Privacy Policy

Last updated: February 12, 2024

Introduction

This Privacy Policy describes how we collect, use, and protect your personal information when you use our appointment booking service. We are committed to protecting your privacy and complying with GDPR and other applicable data protection laws.

Data We Collect

We collect the following types of information:

  • Account Information: Email address and password (hashed)
  • Search Information: Procedure type, province, office preferences, date/time preferences
  • Payment Information: Transaction details processed through LemonSqueezy (we do not store credit card numbers)
  • Technical Information: IP address, browser type, and usage data for service improvement and security

How We Use Your Data

  • To provide and maintain our appointment booking service
  • To communicate with you about your searches and appointments
  • To improve and optimize our service
  • To comply with legal obligations and protect against fraud

Data Storage

Your data is stored securely on servers within the European Union. Sensitive personal information (document numbers, phone numbers, names) is encrypted at rest using industry-standard encryption.

Data Retention

We retain your personal data for 90 days after your search is completed or cancelled. After this period, all personal information is automatically deleted. Payment records are retained for 7 years for accounting and tax purposes as required by law.

Your Rights

Under GDPR, you have the following rights:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate personal data
  • Right to Erasure: Request deletion of your personal data
  • Right to Restriction: Request restriction of processing
  • Right to Data Portability: Receive your data in a portable format
  • Right to Object: Object to certain types of processing

Cookies

We use only essential cookies necessary for the service to function (authentication tokens). We do not use tracking cookies, advertising cookies, or third-party analytics cookies. You can manage cookie preferences through your browser settings.

Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. This includes encryption, secure servers, regular security audits, and access controls.

Third-Party Services

We use the following third-party services:

  • LemonSqueezy: For payment processing and subscription management (PCI-DSS compliant)
  • Sentry: For error monitoring (no personal data sent)
  • Hetzner: For secure server hosting within the EU

Children's Privacy

Our service is not intended for children under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by email or through a prominent notice on our website. Continued use of the service after changes constitutes acceptance of the updated policy.

Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:

Email: [email protected]

CitaRapida - Book Appointments in Spain