In compliance with the provisions of personal data protection legislation (Regulation (EU) 2016/679 and Organic Law 3/2018), we inform you that ASOCIACIÓN DEL DEPORTE ESPAÑOL has adopted the technical and organisational measures necessary to guarantee compliance with the rights of data subjects, and hereby informs you of the data processing that it will carry out through this website.
Likewise, through the following privacy policy, ASOCIACIÓN DEL DEPORTE ESPAÑOL fulfils the obligations established in Law 34/2002 on Information Society Services and Electronic Commerce.
The controller responsible for the processing of the personal data collected on this website is:
Legal name: ASOCIACIÓN DEL DEPORTE ESPAÑOL
Trade name: ADESP
Tax ID (CIF): G87376364
Address: Calle Ferraz, 2, 2º izquierda – 28008 Madrid, Spain
Email: info@adesp.es
Data Protection Officer: Consulting & Strategy GFM S.L.
DPO contact details: dpo@gfmservicios.com
The controller will process the data collected and managed through this website in order to facilitate and fulfil the commitments and services established between the controller’s website and the user; as well as to maintain the relationship established through any forms the user completes, or to respond to a request or enquiry.
At the time personal data is obtained, the user will be informed of the specific purpose or purposes for which the personal data will be used; that is, of the use or uses to be made of the information collected.
Specifically, personal data collected through this website may be processed for the following purposes:
Likewise, in accordance with the provisions of the GDPR and the LOPD, and unless the exception set out in Article 30.5 of the GDPR applies, a record of processing activities is maintained specifying, according to their purposes, the processing activities carried out by the controller and the other circumstances established in the GDPR.
The processing of the user’s personal data will be subject to the following principles set out in the GDPR and the LOPD:
Principle of lawfulness, fairness and transparency: the user’s consent will be required at all times, following fully transparent information regarding the purposes for which the personal data is collected.
Principle of purpose limitation: personal data will be collected for specified, explicit and legitimate purposes.
Principle of data minimisation: the personal data collected will be strictly limited to what is necessary in relation to the purposes for which it is processed.
Principle of accuracy: personal data must be accurate and kept up to date at all times.
Principle of storage limitation: personal data will only be kept in a form which permits identification of the user for as long as is necessary for the purposes of the processing.
Principle of integrity and confidentiality: personal data will be processed in a manner that ensures its security and confidentiality.
Principle of accountability: the controller will be responsible for ensuring that the above principles are complied with.
The processing of personal data will be lawful, in accordance with the provisions of Article 6 of the GDPR (EU) 2016/679, on the following legal bases:
Consent of the data subject (Article 6.1(a)): for the acceptance of processing activities whose purpose is not necessary for the operation of the website or for the provision of the services requested or the enquiries made.
Performance of a contract (Article 6.1(b)): for processing activities related to the provision of a service or the contracting of a product or service.
Legitimate interest of the controller (Article 6.1(f)): for processing activities related to the operation of the website, as well as those arising from the controller’s own activity.
Where the processing of personal data is based on the data subject’s consent, the controller undertakes to obtain the free, express, voluntary and unambiguous consent of the data subject. Likewise, the user will have the right to withdraw their consent at any time, and to do so as easily as it was given. As a general rule, the withdrawal of consent will not affect the use of the website.
Where the user must or may provide their data through forms in order to make enquiries, request information, or for reasons related to the content of the website, they will be informed if completing any of these fields is mandatory because the data is essential for the correct performance of the operation carried out.
The categories of data processed on this website are limited to identification and contact data. In certain cases, other personal data may be processed, such as date of birth or sex.
Under no circumstances will special categories of personal data be processed, in accordance with the provisions of Article 9 of the GDPR (EU) 2016/679. Should a specific processing activity involve the processing of such categories of data, the data subject’s consent will be obtained under the terms described in the previous section.
The personal data processed through this website will originate from the data subject themselves or from their legal representative.
In accordance with Article 8 of the GDPR and Article 7 of the LOPD, only persons over 14 years of age may lawfully give their consent to the processing of their personal data. In the case of a child under 14 years of age, the consent of their legal representatives will be required for the processing, and such processing will only be considered lawful to the extent that they have authorised it.
The personal data processed will be retained for the periods established by law and, in any event, for as long as liability may arise for the controller. Where the user has given their consent, the data will be retained until the user requests its erasure or withdraws their consent.
The personal data processed on this website will be shared with persons and/or entities related to the controller that are necessary for the provision of the services offered through it, such as: IT companies, hosting and email marketing service providers, banks and savings banks. These providers act as processors and are bound by contracts governed by Article 28 of the GDPR.
This website is operated within the framework of project 101246920 — SHIA (Sports and Health Innovation Accelerator), co-funded by the European Union under the Erasmus+ programme. ASOCIACIÓN DEL DEPORTE ESPAÑOL (ADESP) acts as coordinator of the project.
Where necessary for the implementation of the project’s activities, personal data may be communicated to the following beneficiary entities of the consortium:
| Entity | Country |
|---|---|
| ASOCIACION DEL DEPORTE ESPANOL (ADESP) — coordinator | Spain |
| EUROPEAN PLATFORM FOR SPORTS AND INNOVATION (EPSI) | Belgium |
| SPORT ET CITOYENNETE 3S (3S) | France |
| OTTO-FRIEDRICH-UNIVERSITAET BAMBERG (UNI BA) | Germany |
| UNIVERZITA KARLOVA (CU) | Czechia |
| CENTER FOR HEALTH, EXERCISE AND SPORT SCIENCES (CHESS) | Serbia |
| ECHALLIANCE COMPANY LIMITED BY GUARANTEE (ECHA) | Ireland |
| INSTITOUTO ANAPTIXIS EPICHEIRIMATIKOTITAS ASTIKI ETAIREIA (IED) | Greece |
| SYSTEMS INNOVATION CENTER KFT. (CSI) | Hungary |
| UNIVERSITY INDUSTRY INNOVATION NETWORK BV (UIIN) | Netherlands |
| AKMI ANONIMI EKPAIDEFTIKI ETAIRIA (AKMI) | Greece |
| NATSIONALNA SPORTNA AKADEMIYA VASSIL LEVSKI (NSA) | Bulgaria |
The project also involves one associated partner, STICHTING CLUSTER SPORTS & TECHNOLOGY (Netherlands), which may receive personal data only where strictly necessary for the activities in which it participates.
Communication of data to these entities is based on the legitimate interest of the controller and of the consortium members in the implementation of the project, and, where applicable, on the consent given by the data subject.
Personal data may also be communicated to the European Education and Culture Executive Agency (EACEA), the European Commission, the European Court of Auditors, the European Anti-Fraud Office (OLAF) and any bodies appointed by them to carry out checks, reviews, audits or investigations, in compliance with the obligations set out in the Grant Agreement of the project and in the applicable EU financial rules. The legal basis for this communication is compliance with a legal obligation to which the controller is subject.
Most of the recipients indicated above are established in the European Union or the European Economic Area, and therefore no international transfer of data takes place.
However, one consortium member, CENTER FOR HEALTH, EXERCISE AND SPORT SCIENCES (CHESS), is established in Serbia, a country for which the European Commission has not adopted an adequacy decision. Any communication of personal data to this entity is carried out on the basis of the Standard Contractual Clauses adopted by the European Commission in accordance with Article 46.2(c) of the GDPR, together with the additional technical and organisational measures required following the corresponding transfer impact assessment. Users may request a copy of these safeguards by writing to info@adesp.es.
Where any service provider used by the controller processes data outside the European Economic Area, equivalent safeguards will be applied.
Data may also be shared with State law enforcement agencies and judicial authorities where they so require.
The user may exercise the following rights recognised in the GDPR and the LOPD before the controller:
Right of access: the right to obtain confirmation as to whether or not the controller is processing their personal data and, if so, to obtain information on their specific personal data and the processing carried out or being carried out, as well as, among other matters, the information available on the origin of such data and the recipients of the communications made or envisaged.
Right to rectification: the right to have personal data that is inaccurate or, taking into account the purposes of the processing, incomplete, corrected.
Right to erasure (“the right to be forgotten”): the right, provided that current legislation does not establish otherwise, to obtain the erasure of their personal data when such data is no longer necessary for the purposes for which it was collected or processed; the user has withdrawn their consent to the processing and there is no other legal basis for it; the user objects to the processing and there is no other legitimate ground for continuing it; the personal data has been unlawfully processed; the personal data must be erased in compliance with a legal obligation; or the personal data was obtained as a result of a direct offer of information society services to a child under 14 years of age.
In addition to erasing the data, the controller, taking into account available technology and the cost of implementation, must take reasonable steps to inform controllers that are processing the personal data of the data subject’s request for the erasure of any links to such personal data.
Right to restriction of processing: the right to restrict the processing of their personal data. The user has the right to obtain restriction of processing where they contest the accuracy of their personal data; the processing is unlawful; the controller no longer needs the personal data but the user requires it to make claims; and where the user has objected to the processing.
Right to data portability: where the processing is carried out by automated means, the user will have the right to receive their personal data from the controller in a structured, commonly used and machine-readable format, and to transmit it to another controller. Where technically feasible, the controller will transmit the data directly to that other controller.
Right to object: the right to have the processing of their personal data not carried out or to have such processing cease.
Right not to be subject to a decision based solely on automated processing, including profiling: the right not to be subject to an individual decision based solely on the automated processing of their personal data, including profiling, unless current legislation establishes otherwise.
Accordingly, the user may exercise their rights via the email address info@adesp.es, providing due proof of identity.
Should their rights not be attended to, or should the user consider that their rights have been infringed, they may submit a communication to the controller’s Data Protection Officer, as well as lodge a complaint with the competent supervisory authority (Spanish Data Protection Agency, www.aepd.es).
The controller undertakes to adopt the technical and organisational measures necessary, according to the level of security appropriate to the risk of the data collected, so as to guarantee the security of personal data and prevent the accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed, or the unauthorised disclosure of or access to such data.
The website has an SSL (Secure Socket Layer) certificate, which ensures that personal data is transmitted securely and confidentially, as the transmission of data between the server and the user, and vice versa, is fully encrypted.
However, since the controller cannot guarantee the impregnability of the internet or the total absence of hackers or others who may fraudulently access personal data, the controller undertakes to notify the user without undue delay when a personal data breach occurs that is likely to result in a high risk to the rights and freedoms of natural persons.
In accordance with Article 4 of the GDPR, a personal data breach is understood to mean any breach of security leading to the accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed, or the unauthorised disclosure of or access to such data.
Personal data will be treated as confidential by the controller, who undertakes to inform of, and to guarantee by means of a legal or contractual obligation, that such confidentiality is respected by its employees, associates and any person to whom it makes the information accessible.
The website may include hyperlinks or links providing access to websites of third parties other than the website owner, which are therefore not operated by the website owner. The owners of such websites will have their own data protection policies and will themselves be responsible, in each case, for their own files and their own privacy practices.
The user must have read the conditions on the protection of personal data contained in this Privacy Policy, and must accept the processing of their personal data, in order for the controller to proceed with such processing in the manner, for the periods and for the purposes indicated.
The controller reserves the right to amend its Privacy Policy at its own discretion, or as a result of a legislative, case-law or doctrinal change by the Spanish Data Protection Agency. Changes or updates to this Privacy Policy will not be explicitly notified to the user. Users are advised to consult this page periodically in order to keep informed of the latest changes or updates.
This website only uses cookies that are necessary for its technical operation. For more information, please see our Cookie Policy.
Last updated: August 2026
Co-funded by the European Union. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or the European Education and Culture Executive Agency (EACEA). Neither the European Union nor EACEA can be held responsible for them.