Security, minors’ data, and where the money goes

This page is for the clerk, the comptroller and the DPO. No surprises: everything we handle, where it lives, and who can access it.

Where the money goes

Every payment happens at the town bank’s own Redsys TPV, using the town’s own merchant credentials (Bizum included). Money never passes through EnaJoin accounts: we are not a payment intermediary and reconciliation matches the municipal bank statement directly. We store no card data (SAQ-A scope): only order references and statuses.

Minors’ data, minimized

We collect only what the service needs: name, birth date, monitor-relevant medical information, allergies, support needs and image-rights consent — accessible only to the guardian and authorized municipal staff. Legal basis and categories detailed in the DPA annex.

Discount documents

Residence certificates and family cards (which can reveal income and family composition) live in a private EU-jurisdiction bucket, encrypted at rest, accessed only via signed links by authorized staff, and deleted at season end (retention configurable per ordinance).

GDPR: processor with a DPA

The town is the data controller; EnaJoin the processor, with a standard DPA ready to sign (sub-processors listed, EU hosting, 24h incident notification). No transfers outside the EU.

ENS and traceability

ENS básica controls by default: EU hosting, audit logging (every place allocation timestamped, every discount review attributed), daily backups, role-based access and staff 2FA.

Accessibility and transparency

Citizen pages conform to UNE-EN 301 549 / WCAG 2.1 AA (it’s the law for public services, including those delivered through us). Machine translations always carry a visible indicator until staff review them — AI transparency by default.

Request the DPA and compliance dossier