Privacy Policy

Last updated: 30 September 2026

Summary in three sentences: we process only the data needed to provide the service. Your clinic's data and your patients' data belong to your clinic — we only process it on your behalf. You can request export or deletion of your data, subject to the timeframes and limits described below.

1. Who the controller is

Tiago Castro, Barcelona, Spain. For any question about personal data, use privacy@nuve.one.

For end-patient data — not our customers, but the people treated at the clinics that use the Platform — the clinic is the controller and Nuve One is the processor, under Art. 28 GDPR.

2. What data we process

Clinic account data:

  • Clinic name, email, phone, address and clinic country.
  • Name and email of users (administrators, professionals, receptionists).
  • Password hash (never the password in clear text).
  • Login IP, user agent and access timestamps (audit records).
  • Billing data. Card payments are processed by the payment gateway; we do not store card numbers.

End-patient data, entered by the clinic:

  • Name, contact details, date of birth, address.
  • Clinical history, anamnesis and procedures performed.
  • Before/after photographs, stored in AWS S3.
  • Payments and estimates.

Data collected in public forms:

  • The public contact form uses Cloudflare Turnstile as anti-bot protection. The widget generates a token that the Platform sends to Cloudflare together with the visitor's IP address to validate the submission.
  • The public patient pre-registration form collects the data the visitor enters themselves and delivers it to the designated clinic.

Audience measurement data from the public site (only if you accept in the cookie notice):

  • On the public pages (home, contact, FAQ, help, changelog, privacy and terms), Google Analytics 4 receives the IP address, a pseudonymous browser identifier (stored in the _ga cookies), the address of each page visited, where the visit came from, the device and browser type, the approximate region, time on the page, scrolling, clicks on links and highlighted buttons, the start of your interaction with the contact form, and the fact that the form was submitted.
  • We do not send names, email addresses, phone numbers, typed text or any clinic or patient data: the content of forms is never sent. The tool is not loaded on the login, sign-up, clinic dashboard, admin, online booking or patient pre-registration pages.

Technical data processed by Cloudflare when providing DNS and edge services: domain DNS queries and records; IP address; routing and configuration data; and HTTP/HTTPS request properties, including path/URL, headers and, when required for routing, caching or security inspection, request and response content.

For Turnstile, Cloudflare processes the IP address, TLS fingerprint, User-Agent header, sitekey and associated origin, visitor and browser-environment signals, and the token generated by the widget. The Turnstile service does not access, store or transmit form fields; those fields may separately transit through Cloudflare's proxy as part of the request to the Platform.

Health data is a special category under the GDPR (Art. 9). Processing by the clinic is generally based on the provision of care (Art. 9(2)(h)). The clinic must obtain informed consent from its patients or justify another appropriate legal basis.

3. Legal basis for processing

  • Performance of the contract (Art. 6(1)(b) GDPR): creating and managing the account, providing the service.
  • Legal obligation (Art. 6(1)(c)): retention of invoices for tax purposes.
  • Legitimate interest (Art. 6(1)(f)): platform security, abuse and fraud prevention, service improvement.
  • Consent (Art. 6(1)(a)): marketing emails, with explicit opt-in.
  • Consent (Art. 6(1)(a)): audience measurement of the public site with Google Analytics, only after you accept in the cookie notice.

4. Retention periods

  • Active account data: for as long as the account is active.
  • After closure: the account is deactivated and the data is no longer reachable in the product. Definitive deletion is carried out through a controlled manual process, with the timeframe communicated when the request is handled. In this version, physical deletion of a clinic is deliberately contained in the Platform and does not happen automatically.
  • Retention and legal hold: we may retain data beyond a deletion request where there is a legal obligation, litigation, a request from a competent authority, or an ongoing security investigation. In that case we state the reason and the expected duration.
  • Invoices: 6 years, under Spanish tax obligations, or the applicable local period.
  • Audit records: the configured retention rule is 7 years, for both Spain and Portugal. In this version there is no automatic purge — audit records are append-only and stay in the database until a purge process is implemented.
  • Backups: the local copy on the server is kept on a 30-day rotation. The off-site copy in AWS S3 follows its own lifecycle (infrequent-access storage, then Glacier, then expiry), with a longer period than the local copy.
  • Files and photographs: deleting a file in the product removes the reference, but does not immediately remove the object from S3 storage. Removal of the object depends on a controlled storage lifecycle process.
  • Patient clinical records: the clinic sets the period according to applicable law.
  • Audience measurement (Google Analytics): 14 months, the event retention configured on the Google Analytics property.

5. Your rights

Under the GDPR (Arts. 15 to 22) you have the right to:

  • Access: know what data we hold about you.
  • Rectification: correct inaccurate data.
  • Erasure: request deletion, within the limits described in section 4.
  • Restriction: ask us to stop a certain type of processing.
  • Portability: export your data in a machine-readable format.
  • Objection: object to processing based on legitimate interest.
  • Withdraw consent: where processing is based on consent.
  • Complaint: lodge a complaint with the competent supervisory authority.

To exercise any of these rights, write to privacy@nuve.one. We respond within 30 days.

6. Processors and third parties

We use the following providers, each with its own compliance safeguards:

ProviderPurposeLocation
AWS (EC2 and S3)Application and database hosting; file storage and off-site backupseu-west-1 (Ireland, EU)
RedsysCard and Bizum payment processingSpain (EU)
StripeSale of the card-signup subscription, by Stripe/Link, with VAT and receiptsEU / US
ResendTransactional email deliveryUS
SlackDelivery of minimized operational security alerts (action, timestamp and shortened technical references; no clinical content, email address, IP address or free text)Global
CloudflareAuthoritative DNS; HTTP/HTTPS traffic proxy/CDN; edge security (WAF, DDoS protection and request rate limiting); and Turnstile anti-bot protection on public formsGlobal
Google (Google Analytics 4)Audience measurement of the public site, only if the visitor accepts in the cookie notice; no clinic or patient dataGlobal

The application and database are hosted on AWS in eu-west-1 (Ireland, EU).

7. International transfers

Files, backups and primary application hosting remain in the eu-west-1 region (Ireland, European Union). Some of our providers, specifically Resend, Cloudflare, Slack, Stripe and Google (Google Analytics, only with your consent), may process data outside the European Economic Area.

The contractual framework for those transfers — Standard Contractual Clauses or Data Privacy Framework certification — is under review and will be published in this policy. Until that review is complete, we do not claim to have those instruments signed.

8. Google and Microsoft calendar integration

This section only applies if you, as a professional, choose to connect your own Google or Microsoft account to the Nuve One Schedule. The connection is optional and personal: each person connects only their own account, and clinic administrators only see whether the connection is active, never the account or the events.

Purpose: to mark in the Nuve One Schedule the times when you are already busy in your external calendar, so that conflicting bookings are avoided, including through the online booking page.

Permissions we request, all read-only. Nuve One never creates, changes or deletes events in your calendar.

  • Google: calendar.events.freebusy, to see when you are busy. Only if you turn on the “Titles and locations only for me” option do we also request calendar.events.readonly, to read event titles and locations.
  • Microsoft: Calendars.ReadBasic, to read the events in your calendar, plus openid, email and offline_access, to identify the connected account and keep the connection without asking you to sign in again at every sync.

What we read and store:

  • We only read the account's primary calendar, from the previous day to about six months ahead.
  • For each event that takes up your time, we store only its start, its end and whether it lasts all day. Cancelled events, events marked as free and events you declined are ignored.
  • Titles and locations are stored only if you turn on the “Titles and locations only for me” option, up to 500 characters each. Turning the option off deletes the stored titles and locations at once. At Microsoft, the Calendars.ReadBasic permission already includes the title and location; without the option on, they are discarded without being stored.
  • We do not store descriptions, attendees, attachments or meeting links. Of each event's identifier we store only a cryptographic digest (SHA-256).
  • We also store the email address of the connected account, which only you see, and the access tokens issued by Google or Microsoft.

Who sees it: you see your imported events, with title and location if you turned that option on. Everyone else in the clinic, including administrators, and the Nuve One support team when it accesses the account in support mode only see a “Busy” block, with no title, location or source. The private calendar link for your phone does not include imported events.

Security: tokens and the sync cursor are encrypted at rest with AES-256-GCM, under a key used only for this integration, and never appear in logs. The data stays in our database on AWS in eu-west-1 (Ireland, EU). The connection's audit record holds only the provider and the status, with no event data.

Legal basis: your consent (Art. 6(1)(a) GDPR), given when you connect the account and, for titles and locations, when you turn that option on. You can withdraw it at any time by disconnecting the account or turning the option off, without affecting the processing carried out before.

Limited Use: Nuve One's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. We apply the same rules to data received from Microsoft:

  • we use this data only to show and respect your availability in the Nuve One Schedule;
  • we do not sell it, do not use it for advertising and do not use it to develop or train artificial intelligence models;
  • we do not transfer it to third parties, except to the providers that host and deliver the service, listed in section 6 (AWS and Cloudflare), or where the law requires it;
  • no one on our team reads this data, except with your express permission, where needed for security (for example, to investigate abuse) or to comply with the law.

How long we keep it:

  • While the connection is active, busy times are refreshed at every sync, and whatever you delete or change in the external calendar is also deleted or updated in Nuve One.
  • When you disconnect, we delete the imported busy times, titles and locations, the tokens and the connection at once. For Google, we also ask Google to revoke the access. For Microsoft, the app cannot revoke that access; to withdraw it from your Microsoft account too, remove Nuve One at https://account.live.com/consent/Manage (personal account) or https://myapps.microsoft.com (work or school account).
  • If you revoke access in your Google account, or the provider reports that access has ended for good, we delete all of it as soon as the refusal is detected, at the next sync.
  • After any other failure, the imported busy times, titles and locations are deleted automatically after 72 hours without a successful sync. The connection, with its encrypted tokens, remains until you reconnect or disconnect.
  • If you stop being active, no longer hold the administrator or professional role, or the clinic is deactivated, the connection and the imported data are deleted automatically by the check that runs every hour.
  • Backups: data already deleted may remain in the encrypted backups until the end of the rotation described in section 4.

9. Cookies and similar technologies

We use strictly necessary cookies (session, authentication tokens and language preference). In addition, and only if you accept in the cookie notice on the public pages, we use Google Analytics 4 to measure the site's audience: it writes first-party cookies (names starting with _ga) on this domain, valid for up to 2 years, and receives the data described in section 2. Without your acceptance those cookies are not written and nothing is sent to Google. We do not use marketing or advertising cookies: ad storage and ad personalisation always stay denied.

To change your choice, use “Cookie preferences” in the footer of the public pages. If you choose “Essential only”, measurement of new visits stops and this browser's Google Analytics cookies are deleted. The choice is kept in your browser.

Cloudflare may use cookies or identifiers that are strictly necessary for bot detection and traffic filtering. Turnstile processes the technical signals described in section 2; we do not use this integration for analytics or marketing.

10. Minors

The Platform is not directed at minors as account holders. The minimum age of consent applied follows the clinic's jurisdiction: 14 in Spain (LOPDGDD, Art. 7) and 13 in Portugal (Law 58/2019, Art. 16). Data of underage patients is processed by the clinic, which must obtain consent from their legal guardians.

11. Technical security

  • HTTPS on all connections.
  • Passwords stored with bcrypt, never in clear text.
  • Isolation between clinics covered by automated tests in continuous integration.
  • Encrypted daily backups.
  • Audit records of access to sensitive data.
  • Infrastructure credentials mounted read-only and rotated periodically.

12. Data Protection Officer (DPO)

As of this policy, Nuve One has no legal obligation to appoint a DPO. The contact point for all privacy matters is privacy@nuve.one. When we reach the legal thresholds, a DPO will be appointed and this document updated.

13. Supervisory authorities

14. Changes to this policy

Substantial changes will be notified by email at least 30 days in advance. The last-updated date at the top of this page always indicates the current version.