Privacy policy
Last updated: April 16, 2026
1. Data controller
- Controller: Clínica Revita
- NIF: [pending]
- Address: Carrer de Santaló, 105, 08021 Barcelona
- Email: [email protected]
- Data protection contact (DPO): [email protected]
2. Data we collect
- Contact and booking data: name, telephone, email, reason for the visit, preferred times.
- Health data: whatever the patient provides voluntarily in comments or during the consultation (special category — art. 9 GDPR).
- Technical data: IP address, device and browser type, pages visited, date and time of access (see the Cookie policy).
- Conversations with the virtual assistant: messages exchanged with our chat, for the purpose of handling the request.
3. Purposes of processing
- Managing bookings, enquiries and communication with the patient.
- Providing the requested health services and maintaining the medical record.
- Handling requests sent through the contact form or the virtual assistant.
- Complying with legal obligations (invoicing, healthcare, tax).
- With your express consent: sending commercial information, news or reminders.
- Improving service quality and aggregated statistical analysis.
4. Legal basis
- Performance of a contract (art. 6.1.b GDPR) to manage bookings and deliver the health service.
- Compliance with a legal obligation (art. 6.1.c GDPR) in healthcare, tax and accounting matters (Law 41/2002).
- Vital interests (art. 9.2.c GDPR) and healthcare provision (art. 9.2.h GDPR) for the processing of health data.
- Consent (art. 6.1.a GDPR) for commercial communications and the use of non-essential cookies.
5. Retention
Health data is kept for a minimum of five years from the last visit in accordance with Law 41/2002, save for specific archiving periods. Accounting data is kept for six years (art. 30 of the Commercial Code). All other data is kept for the time strictly necessary for the purpose it was collected for, or until consent is withdrawn.
6. Recipients
We do not disclose your data to third parties except where legally required. We may work with processors (hosting, email delivery, analytics, conversational AI assistant), with whom we hold the corresponding processing agreements under art. 28 GDPR.
7. International transfers
Some providers may be located outside the European Economic Area (e.g. AI or analytics providers in the USA). In those cases, standard contractual clauses approved by the European Commission or accredited frameworks (Data Privacy Framework) apply.
8. Rights of the data subject
You may exercise your rights of access, rectification, erasure, objection, restriction, portability and withdrawal of consent at any time by emailing [email protected] together with a copy of your ID or equivalent document.
If you believe the processing does not comply with the regulations, you have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
9. Security measures
Clínica Revita adopts the technical and organisational measures necessary to guarantee the security of personal data and prevent its alteration, loss, unauthorised processing or access, in accordance with article 32 GDPR.
10. Minors
Children under 14 may not provide their data without the consent of their parents or guardians.