Legal information

Privacy policy

Last updated: 2 October 2026

This is an English translation provided for convenience. The Spanish version is the legally binding one.

At Dragón, the American School of Torrelodones, we handle personal data belonging to families who are interested in the school, to families who are already part of it, to students put forward for our scholarship and to people who apply for our job vacancies. This policy explains what data we collect, what for, how long we keep it, who we share it with and what you can do about it.

1. Data controller

Controller: EL DRAGON SCHOOL, S.L.
Tax ID (CIF): B83864793
Address: C/ Tampico 9, Torrelodones (Madrid), Spain
Registry details: Madrid Commercial Registry, Volume 19,330, Folio 129, Section 8, Sheet M-338779, Entry 1
Telephone: 91 859 13 62
Contact email: secretaria@dragonamericanschool.com

Data Protection Officer: Sonsoles Fiter Gómez.
You can contact her by writing to secretaria@dragonamericanschool.com and stating in the subject line that the message is for the Data Protection Officer.

2. What data we handle, and what for

2.1. Information and visit requests

When a family is interested in the school —through the visit form on this website, by phone, by email or on WhatsApp— we handle the contact details they give us, such as name, email address and phone number, and the information about the student needed to guide them, such as the grade they are interested in.

Purpose: to deal with the request, contact the family by phone, email or WhatsApp, arrange the visit to the school and explain the admissions process.
Legal basis: steps taken at the request of the data subject prior to entering into a contract (Article 6.1.b GDPR).

Data from the visit form is stored in a database hosted by Supabase, with servers in Ireland (European Union), which only school staff can read. The origin of the visit is stored with it: the page it was sent from, the website the visitor came from and, if they arrived from an ad, the click identifier and the campaign. It tells us which channels work; it is not used to build profiles.

If you reach the website from a Google ad, the visit form shows an optional box to authorize us to tell Google that your request came from that ad. Only if you tick it do we send Google Ads the click identifier and the date and time of the request; never your name, email address or phone number. Google links that identifier to the click on its ad to tell us how many requests each campaign has generated.

Purpose: to measure the results of our Google campaigns.
Legal basis: your consent (Article 6.1.a GDPR). Not ticking the box has no effect whatsoever on your request.
Recipient: Google Ireland Limited, acting as data processor under the Google Ads Data Processing Terms.

This data is made available to Google for up to 63 days after the request. You can withdraw your consent at any time by writing to the address in section 1: we will stop sharing your request, without affecting what has already been shared.

2.3. Forms in Facebook and Instagram ads

Some of our ads on Facebook and Instagram include a form that is filled in inside those apps. The data you send in it —such as your name, email address, phone number and the grade you are interested in— reaches us through Meta, and we handle it for the same purpose and on the same legal basis as the requests in section 2.1.

Our server collects it from Meta every few minutes and stores it with the other requests, in the Supabase database described in section 2.1. The name of the form, and whether it was sent from an ad, is stored with it.

Meta Platforms Ireland Limited also handles that data, and your interaction with the ad, as an independent controller under its own privacy policy.

2.4. Families at the school

For enrolled families, we handle identification and contact details, the student’s academic records and whatever is needed to provide the educational service and any additional services contracted.

Purpose: to provide the educational service and to communicate with families.
Legal basis: performance of the enrollment contract (Article 6.1.b) and compliance with the school’s legal obligations in educational matters (Article 6.1.c).

2.5. The private family area

To give access to the private area, we handle the account’s email address and password. The password is stored encrypted and nobody can read it, not even the school. We create an account for each email address the family gave the school office, and note which accounts belong to the same family.

Purpose: to give access to content reserved for school families, such as the lunch menu and the coffees with the head teacher.
Legal basis: performance of the enrollment contract (Article 6.1.b).

When a family books a place at a coffee with the head teacher, we handle the name of the person the booking is for and, if given, those of whoever comes along, its account’s email address and the chosen day. The head teacher and whoever manages her diary see them, and we send the family a confirmation email and, if the booking is canceled, a notice. Other families only see how many places are left.

Purpose: to organize the families’ meetings with the head teacher.
Legal basis: performance of the enrollment contract (Article 6.1.b).

2.6. Photographs and videos of students

Publishing images in which students are identifiable requires the prior, express consent of their parents or legal guardians, obtained in writing and separately for each use: public website or social media.

Legal basis: consent (Article 6.1.a GDPR), which may be withdrawn at any time by writing to the address in section 1, without affecting the lawfulness of processing carried out beforehand.

2.7. Job applications

For people who send us their CV, we handle the data they include in it.

Purpose: to assess the application in open recruitment processes.
Legal basis: steps taken at the request of the data subject prior to entering into a contract (Article 6.1.b).

2.8. Dragon Talent Scholarship applications

When a family puts a student forward for the scholarship through the scholarship form, we handle the student’s data (name, date of birth, current school, the stage they would join, their field of talent, the description of their track record and any links to evidence the family chooses to provide) and the contact details of the parent or legal guardian who applies. If the student is shortlisted, we will also handle the documents the family provides.

Purpose: to handle and assess the application under the rules of the scholarship and, if the scholarship is awarded, to process admission.
Legal basis: steps taken at the family’s request prior to entering into a contract (Article 6.1.b GDPR).

Data from the form is stored in the same Supabase database as the visit requests, which only school staff can read. Applying does not authorize any use of the student’s image: if the scholarship is awarded, the talent ambassador role and the use of their image are governed by the specific agreement the family signs to accept it (section 15 of the rules) and by section 2.6 of this policy.

2.9. Browsing this website

This website sets no cookies or advertising pixels, builds no browsing profiles and takes no automated decisions about visitors.

We count visits with a tool installed on our own server, which stores nothing in your browser, does not keep your IP address and produces aggregate counts, not profiles. The details are in the cookie policy.

Purpose: to understand how the website is used and how our campaigns perform, in order to improve them.
Legal basis: our legitimate interest in understanding, in aggregate and without identifying anyone, how our website is used (Article 6.1.f).

Like any internet service, the server receives your device’s IP address in order to deliver each page, but does not keep it in any access log.

When you send the visit form or the scholarship form, the server uses that IP address to stop mass submissions, which would otherwise block the forms for every other family. It does not keep the address, but a code calculated from it with a secret key, apart from your request, and deletes it after one day.

Purpose: protecting the forms against mass submissions.
Legal basis: our legitimate interest in keeping the forms available to every family (article 6.1.f).

3. How long we keep data

  • Information and visit requests that do not lead to enrollment: until the end of the following academic year, unless the family asks us to delete them sooner.
  • Enrolled families: for as long as the relationship with the school lasts and, afterwards, for the periods required by educational and tax law.
  • Scholarship applications that do not lead to enrollment: until the end of the academic year following the one of the round, unless the family asks us to delete them sooner.
  • Job applications: one year from receipt, unless the applicant asks us to delete them sooner.
  • Images published with consent: until consent is withdrawn or the purpose that justified publication no longer applies.
  • Bookings for the coffees with the head teacher: one month from the meeting. They are deleted in the weekly cleanup.
  • Connection code of the forms: one day. It is deleted with the next submission or, if none arrives, in the weekly cleanup.
  • Website analytics counts: 25 months.
  • Backups: 30 days.

Once those periods have passed, the data is deleted or blocked, remaining available only to judges, courts and the competent authorities for as long as any resulting liability could be claimed.

4. Who we share data with

We do not sell or pass on personal data for commercial purposes. The only parties with access are the providers who supply services to us, bound by contract under Article 28 GDPR, and the entities listed below:

Entity What for Role
Hetzner Online GmbH (Germany) Hosting the website and the analytics Data processor
Supabase (servers in Ireland) Visit requests, scholarship applications, private area accounts and bookings for the coffees with the head teacher Data processor
Google Ireland Limited (Google Workspace) The school’s email Data processor
Google Ireland Limited (Google Ads) Measuring ads, only with your consent (section 2.2) Data processor
Meta Platforms Ireland Limited Forms in Facebook and Instagram ads (section 2.3) Independent controller
WhatsApp Ireland Limited Messaging, when the conversation with the school continues on WhatsApp Provides the service under its own terms

We will also share data with public authorities where a legal rule requires it, in particular with the competent education authority.

5. International transfers

The website, the analytics, the visit requests, the scholarship applications and the private area data are hosted in the European Union.

Google, Meta and WhatsApp may process data outside the European Economic Area, particularly in the United States. Those transfers rely on the European Commission’s adequacy decision on the EU-US Data Privacy Framework, to which their parent companies have signed up, or on the standard contractual clauses approved by the Commission.

6. Your rights

You may exercise the following rights at any time by writing to secretaria@dragonamericanschool.com, or to the Data Protection Officer at that same address, saying which right you wish to exercise and providing proof of identity:

  • Access: to know what data of yours we handle.
  • Rectification: to correct inaccurate or incomplete data.
  • Erasure: to ask us to delete data once it is no longer needed.
  • Objection: to object to processing based on our legitimate interest.
  • Restriction: to ask us to suspend processing while a complaint is resolved.
  • Portability: to receive your data in a structured, commonly used format.
  • Withdrawal of consent: where processing is based on it, without affecting the lawfulness of processing carried out beforehand.

We will reply within one month. If you believe we have not dealt with your request properly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es), C/ Jorge Juan 6, 28001 Madrid.

7. Children’s data

Handling the data of children under fourteen requires the consent of their parents or legal guardians, under Article 7 of Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights.

We never collect from a child any data about the professional or financial situation, or the private life, of other members of their family without those members’ consent.

8. Security

We apply appropriate technical and organizational measures to protect data against destruction, loss, alteration or unauthorized access. These include encrypting communications with the website, storing passwords encrypted, encrypting backups and limiting access to data to the staff who need it.

9. Changes to this policy

We may update this policy to reflect changes in the law or new services. The date of the last update appears at the start of the document. If a change significantly affects how your data is handled, we will tell you.