Last revised: 26 July 2026
This policy explains what we do with your data when you subscribe to our updates, when you offer to volunteer, or when you write to us. It is written to be understood, not to protect us.
We are a non-profit association. We do not sell your data, we do not share it for commercial purposes, and we do not live off advertising.
We have not appointed a Data Protection Officer, because our activity and the volume of data we handle do not make it mandatory (Article 37 GDPR). If that changes, we will say so here.
We are governed by Regulation (EU) 2016/679 (GDPR) and by Spanish Organic Law 3/2018 on Data Protection and the guarantee of digital rights (LOPDGDD).
Only what you give us, and the record that you gave it:
We keep that proof because the GDPR requires us to be able to demonstrate that you gave us your consent (Article 7(1)). Without it we could not prove it, and you would have no way to check exactly what you accepted.
We do not ask for your phone, your age, your postal address, or anything we do not need.
We do not build profiles, we do not make automated decisions about you, and we do not use your data for anything else.
The legal basis is your consent (Article 6(1)(a) GDPR): you sign up yourself, ticking the box freely and voluntarily.
You can withdraw it whenever you want, without giving reasons. Every email carries an unsubscribe link, and you can also ask us by writing to the contact address. Withdrawing has no consequences for you, and it does not affect the lawfulness of what we did before you withdrew it.
We do not sell or share your data. To run the list we use two providers, who act as processors and may only use your data on our instructions:
Beyond those providers, we would only disclose data if a law or an authority required us to.
We say this plainly because you have a right to know before giving us your email: the two providers we just named are American, so your data is processed in the United States.
The United States has no general data protection law equivalent to the European one, and its authorities may, in the cases provided for in their legislation, access data hosted there.
That transfer relies on the mechanisms set out in Chapter V of the GDPR: the standard contractual clauses approved by the European Commission that these providers' contracts incorporate and, where the provider adheres to it, the EU-US Data Privacy Framework. You can ask us which specific safeguard applies by writing to us.
You can exercise at any time your rights of access, rectification, erasure, objection, restriction of processing and portability, as well as withdraw your consent.
How: write to hola@noetika.org stating which right you want to exercise. We will reply within one month. It is free. We may ask for something proving your identity, only to make sure we do not hand your data to someone else.
You can complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos: C/ Jorge Juan 6, 28001 Madrid, www.aepd.es.
We would appreciate you writing to us first, in case we can resolve it, but you are not obliged to.
To subscribe on your own you need to be 14 or older, which is the age set by Article 7 LOPDGDD for consenting to data processing in Spain.
If you are under 14, we need the consent of your mother, father or guardian. If we detect that we have collected data from someone under 14 without that consent, we delete it.
This site uses no cookies. Neither ours nor third-party ones. That is why you will not see a banner: there is nothing to accept.
To know how many people visit us we use Cloudflare Web Analytics, which measures without cookies, without storing anything in your browser and without following you from one site to another. It builds no profile of you.
The fonts on this page are hosted on our own server, so loading it sends your IP address to neither Google nor any other third party.
The site is always served encrypted (HTTPS). The data you give us travels encrypted and is stored on our providers' platforms, with their security measures. Access to the list is limited to the people in the association who need it.
No system is infallible. If a breach occurred that posed a risk to your rights, we would tell you and notify the supervisory authority as the GDPR requires.
If we change it, we will update the revision date above. If the change is significant and affects what you accepted, we will tell you by email.