Privacy notice pursuant to Art. 13 of Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on Personal Data Protection (LOPDGDD). This policy describes how personal data collected through the Normachica platform is processed.
1. Data Controller and Contact Details
The Data Controller for personal data collected through the Normachica platform is:
Norma Chica
Owner of the Normachica brand
Email: privacy@normachica.com
Website: www.normachica.com
For any request regarding the processing of personal data or the exercise of the rights set out in this policy, the data subject may contact the Controller at the above details.
The Controller has not appointed a Data Protection Officer (DPO), as such appointment is not mandatory under Art. 37 of the GDPR for the type and scale of processing carried out. Should this assessment change, this section will be updated with the relevant contact details.
2. Types of Personal Data Collected
In connection with the use of the Normachica platform, the Controller processes the following categories of personal data, pursuant to Art. 4 of the GDPR:
a) Identification and contact data
- First and last name
- Email address
- Phone number (if provided)
b) Service usage data
- Booking and appointment history
- Messages exchanged via the platform's internal chat
- User profile preferences and settings
c) Special categories of data (Art. 9 GDPR)
- Information relating to the user's physical and/or psychological wellbeing
- Online session history and related content, insofar as it may reveal health-related data or other sensitive aspects of the individual
d) Financial and payment data
- Transaction data (amount, date, reference) processed through the Stripe payment service. The Controller does not directly process credit/debit card data; Stripe handles payment data in compliance with PCI-DSS standards.
e) Technical browsing data
- IP address
- Browser type and device used
- Technical and session cookies
- Platform access and usage logs
3. Purposes of Processing
The personal data collected is processed for the following purposes:
- Service delivery: Management of registration, platform access, bookings and appointment scheduling.
- Online session management: Delivery of emotional wellbeing sessions conducted through the platform.
- Service communications: Sending booking confirmations, appointment reminders and service notifications.
- Internal chat: Management and storage of messages exchanged between user and professional via the platform chat, intended for organisational communications.
- Administrative and tax management: Issuance of receipts and invoices, fulfilment of accounting and tax obligations.
- Platform security: Prevention of unauthorised access, fraud and misuse of the platform.
- Technical support: Management of user support requests.
The Controller does not use personal data for marketing, commercial profiling or transfer to third parties for promotional purposes.
4. Legal Basis for Processing
The processing of personal data is carried out in compliance with the lawfulness criteria established by Arts. 6 and 9 of the GDPR:
- Performance of a contract (Art. 6(1)(b) GDPR): processing is necessary for the provision of the service requested by the user (booking, online sessions, account management).
- Compliance with legal obligations (Art. 6(1)(c) GDPR): processing is necessary to fulfil applicable tax, accounting and regulatory obligations.
- Legitimate interest of the Controller (Art. 6(1)(f) GDPR): processing is necessary to ensure platform security and prevent fraudulent use, insofar as such interest does not override the rights and freedoms of the data subject.
- Explicit consent of the data subject (Art. 9(2)(a) GDPR): for the processing of special category data relating to the user's health and wellbeing (e.g. session content, medical history). Such consent may be withdrawn at any time without affecting the lawfulness of processing carried out prior to withdrawal.
5. Recipients and Categories of Recipients
The personal data of data subjects may be communicated, exclusively for the purposes indicated in this policy, to the following categories of entities acting as Data Processors pursuant to Art. 28 of the GDPR:
- Stripe, Inc. — Data Processor (payment services) — transaction and payment data.
- Brevo (ex SendinBlue) — Data Processor (transactional emails) — name, email address, communication data.
- Vercel, Inc. — Data Processor (hosting and infrastructure) — technical data, access logs.
- Supabase, Inc. — Data Processor (database and backend) — all data held on the platform.
Personal data is not sold, transferred or shared with third parties for commercial or promotional purposes. The Controller uses the aforementioned providers exclusively to ensure the technical and operational functioning of the platform, entering into appropriate data processing agreements with each of them pursuant to Art. 28 of the GDPR.
Competent public authorities may also access the data in cases provided for by law.
6. Transfer of Data to Third Countries
Some of the technical providers listed above (in particular Stripe and Vercel) are based in the United States of America and may process users' personal data outside the European Economic Area (EEA).
Such transfers are carried out in compliance with the safeguards provided for in Art. 46 of the GDPR and, where applicable, on the basis of the European Commission's adequacy decision regarding the EU-US Data Privacy Framework (adopted on July 10, 2023), which recognises an adequate level of protection for transfers to US organisations adhering to the framework.
Supabase operates on infrastructure located within the European Union.
The data subject has the right to obtain a copy of the safeguards adopted for transfers to third countries by contacting the Controller at the details indicated in Section 1.
7. Data Retention Periods
Personal data is retained for the time strictly necessary to achieve the purposes for which it was collected, in accordance with the following criteria:
- Identification and profile data: for the duration of the contractual relationship and up to 2 years from account closure.
- Online session history: 5 years from the date of the session.
- Internal chat messages: 3 years from the last message exchanged.
- Tax and accounting data (invoices, receipts): 7 years, in compliance with tax law obligations.
- Technical browsing and access logs: 12 months from collection.
- Payment data (transaction references): 7 years, in compliance with applicable regulatory obligations.
Once the above periods have elapsed, data will be deleted or irreversibly anonymised, unless longer retention is necessary to comply with legal obligations, or for the establishment, exercise or defence of legal claims.
8. Data Subject Rights (ARCO-POL)
Pursuant to Art. 13(2)(b) of the GDPR, the data subject has the right to:
- Access (Art. 15 GDPR): obtain confirmation as to whether or not personal data concerning them is being processed and, if so, obtain a copy thereof.
- Rectification (Art. 16 GDPR): obtain the correction of inaccurate data or the completion of incomplete data.
- Erasure — right to be forgotten (Art. 17 GDPR): obtain the deletion of personal data, in the cases provided for by law.
- Restriction of processing (Art. 18 GDPR): obtain the restriction of processing in the cases provided for by law.
- Data portability (Art. 20 GDPR): receive personal data provided in a structured, commonly used and machine-readable format, and transmit it to another controller.
- Objection (Art. 21 GDPR): object at any time to the processing of personal data based on the Controller's legitimate interest.
- Withdrawal of consent (Art. 7(3) GDPR): withdraw at any time consent given for the processing of special category data, without affecting the lawfulness of processing carried out prior to withdrawal.
To exercise one or more of the above rights, the data subject may send a written request to the Controller via the details indicated in Section 1, or modify settings in their profile on the platform. The Controller will respond without undue delay and, in any case, within 30 days of receiving the request.
9. Right to Lodge a Complaint
Pursuant to Art. 13(2)(d) of the GDPR, the data subject has the right to lodge a complaint with the competent supervisory authority for data protection. Depending on the data subject's country of residence, the competent authorities are:
- Spain — Agencia Española de Protección de Datos (AEPD): www.aepd.es
- Italy — Garante per la protezione dei dati personali: www.garanteprivacy.it
- Austria — Datenschutzbehörde (DSB): www.dsb.gv.at
The data subject may also contact the supervisory authority of the Member State where they habitually reside or work, or the Member State where the alleged infringement occurred.
10. Nature of Data Provision
Pursuant to Art. 13(2)(e) of the GDPR, the following is specified:
- The provision of identification, contact and payment data is a contractual requirement necessary to use the service offered by the Normachica platform. Failure to provide such data makes it impossible to register, book sessions or use the platform.
- The provision of special category data relating to health and wellbeing is voluntary and subject to the explicit consent of the data subject. Failure to provide such data may limit the personalisation of the service, but will not prevent access to the platform's basic features.
- The provision of tax data required for invoicing is a legal obligation; failure to provide it prevents the fulfilment of applicable regulatory requirements.
11. Security and Processing Methods
The Controller adopts appropriate technical and organisational measures to ensure a level of security proportionate to the risks arising from the processing, in particular:
- Encryption of communications: all online sessions and data transmissions use cryptographic protocols (TLS/HTTPS) to protect data in transit from unauthorised access.
- Database security: stored data is subject to infrastructure-level security measures, including role-based access controls (RBAC), encryption at rest (AES-256), and Row Level Security policies.
- Internal messaging: messages exchanged via the platform's internal chat are accessible exclusively to the parties involved in the conversation and to the Controller for technical support and security purposes.
- Restricted access: access to personal data is reserved exclusively to authorised personnel and contractually bound data processors, within the limits strictly necessary for the performance of their respective functions.
- Vulnerability management: the Controller carries out periodic security reviews of the platform and adopts necessary corrective measures when vulnerabilities are identified.
In the event of a personal data breach (data breach) that may pose a risk to the rights and freedoms of data subjects, the Controller undertakes to notify the competent supervisory authority within 72 hours and, where necessary, the data subjects, in accordance with Arts. 33 and 34 of the GDPR.
11.1 Cookies
The platform uses only essential technical cookies required for the service to function (authentication and session management). No profiling, tracking or third-party cookies are used for advertising purposes. Therefore, no cookie consent banner is required under Directive 2002/58/EC.
11.2 Internal Chat
The platform provides an internal messaging function between the client and their assigned therapist, intended exclusively for organisational communications (schedules, rescheduling, document sharing, reminders). In particular:
- The chat is not intended for clinical content. Clinical communications must take place exclusively during scheduled sessions. A permanent notice is always visible in the chat interface.
- Messages are accessible exclusively to the sender and recipient. Administrative staff may access messages only for technical support purposes and with documented justification.
- If messages remain unread for more than 24 hours, the system sends an email notification. Users can manage their notification preferences from their profile.
- Messages are protected by encryption in transit (TLS) and at rest (AES-256 at infrastructure level). Access is controlled by Row Level Security policies.
11.3 Online Sessions
Sessions may take place via video call. To protect users' privacy:
- Video sessions use encrypted connections.
- Sessions are not recorded by the platform.
- Users are recommended to participate from a private location with a secure connection.
- The session link must not be shared with third parties.
12. Consent and Declarations
Pursuant to Art. 9(2)(a) of the GDPR, use of the platform requires the following consents, managed through the platform interface:
- Consent to processing of special category data (Art. 9 GDPR): the processing of health and wellbeing data requires the explicit consent of the data subject. Consent is optional and may be withdrawn at any time.
- Acknowledgement of communication to data processors: personal data will be communicated to the data processors indicated in Section 5 for the purposes of platform operation.
- Declaration of reading and understanding: the user declares that they have read and understood this policy, that they have been adequately informed about the purposes, methods and legal basis of the processing, as well as their rights and the methods for exercising them.
Consents can be managed and withdrawn at any time from the Privacy section of your profile on the platform.
13. Changes and Final Provisions
This policy is provided in compliance with Art. 13 of Regulation (EU) 2016/679 and may be updated by the Controller in the event of regulatory or operational changes. The current version is always available on the Normachica platform.
In the event of material changes affecting data processing, the Controller will inform data subjects via email or platform notification and, where necessary, request consent again.
The Data Controller
Norma Chica — Normachica
Back to home