Skip to main content
Eurmes
  • Home
  • Values
  • Contact

Data protection

Privacy Policy

This policy explains what personal data Eurmes processes, what for, for how long and who else sees it. It is reviewed periodically and whenever a new feature processes user data.

Version 2.0 · August 12, 2026

The short version

This summary does not replace the full text, but it does not contradict it either. If you are in a hurry, this is enough:

  • To have an account we ask for an email address and a password. Nothing else is required.
  • Your email is stored encrypted, and your password is not stored in any readable or recoverable form.
  • We do not store your exercise answers, your pronunciation scores, which lessons you have viewed or what you search for. We do store your progress by topic.
  • Your voice is never stored, by us or on our servers: it is transmitted, evaluated and gone.
  • We use no third-party analytics, no advertising and no commercial profiling. We do not sell data.
  • Your IP address is not linked to your account: server logs store it masked and delete it after 14 days.
  • Artificial intelligence providers receive no identifier of yours: not your email, not your name, not your account ID.
  • You can request access, rectification, portability or erasure by writing to hola@eurmes.eu . We answer within 30 days at most.

Data controller

The controller of your personal data is:

Controller: Michael Laudrup Luis González.

Tax ID (NIF): 45980092X.

Project name: Eurmes.

Address for communications: Passatge Còrsega, 7, 08026 Barcelona, Spain.

Contact email: hola@eurmes.eu .

Website: https://eurmes.eu .

Eurmes is a project developed and run by its owner as a natural person. It is not currently provided through a company. These identification details will be updated if that changes.

Scope of this policy

This policy applies to the website https://eurmes.eu and to the Eurmes language-learning and cultural-integration platform.

The platform lets you create an account, access lessons and exercises, practise pronunciation and save your learning progress. Eurmes has no social features today: there are no comments, no likes, no posts and no profiles visible to other people.

Data you give us

Only your email address and password are required. Everything else is data you choose to fill in, and you can leave it blank or delete it from your profile at any time.

  • Email address. Stored encrypted and with technical measures intended to prevent its unnecessary exposure.
  • Password. Not stored in any readable or recoverable form: it is stored as a hash, and we prevent you from reusing a previous one.
  • Public name, avatar, biography, native language, learning languages, interests and visual theme.
  • Region. You pick it from a list; it is not inferred from your IP address.
  • Learning progress by topic and level.
  • Favourite content lists and list subscriptions.
  • Anything you write to us by email.

Data we do NOT collect

This list is as much a part of this policy as the previous one. These are things a learning platform could reasonably store and that Eurmes has decided not to store:

  • The answers you type into exercises and their correction.
  • Your pronunciation exercise scores.
  • Your voice audio, in any form.
  • The history of lessons you have viewed.
  • What you search for inside the platform.
  • Your real name, your age or your date of birth.
  • Payment data: there are no payments on the platform today.
  • Your IP address linked to your account or to your browsing.
  • Special categories of data: they are neither requested nor used in any feature of the service (health, ethnic origin, political opinions, beliefs, trade union membership, genetic data or sexual orientation).
  • Third-party analytics, advertising cookies and commercial profiling of any kind.

Your voice and the microphone

Pronunciation exercises need to hear you. It is the most sensitive part of the service, which is why it is explained separately.

Your voice is transmitted to be evaluated and is not stored, neither on our systems nor on those of the recognition provider.

The evaluation can happen while you speak or on a short recording sent when you finish. In both cases the audio is processed and discarded.

The transcript of what you said is used to correct you on screen and is likewise not retained.

The recognition provider is Microsoft Azure Speech, with the processing region located in Ireland: your voice does not leave the European Economic Area.

The legal basis is performance of the contract (Art. 6(1)(b) GDPR), not consent: evaluating pronunciation is the service you asked for, not an extra.

Eurmes does not use voice for biometric identification, nor to uniquely identify or authenticate a person: what is assessed is how a sentence sounds. Were such a use ever proposed, the data would change category and would require explicit consent, a prior impact assessment and an update to this policy before being switched on.

If you do not grant microphone permission to your browser, pronunciation exercises will not work; the rest of the platform will.

Data that is collected automatically

Running an internet service generates technical records. These are the ones that exist and what they are for:

Web server access log. Stores the masked IP address — incomplete, so that the original cannot be reconstructed — the browser and the address visited. Retained for 14 days.

Application logs. Technical traces of operation and errors, retained for a limited period and deleted through automatic rotation mechanisms.

Abuse-protection counters. To curb mass access attempts, requests are counted per origin. The originating address is not retained and the counters are ephemeral.

Security audit log. Records permission changes and account deletions, with the data needed to evidence who did what and why. It is retained for as long as necessary to demonstrate compliance and to establish or defend legal claims; the specific period is under review and will be published here once set.

Open sessions. For each session we store the browser, the operating system, the device type, the approximate country and city it was started from, and the date of last activity. This is what lets you see where your session is open and close it.

How we know the city without keeping your IP

When you log in we may derive an approximate location from the IP address, to help you recognise a session that is not yours. The IP address used is not sent to any external service and is not retained: only the result is recorded, for example "Spain · Barcelona".

The location is approximate by nature: it may point to your internet provider’s city rather than yours. It is there to help you spot an unfamiliar session, not to locate you.

What we use your data for

We process your personal data for these purposes only:

  • Creating your account, authenticating you and keeping your session open.
  • Giving you access to lessons, exercises and learning tools.
  • Saving your progress and preferences so the platform behaves as you expect.
  • Evaluating your pronunciation when you use the voice exercises.
  • Sending you the essential account emails: sign-up verification, password recovery and security notices.
  • Answering what you write to us and handling requests to exercise your rights.
  • Keeping the platform secure: preventing unauthorised access, brute force and abuse.
  • Diagnosing errors and keeping the service running.
  • Complying with legal obligations where applicable.

Legal bases and retention periods

Each processing operation rests on a legal basis under Art. 6 GDPR. This table says which one, and how long the data is kept in each case.

Purposes, legal bases and periods

Purpose Legal basis Retention
Account, authentication and sessionPerformance of contract (Art. 6(1)(b))For as long as the account exists. Sessions expire automatically
Access to lessons and exercisesPerformance of contract (Art. 6(1)(b))For as long as the account exists
Learning progress and preferencesPerformance of contract (Art. 6(1)(b))For as long as the account exists
Pronunciation evaluation (voice)Performance of contract (Art. 6(1)(b))Not retained: the audio is not stored at any point
Unverified partial sign-upPre-contractual measures (Art. 6(1)(b))Deleted automatically when the verification code expires
Account and security emailsPerformance of contract (Art. 6(1)(b))The duration of the send; only the outcome is logged
Rate limiting and anti-fraudLegitimate interest (Art. 6(1)(f))Very short period; deleted automatically
Web server access logLegitimate interest (Art. 6(1)(f))14 days, with the IP address masked
Application technical logsLegitimate interest (Art. 6(1)(f))Limited period, with automatic rotation
Audit of permissions and deletionsLegitimate interest (Art. 6(1)(f)): traceability, security and defence against claimsFor as long as necessary for those purposes; specific period under review
Handling rights requests and enquiriesLegal obligation (Art. 6(1)(c))As long as needed to handle it and to evidence that it was handled

Who we share data with

These are the providers involved in delivering the service today, with what each one receives and where it processes it. If a new one were added, this table would be updated.

Providers that receive data

Provider What it receives Where it is processed
OVHcloudHosting of the service: this is where the application, the database and the platform files liveEuropean Union (France)
Microsoft Azure SpeechYour voice audio and its transcript, without storing themIreland — inside the EEA
BrevoYour email address and the message content, for account emailsEuropean Union
ElevenLabsTeaching texts that are turned into audio. It receives no user dataUnited States
Google (Gemini)Instructions for generating teaching contentUnited States
OpenAIInstructions for generating teaching contentUnited States
AnthropicInstructions for generating teaching contentUnited States
Mistral AIInstructions for generating teaching contentEuropean Union (France)
Alibaba Cloud (DashScope)Instructions for generating teaching content. Excluded from any feature whose prompt may contain user-written textChina
Fish AudioTeaching texts that are turned into audio. It receives no user dataChina

What we never do with your data

We do not sell personal data, we do not pass it to advertising intermediaries and we do not use it to build commercial profiles.

Data may be disclosed to authorities or courts where there is a legal obligation or a valid request, and no further than that request demands.

If the project were ever restructured or transferred, the data would remain subject to this policy and you would be informed before any change of controller.

Artificial intelligence

Eurmes uses language models to write and adapt teaching material: lessons, exercises, examples and explanations. That material is generated before you ever see it and does not depend on your data.

No AI provider receives any identifier of yours: we do not send them your account ID, your email or your name. Only the instruction needed to generate the content travels. This is a deliberate data-minimisation measure that is maintained when new providers are added.

There is one exception worth knowing about: exam exercise personalisation includes in the prompt the text you wrote to request it. That text is personal data even though the provider does not know who you are. That is why this feature is limited to providers located in countries with recognised safeguards.

The text-to-speech you hear in lessons converts teaching material, not anything of yours.

Eurmes does not use your data to train artificial intelligence models, and contracts generation services under terms that exclude the use of submitted content for training purposes.

Content generated with AI assistance is for educational purposes and may contain errors or inaccuracies. Synthetic audio is identified as such in the player itself.

No decision with legal or similarly significant effects on you is taken automatically. Eurmes’s AI writes study material; it does not score you, classify you or decide anything about your account.

International transfers

Some of the providers in the table above are outside the European Economic Area. What matters is what leaves, and under what safeguard.

Your voice does not leave the EEA: the processing region is set to Ireland.

For providers located in the United States, transfers rely on the mechanisms set out in Chapter V GDPR — the EU-US Data Privacy Framework or, failing that, European Commission standard contractual clauses — whose validity is reviewed periodically.

Providers located in China (Alibaba Cloud and Fish Audio) receive teaching material only. Since China has no adequacy decision, they are excluded from any feature whose prompt could contain user-written text.

If sufficient safeguards ceased to exist for a provider, we would stop using it or replace it with one that does offer them.

Cookies and browser storage

Eurmes uses no analytics, advertising or third-party cookies. The public site (eurmes.eu) works without cookies.

Inside the platform, only technical cookies necessary to maintain and protect your session are used.

In addition, some of your preferences (such as the visual theme or the interface language) are stored in your browser’s local storage and are not sent to any server.

The detail is in the Cookie Policy.

How long we keep your data

The specific periods are in the legal bases table. The general rule is that your account data lives for as long as the account exists and disappears when you delete it.

Technical logs have their own short periods and expire on their own, with nobody intervening.

Deleting your account

You can request deletion of your account by writing to hola@eurmes.eu . It is a real deletion, not a deactivation.

When the account is deleted, your sessions are closed and your profile, progress, favourites, permissions, avatar and access credentials are removed, without prejudice to data that must be retained temporarily by legal obligation or for the establishment, exercise or defence of legal claims.

There is one exception: the audit log keeps a record of the deletion itself, including the email address, so that we can evidence that the erasure took place. It is retained for as long as necessary for that purpose and to defend against claims.

Anti-abuse counters tied to your email address may survive for a short period after deletion and are removed automatically.

Security

Among the measures applied: passwords are stored as hashes and never in readable form; sensitive data is stored encrypted; traffic between your browser and the service is encrypted; access to the data is restricted and authenticated; there are measures against mass access attempts; and development environments are separated from production, with no real user data.

The devices used to administer the service are encrypted.

No internet-connected system can guarantee absolute security. Protect your credentials and use a password you do not reuse elsewhere.

Data breaches

If a breach affecting personal data occurred, we would assess the risk and notify the Spanish Data Protection Agency within 72 hours of becoming aware of it, where the law requires it.

If the breach posed a high risk to your rights, we would tell you directly and without undue delay, explaining what happened and what you can do.

Minors

You must be at least 18 to create an account. Eurmes is not aimed at minors.

We neither ask for nor store a date of birth, so we do not verify age beyond that declaration.

If we learn that an account belongs to a minor without a sufficient legal basis, we will delete the data and deactivate the account. If you are a parent or guardian and believe this is the case, write to us at hola@eurmes.eu .

Your rights and how to exercise them

You have the rights set out in Articles 15 to 22 GDPR:

Today they are exercised by writing to hola@eurmes.eu from your account address, or from any other if you help us verify it is you.

We answer within one month of the request. If the matter were especially complex, the law allows a further two months, and in that case we would tell you within the first month and explain why.

Exercising a right is free. We will only ask for identity verification where reasonably necessary, and we will never ask for an identity document for something that does not require one.

  • Access: know what data of yours we process and get a copy.
  • Rectification: correct anything wrong or incomplete.
  • Erasure: have your data deleted.
  • Objection: object to processing based on legitimate interest.
  • Restriction: ask us to freeze a processing operation while a disagreement is resolved.
  • Portability: take your data away in a machine-readable format.
  • Withdrawal of consent, where processing is based on it, without affecting what was done before.
  • Not to be subject to automated decisions with legal or significant effects. There are none at Eurmes.

Complaints

If you believe we process your data incorrectly, you can complain to the supervisory authority. You do not have to write to us first, although we would like the chance to put it right.

In Spain the competent authority is the Agencia Española de Protección de Datos: https://www.aepd.es

Changes to this policy

Every version of this document carries a number and a date in its header, and changes are recorded in the public legal changelog.

If a change materially affects your data, we will announce it on the platform before it takes effect, not after.

Contact

For anything about this policy or about your data: hola@eurmes.eu

Write in Spanish, English, French or Italian; we will reply in any of the four.

Legal index
Eurmes logo

Eurmes is a European social network designed to bring people closer together, connect cultures, and learn languages.

Navigate

  • Home
  • Values
  • Contact
  • Access

Legal

  • Legal notice
  • Privacy policy
  • Cookie policy
  • Terms and conditions

Transparency

  • How we use AI
Inspired by Europe Diversity, respect and real connection between cultures. More info here
© 2026 Eurmes. All rights reserved.
  • Barcelona, Spain
  • v0.0- Alpha Versión
HomeValuesContactAccess