Privacy Policy

At the Responsible Tourism Institute (“RTI”, “we” or “us”), we treat the personal data provided to us with respect and integrity, and we are committed to protecting the privacy of the individuals whose data we receive through our website www.responsibletourisminstitute.com

This Privacy Policy explains what personal data we process, for what purposes and on what legal basis, how long we keep it, to whom we disclose it and what rights you have. Personal data is always processed in accordance with:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, “GDPR”);
  • Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and the Guarantee of Digital Rights (“LOPDGDD”);
  • Spanish Law 34/2002 of 11 July on Information Society Services and Electronic Commerce (“LSSI”); and
  • any other applicable data protection legislation.

 

SECTION 1. Data controller

The controller of your personal data is:

Responsible Tourism Institute (RTI)

Tax ID (CIF): G81709842

Registered address: C/ La Rosa, 1, 1.º, CP 38002, Santa Cruz de Tenerife, Canary Islands, Spain

Email: info@responsibletourisminstitute.com

 

SECTION 2. Definitions

To make this policy easy to understand, we explain below the main terms we use, in accordance with Article 4 of the GDPR:

  • Personal data: any information relating to an identified or identifiable natural person (“data subject”). An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity.
  • Data subject: the natural person whose personal data is processed.
  • Processing: any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  • Restriction of processing: the marking of stored personal data with the aim of limiting its processing in the future.
  • Profiling: any form of automated processing of personal data consisting of using it to evaluate certain personal aspects of a natural person, in particular to analyse or predict aspects concerning their performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
  • Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing.
  • Processor: the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
  • Recipient: the natural or legal person, public authority, agency or other body to which personal data is disclosed, whether a third party or not. Public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law are not regarded as recipients.
  • Third party: a natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and the persons who, under the direct authority of the controller or processor, are authorised to process personal data.
  • Consent of the data subject: any freely given, specific, informed and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.

 

SECTION 3. Personal data we process

Depending on your relationship with us, we may process the following categories of personal data:

  • Registration and account data: first name and surname, email address, login credentials and, where applicable, job title and the entity you represent, provided when registering on our domain.
  • Training service data: enrolment details, course progress, assessment results and any diplomas or certificates of completion issued.
  • Billing and transaction data: identification and tax details, billing address, details of the services purchased and amounts. Card or other payment details are processed directly by the payment gateway provider; RTI does not have access to them.
  • Enquiry and correspondence data: the information you provide when contacting us by email, web forms, telephone or the messaging system (tickets) on our domain, together with the metadata associated with those communications.
  • Complaints and claims data: the information you provide when submitting a complaint or claim relating to our services.
  • Browsing data: IP address, Internet service provider, browser type and version, operating system, referring website, pages visited, date and time of access and other similar technical data, which are recorded in the server log files. If you accept them through the cookie settings panel, we also collect usage data for analytics purposes (see Section 8).

Where you do not provide the data to us directly, its source will generally be the entity you represent (for example, when a business or destination provides us with the details of its contact person) or the entity that has purchased a service and assigned it to you by means of a code.

If you provide us with personal data relating to other people (for example, colleagues at your entity), you must have informed them in advance of the content of this policy and, where applicable, have the necessary legal basis to do so.

We do not request special categories of data (such as health data, ethnic origin, political opinions or religious beliefs). Please do not include this type of information in the documentation you submit to us, unless it is strictly necessary and you have informed us in advance.

 

SECTION 4. Purposes and legal bases for processing

We process your personal data for the following purposes and on the following legal bases (Article 6(1) GDPR):

  • Managing your registration and user account on our domain. Legal basis: performance of a contract or taking steps at your request prior to entering into a contract (Article 6(1)(b) GDPR).
  • Providing training services and issuing the corresponding diplomas or certificates. Legal basis: performance of a contract (Article 6(1)(b) GDPR).
  • Issuing invoices and complying with our accounting and tax obligations. Legal basis: compliance with legal obligations (Article 6(1)(c) GDPR).
  • Responding to your enquiries and requests for information. Legal basis: taking steps at your request prior to entering into a contract or, where applicable, our legitimate interest in responding to the communications we receive (Article 6(1)(b) and 6(1)(f) GDPR).
  • Handling complaints, claims and appeals. Legal basis: performance of the contract and compliance with the obligations applicable to us, including under consumer protection legislation (Article 6(1)(b) and 6(1)(c) GDPR).
  • Sending our customers marketing communications about our own services similar to those they have contracted. Legal basis: legitimate interest (Article 6(1)(f) GDPR), under the terms of Article 21(2) of the LSSI. You may object at any time, as explained in Section 9.
  • Sending newsletters and marketing communications to people who are not customers. Legal basis: consent (Article 6(1)(a) GDPR), which you may withdraw at any time.
  • Ensuring the security of our websites and systems, preventing fraud and cyberattacks and, where applicable, providing the competent authorities with the information required in the event of a cyberattack. Legal basis: legitimate interest (Article 6(1)(f) GDPR) and, where applicable, compliance with legal obligations (Article 6(1)(c) GDPR).
  • Analysing the use of our websites through non-essential cookies. Legal basis: consent (Article 6(1)(a) GDPR and Article 22(2) LSSI).
  • Establishing, exercising or defending legal claims. Legal basis: legitimate interest (Article 6(1)(f) GDPR).

Where the legal basis is legitimate interest, we have balanced that interest against your rights and freedoms. You can ask us for more information about this balancing test using the contact details in Section 1.

We do not take decisions based solely on automated processing of your data, including profiling, which produce legal effects concerning you or similarly significantly affect you.

Providing the data marked as mandatory in our forms is necessary for us to provide the corresponding service. If you do not provide it, we will not be able to deal with your request or provide that service.

 

SECTION 5. Retention periods

We keep your personal data only for as long as necessary to fulfil the purpose for which it was collected and, thereafter, for the periods required by law:

  • Registration and account data: for as long as your user account remains active.
  • Training service data: for as long as access to the course is valid and, thereafter, for 3 years in order to be able to certify the training completed.
  • Billing data: for a minimum of six (6) years, in accordance with Article 30 of the Spanish Commercial Code, and in any event for the periods required by tax legislation.
  • Enquiries and correspondence: for as long as necessary to deal with them and, where applicable, for the limitation periods of any potential liabilities.
  • Complaints, claims and appeals: while they are being handled and, thereafter, in accordance with RTI's complaints and appeals procedure.
  • Marketing communications: until you object to receiving them or withdraw your consent.
  • Server log files: for a maximum of 3 years.
  • Cookies: for the periods stated in our Cookie Policy.

Once these periods have elapsed, the data will be erased. Where required by law, the data will be kept blocked, in accordance with Article 32 of the LOPDGDD, solely at the disposal of the courts and tribunals, the Public Prosecutor's Office or the competent public authorities, in order to deal with any liabilities arising from the processing, and only for the corresponding limitation period.

 

SECTION 6. Recipients of the data

We do not sell or rent your personal data. We will only disclose it in the following cases:

  • Processors that provide us with services necessary for our activity, with whom we have signed the corresponding data processing agreement in accordance with Article 28 of the GDPR and who may only process the data on our instructions. These include:
    • Projectes a Internet Enginyeria de Software, S.L. (Tax ID B66797119, C/ Aragó 517, 6-1, 08013 Barcelona), developer and maintenance provider of our websites, email and communications server;
    • Google Ireland Limited, as provider of the Google Analytics web analytics service, only if you have accepted analytics cookies.
  • The entity that has purchased a service and assigned it to you by means of a code, which will only receive the data set out in Section 7 of our Terms and Conditions (services assigned and used, company name and contact email address).
  • The general public, with regard to the information published on our domain, under the terms set out in the contractual documentation for the service.
  • Public authorities, courts and tribunals, the Ombudsman, data protection authorities and law enforcement agencies, where there is a legal obligation to provide them with the data or where necessary for the establishment, exercise or defence of legal claims.

 

SECTION 7. International data transfers

As a general rule, we process your data within the European Economic Area (EEA). Some of our providers, such as Google, may process data outside the EEA, in particular in the United States. In such cases, transfers are carried out with the safeguards provided for in Chapter V of the GDPR, such as an adequacy decision of the European Commission (for example, the EU-US Data Privacy Framework, where the recipient participates in it) or the standard contractual clauses approved by the European Commission. You can ask us for more information about these safeguards using the contact details in Section 1.

 

SECTION 8. Cookies

Our websites use technical cookies, which are necessary for them to function and are installed without the need for consent. Other cookies (preference, analytics and advertising cookies) are only installed if you accept them via the banner or the cookie settings panel, where you can also reject them or withdraw your consent at any time. If you disable certain cookies, some features of the websites may not be available.

Details of the cookies we use, their purpose and their duration can be found in our Cookie Policy.

 

SECTION 9. Marketing communications and how to unsubscribe

You can stop receiving our marketing communications and newsletters at any time, free of charge, by any of the following means:

  • by following the unsubscribe link included in each communication;
  • by accessing your user profile and selecting the “Do not receive news” option; or
  • by writing to us at info@responsibletourisminstitute.com

Please note that, if you are a customer, you will continue to receive the communications necessary for the provision of the service you have contracted, as part of the performance of the contract.

 

SECTION 10. Minors

Our services are aimed at professionals and entities and are not intended for minors. We do not knowingly collect personal data from children under the age of fourteen (14), who, under Article 7 of the LOPDGDD, cannot give consent on their own behalf.

If we discover that we have collected data from a child under fourteen without the consent of their parents or guardians, we will erase it as soon as possible. If you believe that we hold data relating to a minor, please let us know at info@responsibletourisminstitute.com.

 

SECTION 11. Data security

We apply appropriate technical and organisational measures, in accordance with Article 32 of the GDPR, to ensure a level of security appropriate to the risk and to protect your personal data against unauthorised destruction, loss, alteration, disclosure or access. For example, access to our databases is restricted to authorised personnel and segmented according to their roles, so that each person only accesses the information they need to carry out their duties.

Payment information is always transmitted encrypted. However, no transmission over the Internet is completely secure, so we recommend that you keep your login credentials safe and do not share them with third parties.

 

SECTION 12. Your rights

In relation to your personal data, you may exercise the following rights:

  • Access: to obtain confirmation as to whether we are processing your personal data and, if so, to access it and information on the purposes of the processing, the categories of data, the recipients, the retention period and its source. The first copy of your data will be free of charge; for additional copies, we may charge a reasonable fee based on administrative costs.
  • Rectification: to request the rectification of inaccurate data and the completion of incomplete data.
  • Erasure: to request the erasure of your data where, among other grounds, it is no longer necessary for the purposes for which it was collected, you withdraw the consent on which the processing was based, you object to the processing or the data has been processed unlawfully. This right does not apply where the processing is necessary, among other cases, to comply with a legal obligation or for the establishment, exercise or defence of legal claims.
  • Restriction of processing: to request that we restrict the processing of your data where you contest its accuracy, while we verify it; where the processing is unlawful and you oppose its erasure; where we no longer need the data but you require it for the establishment, exercise or defence of legal claims; or where you have objected to the processing, pending verification of whether our legitimate grounds override yours.
  • Portability: where the processing is based on your consent or on the performance of a contract and is carried out by automated means, to receive the data you have provided to us in a structured, commonly used and machine-readable format, and to transmit it to another controller, provided that this does not adversely affect the rights and freedoms of others.
  • Objection: to object, on grounds relating to your particular situation, to the processing of your data based on our legitimate interest. In such a case, we will stop processing it unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims. You may also object at any time to the processing of your data for direct marketing purposes, in which case we will stop processing it for that purpose.
  • Not to be subject to automated individual decision-making: not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you.
  • Withdrawal of consent: where the processing is based on your consent, to withdraw it at any time, without affecting the lawfulness of processing carried out before its withdrawal.

How to exercise your rights. You can exercise these rights free of charge by writing to info@responsibletourisminstitute.com or by post to the address given in Section 1, stating the right you wish to exercise. If we have reasonable doubts about your identity, we may ask you for the additional information necessary to confirm it. We will respond within one (1) month of receiving your request, which may be extended by a further two (2) months where necessary, taking into account the complexity and number of requests. In that case, we will inform you of the extension and the reasons for it within the first month.

Complaints to the supervisory authority. If you consider that the processing of your personal data does not comply with the legislation, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, C/ Jorge Juan, 6, 28001 Madrid; www.aepd.es) or with the supervisory authority of the European Union Member State in which you habitually reside or work, or in which the alleged infringement took place. Before doing so, you may contact us to try to resolve the matter.

 

SECTION 13. Accuracy of data

We take reasonable steps to ensure that the personal data we process is accurate and up to date. To this end, we ask you to inform us of any changes to your data, or to update it directly in your user profile. You guarantee that the data you provide to us is true, accurate, complete and up to date, and you are responsible for any damage that may arise from providing false or inaccurate data.

 

SECTION 14. Changes to this policy

We may update this Privacy Policy, for example to adapt it to legal changes or to new services. The current version will always be available on our websites, showing the date of its last update. If the changes are significant, we will inform you by email or through the messaging system (tickets) on our platforms.

 

SECTION 15. How to contact us

For any questions, suggestions or complaints regarding the processing of your personal data, you can contact us at:

Responsible Tourism Institute (RTI)

Tax ID (CIF): G81709842

Registered address: C/ La Rosa, 1, 1.º, CP 38002, Santa Cruz de Tenerife, Canary Islands, Spain

Email: info@responsibletourisminstitute.com

 

Last updated: 28 September 2026