Last update: November 2023
Confidentiality and security are core values of DOCTOMATIC. This means that we are committed to ensuring the privacy of our customers’ personal data at all times, and to collect only the information we need, and no more.
Below you will find all the necessary information about the personal data we collect, how we process it and your rights.
-
Who processes my personal data?
DOCTOMATIC, S.L.. (hereinafter, “DOCTOMATIC“), with NIF B06840276 and registered office at C/ Espronceda, 183, local 2, 08025, province of BARCELONA (SPAIN), may act in any of the following capacities:
- Data controller: You will be responsible for the processing when you establish relations on your own behalf with the data subjects or natural persons who are the owners of the personal data, given that Doctomatic makes available to its patients or
users an application for remote monitoring of their health data, which it makes available to their doctor in an automated way.
- Data Processor: A data processor is a person in charge of the processing when accessing the personal data of such data owners for the provision of the service contracted by a data controller.
For this purpose, DOCTOMATIC informs that it has an e-mail address (info@doctomatic.com) available to all users, and also informs that Doctomatic has the following web domain: https://www.doctomatic.com/
DOCTOMATIC processes your data in accordance with REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation).
-
Who monitors your personal data at DOCTOMATIC?
DOCTOMATIC’s Data Protection Officer, or DPD, is the guarantor of compliance with data protection regulations within DOCTOMATIC.
You may contact DOCTOMATIC’s Data Protection Officer at the following e-mail address: info@doctomatic.com
You can consult the appointment of our Data Protection Delegate on the website of the Spanish Data Protection Agency at the following link.
-
Who are the stakeholder groups?
The personal data collected and processed may come from the following parties:
-
Clients and Prospective Clients, users and/or patients in connection with the use of the DOCTOMATIC website:
-
- People who provided us with their data in the different forms on the website to make inquiries or obtain information about our products and services.
- People who purchased our license packs that are set out on the web.
- Persons who requested communications about news, products and services and / or promotions DOCTOMATIC.
- People who have downloaded our application via Google Play or Apple Store.
- Suppliers:
- Companies that share with us the personal data necessary to formalize a service contract (identification, contact, address, bank account…).
- Candidates:
- People who sent an application to enter into personnel selection processes.
- DOCTOMATIC employees or collaborators
- Current employees for the internal management of their employment relationship.
- Current collaborators for the management of services (health care personnel, physiotherapists, or any other professional or collaborator that offers services through DOCTOMATIC).
- Website visitors:
- People who browse our website and have accepted analytical cookies.
- Users of the chatbot incorporated in the DOCTOMATIC website.
-
What personal data do we process?
The following information is requested through the DOCTOMATIC website:
- Contact information: person in charge, position, health center, telephone number, country, city and number of patients.
-
For what purposes and on what grounds do we use personal data?
In DOCTOMATIC process personal data to respond to requests for information, fulfill your requests or provide contracted services.
This personal data is processed for the legitimate purposes indicated below.
-
DOCTOMATIC as Data Controller
Purpose | Interested parties | Data categories | Basis of legitimization | Retention period |
Formalization, development and execution of the contract
The processing of personal data of contact persons of our customers and suppliers is necessary for the execution of the contract between DOCTOMATIC and our customers and suppliers, as well as for the maintenance, development and execution of the contractual relationship. DOCTOMATIC treats the personal data of the contact persons of our customers and suppliers, among others, to manage the commercial and mercantile relationship with them. |
|
|
Execution of the contract | Once the services listed in the contract
have been completed, the data contained in the contract will be kept for 6 years, duly blocked, and without prejudice to the interested parties having duly exercised their rights of deletion or opposition prior to the end of this period. |
Process payments, collections and invoicing |
|
|
Execution of the contract | In accordance with Article 30 of the Spanish Commercial Code, billing |
In DOCTOMATIC,
we will process the data of our customers to send them invoices and collect the compensation agreed in the service contract. In the same way, DOCTOMATIC will treat the data of its suppliers to proceed to the payment of the agreed services. |
ls. | information (address, corporate email)
|
data will be kept for 6 years after they have been issued. | |
Response to
requests for information or contact or demo of Doctomatic In DOCTOMATIC we use the contact information provided to respond to your requests and inquiries about products and services, whether made through the form available on the websites. |
|
|
Express consent. | Once the
request has been resolved, the personal data will be kept, duly blocked, for one year. |
Sending commercial communicatio ns
DOCTOMATIC treats the contact information |
|
|
Consent | The data will be processed for this purpose as long as the data subject does not duly revoke his/her consent. |
provided to inform interested parties who consented to receive commercial information.
This information may be about products, services, activities, news, and/or any promotion that may be of interest and related to the activity of DOCTOMATIC. |
||||
Website visit analysis
DOCTOMATIC uses various techniques to collect information. These techniques may be used to obtain analytical data about visits and navigation through the pages of our websites. These analytics rely on the use of external services that have their own privacy policy. These companies may cross-reference browsing data with their internal records in order to use it for ad |
|
device, operating system and browser from which the pages are visited. |
Consent | Data will be retained in accordance with the terms identified in our Cookie Policy and the privacy policies of analytics cookie providers. |
personalization, even if you do not have a registered account with their services.
For more information, please see our Cookie Policy. |
navigation data: pages visited. |
- How do we protect personal data?
At DOCTOMATIC, we take technical and organizational security measures to protect your personal data from loss, misuse, unauthorized access or disclosure. Some of the measures we take include data encryption, restricted access to personal data and regular training of our staff on data protection.
-
How do we store personal data?
We store your personal data on secure cloud servers located in the European Union. We maintain technical and organizational measures to ensure the security of personal data and prevent its loss, misuse, unauthorized access or disclosure.
-
Who has access to your personal data?
DOCTOMATIC will only share your personal data with third parties where it is necessary to provide you with our services, where you have requested something from us that we are required to respond to, or where we are legally obliged to do so.
We may also communicate data to companies that provide us with services necessary for the ordinary and administrative activity of the company as data processors, in the framework of the provision of services such as:
- Payment and payment processing service providers.
- Selection process management providers
- Technology service providers, such as cloud hosting and data analytics service providers.
- Legal and financial advisors.
- Regulatory and governmental authorities, when necessary to comply with our legal obligations, or have been legally required by them.
-
International data transfer
As data controllers, we will share personal data between the different subsidiaries of the group, in Brazil and Mexico, based on legitimate corporate interest. In the event that these activities take place between countries in the European Economic Area and our subsidiaries located outside the European Economic Area, international transfers are made under contract and by signing the Standard Contractual Clauses approved by the European Commission: https://eur- lex.europa.eu/legal-content/ES/ALL/?uri=CELEX:32021D0914
-
How do I exercise my rights regarding my personal data?
Any person has the right to obtain information about the data that DOCTOMATIC is processing of its ownership. These are your rights:
- Interested parties have the right to access their personal data, as well as to request the rectification of inaccurate data or, where appropriate, to request its deletion when, among other reasons, the data is no longer necessary for the purposes for which it was collected.
- In certain circumstances, the interested parties may request the limitation of the processing of their data, in which case they will only be kept for the exercise or defense of claims.
- In certain circumstances and for reasons related to their particular situation, data subjects may object to the processing of their data. DOCTOMATIC will stop processing the data, except for compelling legitimate reasons, or the exercise or defense of possible claims.
- Portability: The data subject shall have the right to receive the personal data concerning him/her, which he/she has provided to DOCTOMATIC, in a structured, commonly used and machine-readable format when: a) the processing is based on consent or contract, and b) the processing is carried out by automated means.
We inform you of your right to file a complaint with the supervisory authority (www.aepd.es) in the event that the exercise of your rights here indicated has not been satisfied.
To exercise the aforementioned rights, you may contact: info@doctomatic.com. When doing so, please provide the following information:
- Name and surname
- Contact e-mail address
- Right you wish to exercise
- Data on which your request is based
We will resolve your request within a maximum period of one month, notifying you by e-mail.
-
How long will your personal data be kept?
We will retain your personal data for as long as necessary to provide you with our services or as long as necessary to comply with our legal obligations. When we no longer need your personal data, it will be securely deleted or anonymized.
For a specific retention period, please refer to the tables in Section 5 of this Privacy Policy.
-
Changes to our Privacy Policy
We reserve the right to update this Privacy Policy at any time. If we make significant changes to this Privacy Policy, we will inform you by posting a notice on our app or website, or by other appropriate means.
-
Contact information
If you have any questions or concerns about this privacy policy or how we treat your personal data, you may contact us via email at info@doctomatic.com.