Privacy policy
This is a courtesy translation. In case of discrepancy, the Spanish version prevails.
We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD), with particular care because it involves the health data of minors.
Data controller
[to be completed: company name] · Tax ID (CIF) [to be completed] · Avda. del Infante Don Luis, 8, 28660 Boadilla del Monte, Madrid · privacidad@aduopediatria.com.
Data Protection Officer (DPO)
As a healthcare center legally required to keep its patients' medical records (art. 20 of Law 41/2002), ADÚO is legally obliged to appoint a data protection officer (art. 34.1.g LOPDGDD) and to notify the Spanish Data Protection Agency (AEPD). DPO contact: [to be completed]. Until the formal appointment, any privacy query can be sent to privacidad@aduopediatria.com.
What data we process
Identification and contact details of the guardians (name, phone, email, relationship with the minor); identification details of the children (name, date of birth, sex); and the minor's health data (special category, art. 9 GDPR): medical history, vaccines, growth, allergies, messages with the medical team, and photos attached to messages or to the record for care purposes.
Purposes and legal basis
Healthcare and management of the medical record: processing of health data under art. 9.2.h GDPR (provision of healthcare) and Law 41/2002 on patient autonomy. The informed consent of the guardian or legal representative is obtained when each child is registered, and can be reviewed at any time from the account's Privacy Center.
Appointment management and billing: performance of the contractual relationship with the family (art. 6.1.b GDPR) and compliance with tax obligations (art. 6.1.c GDPR).
Appointment and vaccine reminders, personalized parenting content, and use of images in the medical record: additional processing based on the guardian's express consent (art. 6.1.a GDPR), given separately for each purpose and revocable at any time without affecting the lawfulness of the processing carried out before its withdrawal.
Minors' data and parental authority
The data of underage patients is processed through their parents or legal guardians, who exercise the rights that would correspond to the minor for as long as the minor is not able to do so on their own. From the age of 16, and in accordance with article 7 of the LOPDGDD, patients can exercise their rights over their personal data directly.
Recipients and data processors
We do not disclose data to third parties except where legally required (for example, a court order or a request from the health authority). We use technology providers that act as data processors under a contract in accordance with art. 28 GDPR: Supabase (database, authentication and sending of notifications), with infrastructure located in the European Union; Resend (sending of transactional emails), with the sending region set to Ireland; Cloudflare (website hosting); Google Ireland Limited (measurement of our ads on the public website, only if you accept measurement cookies: see the cookie policy); and Meta Platforms Ireland Limited (sending of appointment reminders via WhatsApp, only for families who expressly turn it on).
WhatsApp reminders contain only the child's first name, the day and time of the appointment and the clinician's name: no clinical information, reasons for the visit or diagnoses are ever sent through that channel. WhatsApp is an optional, additional channel: it is turned on from Settings → WhatsApp reminders with express consent (art. 6.1.a GDPR), can be withdrawn at any time from that same place or by sending BAJA in the WhatsApp chat itself, and anyone who does not turn it on receives exactly the same reminders by email and by app notification. The phone number is shared with Meta so that the message can be delivered.
As a general rule, data is hosted in the European Union. Specifically for the WhatsApp channel, Meta may carry out international transfers to the United States covered by the EU-U.S. Data Privacy Framework and, alternatively, by the standard contractual clauses approved by the European Commission. This is one of the reasons why that channel is optional and why no health data travels through it.
Retention periods
The medical record is kept for the minimum period required by the applicable health regulations [to be completed: period set by the Community of Madrid; as a guide, a minimum of 5 years from the last visit under art. 17 of Law 41/2002], even if closure of the account is requested. Billing data is kept for the periods required by tax and commercial law. All other data is kept while the account is active and, after it is closed, for the period necessary to deal with any possible liabilities.
Your rights
You can exercise your rights of access, rectification, erasure, portability, restriction and objection from your account's Privacy Center (Settings → Privacy Center), where you can manage your consents and request the export or deletion of your data, or by writing to privacidad@aduopediatria.com. You can also file a complaint with the Spanish Data Protection Agency (www.aepd.es) if you believe we have not handled your request properly.
Security
Data is stored encrypted in transit and at rest, with role-based access control (family, clinical staff, administration) enforced through row-level security policies in the database, so that each profile can only access the data that corresponds to it.