This policy explains what personal data are processed through doctorcaudevilla.com and in the medical consultation, for what purpose, and what rights you have. It is drafted in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
Who the data controller is
- Controller: Fernando Caudevilla Gálligo
- Tax ID (NIF): 51061981A
- Address: Calle López de Hoyos 133, 28002 Madrid, Spain
- Contact address for data protection matters: caudevilla@gmail.com
- Telephone: (+34) 608 40 70 19
- Health centre: Regional Government of Madrid registration CS14162
There is no obligation to appoint a Data Protection Officer, so enquiries are handled at the address given above.
What data are processed, and why
1. Medical care (the consultation)
Data: identifying and contact details (name, telephone, email) and health data, including data on substance use, sex life and sexual orientation where these are relevant to your care.
Purpose: to provide medical care, to compile and keep the clinical record, and to follow up the process.
Legal basis: article 9.2(h) GDPR, processing necessary for healthcare by a professional bound by professional secrecy, read together with Spanish Law 41/2002 on patient autonomy. Performance of the care relationship you requested (article 6.1(b)) provides the basis for processing contact details.
Retention: the clinical record is kept for at least five years from the discharge date of each episode of care, in accordance with article 17 of Law 41/2002 and applicable regional legislation.
2. Appointment requests and enquiries by email or telephone
Data: whatever you provide when you write or call.
Purpose: to deal with your request and arrange the appointment.
Legal basis: your consent and the pre-contractual steps you requested (articles 6.1(a) and 6.1(b) GDPR). If your message contains health data, the processing additionally relies on your explicit consent (article 9.2(a)).
Retention: as long as needed to deal with the request. If it does not lead to a consultation, it is deleted.
3. Browsing and audience measurement
Data: IP address, cookie identifiers, pages visited, device and browser type.
Purpose: to understand, in aggregate, how the site is used so that it can be improved.
Legal basis: your consent, given through the cookie notice (article 6.1(a)). If you do not accept, no measurement takes place.
Retention: as set out in the cookie policy.
4. Site security
Data: server access logs, including the IP address.
Purpose: to maintain security and detect abusive use.
Legal basis: legitimate interest in protecting the site and the people who use it (article 6.1(f)).
Retention: the hosting provider’s retention period.
Confidentiality and medical secrecy
What you share in the consultation is covered by professional secrecy. Patient data are held in a file with the level of security corresponding to health data, and are processed in accordance with the LOPDGDD and Law 41/2002 on patient autonomy.
If you need reinforced confidentiality for a first contact, write to the Proton address and encrypt the message with the PGP key published on this site. It is the most protected route available.
Who the data are shared with
Personal data are neither sold nor transferred to third parties for commercial purposes. Only the following providers are involved, as data processors and under a contract compliant with article 28 GDPR:
- IONOS SE (Germany, European Union) — hosting of the site and the server logs.
- Google Ireland Ltd. / Google LLC — the general contact address is a Gmail account.
- Proton AG (Switzerland) — encrypted email for correspondence requiring greater confidentiality.
- Google Ireland Ltd. — Google Analytics, only if you accept the analytics cookies.
- CookieYes Ltd. — cookie consent management.
- Google LLC / YouTube — only if you play an embedded video.
Data will also be disclosed where there is a legal obligation to do so.
Where the data are processed
The website and its logs are hosted on IONOS SE servers located in the European Union.
Email correspondence is handled by two different providers:
- The general contact address is a Gmail account. Google may process the content of messages on servers in the United States, under the EU–US Data Privacy Framework. If you include information about your health in an email, that information is subject to such processing.
- For correspondence requiring greater confidentiality, a Proton address is offered (Switzerland, a country with a European Commission adequacy decision) along with a PGP key you can use to encrypt the message end to end. If you are going to share sensitive data before the first consultation, this is the recommended route.
Analytics cookies and embedded videos involve processing by Google, which may process data in the United States under the same framework. They are only activated if you give your consent.
The clinical record arising from the consultation is not held on services outside the European Economic Area.
What rights you have
You can exercise the following rights by writing to the contact address given above and proving your identity:
- Access: to know what data about you are processed.
- Rectification: to correct inaccurate data.
- Erasure: to request deletion, subject to the mandatory retention periods for the clinical record.
- Restriction: to ask for processing to be suspended while a complaint is resolved.
- Portability: to receive your data in a structured, commonly used format.
- Objection: to object to processing based on legitimate interest.
- Withdrawal of consent: at any time, without affecting the lawfulness of processing carried out beforehand.
A reply will be given within one month at most. If you believe your rights have not been properly attended to, you can complain to the Spanish Data Protection Agency (www.aepd.es, C/ Jorge Juan 6, 28001 Madrid).
Minors
This site and the consultation are aimed at people over 18. Data on minors are not knowingly requested or processed without the consent of whoever holds parental responsibility or guardianship.
Security measures
The site is served exclusively over an encrypted connection (HTTPS). Technical and organisational measures appropriate to the risk are applied, bearing in mind that special categories of data are processed.
Changes to this policy
This policy may be updated to reflect changes in legislation or in the services used. The date of the last revision appears at the top of the page.