Effective Date: 20 Feb 2026
Regenera Luxury Institute (“we,” “our,” “us”) is the educational arm of Regenera Luxury, presented by UN Tourism as the world’s first regenerative management program with external certification, focused on boutique hotels and retreats.
We are committed to protecting your personal data in accordance with:
-
The General Data Protection Regulation (EU) 2016/679 (“GDPR”)
-
Applicable data protection laws in the United States and Mexico
-
Other relevant international privacy laws where applicable
This Privacy Policy explains how we collect, use, process, and protect personal data through our Learning Management System (LMS) and related services.
By accessing our platform, you acknowledge this Privacy Policy.
1. Data Controller
The Data Controller responsible for processing personal data is:
Regenera Luxury Institute
Email: [email protected]
Operational locations:
-
Newark, United States
-
Granada, Spain
-
Playa del Carmen, Mexico
2. Categories of Personal Data Collected
We may collect and process the following categories of personal data:
2.1 Identity Data
-
Full name
-
Professional title
-
Organization affiliation
2.2 Contact Data
-
Email address
-
Phone number
-
Billing address (if applicable)
2.3 Transaction Data
-
Payment details (processed via secure third-party providers)
-
Course enrollment history
-
Certification records
2.4 Technical Data
-
IP address
-
Browser type and version
-
Device identifiers
-
Login data
-
Usage analytics within the LMS
2.5 Communication Data
-
Messages sent through contact forms
-
Email correspondence
-
Support inquiries
3. Lawful Basis for Processing (GDPR Article 6)
We process personal data under the following lawful bases:
Contractual Necessity
To provide LMS access, certification programs, and related services.
Legitimate Interests
To improve our platform, prevent fraud, ensure platform security, and maintain program integrity.
Legal Obligation
To comply with applicable tax, financial, or regulatory requirements.
Consent
For marketing communications, cookies (where required), and optional communications.
You may withdraw consent at any time.
4. Purposes of Processing
We use personal data to:
-
Provide and administer educational and certification programs
-
Process payments and issue confirmations
-
Maintain certification records
-
Communicate important updates
-
Improve user experience and system performance
-
Ensure program credibility and external certification standards
-
Comply with legal obligations
We do not sell or rent personal data.
5. Data Sharing and Processors
We may share personal data with:
-
IT and hosting providers
-
Payment processors
-
Email and communication service providers
-
Certification auditors or verification partners (where applicable)
All third-party processors are required to implement appropriate security measures and process data in accordance with GDPR requirements.
6. International Data Transfers
Given our global operations (United States, Spain, Mexico), personal data may be transferred internationally.
Where data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards, including:
-
Standard Contractual Clauses (SCCs)
-
Adequacy decisions (where applicable)
-
Contractual data protection agreements
7. Data Retention
We retain personal data only for as long as necessary to:
-
Fulfill contractual obligations
-
Maintain certification and training records
-
Comply with legal requirements
-
Resolve disputes
Certification records may be retained for verification and audit integrity purposes.
When data is no longer required, it is securely deleted or anonymized.
8. Data Subject Rights (GDPR)
If you are located in the European Union, you have the following rights:
-
Right of access
-
Right to rectification
-
Right to erasure (“right to be forgotten”)
-
Right to restriction of processing
-
Right to data portability
-
Right to object
-
Right to withdraw consent at any time
-
Right to lodge a complaint with a supervisory authority
To exercise your rights, contact:
[email protected]
We may request identity verification before fulfilling certain requests.
9. Cookies and Tracking Technologies
Our LMS may use cookies and analytics tools to:
-
Authenticate users
-
Improve performance
-
Analyze traffic
-
Enhance user experience
Where required by law, we obtain user consent before placing non-essential cookies.
You may manage cookie preferences through your browser settings.
10. Data Security
We implement appropriate technical and organizational measures, including:
-
Secure servers
-
Encrypted connections (SSL/TLS)
-
Access controls
-
Limited data access policies
While we take reasonable steps to secure data, no transmission method is completely secure.
11. Children’s Data
Our services are intended for hospitality professionals and institutional partners.
We do not knowingly collect personal data from children under 13 years of age.
If such data is identified, it will be promptly deleted.
12. Third-Party Links
Our platform may contain links to third-party websites. We are not responsible for their privacy practices. Users should review their respective privacy policies.
13. Policy Updates
We may revise this Privacy Policy periodically.
The updated version will be posted on this page with a revised effective date. Continued use of our LMS constitutes acceptance of changes.
14. Contact Information
For privacy-related inquiries:
Regenera Luxury Institute
Educational Arm of Regenera Luxury
Email: [email protected]