last updated 20 September 2025
1. Who we are
mpath (“we”, “our”, or “us”) is a nonprofit organisation based in Spain.
We are committed to protecting your personal data and respecting your privacy.
For any questions, you can contact us at:
📧 info@mpath.tech
2. What information we collect
We may collect and process the following personal data when you interact with our website:
- Donations: When you make a donation, we collect your payment details via our payment processor (Stripe or PayPal), your name, email address, and donation amount.
- Analytics: With your consent, we use Google Analytics to collect anonymous usage data (IP address, browser, device type, pages visited, time spent).
- Contact: If you contact us, we may store your email and the content of your message.
3. How we use your data
We use your data for:
- Processing donations and issuing receipts.
- Communicating with you regarding your support.
- Improving our website through analytics.
- Complying with legal obligations.
4. Legal basis for processing
Under GDPR, we process your data on the following legal bases:
- Consent: For analytics and marketing cookies.
- Contract: To process your donation and provide receipts.
- Legal obligation: For financial/tax reporting.
- Legitimate interest: To ensure website security.
5. Sharing your data
We do not sell or rent your data.
We may share it only with:
- Payment processors (Stripe, PayPal) — to securely process donations.
- Analytics provider (Google Analytics) — only if you consent to cookies.
- Legal authorities — if required by law.
6. International transfers
Google Analytics and Stripe may transfer data outside the EU (e.g. to the USA).
We ensure such transfers are covered by Standard Contractual Clauses (SCCs) and GDPR safeguards.
7. Data retention
- Donation records: kept for 10 years (required by Spanish tax law).
- Analytics data: retained for 14 months in Google Analytics (anonymised).
- Contact messages: retained until resolved, then deleted.
8. Your rights
Under GDPR, you have the right to:
- Access your data.
- Rectify incorrect data.
- Request deletion of your data (“right to be forgotten”).
- Restrict or object to processing.
- Withdraw consent at any time (e.g., via the cookie banner).
- File a complaint with the Agencia Española de Protección de Datos (AEPD).
To exercise your rights, contact us at 📧 [your email address].
9. Cookies & Analytics
We use a cookie consent manager to ask for your permission before placing non-essential cookies.
- Essential cookies: Required for the website to function.
- Analytics cookies (Google Analytics): Used only if you Accept in the cookie banner. These cookies help us understand how visitors use the site.
You can change or withdraw your consent anytime via the cookie banner.
10. Security
We take appropriate technical and organisational measures to protect your data from unauthorised access, loss, or misuse.
11. Changes to this policy
We may update this Privacy Policy from time to time. Changes will be published on this page with a new “last updated” date.