Data protection
Privacy policy
What information is handled when you visit the website, contact the practice or request an appointment, why it is used and how to exercise your rights.
Last updated: 21 September 2026
1. Controller
The controller is Juan Blesa Robles, NIF 77347147X, self-employed professional trading as Pulso en Cauce. Contact: contacto@pulsoencauce.es, +34 684 789 128 or Pl. de la Flor del Olivo, s/n, local, consulta interior, Centro, 14001 Córdoba. As an individual healthcare professional, no data protection officer has been appointed.
2. Information, purposes and legal bases
| Activity | Information and purpose | Legal basis |
|---|---|---|
| Enquiries and bookings | Identity, contact details, language, format, appointment type and availability, used to reply and arrange a possible appointment. | Steps requested before a contract: Article 6(1)(b) GDPR. |
| Health information | A request for psychological care and information voluntarily provided may reveal health data. | Where necessary to assess or provide psychological care: Articles 6(1)(b) and 9(2)(h) GDPR, under the responsibility of a healthcare professional bound by confidentiality. |
| Care and clinical record | Information necessary to assess, provide and document psychological care. | Articles 6(1)(b), 6(1)(c) and 9(2)(h), together with applicable healthcare law. |
| Administration and payment | Identification, financial and transaction data needed to manage the service. | Contract and legal obligations: Articles 6(1)(b) and 6(1)(c). |
| Security and claims | IP, date, time, technical logs and information needed to protect the site or handle rights and claims. | Legal obligation and legitimate interests: Articles 6(1)(c) and 6(1)(f). |
3. Data minimisation and contact channels
You do not need to describe your reason for seeking help or send diagnoses, reports, history or clinical documents to book. Keep the first contact to identification, contact details, preferred format, appointment type and availability. Google Calendar, email and WhatsApp should be used for operational information. Only send clinical documents through a channel agreed with the professional in advance.
4. Retention
Enquiries that do not lead to a professional relationship and cancelled bookings are kept only as long as needed and for no more than 12 months from the last communication, unless law or a claim requires longer. Clinical records are retained for the period required by healthcare law and for at least five years after discharge from each course of care. Tax and accounting records are retained for statutory periods.
5. Recipients and providers
Information is not sold or used for advertising. Access may be given only as necessary to Google Workspace, Calendar and Meet; WhatsApp Business/Meta when that channel is chosen; website hosting, delivery and security providers; and administrative or payment providers disclosed before use. Information may also be disclosed to authorities, courts, insurers or professional bodies where legally required or necessary for a claim.
If operational information is strictly necessary to facilitate access to the consulting room, it will be limited to the person’s name and appointment time. No clinical information will be shared for this purpose.
6. International transfers
Some technology providers may process information outside the European Economic Area. Where this amounts to an international transfer, an adequacy decision or appropriate safeguards such as standard contractual clauses and supplementary measures will be used in accordance with Articles 45 and 46.
7. Your rights
Where applicable, you may request access, correction, erasure, restriction, objection or portability by writing to contacto@pulsoencauce.es. Additional identification will only be requested when needed to verify identity. You may also complain to the Spanish Data Protection Agency (AEPD) or to the competent supervisory authority where you live.
8. Security, automated decisions and minors
Appropriate technical and organisational security measures, access controls and confidentiality duties are applied. No ordinary electronic channel is completely secure, so clinical documents should not be sent without prior agreement. There is no commercial profiling or solely automated decision-making with legal or similarly significant effects.
Contact and care for minors are organised according to age, maturity, family circumstances and applicable law. Representation will be verified where required and information will be provided in an understandable form.
9. Website and updates
To understand website use, we keep only daily aggregate counts of website openings and WhatsApp clicks, grouped by general source. The browser classifies the source without sending its full URL or the pages viewed to the counter. These statistics contain no personal identifiers, IP addresses, searches, phone numbers or message content. Measurement uses no cookies or browser storage and is not matched with bookings or clinical records.
Counters are stored in the website hosting and can only be read through administration access. Automatic cleanup during activity removes counters older than thirteen months; separate test counters are cleaned after seven days. A browser Do Not Track or Global Privacy Control signal disables measurement. Hosting security logs are handled separately as described in this policy.
The website currently uses no advertising analytics, profiling or native contact forms. This policy will be updated if providers, channels, functionality or legal requirements change.