Privacy Policy
If you’re here, you want to know what we do with your data. Fair enough — our job is to tell you plainly, and yours is to be properly informed.
This page explains who we are, what data we collect, what we use it for, who we share it with, and what you can ask of us at any time. No small print.
Last updated: 24 August 2026
Who we are
The controller of your personal data is:
- Legal name: American School Online OÜ
- Trading as: TEFL Madrid Academy
- Estonian registry code: 17175028
- EU VAT number: EE102830945
- Registered office: Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia
- Establishment in Spain: Calle de Alberto Aguilera 36, Bajo Derecha, 28015 Madrid
- Email: info@tefl-madrid.com
- Phone: +34 628 980 916
We are an Estonian company with our own academy in Madrid, where we deliver in-person training. We also operate american-school.com and exam-madrid.com.
The law we follow
- GDPR — Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data.
- LOPDGDD — Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and guarantee of digital rights, which applies to the activity of our establishment in Spain.
- LSSI-CE — Spanish Law 34/2002 of 11 July on Information Society Services and Electronic Commerce.
What we collect
Only what you give us and what your browsing generates. Nothing else.
- When you request information or fill in a form: your name and surname, email, phone or WhatsApp number, the country you’re interested in, whether you already hold a TEFL certificate, when you want to start, how long you want to stay abroad, and whatever you tell us in the free-text field.
- When you enrol: in addition, the identification, academic and documentary data needed to manage your training, issue your certificate and, where applicable, process your student visa.
- If you comment on the blog: your name, email, IP address and browser details.
- As you browse: IP address, device, browser, pages visited and time spent, through cookies and similar technologies.
We don’t ask for data about your health, political views, ethnic origin, religion or sexual orientation, and we don’t want it. Please don’t enter it in the free-text fields of our forms.
What we use it for, and on what legal basis
This matters more than it looks: each purpose has its own legal basis, and that basis determines what you can ask of us afterwards.
| Purpose | Legal basis |
|---|---|
| Answering your questions about courses, destinations and prices. | Your consent (Art. 6(1)(a) GDPR). |
| Managing your enrolment, your training and your certificate. | Performance of a contract (Art. 6(1)(b) GDPR). |
| Helping you find work and sharing your teaching profile with partner schools. | Your consent (Art. 6(1)(a) GDPR). |
| Invoicing and meeting our tax and accounting obligations. | Legal obligation (Art. 6(1)(c) GDPR). |
| Sending you news and marketing communications. | Your consent, which you can withdraw at any time (Art. 6(1)(a) GDPR and Art. 21 LSSI-CE). |
| Analysing how the site is used so we can improve it. | Your consent through the cookie banner. |
| Preventing spam and protecting the security of the site. | Our legitimate interest in protecting our systems (Art. 6(1)(f) GDPR). |
One clarification that matters: not everything rests on your consent. If you enrol, we process your data to perform the contract we signed with you, and we keep your invoicing because the law requires it. So you can withdraw your consent and we’ll stop sending you marketing — but we can’t delete your academic record or your invoices while those obligations are still running.
How long we keep it
- Enquiries that don’t lead to an enrolment: 1 year from our last contact with you.
- Student data: for the duration of our relationship and, afterwards, for the limitation period of any claims arising from the contract.
- Invoicing and accounting: 7 years under Estonian accounting and tax rules, and 6 years under Article 30 of the Spanish Commercial Code for the activity of our Madrid establishment.
- Blog comments: until you ask us to remove them.
- Mailing list: until you unsubscribe.
Who we share it with
We don’t sell your data. Ever. What we do is work with suppliers who process it on our behalf, purely to provide us with their service, and under a signed processing agreement (Art. 28 GDPR). These are the categories of recipient:
- Web hosting and content delivery network (CDN) providers.
- Contact form handling and delivery tools.
- Email marketing and communication platforms.
- Web analytics and audience measurement services.
- Security and spam filtering services.
- Video and embedded content platforms.
- Instant messaging services, when you are the one who starts the conversation.
- Tax and accounting advisors and financial institutions, for payment and invoicing.
If you want to know exactly which supplier we use in any of these categories, email us at info@tefl-madrid.com and we’ll tell you. You’ll also find the third parties that set cookies listed in our Cookie Policy.
On top of that, if you join one of our programs abroad, we pass on to the academy or centre at your destination the data strictly needed for your training and your placement — always with your prior consent.
We will also disclose your data to courts, public authorities and law enforcement where a legal obligation requires us to.
Transfers outside the European Union
Estonia and Spain are both in the European Economic Area, so moving data between our Tallinn office and our Madrid academy is not an international transfer.
These two are:
- Our programs in Latin America. If you enrol in Costa Rica, Peru, Guatemala, Colombia, Argentina, Mexico or another destination outside the EEA, we send your data to the centre at your destination. The transfer is necessary to perform the contract you asked for (Art. 49(1)(b) GDPR) and we tell you before we make it.
- Some technology suppliers may process data on servers in third countries, mainly the United States. Where that happens, the transfer relies on the EU-US Data Privacy Framework if the supplier is certified, or on the Standard Contractual Clauses approved by the European Commission.
What you can ask of us
Regarding your data, you have the right to:
- Access — ask us what data of yours we hold.
- Rectification — have us correct anything wrong or incomplete.
- Erasure — have us delete it once it’s no longer needed.
- Object — tell us to stop processing where we rely on our legitimate interest.
- Restriction — have us freeze the processing while a disagreement is resolved.
- Portability — receive your data in a format you can take elsewhere.
- Withdraw your consent at any time, without affecting what we lawfully did before.
To exercise any of these, email info@tefl-madrid.com or write to Calle de Alberto Aguilera 36, Bajo Derecha, 28015 Madrid, telling us which right you want to exercise and enclosing a copy of your ID. We’ll reply within one month at the latest.
If you think we haven’t handled your request properly, you can complain to a supervisory authority:
- If you are in Spain: Agencia Española de Protección de Datos — C/ Jorge Juan 6, 28001 Madrid — www.aepd.es
- The authority where our company is registered: Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate) — www.aki.ee
You can also complain to the data protection authority of the country you live in, wherever that is.
Children
Our courses are for people aged 18 and over. Under Article 7 of the Spanish LOPDGDD, processing the data of anyone under 14 requires the consent of their parent or guardian. If we find we’ve received a child’s data without that authorisation, we delete it.
Security
We apply appropriate technical and organisational measures to protect your data against loss, alteration and unauthorised access, in line with Article 32 GDPR. The whole site runs over HTTPS.
That said, let’s be honest: no system connected to the internet is invulnerable. If a security breach affecting your data occurred, we would notify the supervisory authority within 72 hours as required by Article 33 GDPR, and we would tell you directly and without undue delay where the breach posed a high risk to your rights, as Article 34 requires.
Accuracy of your data
The data you give us comes from you, so you’re the one who answers for it being true and up to date. If something changes, tell us and we’ll correct it.
Marketing emails
We don’t spam. We only send you marketing if you’ve given us your express consent, and we always identify it as a commercial communication, as the LSSI-CE requires. Every email carries an unsubscribe link, and you can also ask to be removed by writing to info@tefl-madrid.com.
Cookies
We use our own and third-party cookies to make the site work, to analyse how it’s used and to show you embedded content. You’ll find the full detail and the settings panel in our Cookie Policy.
Changes to this policy
We may update it to reflect changes in the law or in our services. The version in force is always the one published on this page, and the last-updated date appears at the top.
Versión en español: Política de Privacidad.
