Privacy Policy

Information about the processing of your personal data

Data Controller

In accordance with Regulation (EU) 2016/679 General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and guarantee of digital rights (LOPDGDD), the data controller is:

Purposes of Processing

The personal data you provide will be processed for the following purposes:

  • Management of medical appointments, healthcare provision and clinical follow-up of patients.
  • Preparation and maintenance of the patient's medical records, in accordance with Spanish Law 41/2002 on patient autonomy.
  • Invoicing and administrative and accounting management of services provided.
  • Responding to enquiries, requests and communications received through the contact form, telephone, email or WhatsApp.
  • Sending information about health services and clinic news, with prior express consent.
  • Compliance with legal obligations in healthcare, tax, accounting and anti-money laundering matters.
  • Website management and improvement of user experience.

Legal Basis for Processing

The processing of personal data is based on the following legal grounds (Art. 6 GDPR):

  • Performance of a contract (Art. 6.1.b): Provision of medical and healthcare services requested by the patient.
  • Legal obligation (Art. 6.1.c): Compliance with applicable healthcare legislation (Law 41/2002, General Health Law 14/1986), tax and accounting regulations.
  • Vital interest (Art. 6.1.d): Protection of the patient's health in medical emergency situations.
  • Consent (Art. 6.1.a): For sending commercial communications and newsletters.
  • Special categories of data (Art. 9.2.h): The processing of health data is based on the provision of healthcare by a professional subject to the obligation of professional secrecy.

Data Recipients

Personal data may be communicated to:

  • Public health authorities, where there is a legal obligation (disease reporting, health registries).
  • Public tax authorities, for compliance with tax obligations.
  • Insurance companies and mutual funds, for the management of the patient's health insurance, with prior consent.
  • Analysis laboratories, hospital centres and collaborating centres, when necessary for the provision of medical services.
  • Technology service providers (hosting, email, management software), as data processors with a signed contract in accordance with Art. 28 GDPR.

No international data transfers are made outside the European Economic Area (EEA), unless adequate safeguards exist in accordance with Art. 46 GDPR.

Data Retention

Personal data will be retained for the following periods:

  • Clinical data: Minimum 5 years from the last visit (Law 41/2002), which may be extended under regional regulations.
  • Billing data: 6 years (Commercial Code) and 4 years (tax obligations).
  • Contact and enquiry data: Until the request is completed and for the legally established periods to address potential liabilities.
  • Marketing data: Until the data subject withdraws their consent.

Data Subject Rights

In accordance with the GDPR and the LOPDGDD, the user may exercise the following rights:

  • Access (Art. 15): Obtain confirmation of whether personal data is being processed and access such data.
  • Rectification (Art. 16): Request the correction of inaccurate or incomplete data.
  • Erasure (Art. 17): Request the deletion of data when it is no longer necessary, subject to legal limitations applicable to health data.
  • Restriction of processing (Art. 18): Request the restriction of processing in certain circumstances.
  • Data portability (Art. 20): Receive data in a structured, commonly used and machine-readable format, and transmit it to another controller.
  • Objection (Art. 21): Object to the processing of data, including for direct marketing purposes.
  • Not to be subject to automated decisions (Art. 22): Not to be subject to a decision based solely on automated processing.

To exercise these rights, you may send an email to info@clinicaeupnea.com enclosing a copy of your identity document (passport or national ID).

If you believe that the processing of your data does not comply with current regulations, you have the right to file a complaint with the Spanish Data Protection Agency (AEPD):
www.aepd.es – C/ Jorge Juan, 6 – 28001 Madrid.

Data Security

Clinica Eupnea S.L.P. has adopted the necessary technical and organisational measures to ensure the security and integrity of personal data, preventing its alteration, loss, processing or unauthorised access, taking into account the state of technology, the nature of the data and the risks to which it is exposed.

Measures implemented include: encrypted communications (SSL/TLS), access controls for information systems, periodic backups, staff training in data protection and security incident management protocols.

Policy Updates

This Privacy Policy may be updated to adapt to regulatory, technical or internal practice changes at Clinica Eupnea S.L.P.. We recommend reviewing it periodically. Any changes will be published on the Website.

Last updated: March 2026.