PRIVACY POLICY – OREA APP
(Adapted to GoodBarber – GDPR Compliant)
Last updated: 21/02/2026
1. Data Controller
Data Controller:
Ayuntamiento de Orea
Plaza Mayor, 1
19311 Orea (Guadalajara)
Spain
Email: ayuntamiento@orea.es
The Ayuntamiento de Orea is responsible for the processing of personal data collected through the Orea App and website https://oreate.goodbarber.app.
2. Data Processor – GoodBarber
The Orea App is developed and technically hosted through the platform:
GoodBarber
GoodBarber
SAS GoodBarber
10 rue Pergolèse
75116 Paris
France
GoodBarber acts as Data Processor (Processor under Article 28 GDPR) on behalf of the Ayuntamiento de Orea.
A Data Processing Agreement (DPA) is incorporated into the contractual relationship between the Ayuntamiento de Orea and GoodBarber in accordance with Article 28 of Regulation (EU) 2016/679.
GoodBarber processes data exclusively under the documented instructions of the Ayuntamiento de Orea and implements appropriate technical and organisational measures to guarantee GDPR compliance.
3. What data is collected?
Depending on your interaction with the App, we may collect:
A. Identification Data (provided voluntarily)
Name and surname
Email address
Telephone number
Postal address (if included in a report)
B. User-generated content
Text submitted in forms
Incident reports
Images or photos uploaded
Videos voluntarily submitted
C. Technical Data (collected automatically via GoodBarber infrastructure)
IP address
Device model (anonymous)
Operating system version
Device language
Country and city (approximate, if geolocation enabled)
App usage statistics
D. Geolocation
Only if you expressly authorize location services on your device.
4. Legal Basis for Processing
Data is processed under:
Article 6(1)(e) GDPR – Public interest / Exercise of official authority
Article 6(1)(a) GDPR – Consent (geolocation, notifications, image upload)
Article 6(1)(c) GDPR – Legal obligation
5. How we use your data
Your personal data is used to:
Manage citizen incident reports
Provide municipal information and notifications
Improve public services
Ensure app security and technical performance
Comply with legal obligations
The Ayuntamiento de Orea does not sell or commercially exploit personal data.
6. Data Hosting and Storage
Personal data processed through the App is stored within the European Union.
GoodBarber’s infrastructure is hosted in secure data centres located in the European Economic Area (EEA) and/or through GDPR-compliant providers.
Data is protected by:
HTTPS encryption
Secure cloud hosting
Role-based access control
Authentication mechanisms
Logging and monitoring systems
7. Sub-processors
GoodBarber may use authorized sub-processors necessary for app functionality, such as:
Cloud hosting providers
Apple App Store services
Google Play services
Firebase (analytics infrastructure)
All sub-processors are contractually bound by GDPR-compliant agreements.
GoodBarber maintains an updated list of its sub-processors in accordance with Article 28 GDPR.
8. International Data Transfers
Data is primarily processed within the European Union.
If any data transfer outside the EU occurs (e.g., via Apple or Google services), such transfers are protected by:
Adequacy Decisions
Standard Contractual Clauses (SCCs)
Other lawful transfer mechanisms under GDPR
9. Data Retention
Personal data is retained:
Incident reports: according to Spanish public administration archiving regulations.
Contact data: until resolution of the request.
Technical analytics data: according to GoodBarber/Firebase retention policies.
Geolocation: only when actively submitted and not stored permanently unless part of a report.
After retention periods expire, data is securely deleted or anonymized.
10. Your Rights under GDPR
You have the right to:
Access your data
Rectify inaccurate data
Erase data (where applicable)
Restrict processing
Object to processing
Data portability
Withdraw consent at any time
Requests can be made at:
📧 ayuntamiento@orea.es
We will respond within one month as required by GDPR.
11. Security Measures
The Ayuntamiento de Orea and GoodBarber implement:
Encryption in transit
Secure data centres
Restricted administrative access
Audit and logging controls
Compliance monitoring
No system is completely risk-free, but appropriate safeguards are implemented.
12. Children’s Data
The App is not specifically directed to children under 14 years old.
If minors use the App, parental authorization is presumed under Spanish law (LOPDGDD).
13. Complaints – Supervisory Authority
You may lodge a complaint with:
Agencia Española de Protección de Datos (AEPD)
Calle Jorge Juan, 6
28001 Madrid – Spain
https://www.aepd.es
14. Updates
This Privacy Policy may be updated to reflect legal or technical changes.
Last updated: 21/02/2026
COOKIE & TRACKING POLICY (GoodBarber Integration)
The Orea App may use cookies and similar technologies managed by GoodBarber and its infrastructure providers.
Types used:
Strictly Necessary Cookies
Required for authentication and app functionality.
Performance & Analytics Cookies
Used for anonymous usage statistics and performance monitoring (e.g., Firebase analytics).
The App does NOT use advertising or profiling cookies.
Users may manage tracking preferences through their device settings.

