Privacy policy
Last updated: 12 September 2026
This policy explains how the personal data of visitors to fisiofemenina.com and of patients who book a consultation or programme is processed, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on the protection of personal data and digital rights (LOPDGDD).
1. Data controller
- Identity: IT KNOWLEDGE GROUP SL, Tax ID B66306689
- Postal address: Calle Balmes 456, local esquerre, 08022 Barcelona (España)
- Email: laura@fisiofemenina.com
Healthcare is provided personally by Laura Camprubí Roca, registered physiotherapist no. 3878, who handles clinical information under the duty of professional secrecy.
2. Data we process
Depending on how you interact with us, we may process the following categories of data:
- Browsing data: the website is static and uses no analytics or advertising cookies. Only two technical cookies (language and cookie choice) are stored in your browser. The hosting provider may temporarily log IP addresses for security purposes.
- Booking data: full name, email, telephone, type of consultation, date and time, and any comments you add when booking through meetergo.
- Payment data: payment is made through a secure link from a payment service provider. We do not store card details; we only receive confirmation of payment and the details needed to issue the invoice.
- Health data: the information you choose to share about your symptoms, history, reports or tests, and the clinical notes from the consultation. This is special-category data and is processed with reinforced safeguards.
- Invoicing data: name, tax ID and address when you request an invoice (for example, for reimbursement by your health insurer).
3. Purposes and legal basis
| Purpose | Legal basis |
|---|---|
| Managing your booking, payment and communication before and after the consultation | Performance of the contract (art. 6.1.b GDPR) |
| Providing physiotherapy care by video call and drawing up your plan | Your explicit consent and healthcare provided by a professional bound by secrecy (art. 9.2.a and 9.2.h GDPR) |
| Keeping clinical records | Legal obligation (Spanish Law 41/2002 on patient autonomy) |
| Issuing and keeping invoices | Legal obligation (tax and commercial law) |
| Answering your email enquiries | Legitimate interest in handling your request (art. 6.1.f GDPR) |
| Keeping the website secure | Legitimate interest (art. 6.1.f GDPR) |
We make no automated decisions and build no profiles. We send no marketing communications.
4. Recipients and processors
We do not share your data with third parties unless legally required. To provide the service we use providers acting as data processors:
- meetergo GmbH (Germany): booking platform and calendar. Data hosted in the European Union.
- Google Ireland Ltd.: email (Google Workspace) and video calls (Google Meet). Google may transfer data to the United States under the EU-US Data Privacy Framework and standard contractual clauses.
- Amazon Web Services EMEA SARL: website hosting in the Ireland region (EU).
- Payment service provider named in the payment link you receive by email, which processes your card data as an independent controller under its own privacy policy.
5. Retention periods
- Clinical records: at least five years from the discharge date of each episode of care (art. 17 of Law 41/2002), and up to fifteen years for records that Catalan law (Law 21/2000) deems relevant.
- Booking data and communications: for the duration of the relationship and afterwards for the limitation periods of any liability (up to five years).
- Invoices: the period required by tax and commercial law (generally six years).
- Technical cookies: six months (cookie choice) and one year (language).
6. Your rights
You may at any time exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw any consent given, by writing to laura@fisiofemenina.com or to the postal address above, enclosing a copy of an identity document if there is reasonable doubt about your identity. We will reply within one month.
If you believe the processing does not comply with the law, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) or with the Catalan Data Protection Authority.
7. Security
We apply appropriate technical and organisational measures to protect your data: encrypted communications (HTTPS), restricted access to clinical information, providers with contractual data-protection guarantees, and the duty of professional secrecy. We recommend that you do not send clinical reports through channels other than those we indicate.
8. Minors
The services are intended for adults. If you are under 18, the booking must be made by your parent or legal guardian.
9. Changes to this policy
We may update this policy to reflect changes in the law or in the service. The current version is always the one published on this website, with its update date. The Spanish version is binding.