Counsellor mobile app privacy (LayosCamp)

This page describes how we process personal data when you work as a counsellor at LayosCamp and use the counsellor mobile app (LayosCamp Monitor, available on the App Store and Google Play). It forms part of our general privacy policy and adds what is specific to the mobile channel.

If you only want to delete your account and do not use the app, go straight to delete my counsellor account.

Who the controller is

CompanyCastillo de Layos S.L. (LayosCamp is our trade name)
CIF (tax ID)B-78583366
AddressCalle Garza 11, 28023 Madrid
General contactinfo@layoscamp.com
Data Protection Officer (DPO)Pelayo de Gregorio Oriol — public contact dpo@layoscamp.com
DPO designationInternal (Art. 37.6 GDPR), notified to the AEPD (Spanish Data Protection Agency) on 03/06/2026 under registration number REGAGE26e00052733552

For any matter relating to your personal data, write to the DPO.

What data we process in the app

Your data as a counsellor

  • Identification and contact: first name, surnames, photo, login email, mobile number, city, gender, date of birth.
  • Employment documents: DNI or NIE, Social Security number, IBAN.
  • Criminal record certificate (sexual offences) — required by law to work with minors.
  • Academic and internship: academic tutor, internship agreement, parental authorisation if you are 16-17 years old.
  • Operational: role, availability, session assignments, internal evaluations.
  • Device technical data: push notification token, app version, platform (iOS/Android). We do not collect advertising identifiers (IDFA/AAID), we do not access your GPS location and we do not read your contacts or your calendar.

Data of the minor camper (whom you see in your app because their parents entrusted them to us)

  • Identification: name, age, gender, photo.
  • Health (specially protected data — Art. 9 GDPR): allergies, intolerances, medication, medical observations, mental health, disability, daily health checks.
  • Operational: registrations, journeys, room assignment, emergency contacts.
  • Financial: pocket money (balance and transactions).
  • Multimedia: photos taken during the session.

These data were provided by the camper’s parents when they registered them on our website. The app is a work tool so that you can look after the camper properly; it is not a channel for collecting new data.

Why we process them (legal bases)

CategoryLegal basis
Your employment and contact dataPerformance of the employment contract / internship agreement (Art. 6.1.b GDPR) + legal obligations (Art. 6.1.c)
Your criminal record certificateLegal obligation — Organic Law 1/1996 as amended by Law 26/2015
Health data of the minorHealthcare and custody (Art. 9.2.h GDPR) + vital interest of the minor (Art. 9.2.c)
Other data of the minorPerformance of the service contracted by their parents (Art. 6.1.b)
Photos of the minorSpecific parental consent obtained at web registration (Art. 6.1.a + Art. 8 GDPR + LO 1/1996)
Push notifications and operational communicationsPerformance of the service (Art. 6.1.b) and legitimate organisational interest (Art. 6.1.f)
Audit logsCompliance with the accountability principle (Art. 5.2)

How long we keep each item

Summary — full details are in our counsellor app retention policy:

  • Your employment and tax data: 4 years from the end of the employment relationship (4-6 years for accounting and tax data).
  • Health data of minors recorded under your name: 5 years (reinforced regime of Art. 9 + LOPDGDD). Your name is anonymised when you close your account.
  • The minor’s pocket money: 6 years (Commercial Code).
  • Technical and communication logs: 4-5 years.
  • Your photo, your password and your notification token: deleted when you close your account.

Who we send your data to (processors)

ProcessorPurposeLocation
Hetzner Online GmbHApp serverGermany (EU)
Amazon Web Services (S3)Photos and documentsEuropean region (EU)
Microsoft 365 (Office)Internal emailIreland (EU)
Google (Firebase Cloud Messaging)Delivery of Android and iOS push notificationsUnited States
Apple (APNs)Delivery of iOS push notificationsUnited States

Transfers outside the EU

Only to the United States, to deliver push notifications (Google and Apple). These transfers are covered by the European Commission’s Standard Contractual Clauses and by the EU-US Adequacy Decision of 10 July 2023 (Data Privacy Framework). The content of push notifications is sanitised: they contain neither your name nor health data, only an identifier so that the app knows which screen to open when you tap them.

We do not sell your data to third parties. We do not use advertising or behavioural analytics within the app.

How we protect your data

  • TLS 1.2+ encryption for all communications between the app and our server.
  • Your login session is stored in the operating system’s native secure storage (iOS Keychain or Android EncryptedSharedPreferences).
  • Your password is stored as a non-reversible bcrypt hash, never in plain text.
  • Mandatory re-authentication for sensitive actions such as deleting your account or changing your password.
  • Push notifications with generic content on the lock screen — health data only appear after the device has been unlocked and the authenticated app opened.
  • Access restricted by role and by assigned session: a counsellor only sees the campers in their session.
  • Particularly sensitive data (mental health, disability) are accessible only to coordinators and medical staff.
  • Full audit trail of access and exports.
  • No advertising tracking and no third-party analytics SDKs.

Your rights

You can exercise the following rights at any time:

  • Access — find out what data we hold about you and obtain a copy.
  • Rectification — correct anything that is inaccurate.
  • Erasure (right to be forgotten) — from Mi perfil → Seguridad → Borrar mi cuenta (My profile → Security → Delete my account) in the app, or by writing to us.
  • Objection — to processing that is not mandatory.
  • Restriction — freeze the processing while a dispute is being resolved.
  • Portability — receive your data in a structured format.

Single channel: dpo@layoscamp.com. We reply within 1 month at most (extendable to 2 if the request is complex; we would let you know).

If you believe we have not responded properly, you can lodge a complaint with the Spanish Data Protection Agency (aepd.es).

Direct account deletion

If you only want to delete your account without opening the app, follow the deletion instructions.

Changes to this policy

When the retention periods, processors, purposes or security measures change. Each version is dated. Substantial changes: we will notify you by email and in the app.


Last updated: 2026-06-05 · Version: 1.1
Castillo de Layos S.L. · CIF B-78583366 · Calle Garza 11, 28023 Madrid
Data Protection Officer: Pelayo de Gregorio Oriol — dpo@layoscamp.com (designated 03/06/2026, AEPD REGAGE26e00052733552)