Privacy policy
This policy describes personal-data processing on the Podología Priego website. It does not cover clinical records kept at the practice (Spanish Act 41/2002), which are explained in the clinic at the time of care.
1. Controller
Sonia Aguilera Montes, professional address Av. América 17, 14800 Priego de Córdoba (Córdoba), Spain. Email: podologiapriego@gmail.com. Phone: 957 540 169.
No data-protection officer is appointed: the website processing described here does not require one. You may exercise rights with the controller at the addresses above.
2. Data processed on this website
Only data you provide or that the site generates technically:
- Contact form: name, email, optional phone, message and the consent tick. Kept for 365 days unless a claim requires longer.
- Blog comments: name, email, text, date and a technical hash of the IP address for abuse control. Comments are published only after review. Kept while the article is published or until you ask for erasure.
- Staff accounts: email, display name, password hash, roles, locale preference, last activity and device-security signals (cookie
di_obs). There is no public patient registration. - Cookie-consent log: your choice, categories, an anonymous key and technical metadata (GDPR accountability).
- Administrative HTTP log: path, status, duration, redacted headers, user id and client IP, for 30 days, for security and debugging.
- Operational email: if a staff member uses password reset or a magic link, a transactional message is sent to their account (not marketing).
If a contact message includes health data (symptoms, treatments), it is special-category data (GDPR Art. 9) used only to answer that enquiry, with the explicit consent given when you submit the form.
3. Purposes and legal bases
- Answering messages and helping you book: GDPR Art. 6(1)(a) (consent) and 6(1)(b) (steps at your request before a contract).
- Publishing moderated comments: Art. 6(1)(a).
- Staff sign-in and protecting the private area: Art. 6(1)(b), 6(1)(c) and 6(1)(f) (clinic security).
- Strictly necessary cookies and the consent record: Art. 6(1)(c) and 6(1)(f), plus the LSSI exception for what the service cannot work without.
- Optional cookies (preferences, analytics, marketing): Art. 6(1)(a). Google Analytics / GTM (analytics) and Meta Pixel (marketing) load only after you accept the matching category, and only when the operator has set the corresponding IDs. Hotjar, Clarity, LinkedIn and TikTok follow the same rule if those IDs are filled.
- Calls, WhatsApp or email you start: 6(1)(b) / 6(1)(f), and the provider’s terms (Google or Meta) once the message leaves our systems.
4. Recipients
Data are not sold. The following may access them under GDPR Art. 28:
- Google Ireland Limited, for Google Analytics / Tag Manager when you accept analytics, and if podologiapriego@gmail.com (Gmail) is used to read or answer enquiries.
- Meta Platforms Ireland Limited, for the Meta Pixel when you accept marketing, and if you write on WhatsApp or open the linked Facebook or Instagram pages.
- Hosting, transactional-mail or backup providers the controller contracts in the EEA, solely to run this site.
- Public authorities or courts where the law requires it.
The site runs on infrastructure controlled by the publisher, with processing intended in the European Union. Using Gmail or WhatsApp may involve those providers’ international transfers (standard contractual clauses and adequacy decisions they publish). You choose those channels when you write.
5. Retention
- Contact form: 365 days.
- Comments: while the content is published or until erasure.
- Staff accounts: until deletion or anonymisation.
- HTTP log: 30 days.
- Cookie-consent log: aligned with consent-cookie lifetime (one year, unless longer is needed to demonstrate compliance).
- Clinical records: off this website, under health-care law.
6. Your rights
You may request access, rectification, erasure, restriction, portability, objection and withdrawal of consent, without affecting earlier lawfulness. Write to podologiapriego@gmail.com or visit the clinic. If you are not satisfied, you may complain to the Spanish Data Protection Agency (www.aepd.es).
Authorised staff can export or anonymise accounts from the private area. Contact-form submissions are handled through the same rights channel.
7. Children
The site is not aimed at children under 14. Do not create accounts or send a child’s data without the person who holds parental authority or guardianship.
8. Security
Reasonable technical measures are used (HTTPS, hashed passwords, HttpOnly cookies, secret redaction in logs). No system is infallible.
9. Changes
If processing changes in a material way, this policy and the date above will be updated.