Privacy policy

Last updated: [publication date]

1. Who is the controller

  • Data controller: [Full legal name or company name]
  • Tax ID (NIF/CIF): […]
  • Registered address: […]
  • Contact email: privacidad@darcemi.es

Darcemi is an appointment-management platform for businesses with premises (clinics, veterinary practices, hair salons, workshops, studios and similar), available at darcemi.es and on each client company's subdomain.

2. Two distinct roles, depending on whose data it is

This distinction is the key to understanding the rest of the document.

Darcemi is the controller of the data of the businesses that contract the service and of the people who use the administration panel: sign-up, billing, support, account security.

Darcemi is the processor of the data of the end customers (patients, users, the business's customers) that each business enters or generates on the platform. In that case the controller is the client business, which decides what data it collects and why. Darcemi only processes it following their instructions and under the data-processing agreement signed with them.

If you are an end customer of a business that uses Darcemi and want to exercise your rights, contact that business. If you contact us, we will forward your request to the controller.

3. What data we process

Of client businesses and their panel users: first and last name, email address, password (stored hashed, never in plain text), role and permissions, business details (name, address, phone, hours, services, professionals), billing data and activity and access logs.

Of end customers, on behalf of the business: name, phone, email if provided, appointment history, notes the professional records and the content of the conversations held over WhatsApp with the business.

Technical data: IP address, browser type, date and time of access and session identifiers, for security and abuse-prevention purposes.

4. Your Google account data

When you sign in with Google or connect your calendar, Darcemi requests the following permissions and only for what is stated:

Permission requestedWhat it is used for
openid, userinfo.email, userinfo.profileIdentify you when signing in, create or link your account and show your name and photo in the panel.
https://www.googleapis.com/auth/calendar.eventsCreate, update and cancel in your Google Calendar the events corresponding to the appointments managed in Darcemi, and read existing events so as not to offer slots that are already taken.

Limited Use. Darcemi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:

  • We do not sell Google user data to third parties.
  • We do not use it for advertising or to build advertising profiles.
  • We do not use it to train generalized or third-party artificial-intelligence models.
  • We do not transfer it except to the providers strictly necessary to deliver the service (section 7), to comply with the law or with your express consent.
  • No human reads it, unless you give us explicit permission for support cases, it is necessary for security or to comply with the law, or the data is aggregated and anonymized.

You can revoke access at any time from myaccount.google.com/permissions. When you revoke it, we stop syncing the calendar and delete the stored tokens; appointments already created in your Google Calendar remain under your control.

5. Why we process the data and on what legal basis

PurposeLegal basis
Provide the contracted service (agenda, appointments, panel, reminders)Performance of the contract
Process end-customer data on behalf of the businessData-processing agreement (art. 28 GDPR)
Security, fraud prevention and access loggingLegitimate interest
Billing and tax and accounting obligationsLegal obligation
Commercial communications about DarcemiConsent, revocable at any time

6. How long we keep it

For as long as the contract is in force. When it ends, the client business's data is kept for 30 days to allow its export and is then deleted or anonymized, except for what the law requires to be kept (billing: six years under the Commercial Code). Security logs are kept for 12 months.

7. Who we share data with

We do not sell data. We rely on the following providers, all with a data-processing agreement:

ProviderWhat forLocation
Hostinger (VPS)Hosting of the application and the database (VPS managed with Dokploy)Spain (EU)
Meta Platforms Ireland Ltd.Sending and receiving messages over WhatsApp BusinessEU / USA
Google Ireland Ltd.Sign-in and Google Calendar syncEU / USA
Groq, Inc.Optional classification of the intent of free-text messagesUSA

We also disclose it to public authorities when there is a legal obligation.

About Groq: the conversational bot works deterministically with its own rules. Language-model classification is an optional add-on and can be disabled; when active, the end customer's message text is sent to classify its intent. No clinical histories or files are sent.

8. International transfers

Some providers process data outside the European Economic Area. In those cases the transfer relies on the standard contractual clauses approved by the European Commission and, where applicable, on the EU–US Data Privacy Framework.

9. Your rights

You can exercise the rights of access, rectification, erasure, objection, restriction, portability and not to be subject to automated decisions by writing to privacidad@darcemi.es, proving your identity. We will respond within a maximum of one month.

If you believe we have not handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency (aepd.es).

10. Security

We encrypt traffic with TLS, store passwords hashed with bcrypt, isolate each client business's data by client identifier in every query, apply role-based access control, limit sign-in attempts and log administrative actions.

No system is invulnerable. If a breach occurs that poses a high risk to your rights, we will notify you and report it to the AEPD within 72 hours of detecting it.

11. Minors

Darcemi is aimed at businesses. We do not create panel accounts for people under 18. If a client business records data of minors as end customers, it is that business that must obtain the consent of the holders of parental authority.

12. Cookies

We use only technical cookies necessary to maintain the session and the language and theme preference. We do not use advertising cookies or third-party analytics.

13. Changes to this policy

If we change this policy, we will publish the new version at this same address and update the date in the header. If the change is substantial, we will notify client businesses by email at least 30 days in advance.

Privacy policy · Darcemi