] |
| Sending of commercial communications from the NAMENCIS Group about programmes, scholarships and events | Consent [Art. 6(1)(a)] |
| Supervision and verification of identity in online assessments | Performance of a contract / legitimate interest [Art. 6(1)(b) and (f)] |
| Security of the platforms, fraud prevention and improvement of services | Legitimate interest [Art. 6(1)(f)] |
The sending of commercial communications is based on the data subject's consent, which may be withdrawn at any time without affecting the lawfulness of processing carried out prior to its withdrawal or the provision of the contracted educational service.
Where processing is based on legitimate interest, this has been weighed by the controller and prevails only where the data subject's rights and freedoms are not thereby overridden.
Retention Periods
Data will be retained for as long as the relationship with the Student continues and, once it has ended, for the periods required by applicable law to address any potential liabilities.
As a general guide: academic and qualification data will be retained in accordance with applicable academic and registry regulations; financial and billing data, for the periods set out in commercial and tax law (generally, six years under the Commercial Code and four years under tax law); and data processed on the basis of consent, until such consent is withdrawn. Once these periods have elapsed, the data will be erased or blocked in accordance with Article 32 of the LOPDGDD.
Recipients and Disclosures of Data
For the purposes described, data may be disclosed to the following recipients:
- Universidad Isabel I (UI1), as an independent controller, for registration, safekeeping of the academic record and issuance of the university certification of ECTS credits.
- Università degli Studi Guglielmo Marconi, where the programme enrolled in leads to its qualification, for the management, issuance and registration of the degree, in accordance with that university's regulations.
- Collaborating financial institutions, where the Student requests financing for the programme, for the processing and assessment of the financing arrangement.
- Service providers acting as data processors (hosting, learning platform, support, messaging and payment providers), with whom the contract required under Article 28 of the GDPR has been entered into.
- Public administrations, courts and tribunals, where there is a legal obligation to disclose data.
Outside of the above cases and applicable legal obligations, data will not be disclosed to third parties without the data subject's consent.
International Transfers
As a general rule, data is processed within the European Economic Area. Where any processor or recipient is located outside that area, transfers will be carried out with the appropriate safeguards provided for in Chapter V of the GDPR, in particular adequacy decisions or standard contractual clauses, a copy of which the data subject may request from the Data Protection Officer.
Data Subject Rights
The Student may exercise the following rights by contacting datos@namenciseducation.com or the controller's registered address, providing proof of identity:
- Access to their personal data.
- Rectification of inaccurate data.
- Erasure of data where the legal requirements are met.
- Objection to processing on grounds relating to their particular situation.
- Restriction of processing in the cases provided for by law.
- Portability of the data provided, in a structured, commonly used format.
- Withdrawal of any consent given, without retroactive effect.
The data subject has the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) where they consider that the processing does not comply with applicable law, in particular where they have not obtained satisfaction in the exercise of their rights.
Data Security
The controller applies the appropriate technical and organisational measures required under Article 32 of the GDPR, taking into account the state of the art and the risks of processing, to guarantee the confidentiality, integrity and availability of the data.
Amendment of the Privacy Policy
This Privacy Policy may be amended to adapt it to legislative or case-law developments. Material changes will be communicated to the data subject through the usual channels. The applicable version will be the one published on the website at any given time.
Privacy Policy
Last updated: February 2026
At […], your privacy is our priority. We are committed to protecting your personal data and being fully transparent about the information we collect and how we use it. This Privacy Policy explains how we process your data in compliance with Regulation (EU) 2016/679 (GDPR).
1. Who is the Data Controller?
The Data Controller is […, S.L.U.], Tax ID B66412644, with registered address at Avenida de Europa, 24, Alcobendas, 28108, Madrid, Spain (hereinafter, “THE SCHOOL”).
THE SCHOOL is part of the NAMENCIS business group. You may contact the Group Data Protection Officer (DPO) at datos@namenciseducation.com.
2. Purpose and legal basis for data processing
A. Academic relationship management (contract performance)
- Enrollment and registration management.
- Academic record creation and maintenance.
- Access to the Virtual Campus and learning resources.
- Tutorials, assessments, grading and assignments.
- Issuance and delivery of certificates.
- Billing, payments and administrative obligations.
- Essential academic service communications.
B. Commercial communications (consent)
Only if you give explicit consent, we will send you information about programs, scholarships, events and promotions from the NAMENCIS Group. Consent may be withdrawn at any time.
C. Security and service improvement (legitimate interest)
We process platform usage data to ensure system security, prevent academic fraud and protect the learning environment.
3. Data retention
Your data will be retained for the duration of the academic relationship and subsequently for the legally required retention periods. Afterward, data will be securely deleted.
4. Data sharing
- Service providers acting as data processors.
- Partner universities for academic accreditation.
- Public authorities where legally required.
5. International data transfers
Where transfers outside the EEA occur, appropriate GDPR safeguards will be applied.
6. Your rights
- Access
- Rectification
- Erasure
- Objection
- Restriction
- Portability
You may exercise your rights by contacting datos@namenciseducation.com.
7. Security measures
THE SCHOOL applies appropriate technical and organizational security measures.
8. Policy updates
We reserve the right to amend this policy. Significant changes will be communicated accordingly.
