Privacy Policy
Sóller Town Council (Ajuntament de Sóller), in compliance with Article 13 of Regulation (EU) 2016/679 (GDPR) and Article 11 of Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD), informs users of the platform about the processing of their personal data.
Consulting the platform does not require you to provide any personal data. Personal data are processed only for persons who create a participant account in order to post comments and for staff authorised to manage and moderate the platform.
1. Data controller
Ajuntament de Sóller · Tax ID (NIF) P0706100E · Plaça de la Constitució, 1 · 07100 Sóller (Balearic Islands) · Telephone: 971 63 02 00 · Email: ajuntament@a-soller.es
2. Data Protection Officer
Data subjects may contact the Ajuntament's Data Protection Officer regarding any matter relating to the processing of their data: AUDIDAT · consultasjuridico@audidat.com.
3. Purposes and legal bases of processing
| Purpose | Legal basis |
|---|---|
| Registration and management of participant accounts, including email address verification, password reset and sending notifications relating to the user's own comments. | Consent of the data subject, given when creating the account (Art. 6.1.a GDPR). |
| Receipt, moderation and publication of comments on the Action Plan measures. | Performance of a task carried out in the public interest (Art. 6.1.e GDPR and Art. 8.2 LOPDGDD), in connection with the promotion of citizen participation in municipal management provided for in Articles 69 and 70 bis of Law 7/1985 regulating the Bases of Local Government. |
| Management of the accounts of municipal and technical staff authorised to edit and moderate the platform. | Performance of a task carried out in the public interest (Art. 6.1.e GDPR). |
| Ensuring the security, integrity and traceability of the service, and preventing abusive use. | Compliance with a legal obligation (Art. 6.1.c GDPR), in connection with Article 32 GDPR and Royal Decree 311/2022 regulating the National Security Framework (ENS). |
4. Categories of data processed
The data processed are strictly those necessary for the purposes indicated:
- Email address, used to identify the account and for communications relating to the service.
- Password, stored exclusively in irreversibly encrypted form (cryptographic hash), so that no one can know its content.
- Public name chosen by the user on registration, which is displayed next to their comments.
- Language preference.
- Declaration of being of legal age and the date on which it was made.
- Version of the privacy policy in force at the time of registration.
- Content of the comments submitted.
- Technical connection data: IP address, stored only in cryptographic hash form, and system activity logs.
No identity document numbers, telephone numbers, postal addresses, bank details or special categories of data are requested or processed. Users are advised not to include their own personal data or those of third parties in the text of their comments.
The data are provided directly by the data subject. The email address, password, public name and declaration of legal age are essential for creating the account. If they are not provided, it is not possible to participate, although the entire platform may still be freely consulted.
5. Minors
The creation of participant accounts is restricted to persons aged 18 or over, who must declare this at the time of registration. If the Ajuntament becomes aware that an account belongs to a minor, it will delete the account together with the associated data.
6. Recipients of the data
Publication. The public name and the content of approved comments are displayed on the platform and are accessible to anyone who consults it. The email address is never published.
Data processors. In order to provide the service, certain entities access the data on behalf of the Ajuntament, solely for the purposes indicated and under its instructions, by virtue of the data processing agreements provided for in Article 28 GDPR:
- The entity that provides the Ajuntament with the comment moderation service, as part of the technical support for the Action Plan.
- The entity that provides the technological development and maintenance services for the platform.
- The provider of the service for sending verification and notification emails, as a sub-processor.
The data are hosted on servers of the Ajuntament.
Disclosures to third parties. No data are disclosed to third parties, except where there is a legal obligation to do so, such as requests from courts and tribunals, the Public Prosecutor's Office, the law enforcement agencies, the Ombudsman (Defensor del Pueblo) or the Spanish Data Protection Agency (AEPD).
7. International transfers
The provider of the email sending service is established in the United States of America. The transfer of data involved in this service, limited to the email address and the content of the notifications, is covered by the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023), to which this provider has adhered.
8. Retention periods
| Data | Retention period |
|---|---|
| Verified participant accounts | Until the account holder requests deletion or, in any event, after 24 months of inactivity, with prior notice sent to the account's email address. |
| Unverified participant registrations | 7 days from registration, if email address verification has not been completed. |
| Approved comments | Until two years after the end of the Action Plan's period of validity (2030), unless the author's account is deleted earlier. |
| Comments rejected or identified as spam | 30 days from the moderation decision. |
| IP addresses associated with the submission of comments (in cryptographic hash form) | 24 hours. |
| Authenticated sessions | 8 hours from the last activity. |
| System activity log | 2 years. |
| Records of acceptance of the privacy information | For as long as the account exists and for a further 3 years after its deletion, being the limitation period for very serious infringements provided for in Article 72 LOPDGDD. |
All of the above is without prejudice to any retention obligations arising from the applicable legislation on archives and documentary heritage.
9. Rights of data subjects
Data subjects may at any time exercise the rights of access, rectification, erasure, restriction of processing, portability and objection recognised in Articles 15 to 22 GDPR, and may withdraw the consent given, without affecting the lawfulness of processing carried out prior to its withdrawal.
To exercise these rights, they should contact the Ajuntament through the electronic office (sede electrónica) (https://soller.sedelectronica.es), the general registry (Plaça de la Constitució, 1 · 07100 Sóller) or by email to the Data Protection Officer (consultasjuridico@audidat.com), duly identifying themselves and indicating the right they wish to exercise. The Ajuntament will respond within one month, which may be extended under the terms provided for in Article 12.3 GDPR.
Account holders may also change their public name and request deletion of their account directly from the platform.
10. Complaints to the supervisory authority
If data subjects consider that the processing of their data does not comply with the regulations, they may lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan, 6, 28001 Madrid; www.aepd.es). Beforehand, and on an optional basis, they may contact the Ajuntament's Data Protection Officer.
11. Automated decision-making
No automated decisions are taken and no user profiling is carried out. Comments are moderated by people.
12. Security
The Ajuntament applies appropriate technical and organisational measures to ensure the confidentiality, integrity and availability of the data, in line with the risk of the processing, including encryption of communications, encrypted storage of passwords, pseudonymisation of IP addresses and access control for authorised staff.
13. Amendments
This policy may be updated to adapt it to regulatory or functional changes. Where the changes are substantial, account holders will be informed by email.
Last updated: 29 September 2026