Privacy Policy

In accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), Organic Law 3/2018 of 5 December on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD), and Law 41/2002 of 14 November on patient autonomy, users of this website and patients at the practice are hereby informed about the processing of their personal data. The data controller is Marian Jose Taboada Vázquez, with Tax Identification Number (NIF) 77463615Y, address for notification purposes at Calle Princesa 25, Madrid, email: Mariantaboadav@gmail.com and contact telephone number 623931925.

The personal data that may be collected includes identifying data (first name, surname, date of birth, email address, telephone number), administrative and tax details (tax identification number, billing address, bank details) and health-related data, which constitute special categories of data in accordance with Article 9 of the GDPR, such as relevant clinical information, medical history, medication use and any other information necessary for psychological assessment and therapeutic treatment. In certain cases, an emergency contact may also be requested to ensure the patient receives appropriate care.

The main purposes of data processing are to manage requests for information or appointments; to provide assessment and psychotherapy services; to compile, store and maintain medical records in accordance with healthcare regulations; to carry out the administrative, accounting and tax management arising from the professional relationship; and to comply with the legal and ethical obligations inherent in the practice of psychology. The data will be processed exclusively for these purposes and will not be used for any other incompatible purposes.

The legal basis for the processing is the data subject’s express, freely given, specific, informed and unambiguous consent to the processing of their personal data, including health data (Articles 6(1)(a) and 9(2)(a) of the GDPR), the performance of the contract for the provision of psychological services (Article 6(1)(b) of the GDPR), on compliance with legal obligations in the fields of healthcare and taxation (Article 6(1)(c) of the GDPR), on the protection of the patient’s vital interests in emergency situations (Articles 6(1)(d) and 9(2)(c) of the GDPR) and on the provision of healthcare within the framework of a regulated profession (Article 9(2)(h) of the GDPR).

Services may be provided in person or remotely. For online consultations, the Data Controller uses video-conferencing platforms such as Zoom, Google Meet and “It’s Complicated”. These providers act as data processors pursuant to Article 28 of the GDPR and have Data Processing Agreements in place to ensure compliance with the regulations. Certain features of these platforms involve international data transfers outside the European Economic Area, in particular to the United States, carried out on the basis of Standard Contractual Clauses approved by the European Commission, ensuring an adequate level of protection in accordance with Chapter V of the GDPR. Patients are informed that, when using these platforms, their data will be processed as described herein.

With regard to payments, the Data Controller states that, as a general rule, these are managed via the “It’s Complicated” platform, which acts as a data processor in accordance with Article 28 of the GDPR. In this case, the Data Controller does not access or store bank or card details, but merely receives confirmation of payment and the data necessary for invoicing and compliance with tax obligations. However, in certain cases, the patient may pay the fees directly to the Data Controller by bank transfer, Bizum or other agreed means of payment. In such cases, the Data Controller will process only the data essential for managing the transaction (first name, surname, amount, payment date and, where applicable, account number or transaction identifier), integrating this data into its invoicing and accounting system, retaining it for the periods required by tax regulations and ensuring its confidentiality through appropriate security measures.

The data will be retained for the periods required by law. In particular, medical records and health data will be retained for at least five years from the date of discharge from the care process, in accordance with Article 17 of Law 41/2002, unless regional regulations establish longer retention periods. Administrative, tax and accounting data will be retained for the limitation periods set out in tax legislation, generally four years in accordance with Article 66 of the General Tax Law. Once these periods have elapsed, the data will be blocked and will only be available to judges, courts and competent authorities for the duration of the statutory limitation periods, after which it will be permanently deleted.

The data will not be disclosed to third parties unless required by law or by the competent authorities. Access to the data will be restricted to certain technology and administrative service providers acting as data processors (hosting, email, appointment management, video conferencing and invoicing services), with whom the data processing agreements required under Article 28 of the GDPR have been formalised.

The data subject may, at any time, exercise their rights of access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to withdraw their consent, without this affecting the lawfulness of the processing carried out prior to the withdrawal (Articles 15 to 22 of the GDPR). To do so, they must contact the email address provided, enclosing a copy of a document proving their identity. Furthermore, the data subject has the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) if they consider that their rights have been infringed (Article 77 of the GDPR).

The Data Controller maintains an up-to-date Record of Processing Activities in accordance with Article 30 of the GDPR, which details the operations carried out on the data, the categories of data processed, the purposes, legal bases, retention periods, recipients and security measures applied. This record shall always be available to the Spanish Data Protection Agency and may be made available to data subjects upon request.

The Data Controller implements appropriate technical and organisational measures in accordance with Article 32 of the GDPR to ensure the confidentiality, integrity and availability of personal data, particularly that relating to health. These include restricted access controls, the use of secure passwords, encryption systems, servers meeting European standards, regular backups and protocols for the safekeeping of medical records. However, users are advised that electronic communications such as email or web forms can never guarantee absolute security, despite the measures in place; it is therefore recommended that the channels specifically designated for the exchange of sensitive clinical information be used.

Finally, the Practitioner is bound by the duty of professional confidentiality as set out in healthcare regulations and the Code of Ethics for Psychologists. Consequently, all information provided by patients will be treated with the utmost confidentiality, as professional confidentiality is an essential obligation, and may only be disclosed in cases where this is expressly required by a statutory provision or where it is essential for the protection of a patient’s vital interests.