Data Processing Agreement
Last updated: 1 September 2026
1. What this document is and who it binds
This is the data processing agreement required by Article 28 of Regulation (EU) 2016/679 (GDPR). It forms part of the Terms and Conditions and is accepted when you subscribe to the Service, with no separate signature needed. If you would rather have a signed copy, email contact@darcemi.com and we will send you one.
- Controller: the client business (the clinic, practice or shop). Its end clients' data belongs to it, and it decides what happens to that data.
- Processor: Enrique Rodríguez Marty, owner of Darcemi, who processes it solely to provide the Service.
Plainly: Darcemi does nothing with your clients' data beyond what the application needs to work. We do not sell it, we do not share it with anyone other than the providers listed below, and we do not use it to train models or for our own business.
2. What is processed, whose, and why
The subject of this processing is the Service described in the Terms: appointment and calendar management, client records, communication over WhatsApp and email, consents, online booking and deposit payments.
| Item | Detail |
|---|---|
| Categories of data subjects | The Controller's end clients (patients, customers, animal owners…), people who request an appointment without becoming clients, and the Controller's staff with access to the panel. |
| Categories of data | Identifying data (name, phone, email), appointment data (date, service, professional, status, amount), the content of WhatsApp conversations and of the booking form, notes written by the Controller itself, and a record of accepted consents with their date and version. |
| Special categories | Health data (Art. 9 GDPR) may occur when a data subject writes it in a message or the Controller records it in a file. The Controller decides what gets recorded; Darcemi neither asks for it nor needs it to work. |
| Payment data | Handled by Stripe directly. Darcemi never stores card numbers: only the payment status and its Stripe identifier. |
| Operations | Collection, recording, structuring, storage, retrieval, disclosure to the sub-processors listed, and erasure. |
| Duration | That of the service contract, plus the return and erasure period in clause 10. |
3. Only on the Controller's instructions
Darcemi processes the data solely on the Controller's documented instructions. In practice those instructions are: the service contract itself, this document, and the Controller's use of the application — what it creates, configures and deletes from its panel.
If Darcemi believes an instruction infringes data protection law, it will say so before carrying it out. If a legal obligation required processing the data otherwise, the Controller will be informed beforehand, unless that same law forbids it on important grounds of public interest.
4. Confidentiality
Only those who need the data to provide the Service have access to it, under an express confidentiality commitment. That commitment survives the end of the relationship.
Darcemi support access to a client's panel is logged and visible to that client on its Activity screen: anyone entering from outside appears identified as support, with the date and what they did.
5. Security measures
These are the measures actually in place, not a generic list:
- Encryption in transit: all traffic runs over HTTPS with automatically renewed certificates. The database exposes no port to the internet.
- Passwords: stored with bcrypt and never in clear text. Changing or resetting a password invalidates every open session at once.
- Sessions: a cookie signed with HMAC-SHA256, marked httpOnly, secure and sameSite, with a sign-in attempt limit.
- Third-party secrets encrypted: the business's WhatsApp token and its Google Calendar token are stored encrypted with AES-256-GCM, not in plain text.
- Isolation between clients: every database query is scoped to the business identifier, and automated tests fail if a new query skips that filter. This is what guarantees one client cannot see another's data.
- Access control: by role (administration or front desk) and, if the business enables it, scoped to each professional's own calendar.
- Audit log: actions on data are recorded and the Controller can review them from its panel.
- Scheduled erasure: the periods in clause 10 are carried out by an automated process; they do not depend on anyone remembering.
Measures are reviewed periodically and may be replaced by equivalent or better ones.
6. Sub-processors
The Controller generally authorises Darcemi to use the following sub-processors, all under a processing agreement and with access limited to what they need:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hostinger | Hosting of the application and the database | Spain (EU) |
| Meta Platforms Ireland Ltd. | Sending and receiving WhatsApp Business messages | EU / USA |
| Google Ireland Ltd. | Sign-in and Google Calendar synchronisation | EU / USA |
| Stripe Payments Europe, Ltd. | Charging booking deposits | Ireland (EU) / USA |
| Resend, Inc. | Sending the Service's emails | USA |
| Groq, Inc. | Classifying the intent of messages written in free text | USA |
Darcemi will give 30 calendar days' notice of any new or changed sub-processor. During that period the Controller may object on reasonable data protection grounds; if the objection cannot be resolved, it may terminate the contract without penalty.
On Groq specifically: it receives the text of the message the end client writes in order to work out what they are asking for. It does not receive records, histories or files. It is the part that lets the bot understand natural language, and it can be switched off at the Controller's request, in which case the bot runs on its own rules and understands less.
7. International transfers
Sub-processors located outside the European Economic Area process the data under the Standard Contractual Clauses approved by the European Commission or under a valid adequacy decision, as applicable. Darcemi keeps that documentation available to any Controller who asks for it.
8. Help with data subject rights
If an end client exercises their rights — access, rectification, erasure, objection, restriction or portability — it is the Controller who must respond, because the data is theirs.
Darcemi helps with whatever is needed: if the Controller receives a request, the application lets it review, correct and delete the record from its panel. Anything that cannot be done there is done on written request to contact@darcemi.com at no extra cost. If a request reaches Darcemi by mistake, it is forwarded to the Controller without being answered.
Darcemi also assists the Controller with impact assessments and prior consultations with the supervisory authority, to the extent the information is on its side.
9. Security breaches
If Darcemi detects a security breach affecting the Controller's data, it will report it without undue delay and within 48 hours at the latest of becoming aware, with what is known at that point: what happened, which data and how many people are affected, the likely consequences and what is being done.
Notifying the supervisory authority and, where applicable, the data subjects is the Controller's responsibility, as the party with the relationship with them. Darcemi will provide everything needed to do so.
10. What happens when the contract ends
On termination, at the Controller's choice, Darcemi returns or erases the personal data processed on its behalf.
- For 30 calendar days after termination the data remains available for the Controller to export.
- After that period it is erased automatically, without anyone having to remember: it is a scheduled system process, and the erasure is logged as evidence that it ran.
- Only data a law requires us to keep is retained — invoicing, six years under the Spanish Commercial Code — blocked and not used for anything else.
Erasure extends to copies held by sub-processors, in line with their own periods.
11. Information and audit
Darcemi will make available to the Controller the information needed to demonstrate compliance with this agreement, and will allow audits — including inspections — carried out by the Controller or an auditor it appoints.
Thirty days' notice will be given, audits take place during business hours, no more than once a year unless there has been an incident or an authority requires it, and without compromising the security or confidentiality of other clients.
12. Liability
Each party is liable for its own breaches under the GDPR and subject to the limitation of liability agreed in the Terms and Conditions.
The Controller warrants that it has informed its end clients about the processing and that it has a legal basis for it — including, where health data is involved, the one required by Article 9 GDPR. Darcemi does not verify this: it has no way to, and that is where what a provider can know ends.
13. Requests from public authorities
A public authority may ask us for personal data. It is not handed over merely because it is requested: every request goes through the same procedure.
- Its legality is checked: who signs it, on what legal basis and with what scope. An informal request, one with no legal basis, or one from an authority without jurisdiction is not acted upon.
- The minimum is disclosed: only the specific data the request requires, never a dump of the account or data about other data subjects.
- It is documented: what was asked, what was handed over, when, who authorised it and on what reasoning. The record is kept.
- It is challenged where appropriate: if the request is unlawful, disproportionate or exceeds the powers of the authority making it, it is challenged through the available channels.
- The Controller is notified, unless the law expressly forbids it, so that it can take its own action.
As at the date of this document, Darcemi has received no such request.
14. Term, changes and governing law
This agreement is in force for as long as the service contract is, and as regards confidentiality and erasure, until those have been fulfilled.
If it changes, 30 days' notice will be given by email or from the panel, and the version in force will always be the one published on this page, with its update date at the top.
It is governed by Spanish law and by the GDPR. For any dispute, the parties submit to the Courts of Madrid.