Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored and protected through the websites, digital platforms, admission forms, virtual campus and educational services operated under the SEIUM University brand.
The data controller is NEXORA GENERATION, SOCIEDAD DE RESPONSABILIDAD LIMITADA, the Spanish company responsible for the management and provision of the educational services offered under the SEIUM brand.
Personal data is processed in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD), Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE) and any other legislation applicable to the processing activities described below.
1. DATA CONTROLLER DETAILS
The entity responsible for processing personal data collected through this website and associated SEIUM services is:
Legal name: NEXORA GENERATION, SOCIEDAD DE RESPONSABILIDAD LIMITADA
Short company name: Nexora Generation, S.L.
Legal form: Single-Member Limited Liability Company (Sociedad de Responsabilidad Limitada Unipersonal – SLU)
Tax Identification Number (NIF/CIF): B93900314
Registered and tax address: C/ Lladró y Mallí, 10, Esc. C, Piso 3, Pta. 14 — 46007 València (Valencia), Spain
Principal CNAE activity: 8559 — Other education not elsewhere classified
Commercial educational brand: SEIUM University
Privacy and general contact email: admision@seium.university
For data protection purposes, Nexora Generation, S.L. is the data controller, as it determines the purposes and means by which personal data is processed.
References to “SEIUM”, “SEIUM University”, “we”, “us” or “our” throughout this Policy refer to the educational activity carried out by Nexora Generation, S.L. under the SEIUM commercial brand.
Questions concerning privacy or the exercise of data protection rights may be submitted to admision@seium.university.
2. EDUCATIONAL SERVICES COVERED BY THIS POLICY
SEIUM provides and commercialises proprietary educational and professional training programmes developed and managed by Nexora Generation, S.L.
Depending on the programme catalogue available at any given time, these services may include courses, diplomas, master’s-level proprietary programmes, executive education, specialist programmes and other forms of professional or advanced technical training.
Unless expressly stated otherwise for a specific programme, the educational programmes offered directly by SEIUM constitute proprietary training programmes and are not presented as official Spanish university degrees or qualifications registered in the Spanish Registry of Universities, Centres and Degrees (RUCT).
Personal data may therefore be processed throughout the entire educational relationship, including enquiries, admissions, enrolment, payment, access to learning environments, academic participation, assessments, student support and the preparation or issuance of proprietary certificates, diplomas or training credentials where applicable.
3. PURPOSES OF PERSONAL DATA PROCESSING
SEIUM processes personal data only where there is a defined, legitimate and proportionate purpose.
Personal information may be used for the following activities.
3.1. Enquiries and information requests
We may process identification and contact details to respond to enquiries submitted through:
Website forms.
Email.
Chat or messaging systems.
Admission forms.
Telephone or other authorised communication channels.
This may include requests for information concerning courses, diplomas, master’s programmes, programme content, duration, tuition fees, admission requirements, enrolment procedures, study methods or other SEIUM services.
3.2. Admission and enrolment management
We may process personal, academic and professional information necessary to:
Register applications.
Review submitted information.
Assess entry requirements where applicable.
Contact prospective students.
Complete enrolment procedures.
Create student profiles.
Maintain records relating to the admission process.
Where documentation is required for a particular programme, only information reasonably necessary for that process should be requested.
3.3. Delivery of proprietary educational services
Following enrolment or contracting, personal data may be used to provide the educational service purchased by the student.
This may include:
Creating or activating access to the learning platform.
Assigning the student to the appropriate programme.
Providing access to educational content.
Monitoring programme progress.
Managing learning activities and assessments.
Communicating academic or operational notices.
Providing technical and student support.
Managing completion records.
Preparing proprietary certificates, diplomas or other training documentation.
3.4. Academic administration
Data may be processed to maintain appropriate records relating to:
Enrolment.
Student participation.
Progress.
Assessments.
Completed activities.
Results.
Programme completion.
Certificates or diplomas issued.
Requests relating to academic documentation.
Such processing is carried out to ensure the proper administration of SEIUM’s proprietary training services.
3.5. Billing, accounting and financial administration
Where a paid service is purchased, information may be processed for:
Payment management.
Invoice preparation.
Accounting.
Transaction reconciliation.
Refund management.
Financial administration.
Tax compliance.
Compliance with commercial and accounting obligations.
Payment card details may be processed directly by authorised banks or payment service providers rather than being stored by SEIUM itself, depending on the payment infrastructure used.
3.6. Service communications
We may send communications that are necessary for the performance of the educational or contractual relationship.
These communications may include:
Enrolment confirmations.
Payment information.
Access credentials.
Academic notices.
Programme updates.
Assessment-related information.
Support communications.
Certificate or diploma notifications.
Administrative requests.
Security notices.
Communications strictly required for service delivery are not treated as optional marketing messages.
3.7. Marketing and educational communications
Where permitted by law, SEIUM may send information regarding:
New training programmes.
Programme intakes.
Related courses.
Educational events.
Academic or professional content.
Promotions.
News and updates relating to SEIUM.
Where consent is required, marketing communications will only be sent after valid consent has been obtained.
Recipients may withdraw consent or object to marketing communications at any time.
3.8. Platform security and fraud prevention
Technical and usage data may be processed for purposes such as:
Preventing unauthorised access.
Protecting user accounts.
Detecting suspicious activity.
Preventing identity fraud.
Maintaining system integrity.
Investigating technical incidents.
Protecting databases and learning platforms.
Maintaining security records.
3.9. Compliance with legal obligations
Personal data may also be processed where necessary to comply with applicable:
Tax requirements.
Accounting rules.
Commercial legislation.
Consumer protection obligations.
Data protection requirements.
Court orders.
Regulatory requests.
Requests from competent public authorities.
4. LAWFUL BASIS FOR PROCESSING
The legal basis applied depends on the specific processing activity.
4.1. Performance of a contract and pre-contractual measures
Article 6(1)(b) GDPR applies where processing is necessary to:
Respond to a request prior to enrolment.
Manage an admission process.
Formalise an enrolment.
Deliver purchased training.
Provide access to the learning platform.
Manage academic participation.
Provide student support.
Issue training documentation associated with the contracted programme.
4.2. Legal obligations
Article 6(1)(c) GDPR applies where information must be processed to comply with obligations imposed on Nexora Generation, S.L., including tax, accounting, commercial, regulatory or legally binding public authority requirements.
4.3. Consent
Article 6(1)(a) GDPR may apply to processing activities such as:
Certain marketing communications.
Newsletter subscriptions.
Non-essential cookies.
Optional forms.
Other processing activities for which consent is expressly requested.
Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
4.4. Legitimate interests
Article 6(1)(f) GDPR may apply where processing is reasonably necessary for legitimate interests pursued by Nexora Generation, S.L., including:
Protecting its digital infrastructure.
Preventing fraud.
Managing information security.
Defending legal claims.
Improving internal operational processes.
Preventing misuse of educational services.
Where legitimate interest is relied upon, SEIUM will consider the impact of the processing on the rights and freedoms of the individuals concerned.
5. CATEGORIES OF PERSONAL DATA
The categories of information processed will depend on the user’s relationship with SEIUM.
5.1. Identification and contact information
This may include:
First name.
Surname.
Email address.
Telephone number.
Postal address where required.
Identification document information where legitimately necessary.
5.2. Admission and enrolment information
Depending on the programme and its access conditions, information may include:
Programme selected.
Application details.
Previous education.
Professional background.
Academic documentation.
Curriculum vitae.
Other information voluntarily submitted as part of the admission process.
5.3. Academic information
This may include:
Programmes in which the student is enrolled.
Course or programme progress.
Learning activities.
Assessments.
Results.
Participation records where applicable.
Completion status.
Certificates, diplomas or proprietary training credentials issued.
5.4. Financial and billing information
Where applicable, SEIUM may process:
Billing name.
Company name.
Tax identification information.
Billing address.
Payment status.
Amounts paid.
Invoice records.
Refund records.
Transaction references.
Sensitive payment credentials may be handled directly by the relevant financial institution or payment processor.
5.5. Technical information
Depending on the website and platform configuration, technical data may include:
IP address.
Login records.
Session identifiers.
Browser information.
Device information.
Date and time of access.
Security events.
Platform activity logs.
5.6. Learning platform usage information
Where necessary for educational delivery, we may process information regarding:
Login activity.
Access to learning materials.
Programme progress.
Submitted activities.
Assessment participation.
Completion history.
Interaction with the virtual campus.
6. SPECIAL CATEGORIES OF PERSONAL DATA
As a general rule, SEIUM does not request special categories of personal data within the meaning of Article 9 GDPR, such as information concerning:
Health.
Racial or ethnic origin.
Political opinions.
Religious or philosophical beliefs.
Trade union membership.
Genetic information.
Biometric identification.
Sexual life or sexual orientation.
If such information becomes genuinely necessary in an exceptional situation, SEIUM will identify an appropriate legal basis and provide any additional information required by law before processing it.
Users are requested not to submit unnecessary sensitive information through general contact forms or communication channels.
7. SOURCE OF PERSONAL DATA
Personal information processed by SEIUM may originate from several sources.
7.1. Information supplied directly by the individual
This includes information provided through:
Contact forms.
Admission applications.
Enrolment forms.
Emails.
Communications with SEIUM.
Payment or invoicing procedures.
Student support requests.
7.2. Information generated during service use
Certain information is generated as part of the educational relationship, such as:
Programme progress.
Assessment records.
Access logs.
Learning platform activity.
Academic completion data.
Security records.
7.3. Payment-related information
Payment service providers or financial institutions may provide SEIUM with transaction status information, such as whether a payment was successful, rejected, refunded or pending.
8. ACCURACY OF INFORMATION PROVIDED
Users are responsible for ensuring that personal data supplied to SEIUM is accurate, complete, current and truthful.
Where information changes, users should update it through the available systems or notify SEIUM when the change is relevant to the educational or contractual relationship.
If a person provides information relating to another individual, they must have an appropriate legal basis for doing so and, where required, must have informed that person about the disclosure.
9. MANDATORY AND OPTIONAL INFORMATION
Certain data fields may be marked as mandatory because the information is required to:
Respond to a request.
Assess an application.
Process an enrolment.
Complete a contract.
Issue an invoice.
Provide access to educational services.
Comply with a legal obligation.
Failure to provide mandatory information may prevent SEIUM from processing the corresponding request or providing the relevant service.
Optional information will only be processed for the purposes indicated when it is collected.
10. RECIPIENTS AND DATA PROCESSORS
Nexora Generation, S.L. does not sell personal data to third parties.
Personal information may, however, be accessible to third-party providers where their services are necessary for SEIUM’s operations.
These may include:
Website hosting providers.
Cloud infrastructure providers.
Virtual learning platform providers.
Email service providers.
Customer support systems.
Administrative management tools.
Analytics providers.
IT and cybersecurity service providers.
Backup and storage providers.
Banks and payment gateways.
Accounting, tax or legal advisers.
Where a provider processes personal data on behalf of Nexora Generation, S.L., the relationship will be governed, where required, by an appropriate data processing agreement in accordance with Article 28 GDPR.
Personal data may also be disclosed to:
Tax authorities.
Courts and tribunals.
Law enforcement authorities.
Public administrations.
Regulators.
Other competent authorities.
Such disclosures will only take place where required or authorised by applicable law.
SEIUM will not disclose personal information to unrelated third parties for their independent marketing activities without an appropriate lawful basis.
11. INTERNATIONAL DATA TRANSFERS
Some technology providers may operate outside the European Economic Area (EEA) or use infrastructure located in third countries.
Where a transfer of personal data outside the EEA takes place, Nexora Generation, S.L. will ensure that an appropriate mechanism recognised under the GDPR is available.
Depending on the circumstances, this may include:
An adequacy decision adopted by the European Commission.
Standard Contractual Clauses approved by the European Commission.
Binding Corporate Rules.
Additional contractual, organisational or technical safeguards.
Another legally recognised transfer mechanism.
Where required, additional measures may be implemented to protect personal data transferred internationally.
12. DATA RETENTION PERIODS
Personal data will not be retained indefinitely without justification.
Retention periods depend on the purpose for which the information was collected and on applicable legal requirements.
12.1. Enquiries
Information submitted through general enquiries will normally be retained for the period necessary to respond to the request and subsequently for a reasonable period where required to manage follow-up communications or possible legal claims.
12.2. Admission applications
Admission-related information may be retained throughout the application process and afterwards for the period reasonably necessary to address administrative matters, disputes or legal responsibilities.
12.3. Enrolled students
Data required for the educational and contractual relationship will generally be retained for the duration of the programme and for the additional periods required by law or necessary to manage legitimate claims.
12.4. Academic and certification records
Essential academic information may be retained where reasonably necessary to document:
Programme completion.
Assessments.
Certificates issued.
Diplomas issued.
Requests for subsequent verification of training credentials.
Retention will be limited to information necessary for the corresponding purpose.
12.5. Accounting and tax information
Invoices, payments and accounting documentation will be retained for the periods required under applicable Spanish tax, commercial and accounting legislation.
12.6. Marketing information
Where processing is based on consent, information may be retained until the individual withdraws that consent.
Where the processing is based on legitimate interest, it may continue until the individual validly objects or the legitimate purpose ceases to apply.
12.7. Security logs
Technical and security records will be retained only for the period reasonably required for:
Cybersecurity.
Fraud prevention.
Incident investigation.
Regulatory compliance.
Protection of systems and user accounts.
Once the applicable retention period expires, information will be deleted, anonymised or blocked where required by Spanish law.
13. DATA PROTECTION RIGHTS
Individuals whose personal data is processed by Nexora Generation, S.L. may exercise the rights granted by the GDPR and applicable Spanish legislation.
13.1. Right of access
You may request confirmation as to whether your personal data is being processed and obtain access to the relevant information.
13.2. Right to rectification
You may request correction of inaccurate personal data or completion of incomplete information.
13.3. Right to erasure
You may request deletion of personal data where the conditions established by applicable law are satisfied.
This right is not absolute and may be restricted where information must be retained to comply with a legal obligation or defend legal claims.
13.4. Right to object
You may object to processing carried out on the basis of legitimate interests in the circumstances established by the GDPR.
You may object to direct marketing at any time.
13.5. Right to restriction of processing
You may request that the use of your personal information be restricted in the situations provided for by data protection legislation.
13.6. Right to data portability
Where legally applicable, you may request personal data that you provided in a structured, commonly used and machine-readable format and may request its transmission to another controller where technically feasible.
13.7. Right to withdraw consent
Where processing is based on your consent, you may withdraw it at any time.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
13.8. Rights relating to automated decision-making
Where applicable, individuals have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect them, except in the circumstances permitted by law.
14. HOW TO EXERCISE YOUR RIGHTS
Requests relating to data protection rights may be sent to:
NEXORA GENERATION, SOCIEDAD DE RESPONSABILIDAD LIMITADA
C/ Lladró y Mallí, 10, Esc. C, Piso 3, Pta. 14
46007 València (Valencia), Spain
Email: admision@seium.university
Suggested subject: “Data Protection”
The request should clearly identify the right being exercised and provide sufficient information for SEIUM to understand and process the request.
Where there are reasonable doubts concerning the identity of the person submitting the request, additional information may be requested solely to verify identity.
Requests will be handled within the time limits established by the GDPR.
15. RIGHT TO LODGE A COMPLAINT
If you believe that the processing of your personal data infringes applicable data protection legislation or that your rights have not been properly addressed, you are entitled to lodge a complaint with the competent supervisory authority.
For processing carried out by Nexora Generation, S.L. in Spain, the competent supervisory authority is the Spanish Data Protection Agency (Agencia Española de Protección de Datos – AEPD).
You may also contact SEIUM first through admision@seium.university so that the matter can be reviewed directly.
16. MARKETING COMMUNICATIONS
SEIUM may provide information about programmes, new enrolment periods, educational activities, related training opportunities, events or commercial promotions where there is a lawful basis for doing so.
Where consent is required, marketing communications will only be sent after valid consent has been obtained.
Where permitted under applicable electronic communications legislation, certain information concerning services similar to those previously purchased may be sent to existing customers on the basis permitted by law.
Every electronic marketing communication will provide, where legally required, a straightforward method for unsubscribing or objecting to future communications.
17. COOKIES AND SIMILAR TECHNOLOGIES
SEIUM websites may use cookies and similar technologies for purposes including:
Website operation.
Session management.
Security.
User authentication.
Preference management.
Analytics.
Performance measurement.
Advertising or campaign measurement where applicable.
Cookies strictly necessary to provide a service expressly requested by the user may be used without consent where permitted by law.
Non-essential cookies will only be activated where the legally required consent has been obtained.
Further details regarding categories of cookies, providers, purposes and retention periods are available in the website’s Cookie Policy.
18. INFORMATION SECURITY
Nexora Generation, S.L. applies technical and organisational measures designed to protect personal information against risks such as:
Unauthorised access.
Accidental loss.
Unlawful disclosure.
Alteration.
Destruction.
Account compromise.
Misuse of systems.
Depending on the nature of the processing, safeguards may include:
Access controls.
Authentication mechanisms.
Role-based permissions.
Logging.
Backups.
Security monitoring.
Encryption where appropriate.
Internal confidentiality procedures.
Incident response measures.
No Internet-based service can guarantee absolute security. SEIUM therefore reviews its safeguards taking into account the nature of the information processed, available technology and the risks identified.
19. CONFIDENTIALITY
Personnel and authorised collaborators who may access personal information in connection with SEIUM’s activities must treat that information confidentially and use it solely for authorised professional purposes.
Access to personal data should be restricted to individuals whose responsibilities genuinely require it.
20. CHILDREN AND MINORS
SEIUM educational services are generally intended for persons 18 years of age or older.
SEIUM does not intentionally seek to collect personal information from minors through services intended exclusively for adults without an appropriate lawful basis.
If information relating to a minor is identified and there is no lawful basis supporting its processing, appropriate steps may be taken to restrict or delete the information.
21. AUTOMATED DECISION-MAKING
As a general rule, SEIUM does not make decisions based solely on automated processing that produce legal effects or similarly significant consequences for individuals.
If such technology is introduced in the future, affected individuals will be provided with the information required under the GDPR, including information concerning the logic involved and the potential consequences of the processing.
22. THIRD-PARTY WEBSITES AND SERVICES
SEIUM websites may contain links to websites, applications, platforms or online services operated independently by third parties.
Nexora Generation, S.L. is not responsible for the privacy practices of independent third-party services.
Users should review the privacy information provided by the corresponding third party before submitting personal information through an external service.
23. CHANGES TO THIS PRIVACY POLICY
Nexora Generation, S.L. may amend this Privacy Policy where necessary due to:
Legislative changes.
Regulatory guidance.
Changes to SEIUM services.
Technological developments.
Changes to service providers.
New processing activities.
Internal operational changes.
The version published on the website at any given time will be considered the current version.
Where a change materially affects the way personal data is processed, additional notice will be provided where legally required.
24. APPLICABLE DATA PROTECTION LEGISLATION
This Privacy Policy is primarily governed by:
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 – General Data Protection Regulation (GDPR).
Spanish Organic Law 3/2018 of 5 December on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD).
Spanish Law 34/2002 of 11 July on Information Society Services and Electronic Commerce (LSSI-CE).
Any other Spanish or European Union legislation applicable to the processing activities carried out by Nexora Generation, S.L.
25. CONTACT
For questions regarding this Privacy Policy, the processing of personal data or the exercise of privacy rights, you may contact:
NEXORA GENERATION, SOCIEDAD DE RESPONSABILIDAD LIMITADA
Tax Identification Number (NIF/CIF): B93900314
Registered and tax address: C/ Lladró y Mallí, 10, Esc. C, Piso 3, Pta. 14 — 46007 València (Valencia), Spain
Commercial educational brand: SEIUM University
Email: admision@seium.university