Privacy Policy
Last updated: June 25th, 2026
This Privacy Policy explains, in a clear and layered manner, how SERVICE CLUB ACQUISITION AND DEVELOPMENT OF LABOR TALENT, S.L. ("Service Club", "we", "us" or "our") collects and processes personal data in connection with the Service Club websites, platform environments, mobile or web applications, operational channels and service verticals, including Jobs, Academy, Micro Academy, Perks, Shop, Marketplace, Services and any related recruitment-support, training, marketplace, customer, supplier, security, support and commercial communications.
This Policy is intended to satisfy the information obligations under Articles 12, 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation or "GDPR"), Spanish Organic Law 3/2018 on the Protection of Personal Data and guarantee of digital rights ("LOPDGDD"), Spanish Law 34/2002 on Information Society Services and Electronic Commerce ("LSSI-CE"), and the transparency criteria published by the Spanish Data Protection Agency ("AEPD") and the European Data Protection Board ("EDPB"). It should be read together with any specific privacy notice, cookie notice, consent wording, data processing agreement, Client-specific notice, recruitment flow, Academy notice or platform notice shown to you at the point of collection.
1. Who is responsible for your personal data?
Controller: SERVICE CLUB ACQUISITION AND DEVELOPMENT OF LABOR TALENT, S.L., with Spanish Tax ID (CIF) B67127522.
Registered office: Avenida Diagonal 601, 8th Floor, 08028 Barcelona, Spain.
Brand and platform: Service Club.
Contact for data protection matters: privacy@serviceclub.com, or any other specific contact channel indicated in the relevant service notice, order form, training notice, platform flow or email disclaimer.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es if you consider that your personal data have not been processed in accordance with applicable data protection law.
Service Club may process personal data in different GDPR roles depending on the processing scenario. In many direct platform, account, Jobs, Academy, marketing, support, security and compliance activities, Service Club acts as an independent controller. In certain Client-nominated training, reporting, document-management or bespoke operational support activities, Service Club may act as processor on the Client's documented instructions, in which case an Article 28 GDPR data processing agreement must apply. Where Service Club and a Client jointly determine the purposes and essential means of a specific processing operation, the parties will assess whether an Article 26 GDPR joint-controller arrangement is required and will make the essential content of the arrangement available to affected data subjects where required.
This Privacy Policy mainly describes the processing carried out by Service Club as controller. Where a Client, employer, fleet operator, training customer or other business partner acts as controller, that party remains responsible for providing its own privacy information, defining its legal basis, answering rights requests, setting retention periods and complying with its own employment, labour, tax, health and safety, AI, electronic communications and data protection obligations.
2. Who does this Policy apply to?
This Policy applies to the following categories of individuals, without prejudice to any more specific notice that may be provided in a particular Service Club vertical or user flow:
- 2.1. website visitors and users of public pages, landing pages, forms, content, events, newsletters or online resources;
- 2.2. drivers, couriers, delivery workers, warehouse workers, fulfilment workers, forklift operators, trainees, candidates, applicants and other logistics workers who register, apply, train, purchase, interact with or are introduced through Service Club;
- 2.3. users of Jobs, including individuals who apply to specific Client opportunities or who submit spontaneous/general applications for future opportunities;
- 2.4. Academy and Micro Academy participants, including individuals nominated by a Client, enrolled directly by Service Club, trained by Partner Trainers or participating in classroom, virtual, VR, behind-the-wheel, AI-supported or blended training;
- 2.5. users of Perks, Shop, Marketplace, Services or equivalent current or future Service Club verticals;
- 2.6. representatives, employees, contractors and professional contacts of Clients, prospective Clients, suppliers, partners, trainers, venues, payment providers, technology providers and other B2B counterparties;
- 2.7. people who contact us through email, telephone, WhatsApp, Telegram, SMS, web forms, in-app channels, social media, job boards, referral programmes, events, support channels or complaints channels;
- 2.8. people whose personal data are included in documents, communications, invoices, contracts, audit records, fraud or incident reports, legal claims or similar corporate records.
The Service Club services are primarily intended for adults and for professional, recruitment, training, logistics and B2B contexts. The platform is not directed at children.
3. What data we collect
We collect personal data directly from you when you browse the website, register, create an account, complete a profile, apply for an opportunity, upload documents, answer screening questions, attend training, complete a quiz, contact support, purchase or use a service, subscribe to updates, communicate with us or otherwise interact with the Service Club platform or team.
We may also receive personal data from Clients, employers, fleet operators, training customers, Partner Trainers, driving schools, instructors, venues, service providers, payment providers, job boards, social media platforms, referral sources, business partners, public sources, group entities, fraud-prevention sources, analytics tools, security tools and other third-party channels where the sharing is lawful and relevant to the service.
Where a Client nominates you for training, asks us to support recruitment or onboarding, or requests a Client-specific opportunity flow, the Client should provide you with its own privacy information where required. Service Club may provide additional layered information before collecting or sharing data for a particular opportunity, training, VR/telematics module, AI-supported learning feature, document collection process, consent-based activity or marketing communication.
If you provide personal data about another person, you must ensure that you are authorised to do so and that the other person receives any privacy information required by law, unless an exemption applies.
4. What categories of personal data do we process?
Depending on the relevant service, channel, country, Client arrangement and user type, Service Club may process the following categories of personal data. We apply the principles of data minimisation and purpose limitation and do not request data that are not necessary for the relevant service or legal purpose.
- 4.1. Identification and contact data: name, surname, email address, telephone number, postal address, preferred language, country, city, profile identifiers, account identifiers and similar contact details.
- 4.2. Account and authentication data: username, password or authentication tokens, account status, account settings, profile completion, consents, opt-ins/opt-outs, login records, platform permissions, roles and user activity.
- 4.3. Candidate and Logistics Worker profile data: CV or profile details, work history, delivery/driving/warehouse experience, availability, preferred roles, location or operating area, languages, training history, licenses, vehicle-related information, certifications, answers to screening questions, interview availability, application status, onboarding status and communication history.
- 4.4. Document and verification data: copies, extracts, metadata or status information relating to identity, right-to-work, driving license, vehicle, insurance, certifications, professional qualifications or other documents where required for a specific opportunity, onboarding support, training, fraud prevention or legal compliance purpose. Unless expressly justified, Service Club should not collect excessive identity documents, criminal record information, health data or special category data.
- 4.5. Academy and training data: enrolment records, attendance, completion status, training scores, quiz answers, certificates, learning progress, training feedback, incident records, trainer notes, content interaction data, course preferences and learning support information.
- 4.6. VR, telematics, attention-related and learning analytics data: where relevant to a specific training module, data generated by VR devices, simulation tools, telematics, attention-related indicators, interaction logs, performance metrics, movement or device signals, knowledge checks and AI-supported learning features. These data are processed only where necessary, proportionate and explained in the applicable training notice. Eye-movement or attention-related data are not used for biometric identification unless a specific, separate and lawful configuration is implemented and assessed.
- 4.7. AI-supported tool data: prompts, outputs, recommendations, scores, flags, summaries, classifications, matching-support signals, learning analytics, call-center scripts, automated reminders or other outputs generated or assisted by digital or AI-supported systems. Unless clearly stated otherwise, these tools support operations and do not make final hiring, dismissal, disciplinary, work allocation or legally significant employment decisions.
- 4.8. Client and B2B contact data: name, surname, professional email, telephone number, job title, company, department, role, authority to sign, business requirements, commercial preferences, meeting notes, proposals, order forms, contracts, billing contacts, support tickets and relationship history.
- 4.9. Payment, billing and transaction data: invoicing details, payment status, order history, subscription status, transaction references, billing address, VAT/tax details, payment provider status information, debt management records and accounting records. Card or payment instrument details may be processed directly by payment providers such as Stripe, Billie or equivalent providers under their own terms and privacy notices.
- 4.10. Communications data: emails, telephone notes, call or message metadata, WhatsApp/Telegram/SMS/in-app communications, support requests, complaints, feedback, event registrations, consent records and opt-out records.
- 4.11. Technical, usage and security data: IP address, device identifiers, browser type, operating system, logs, timestamps, pages visited, actions taken, referral URLs, cookie identifiers, local storage data, approximate location derived from IP or user settings, access logs, API logs, security alerts, fraud signals and diagnostic data.
- 4.12. Marketing and preference data: newsletter subscriptions, commercial preferences, event attendance, campaign interactions, unsubscribe records, cookie choices, consent records and similar preference information.
- 4.13. Legal, compliance and risk data: records of rights requests, complaints, incidents, suspected fraud, misuse, abusive conduct, forged documents, duplicate profiles, circumvention, safety concerns, legal claims, authority requests, audit evidence and compliance documentation.
Special category data, criminal offence data and high-risk data
Service Club does not intend to collect or process special categories of personal data under Article 9 GDPR, criminal offence data under Article 10 GDPR, or other high-risk data unless this is strictly necessary, lawful, proportionate and supported by appropriate safeguards. Examples include health data, biometric data for unique identification, trade union membership, criminal record information or similar sensitive information.
VR, telematics, eye-movement, attention-related and learning analytics data are used for training, support, quality, safety awareness and learning purposes. They should not be processed as biometric identification data unless the relevant technology is specifically configured to identify or authenticate an individual through biometric characteristics. Where data could reveal health, fatigue, behavioral or other sensitive inferences, Service Club will apply stricter minimisation, transparency, access control, retention and human review safeguards.
Data categories by data subject type
| Data subject type | Typical data | Main use |
|---|---|---|
| Website visitors | IP address, cookie identifiers, device/browser information, pages visited, forms submitted, consent settings. | Website operation, analytics where consented/allowed, security, cookie management, responding to forms. |
| Logistics Workers / candidates | Contact details, profile, CV, experience, licences, availability, location, application status, documents where necessary, communications. | Jobs, recruitment-support, matching, onboarding support, fraud prevention, Client sharing where lawful. |
| Trainees / Academy users | Enrolment, attendance, training progress, scores, certificates, feedback, VR/telematics/learning analytics where applicable. | Training delivery, reporting, certificates, safety awareness, quality, support, Client reporting where agreed. |
| Client representatives | Professional contact details, job title, company, authority, requirements, contracts, billing and support data. | B2B relationship, proposals, contracts, billing, service delivery, legal compliance. |
| Suppliers / trainers / partners | Professional contact, contract, service, payment, compliance and communications data. | Supplier management, training delivery, payments, compliance, audit and claims. |
| Complainants / rights requesters | Identity/contact data, request details, supporting evidence, response records. | Handling requests, complaints, compliance evidence and legal defence. |
5. How we use your data
The table below describes the main processing purposes, examples of data used and legal bases. More than one legal basis may apply depending on the specific user type, service, Client arrangement and country. Where we rely on legitimate interests, we balance those interests against the rights and freedoms of the affected individuals and apply safeguards such as transparency, minimisation, opt-out mechanisms, access controls and retention limits.
| Purpose | Description | Data examples | Legal basis |
|---|---|---|---|
| Website and platform operation | To operate websites, landing pages, forms, accounts, login areas, platform functions, user profiles, service flows and support tools. | Contact, account, technical, usage, cookie and security data. | Contract or pre-contractual steps, where the service is requested by the user; legitimate interests in operating and securing the platform; legal obligation where applicable. |
| Jobs, recruitment-support and matching | To receive applications, create profiles, identify relevant opportunities, communicate with Logistics Workers, share relevant profile data with Clients, manage interview/onboarding flows, support document collection, prevent duplicate profiles and manage lead status. | Candidate profile, contact, availability, experience, licences, documents where necessary, communications, application status and Client interaction data. | Pre-contractual steps or contract with the user; legitimate interests in operating recruitment-support services; Client legitimate interests in evaluating candidates; consent where legally required for specific sharing or optional features; legal obligation where applicable. |
| Spontaneous applications and future opportunities | To keep profiles available for future roles, similar opportunities, training or Client needs where the user has applied generally or has asked to be considered for future opportunities. | Profile, CV, preferences, availability, location, communication history and consent/objection records. | Consent where the applicable flow requires it; legitimate interests in managing a talent pool, subject to transparency and the right to object; pre-contractual steps where the user asks to be considered. |
| Academy and Micro Academy training | To enrol participants, deliver classroom, virtual, VR, behind-the-wheel, AI-supported or blended training, manage attendance, issue certificates/reports, support trainers, ensure quality and handle complaints. | Enrolment, attendance, scores, learning progress, certificates, trainer notes, feedback, technical and communications data. | Contract or pre-contractual steps; legitimate interests in delivering and improving training; Client legitimate interests where training is Client-nominated; legal obligation where applicable; consent for optional or legally consent-based features. |
| VR, telematics and attention-related learning | To provide simulations, learning analytics, progress assessment, content adaptation, safety training, technical support and agreed reporting. | VR/session data, device logs, interaction data, performance metrics, attention-related indicators, learning analytics and reports. | Contract or pre-contractual steps; legitimate interests in effective training and safety awareness; consent where required by law or for optional features; explicit consent or another Article 9 condition if special category data are processed. |
| AI-supported operational and learning tools | To support matching, recommendations, reminders, call-centre scripts, learning analytics, content adaptation, quality assurance, fraud flags and operational efficiency. | Profile data, application data, training data, communication metadata, usage data, prompts/outputs and quality signals. | Contract or pre-contractual steps; legitimate interests in efficient and accurate service delivery, security and quality; consent where required; legal safeguards under Article 22 GDPR where solely automated legally significant decisions are involved. |
| Perks, Shop, Marketplace and partner services | To manage orders, benefits, offers, third-party services, marketplace interactions, support, fulfilment, disputes and communications. | Account, contact, order, delivery, payment, support, preference and partner interaction data. | Contract or pre-contractual steps; legitimate interests in managing the marketplace and preventing fraud; consent for optional marketing; legal obligation for invoicing/tax. Where the user acts as a consumer in connection with the purchase of goods or services, processing is also carried out to ensure compliance with mandatory consumer protection rights. |
| Client, B2B and supplier relationship management | To manage enquiries, proposals, order forms, contracts, enterprise accounts, service delivery, renewals, billing, support, complaints, relationship history and professional communications. | Professional contact details, company data, job title, authority, communications, contract data, billing contacts and support records. | Contract or pre-contractual steps; legitimate interests under Article 6(1)(f) GDPR and, in Spain, Article 19 LOPDGDD for professional contact data; legal obligation where applicable. |
| Payments, invoicing and accounting | To process payments, reconcile transactions, issue invoices, manage receivables, administer enterprise payment terms, handle chargebacks and comply with tax/accounting obligations. | Billing data, payment status, order history, tax details, payment provider references, accounting and debt management data. | Contract; legal obligation; legitimate interests in fraud prevention, debt recovery and financial control. |
| Operational communications | To contact users about registrations, profile completion, applications, interviews, document collection, training, reminders, account security, service updates, support, complaints and fraud prevention. | Contact details, account data, application/training status, communication history and preference data. | Contract or pre-contractual steps; legitimate interests in service administration and security; legal obligation where applicable. Electronic communications will comply with LSSI-CE. |
| Marketing and commercial communications | To send newsletters, offers, event invitations, service updates or similar commercial information about Service Club products and services. | Contact data, professional contact data, preferences, consent/opt-out records, campaign interactions and segmentation data. | Consent; or legitimate interests and LSSI-CE soft opt-in where legally available for similar products/services to existing customers or professional contacts, always with an easy opt-out. |
| Security, fraud prevention and platform integrity | To detect and prevent false profiles, duplicate accounts, forged documents, impersonation, unauthorised access, scraping, abusive communications, circumvention, payment fraud, cybersecurity incidents and violations of platform rules. | Account, documents where necessary, technical logs, fraud signals, communications, incident reports and audit evidence. | Legitimate interests in security, fraud prevention and legal defence; legal obligation where applicable. |
| Legal compliance, claims and authorities | To comply with laws, respond to rights requests, cooperate with authorities, maintain mandatory records, manage audits, establish, exercise or defend legal claims and preserve evidence. | Relevant account, contract, communication, transaction, security, incident, rights request and compliance records. | Legal obligation; legitimate interests in legal defence and compliance management. |
5.1. Consent and withdrawal of consent
Where Service Club relies on consent, the consent request will be specific, informed, freely given and unambiguous. Consent will not be bundled into general terms and conditions where separate consent is required. Examples may include optional marketing, non-essential cookies, certain partner offers, specific voluntary data sharing, or optional training/technology features where consent is the appropriate legal basis.
You may withdraw consent at any time through the mechanism provided in the relevant flow, by using an unsubscribe link, by changing cookie settings where available, or by contacting privacy@serviceclub.com. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal and does not prevent Service Club from continuing processing where another legal basis applies, such as legal obligation, contract performance, security, fraud prevention or legal claims.
Consent is not used as a blanket authorisation to share data with all Clients or partners for any purpose. Data sharing must always be linked to a defined purpose, lawful basis, recipient category and minimised dataset.
5.2. Jobs, recruitment-support and Client sharing
In the Jobs context, Service Club operates a platform and managed recruitment-support infrastructure that may introduce, filter and support the flow of Logistics Worker profiles to Clients. Service Club does not act as the final employer, hiring company, temporary work agency, payroll provider, transport operator, immigration adviser or final decision-maker unless expressly stated in a separate written arrangement.
When you apply for a specific Client opportunity, Service Club may process and share relevant profile, contact, experience, availability, location, document status, training status, interview or onboarding information with the Client or its authorised recipients where necessary for recruitment, evaluation, onboarding support, training, fraud prevention, compliance or operational purposes. The specific Client or recipient category should be made sufficiently clear in the relevant application or sharing flow.
When you submit a spontaneous or general application, Service Club may keep your profile for future opportunities where there is an appropriate legal basis and transparency information. You may object to processing based on legitimate interests or withdraw consent where consent applies.
Clients that receive candidate or Logistics Worker data are normally independent controllers for their own recruitment, onboarding, employment, payment, workplace, safety, tax and legal-compliance decisions. They must provide their own privacy information where required and must not use Service Club data for unrelated marketing, resale, excessive profiling, discriminatory filtering or purposes incompatible with the original sharing.
Service Club may support document collection or onboarding workflows, but unless expressly agreed, it does not guarantee the authenticity, validity or legal sufficiency of documents, licences, certifications, right-to-work evidence or Client-side employment decisions. Where Service Club acts only on documented Client instructions, an Article 28 GDPR data processing agreement must apply.
5.3. Academy, Micro Academy, VR, telematics and AI-supported training
Service Club may provide or coordinate classroom, virtual, VR, behind-the-wheel, AI-supported, blended and other training services. Training may be delivered directly by Service Club, through Partner Trainers, training providers, instructors, venues, LMS providers, VR providers, telematics providers or other approved service providers.
Academy processing may include enrolment, identity/contact information, attendance, course completion, scores, quizzes, certificates, learning progress, feedback, incident reports, trainer notes, content interaction data, technical logs and reporting to the relevant Client where training has been commissioned or nominated by that Client.
VR, telematics, eye-movement, attention-related indicators and learning analytics must be used transparently, proportionately and only for defined training, safety awareness, quality, support, technical, reporting or compliance purposes. They must not be repurposed for hidden surveillance, medical assessment, biometric identification, disciplinary measures or final employment decisions unless a separate lawful basis, transparency notice, necessity assessment and applicable safeguards have been implemented.
AI-supported training features may assist with content adaptation, feedback, recommendations, knowledge checks, summaries, risk flags or learning analytics. Unless clearly stated otherwise in a specific notice, such features are support tools and do not make final hiring, dismissal, work allocation, disciplinary or legally significant employment decisions. If any tool is used in a manner that produces legal or similarly significant effects, the relevant controller must comply with Article 22 GDPR and any applicable AI, labour, non-discrimination and fundamental-rights safeguards, including meaningful human involvement where required.
Where training data are reported to a Client, the report should be limited to information that is adequate, relevant and necessary for the agreed training or compliance purpose, such as attendance, completion, certificate status or agreed performance indicators. Raw VR, telematics, eye-movement or detailed behavioural data should not be disclosed unless strictly necessary, disclosed in advance and supported by an appropriate legal basis and safeguards.
5.4. Electronic communications: email, telephone, SMS, WhatsApp, Telegram and in-app messages
Service Club may contact you through email, telephone, SMS, WhatsApp, Telegram, in-app notifications or similar channels for operational purposes, including registration, profile completion, applications, interviews, document collection, training enrolment, training reminders, support, account security, service updates, complaints, fraud prevention and other communications necessary or useful for the service you have requested or the process in which you are participating.
Operational communications are not the same as unrelated marketing. Marketing or promotional communications will be sent only where Service Club has a valid legal basis and complies with the LSSI-CE, including any consent or soft opt-in requirements and the obligation to provide a simple and free means to object or unsubscribe.
Where we first contact you through WhatsApp, Telegram, SMS or similar channels, the initial message should identify Service Club, the purpose of the contact and a link or reference to the relevant privacy information. Sensitive documents should not be requested or exchanged through insecure channels where a more secure alternative is reasonably available.
5.5. Cookies and similar technologies
Service Club websites and platform environments may use cookies, pixels, SDKs, local storage, device identifiers and similar technologies for technical, preference, analytics, advertising, security, fraud-prevention and service-improvement purposes.
Cookies or similar technologies that are strictly necessary for the website or service requested by the user may be used without consent where permitted by law. Non-essential analytics, advertising, behavioural, personalisation or similar technologies will be used only where the applicable consent or legal requirements are met.
Detailed information on cookie categories, providers, purposes, duration and settings should be provided in a separate Cookie Policy and/or consent management platform. Users should be able to accept, reject or configure non-essential cookies in a granular and accessible manner, and to withdraw or modify consent as easily as it was given.
5.6. Data sharing
We do not sell, rent, or trade your personal data. We share your information, where necessary and lawful, with the following recipient categories:
- Clients, potential employers, fleet operators, companies, training customers, perks providers, or business partners involved in a specific opportunity, recruitment, training, onboarding, Perks, Shop, Marketplace or service flow;
- Partner Trainers, training providers, driving schools, instructors, venues, LMS providers, VR/telematics providers and other parties involved in delivering Academy or Micro Academy services;
- technology and service providers, including hosting, cloud, cybersecurity, analytics, CRM, communications, call-center, support, payment, billing, document, e-signature, job board, marketing, consent-management and platform providers, acting as processors or independent controllers depending on the service;
- payment providers such as Stripe, Billie or equivalent providers where payment, financing, billing, credit assessment, fraud prevention or transaction management is involved;
- social media platforms, job boards, referral partners, advertising networks or event platforms where users interact with us through those channels or where campaigns are lawfully conducted;
- professional advisers, auditors, insurers, banks, investors, group entities and corporate service providers where necessary for legal, financial, audit, risk-management, insurance, corporate, compliance or business-continuity purposes;
- competent authorities, courts, regulators, law enforcement bodies, public administrations or other third parties where required by law, necessary for legal claims, necessary to protect rights or security, or necessary to investigate suspected fraud or unlawful conduct;
- third parties involved in corporate transactions, restructuring, financing, merger, acquisition, asset sale or business transfer, subject to appropriate confidentiality and data protection safeguards.
Before sharing candidate, Logistics Worker or trainee data with a Client, Service Club will link the sharing to a defined opportunity, training, reporting, onboarding, compliance, fraud-prevention or service purpose and limit the data to what is adequate, relevant and necessary. Clients must not use the data for incompatible purposes.
5.7. Processors and sub-processors
Where Service Club engages service providers to process personal data on its behalf, it will require them to process the data only on documented instructions, to implement appropriate security measures, to support Service Club in complying with data protection obligations, and to enter into a data processing agreement meeting Article 28 GDPR requirements.
Where Service Club acts as processor for a Client, Service Club may use authorised sub-processors in accordance with the applicable data processing agreement. The list of sub-processors, approval mechanism, objection rights and international transfer safeguards should be addressed in the applicable Client DPA or service documentation.
Not all third parties are processors. Some providers, platforms, payment services, job boards, social media platforms, Clients or public authorities may act as independent controllers for their own purposes. In those cases, their own privacy notices and responsibilities apply.
5.8. International transfers
Service Club aims to use providers and infrastructure located in the European Economic Area where reasonably possible. However, some providers, group entities, support teams, platforms or technical services may process personal data outside the EEA.
Where personal data are transferred outside the EEA to a country that has not been recognised as providing an adequate level of protection, Service Club will implement an appropriate transfer mechanism under Chapter V GDPR, such as an adequacy decision, the European Commission Standard Contractual Clauses, the EU-US Data Privacy Framework where applicable, Binding Corporate Rules where applicable, or another lawful mechanism. Where required, Service Club will also assess the transfer risks and adopt supplementary technical, organisational or contractual measures.
Users may request further information about the transfer mechanisms applicable to their data by contacting Service Club, subject to confidentiality and security limitations.
6. How long do we keep personal data?
Service Club keeps personal data only for as long as necessary for the purposes for which they were collected and for any related legal, contractual, security, fraud-prevention, audit, accounting and claims obligations. Retention periods vary depending on the data category, service, user relationship, country, legal limitation periods and applicable Client arrangements.
A general retention framework is set out below. Specific service notices, Client arrangements or legal obligations may apply shorter or longer periods where justified. Once the relevant period expires, Service Club will delete, anonymise or securely restrict the data unless continued retention is legally required or justified for legal claims, fraud prevention, security or compliance evidence.
Upon account closure or a valid deletion request, deletion or anonymisation will be carried out without undue delay for data that are no longer needed. However, some data may need to be retained for statutory accounting/tax periods, contractual limitation periods, security logs, fraud evidence, rights-request evidence, complaints, Client reporting obligations or legal claims. Any legally retained data will be blocked or restricted where appropriate.
| Data category / processing area | Indicative retention approach |
|---|---|
| Website, cookie and consent data | For the periods stated in the Cookie Policy or consent management platform; consent/withdrawal evidence may be retained while necessary to evidence compliance. |
| Account and profile data | While the account is active and for a reasonable period afterwards to manage reactivation, support, complaints, fraud prevention, security, audit and legal claims. |
| Candidate / Logistics Worker applications | While the relevant process is active; for future opportunities where lawful; and afterwards for a limited period to manage complaints, anti-fraud controls, evidence of notices/consents and potential claims. |
| Client-specific sharing and onboarding records | For the duration of the Client process and afterwards as needed for reporting, audit, dispute management, legal claims and compliance with the applicable Client arrangement. |
| Academy and training records | While necessary to deliver training, evidence attendance/completion, issue certificates or reports, manage quality, comply with Client arrangements and defend claims. |
| VR, telematics and detailed learning analytics | Only for the shortest period compatible with the training, reporting, quality and security purpose; raw or granular data should be deleted, aggregated or anonymised where no longer necessary. |
| B2B contacts, contracts and commercial records | During the pre-contractual/contractual relationship and afterwards for statutory limitation periods, accounting/tax obligations and legal claims. |
| Payment, invoice and accounting data | For statutory tax and accounting retention periods and any related limitation periods. |
| Security, fraud and audit logs | For the period necessary to protect the platform, investigate incidents, preserve evidence and defend claims, subject to proportionality and access controls. |
| Marketing data | Until consent is withdrawn, an objection/unsubscribe is received, or the data are no longer necessary for the relevant campaign or relationship; suppression lists may be retained to respect opt-outs. |
| Rights requests and complaints | For the period necessary to answer the request and evidence compliance, usually aligned with limitation periods for potential claims. |
7. Your data protection rights
Subject to the conditions and limits set out in the GDPR and LOPDGDD, you may exercise the following rights:
- access: obtain confirmation as to whether Service Club processes your personal data and receive a copy of the data and relevant information;
- rectification: ask us to correct inaccurate or incomplete personal data;
- erasure: ask us to delete personal data where the legal conditions are met;
- restriction: ask us to restrict processing in certain circumstances;
- objection: object to processing based on legitimate interests, including profiling based on legitimate interests, and object at any time to direct marketing;
- portability: receive data that you provided to us in a structured, commonly used and machine-readable format, and transmit it to another controller where processing is based on consent or contract and carried out by automated means;
- withdrawal of consent: withdraw consent at any time where processing is based on consent;
- automated decisions: not be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significant effects, except where permitted by Article 22 GDPR and subject to safeguards;
- complaint: lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es, without prejudice to any other administrative or judicial remedy.
You may exercise your rights by contacting privacy@serviceclub.com and clearly identifying the right you wish to exercise. We may ask you for information reasonably necessary to verify your identity and locate your data. If your request concerns processing carried out by a Client or another third party as controller, we may direct you to that controller or cooperate with it as required by applicable arrangements.
Rights are not absolute. For example, we may need to retain certain data for legal obligations, legal claims, fraud prevention, security or accounting purposes, or we may be unable to provide information that adversely affects the rights and freedoms of others. Where we cannot fully comply with a request, we will explain the reason where required by law.
8. Automated processing, profiling, AI and human review
Service Club may use digital tools, matching logic, automated reminders, AI-supported learning tools, screening-support features, call-center scripts, recommendation features, fraud flags and analytics to support platform operations, recruitment-support services, training and security.
Unless clearly stated in a specific notice, these tools are intended to support human-operated processes and do not make final hiring, dismissal, disciplinary, work allocation or legally significant employment decisions on behalf of Clients or users. Service Club does not guarantee employment suitability and does not act as the final employer or hiring decision-maker.
Where automated processing or profiling is used, Service Club will seek to ensure that the processing is transparent, proportionate, accurate and subject to appropriate safeguards. Where Article 22 GDPR applies because a decision is based solely on automated processing and produces legal or similarly significant effects, the relevant controller must implement the safeguards required by the GDPR, including the right to obtain human intervention, express a point of view and contest the decision, unless an exception applies.
Client-side use of Service Club outputs for recruitment, ranking, worker management, discipline, dismissal, work allocation or similar employment-related decisions is the Client's sole responsibility unless Service Club expressly agrees to assume a specific role in writing. Where a Client utilizes AI-supported tools or automated outputs for legally significant employment decisions, the Client remains independently responsible for compliance with Article 22 GDPR, applicable labour laws, and the AI Act.
9. Security and confidentiality
Service Club applies appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access and other security risks. Measures may include access controls, authentication, role-based permissions, encryption or pseudonymisation where appropriate, confidentiality obligations, logging, backups, secure development practices, provider due diligence, vulnerability management, incident response, business continuity controls and internal policies.
Access to personal data is limited to personnel, contractors, providers and recipients who need access for the relevant purpose and are subject to appropriate confidentiality, security and data protection obligations.
No online service can be guaranteed to be completely secure. However, Service Club will maintain security measures appropriate to the nature, scope, context and risks of the processing and will manage personal data breaches in accordance with Articles 33 and 34 GDPR where applicable. Users should also protect their credentials, use secure devices and notify Service Club promptly of suspected unauthorised access, account misuse or security incidents.
10. Third-party websites, platforms and services
Service Club services may link to or integrate third-party websites, job boards, social media platforms, Client platforms, payment providers, training providers, communication channels, maps, analytics tools, marketplace partners or other services. Those third parties may process personal data as independent controllers under their own privacy policies.
Service Club is not responsible for third-party privacy practices where the third party determines its own purposes and means of processing. You should review the privacy information of the relevant third party before using its service or providing data through it.
Where Service Club embeds, configures or otherwise controls a third-party technology on its own website or platform, Service Club will assess the corresponding privacy and cookie obligations and provide appropriate information or consent mechanisms where required.
11. Minors
The Service Club platform and services are intended for adults and for professional, logistics, recruitment, training and B2B contexts. We do not knowingly collect personal data from children through our platform services.
If Service Club becomes aware that a minor has provided personal data without a valid legal basis or required authorisation, Service Club will take appropriate steps to delete or restrict the data unless retention is legally required, necessary to protect the minor or necessary for legal claims.
12. Changes to this Policy
Service Club may update this Policy to reflect changes in services, technologies, legal requirements, regulator guidance, security practices, corporate structure or business model. The updated version will be published on this page with its effective date.
Where changes are material and affect ongoing users, Service Club will provide reasonable notice through the website, platform, email or other appropriate means. Continued use of the relevant service after the effective date may be subject to the updated Policy, without prejudice to any rights that require separate consent or notice.
13. Your privacy rights if you are in the United States
If you are a resident of California or another US state with a comprehensive privacy law (such as Colorado, Connecticut, Texas, Virginia, Oregon, and others), you have the following rights regarding your personal information:
- Right to know: request the categories and specific pieces of personal information we have collected about you.
- Right to delete: request that we delete the personal information we hold about you.
- Right to correct: request correction of inaccurate personal information.
- Right to opt out of sale or sharing: we do not sell your personal information for money. We do use analytics and advertising cookies that, under some state laws, may be considered a "sale" or "sharing" of personal information. You can opt out at any time.
- Right to non-discrimination: we will not discriminate against you for exercising any of these rights.
How to opt out: use the "Your Privacy Choices" link in the website footer to manage your cookie preferences, or email us at privacy@serviceclub.com. We also honour the Global Privacy Control (GPC) browser signal: if your browser sends a GPC signal, we automatically treat it as a request to opt out of the sale or sharing of your personal information.