Privacy Policy
Last updated: May 2026
In compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and Spanish Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD), this policy explains how Red Española de Microscopía Óptica Avanzada (REMOA), through the REMOA Labs platform, collects, uses and protects your personal data.
1. Data Controller
Red Española de Microscopía Óptica Avanzada (REMOA)
Association registered in the Registro Nacional de Asociaciones (National Register of Associations), Ministerio del Interior (Ministry of the Interior), September 2017.
Tax ID (CIF): G67434159
Registered address: c/ Casanova, 143 — 08036 Barcelona, Spain
Contact email: info@remoa.net
Website: https://remoa.net
Data Protection Officer (DPO): dpo@labs.remoa.net
You may contact the DPO at the address indicated for any matter relating to the processing of your personal data.
2. Data We Collect
We collect the following categories of personal data, strictly limited to what is necessary for the provision of the service (data minimisation principle, Art. 5.1.c GDPR):
- Identity data: first name, last name, email address.
- Professional data: associated laboratory, role in the network, research centre, institution.
- Technical data: IP address, browser type, session data, system activity logs.
- Transparency and acknowledgement data: date and version of the privacy policy made available to the user, together with any related accountability records kept to evidence compliance.
Providing identity, professional and account-related data is necessary to create and manage your account and to provide access to the REMOA Labs service. Failure to provide such data may prevent us from creating your account or providing the requested service. For information on the use of cookies and similar technologies, please refer to our Cookie Policy.
3. Purpose and Legal Basis for Processing
Your data is processed for the following purposes, each with its corresponding legal basis under Art. 6.1 GDPR:
- Account management and authentication: Performance of a contract (Art. 6.1.b GDPR).
- Laboratory network and content management: Legitimate interest in operating, coordinating and maintaining the REMOA network and REMOA Labs platform, including publishing and managing information submitted by authorised users or participating laboratories about laboratories, equipment, training activities and related network content (Art. 6.1.f GDPR), and performance of the service relationship with the user where applicable (Art. 6.1.b GDPR).
- Technology information management: Legitimate interest in publishing and maintaining the base catalogue of technologies available within the REMOA network, including technology information curated or maintained directly by REMOA or administrators where applicable (Art. 6.1.f GDPR).
- Security, audit and fraud prevention: Legitimate interest in protecting the REMOA Labs platform, users, systems and data, and legal obligation where applicable (Art. 6.1.f and, where applicable, Art. 6.1.c GDPR).
- Service-related communications: Performance of a contract (Art. 6.1.b GDPR).
Where processing is based on legitimate interest, the interests pursued include operating, coordinating, securing and maintaining the REMOA network and its associated services, publishing and managing network-related information submitted by authorised users or participating laboratories, maintaining the base catalogue of technologies where applicable, and protecting the website and public forms against abuse.
4. Data Recipients
Your personal data may be disclosed to the following recipients:
- Authorised REMOA personnel: System administrators and network coordinators, with access limited to their duties.
- Service providers acting as data processors: providers that support hosting, infrastructure, security, anti-abuse protection, email delivery, authentication, backup or technical support services, always under a data processing agreement and subject to confidentiality and security obligations.
- Public authorities and bodies: where disclosure is required by law or is necessary for the exercise or defence of legal claims.
Where legally required, REMOA will provide additional information about recipients or categories of recipients relevant to the specific processing activity.
5. International Transfers
REMOA may use service providers that process personal data within or outside the European Economic Area (EEA), including providers supporting hosting, email delivery, security or anti-abuse measures on public forms. Where such processing involves an international transfer, REMOA will ensure that appropriate safeguards recognised under the GDPR are in place, such as data processing terms, Standard Contractual Clauses, adequacy decisions or other mechanisms provided for in Articles 45 to 47 GDPR.
6. Data Retention Period
We retain your data for the following periods, in accordance with the storage limitation principle (Art. 5.1.e GDPR):
- Active accounts: For as long as your account remains active in the system.
- Deleted accounts: 90 days after deletion, as a grace period for possible recovery, unless a longer retention period is required by law.
- Inactive accounts: REMOA may review accounts showing prolonged inactivity. At present, automatic deletion of inactive accounts is not applied solely on the basis of inactivity. Where account deletion is initiated, the retention periods applicable to deleted accounts will apply.
- Activity logs: 365 days, after which they are deleted or anonymised in accordance with REMOA's log retention process.
- System technical logs: retained for a shorter operational period, currently up to 30 days, unless a longer retention period is required for security, incident investigation or legal reasons.
- Sessions: 120 minutes of activity; expired sessions are purged after 1 day.
- GDPR data export files: generated export files are stored temporarily and are deleted after 7 days.
After these periods, data will be deleted or irreversibly anonymised, unless retention is required by law.
7. Your Rights
In accordance with the GDPR and the LOPDGDD, you have the following rights:
- Access (Art. 15 GDPR): Obtain confirmation of whether your data is being processed and access a copy thereof.
- Rectification (Art. 16 GDPR): Request the correction of inaccurate or incomplete personal data.
- Erasure (Art. 17 GDPR): Request the deletion of your data ("right to be forgotten").
- Restriction of processing (Art. 18 GDPR): Request the restriction of processing in certain circumstances.
- Portability (Art. 20 GDPR): Receive your data in a structured, commonly used and machine-readable format, and transmit it to another controller.
- Objection (Art. 21 GDPR): Object to the processing of your data in certain circumstances.
- Withdrawal of consent: Where processing is based on consent, you may withdraw it at any time, without affecting the lawfulness of processing based on consent given prior to its withdrawal.
To exercise these rights, contact our DPO at the address indicated in section 1. We may request additional information necessary to confirm your identity where we have reasonable doubts about the identity of the person making the request. We will respond without undue delay and, in any event, within one month of receipt. This period may be extended by two further months where necessary, taking into account the complexity and number of requests. In such cases, we will inform you of the extension and the reasons for the delay within one month of receiving your request.
8. Right to Lodge a Complaint with a Supervisory Authority
If you consider that the processing of your personal data does not comply with the applicable regulations, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD).
https://www.aepd.es
C/ Jorge Juan, 6 — 28001 Madrid, Spain
9. Automated Decision-Making
No decisions are made based solely on automated processing of data, including profiling, that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).
10. Security Measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Art. 32 GDPR). Such measures may include HTTPS/TLS configuration at infrastructure level, secure cookie configuration, security headers, encryption of selected sensitive data where implemented, role-based access control, action auditing, multi-factor authentication (MFA) for administration accounts, session protection measures and regular backups. These measures are reviewed periodically and may be updated to reflect changes in the REMOA Labs platform, infrastructure, applicable risks and legal requirements.
11. Applicable Legislation
This policy has been prepared in accordance with the following regulations:
- Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016 (GDPR).
- Spanish Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
12. Contact
For any queries regarding this policy or the processing of your personal data, contact our Data Protection Officer at: dpo@labs.remoa.net