Courtesy translation
This is a translation provided for convenience. The legally binding version is the Spanish text, available at Política de Privacidad.
2.1. Data controller
- Controller
- Dr Fernando Casals Seoane
- Tax ID (NIF)
- 51098888H
- Professional address
- Hospital Universitario Ruber Juan Bravo, C/ Juan Bravo 39, 9th floor, 28006 Madrid
- Telephone
- +34 682 92 97 32
2.2. What the website processes
www.doctorcasals.com allows users to consult professional information, contact the practice and book an appointment through a Cal.com module integrated into the website.
Unlike the initial version of the site, booking through Cal.com does involve the transmission and storage of the data needed to manage the appointment within the provider infrastructure.
2.3. Data processed when booking
The following may be processed, depending on the final configuration of the event:
- Name and surname.
- Email address.
- Telephone number, where requested.
- Selected date and time.
- Time zone and technical data required for the booking.
- Technical connection information such as IP address, browser, device and timestamps.
- Data required to cancel or reschedule the appointment.
Cal.com will not request a medical reason for the consultation, description of symptoms, diagnoses, medical history, test results, clinical reports or healthcare documentation.
Data allowing health information to be inferred
Requesting an appointment with a specialist may in itself allow information about health to be inferred. Booking data is therefore processed with particular caution and minimisation.
2.4. Purposes
- Displaying the real availability of the practice.
- Allowing users to select and book a day and time.
- Sending confirmations, reminders, cancellations or changes relating to the appointment, where configured.
- Administratively coordinating the appointment with the practice and, where appropriate, with Hospital Universitario Ruber Juan Bravo.
- Ensuring the security and correct operation of the booking system.
- Responding to requests relating to data protection rights.
2.5. Legal basis
Processing of the identifying and contact data needed to book an appointment is based on the request made by the data subject and on taking the measures necessary to manage the care requested.
Where the information allows health data to be inferred, processing is carried out only to the extent necessary for managing healthcare and subject to the confidentiality safeguards applicable to healthcare activity.
Acceptance of this Privacy Policy is not used as generic consent for processing that does not require it. Specific consents, where necessary for any additional purpose, are requested separately.
2.6. Cal.com as provider
Cal.com is used as the technology provider for scheduling. In relation to the data of people booking an appointment, Cal.com acts as a processor on behalf of the controller, in accordance with its data processing agreement.
Cal.com may use sub-processors to provide, secure and maintain the service. The applicable relationship and terms must be reviewed periodically in the provider contractual and compliance documentation.
The current Cal.com policy indicates that data may be processed in the United States and other locations by its sub-processors, using mechanisms such as standard contractual clauses or other applicable adequacy mechanisms for international transfers. Where feasible, EU data residency should be configured or requested.
2.7. Recipients
Data may be disclosed or made available to:
- Cal.com, as scheduling provider and processor.
- Sub-processors necessary for the technical provision of the Cal.com service, under its contractual documentation.
- Hospital Universitario Ruber Juan Bravo, where necessary to coordinate the appointment or provide care.
- Authorities or public bodies where there is a legal obligation.
2.8. International transfers
Use of Cal.com may involve international transfers of data outside the European Economic Area. Such transfers must be covered by a valid mechanism under the GDPR, such as an adequacy decision, the EU-US Data Privacy Framework where applicable, or standard contractual clauses.
The controller will document the applicable safeguards in the contract or data processing agreement with Cal.com and will review the location of data and sub-processors.
2.9. Retention
Booking data is retained for as long as necessary to manage the appointment and for the periods required to address any liabilities. The Cal.com retention settings must be reviewed and limited to what is necessary.
Data subsequently forming part of healthcare provision or the medical record is processed and retained by Hospital Universitario Ruber Juan Bravo under healthcare legislation and its internal policies.
2.10. WhatsApp and email
WhatsApp and email are intended primarily for administrative communications. Please do not use these channels to send sensitive clinical documentation spontaneously unless a suitable channel has been expressly indicated.
The professional email address of the practice is citas@doctorcasals.com.
2.11. Technical browsing data
The hosting provider and integrated services may generate technical logs necessary for security and operation, such as IP address, browser, device, referring URL, pages or components consulted and timestamps. This data is limited to technical and security purposes and, where applicable, to additional purposes expressly notified.
2.12. Rights
Data subjects may exercise, where applicable, their rights of access, rectification, erasure, objection, restriction and portability by writing to citas@doctorcasals.com.
Where the request concerns medical record data or processing under the responsibility of Hospital Universitario Ruber Juan Bravo, it should be addressed to the hospital through its established channels.
A complaint may also be lodged with the Spanish Data Protection Agency.
2.13. Security and confidentiality
Technical and organisational measures appropriate to the risk are adopted. The booking system configuration applies data minimisation, access control, strong credentials and, where available, multi-factor authentication.
All healthcare information is subject to the obligations of secrecy and confidentiality inherent to the medical profession.
2.14. Minors
Where a booking concerns a minor, the data must be provided by a parent, guardian or legal representative where required under applicable law.
2.15. Changes
This Privacy Policy will be reviewed when the scheduling provider, its configuration, the data requested, connected integrations, the location of data or third-party services change.