Privacy policy
Processing of personal data under the GDPR
Last updated: June 22, 2026
Working translation. In case of discrepancy, the Spanish version at /privacidad prevails.
1. Data controller
Controller: LOORU / Juan Álvarez.
Email: hola@looru.org
Phone: +1 305 345 0149
Website: https://looru.org
In accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD), LOORU informs users of the following privacy policy.
2. Purposes and legal basis
2.1. Managing requests and meetings. When you book a meeting via Calendly or contact us by WhatsApp or email, we process the data you provide (name, email, phone, professional profile) to handle the communication and assess your candidacy. Legal basis: pre-contractual measures (art. 6.1.b GDPR).
2.2. Program management and contract. Once enrolled, we process the data needed to deliver the service: J1 visa processing, hotel placement, health insurance, US bank account, and on-site support. Legal basis: performance of contract (art. 6.1.b GDPR).
2.3. Marketing communications. With your express consent we may send information about the program, new cohorts, testimonials and relevant content. Legal basis: consent (art. 6.1.a GDPR); can be withdrawn at any time.
2.4. Legal obligations. Where required by law. Legal basis: art. 6.1.c GDPR.
3. Data processed
- Identification: name, surname, email, phone, date of birth.
- Professional: qualifications, work experience, English level, hospitality profile.
- Browsing: IP address, browser, pages visited, cookies (see Cookie Policy).
- Visa process: passport number, SEVIS, photos, travel history and other data required by US authorities.
4. Recipients
LOORU does not share personal data with third parties except:
- J1 visa sponsors (US Department of State-authorized entities issuing the DS-2019).
- Partner hotels in the US for selection and employment.
- Technology providers: Calendly, WhatsApp Business, email platforms — acting as data processors under GDPR-compliant contracts.
- Public authorities when required by law.
Some recipients are located outside the EEA (notably in the US). LOORU ensures transfers are made with appropriate safeguards (Standard Contractual Clauses or other GDPR-recognized mechanisms).
5. Retention periods
- Non-enrolled candidates: up to 2 years from last contact, or until deletion is requested.
- Enrolled clients: for the duration of the contract and the applicable statute of limitations afterwards (generally 5 years for contractual obligations in Spain).
- Visa data: as required by US immigration authorities, which may demand at least 3 years after the J1 program ends.
6. Your rights
You may at any time exercise the rights of access, rectification, erasure («right to be forgotten»), objection, restriction, portability and withdrawal of consent. To exercise any of these rights, contact LOORU at hola@looru.org indicating the right exercised and providing a copy of your ID.
If you believe your rights have not been properly addressed, you may file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.
7. Minors
The Website is intended for users aged 18 or older. LOORU does not knowingly collect or process personal data of minors. If such data is detected without parental consent, it will be deleted immediately.
8. Security
LOORU has implemented appropriate technical and organizational measures to ensure the security and integrity of personal data. However, no internet transmission is fully secure, so absolute security cannot be guaranteed.
9. Changes
LOORU may update this Privacy Policy to reflect legal or jurisprudential changes. Material changes will be communicated through the Website.
