Privacy Policy
Last updated: 21 May 2026 · Version 2.0
Kliniqa processes your personal data with the utmost responsibility and in accordance with Regulation (EU) 2016/679 (GDPR), Portuguese Law No. 58/2019 and other applicable national legislation. This document fulfils the information duties of Articles 13 and 14 of the GDPR.
This platform processes health data (special category under GDPR Art. 9(2)(h) - provision of care by a professional bound by medical secrecy). HIPAA (US law) compliance is not applicable or claimed; the service is not directed at US residents.
Table of Contents
1. Data Controller
Pursuant to Article 13 GDPR and Article 10 of Portuguese Decree-Law No. 7/2004, the data controller is the individual healthcare professional operating the Kliniqa service as a self-employed practitioner (trabalhadora independente):
Name: Daniela Jaramillo Alzate Portuguese Tax Number (NIF): 316 151 297 Medical Council Licence (Ordem dos Médicos): 77592 Health Regulatory Authority (ERS) Registration: E182294 Professional Address: Avenida Gonçalo Ribeiro Telles, 400, 4405-732 Vila Nova de Gaia, Portugal Email: geral@kliniqa.net Phone: +351 933 496 991
"Kliniqa" is the trade name under which the service is provided. There is no separate company - all processing activities are imputable to the practitioner identified above, in her individual professional capacity and bound by medical professional secrecy under Article 139 of the Statute of the Portuguese Medical Council and Article 195 of the Portuguese Penal Code.
2. Data Protection Officer (DPO)
As of this date, Kliniqa has NOT appointed a Data Protection Officer (DPO). This is lawful: Article 37(1)(c) GDPR requires DPO appointment only where "core activities consist of processing on a large scale" of health data, and EDPB Guidelines 243 rev.01 § 2.1.3 explicitly cite "an individual physician" as an example that does NOT constitute large-scale processing.
Commitment: the controller actively monitors patient volume, associated practitioner count, and processing typology. A DPO will be appointed - and this document updated - as soon as the quantitative or qualitative thresholds for "large-scale" processing under CNPD and EDPB guidance are reached.
Until then, all data protection enquiries may be addressed directly to the controller at geral@kliniqa.net, with response within 30 days.
3. Personal Data Collected
Kliniqa collects the following categories of data, only for the period strictly necessary for the purposes listed in section 6:
▸ Identification: full name, date of birth, national ID number, NHS patient number, gender. ▸ Contact: email, phone number, postal address. ▸ Access & security: IP address, browser identifier, session timestamps (fraud prevention and security incident investigation). ▸ Payment: last 4 digits, card brand, payment token issued by Stripe. Full card numbers are NEVER transmitted to Kliniqa servers - they are handled directly by Stripe in a PCI-DSS certified environment.
⚠️ Health Data (Special Category - GDPR Art. 9): Kliniqa processes health data including clinical complaints, personal and family medical history, current medication, diagnoses, test results, prescriptions, clinical reports, video consultation notes and any other data relating to physical or mental health. This data benefits from the enhanced protection of Article 9 GDPR and is processed under medical professional secrecy.
4. Source of Data (GDPR Art. 14)
The vast majority of personal data is collected directly from the data subject (the patient) at registration, booking, and during the consultation.
Exceptionally, data may be collected from third parties in the following situations: (i) paediatric consultations - minor data provided by the legal guardian; (ii) referrals between doctors - when another healthcare professional sends clinical information with the patient's consent; (iii) future NHS integrations - only with the patient's explicit consent.
Whenever data is not collected directly from the subject, Kliniqa provides - within the Art. 14(3) GDPR timeframe - information about the source, categories processed and subject's rights.
5. Legal Basis for Processing
Processing rests on the following cumulative grounds, depending on the data category:
▸ For ordinary personal data (identification, contact, payment): • Art. 6(1)(b) GDPR - performance of the medical care contract. • Art. 6(1)(c) GDPR - compliance with legal obligations (invoicing, taxation, clinical record retention). • Art. 6(1)(f) GDPR - legitimate interests (fraud prevention, platform security), only where these do not override fundamental rights.
▸ For health data (special category - GDPR Art. 9): • Art. 9(2)(h) GDPR - processing necessary for medical diagnosis, the provision of health or social care or treatment, carried out by a health professional bound by professional secrecy. This is the primary basis and the appropriate one for telemedicine. • Art. 9(2)(a) GDPR - explicit consent only for non-essential processing (e.g. marketing communications, clinical research participation).
Article 9(2)(h) is robust and does not depend on consent, avoiding the contradiction noted by the EDPB (Guidelines 05/2020) whereby consent is not "freely given" when refusal means inability to access a necessary service.
6. Purposes of Processing
Data is processed exclusively for the following purposes:
▸ Provision of medical services (booking, identification, video consultation, clinical report, e-prescription, referrals). ▸ Payment processing and electronic invoicing. ▸ Compliance with legal obligations (clinical records - Decree-Law 48/95; tax - VAT Code). ▸ Platform security and fraud prevention. ▸ Handling data subject rights requests (GDPR Arts. 15–22). ▸ Strictly operational email communications (booking confirmation, consultation reminder, report delivery).
Data is NOT used for advertising profiling, sale to third parties, training of generative AI models, or any other purpose incompatible with those listed above.
7. Recipients & Sub-processors (GDPR Art. 28)
Your data is accessed exclusively by: (i) the responsible practitioner; (ii) any collaborating physicians on the platform, equally bound by professional secrecy; (iii) the technical sub-processors below, strictly within their assigned tasks.
Active sub-processors: ▸ Supabase, Inc. - database and authentication hosting. Data stored on EU servers (Frankfurt, Germany). ▸ Stripe Payments Europe, Ltd. - payment processing. Headquartered in Ireland (EU); fraud-screening transfers to the US under Standard Contractual Clauses (Decision 2021/914). ▸ Resend, Inc. - transactional email delivery. US-established; transfers under SCCs. ▸ PostHog Inc. - usage analytics. EU servers (Frankfurt). Only activated with analytics-cookie consent. ▸ Vercel Inc. - web application hosting and CDN. Global edge servers; European traffic served from the EU.
All sub-processors are bound by GDPR-compliant data processing agreements. The current list (including future additions) is available on request at geral@kliniqa.net.
8. International Data Transfers
Kliniqa always seeks to process data within the European Economic Area (EEA). When transfers to third countries occur (notably the US), they take place exclusively under Chapter V GDPR mechanisms - namely Standard Contractual Clauses (Commission Decision (EU) 2021/914) and, where applicable, supplementary technical measures (encryption in transit and at rest, pseudonymisation).
You may request a copy of the SCCs and Transfer Impact Assessment (TIA) carried out for each non-EU sub-processor by contacting geral@kliniqa.net.
9. Data Retention
Data is retained for the minimum legal periods applicable to each category:
▸ Clinical records: 5 years after the last consultation, pursuant to Article 3 of Decree-Law 48/95 and DGS clinical records rules. For minors, the period runs from majority. ▸ Billing and tax data: 10 years, per Article 52 of the Portuguese VAT Code and Article 123 of the Corporate Income Tax Code. ▸ Account data (without clinical records): until account closure plus 30 days for accidental-reactivation grace period. ▸ Access logs and security records: 12 months. ▸ Consent records (GDPR Art. 7(1)): 5 years after withdrawal or expiry.
Once retention periods expire, data is securely deleted or irreversibly anonymised. Erasure requests under Art. 17 do not override the legal retention obligations above, as expressly permitted by Art. 17(3)(b) GDPR.
10. Data Subject Rights
Under Articles 15 to 22 GDPR, you have the right to:
▸ Access (Art. 15) - obtain confirmation of processing and a readable copy of your data. Self-service: Personal Area → Privacy → "Request access". ▸ Rectification (Art. 16) - correct inaccurate data. Most fields editable directly in Personal Area → Profile. For clinical record corrections, contact the practitioner. ▸ Erasure (Art. 17) - self-service: Personal Area → Privacy → "Request deletion". Subject to mandatory retention exceptions (clinical records, tax). ▸ Portability (Art. 20) - self-service: Personal Area → Privacy → "Export my data". ▸ Restriction (Art. 18) - by written request to geral@kliniqa.net. ▸ Object (Art. 21) - by written request to geral@kliniqa.net. For direct marketing, opt out via the unsubscribe link in every email. ▸ Not be subject to automated individual decisions (Art. 22) - see section 13.
All requests are handled free of charge within 30 days (extendable to 90 days in clearly complex cases, with prior notice). Manifestly unfounded or excessive requests, particularly repetitive ones, may incur a reasonable fee or be refused (Art. 12(5) GDPR).
11. Withdrawal of Consent
Where a processing operation is based on your consent (analytics/marketing cookies, promotional emails, research-sharing), you may withdraw it at any time, with prospective effect, without affecting the lawfulness of previous processing.
IMPORTANT: the processing of health data for the provision of care is NOT based on your consent (it is based on Art. 9(2)(h) GDPR). Therefore "consent withdrawal" does not stop the medical service. If you wish to stop using the platform, you can close your account - clinical records are retained for the legal minimum and then deleted.
To withdraw consents, visit Personal Area → Privacy → Cookie Preferences, or contact geral@kliniqa.net.
12. Minors
Under Article 8 GDPR and Article 16 of Law 58/2019, processing of children's personal data based on consent is lawful only where the child is at least 13 years of age (Portugal exercised the GDPR option to lower the default 16-year threshold to 13).
For users under 13, consent must be given by the holder of parental responsibility. In any case, for paediatric consultations, the legal guardian creates the account, books the appointment and is present during it.
Kliniqa takes reasonable steps to verify user age at registration. If you become aware that we have inadvertently collected data from a minor without proper parental consent, contact geral@kliniqa.net immediately for deletion.
13. Automated Decisions and AI
Kliniqa does NOT make decisions with legal or significant effects solely based on automated processing (Art. 22 GDPR). All medical acts - diagnoses, prescriptions, certificates - are the sole responsibility of the human medical professional, in the exercise of her autonomous clinical judgement.
Some support features may use AI systems, namely: (i) triage suggestions to help categorise requests; (ii) automated video transcription (only with patient consent, with limited retention). These systems are merely auxiliary and do not replace clinical judgement. The patient has the right to request human intervention, express their point of view, and contest decisions in which automated systems played a relevant role.
14. Security & Breach Notification
We apply technical and organisational measures appropriate to the nature of the data (Art. 32 GDPR), including: encryption in transit (TLS 1.3) and at rest (AES-256), multi-factor authentication for admin access, environment segregation, audit logs, role-based access control (RBAC), encrypted backups, and periodic security reviews.
In the event of a personal data breach likely to result in risk to your rights and freedoms, Kliniqa will notify the CNPD within 72 hours (Art. 33 GDPR). Where the breach is likely to result in high risk, we will communicate directly to affected subjects (Art. 34 GDPR).
16. Right to Lodge a Complaint (CNPD)
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with the competent supervisory authority in Portugal:
Comissão Nacional de Proteção de Dados (CNPD) Av. D. Carlos I, 134, 1.º, 1200-651 Lisbon Phone: +351 213 928 400 Email: geral@cnpd.pt Website: www.cnpd.pt
Without prejudice to this right, we encourage you to contact us first at geral@kliniqa.net so we can try to resolve your matter directly.
17. Policy Changes
Kliniqa may update this Policy to reflect material changes in processing practices, applicable legislation, or services provided. When a material change occurs, the policy version is incremented and the cookie consent banner is re-shown for reconfirmation.
Material changes are additionally communicated by email with at least 30 days' notice to active users. The date and version at the top of this document indicate the current revision.
18. Contact
To exercise rights, for privacy questions or information requests: 📧 geral@kliniqa.net 📞 +351 933 496 991 (Mon–Fri, 9am–6pm, Lisbon time) 📮 Daniela Jaramillo Alzate · Avenida Gonçalo Ribeiro Telles, 400 · 4405-732 Vila Nova de Gaia, Portugal
We aim to respond within 30 days, extendable to 90 days in complex cases (with notice to the subject within the first 30).
Privacy questions? Contact geral@kliniqa.net
Back to home