These Terms, together with the Data Processing Annex (the “DPA”), govern the relationship between CLEQUI S.L (Tax ID B000000, registered at Calle del Espino, 9, contact hola@clequi.com) and the nutritionist using the CLEQUI S.L platform (the “Practitioner” and the “Platform”).
1. Subject
CLEQUI S.L provides the Practitioner with a SaaS platform to manage patients, consultations, meal plans, communications, invoicing and, generally, their professional nutrition activity.
2. Eligibility and verification
- The Practitioner declares that they are legally qualified to practise nutrition and dietetics in Spain and that they hold a current professional licence number or equivalent qualification.
- CLEQUI S.L may request documentary verification before activating the account or at any time afterwards. The account may be suspended if verification is not possible or expires.
- The Practitioner must keep professional, tax and banking details up to date.
3. GDPR roles
With respect to their patients’ clinical data, the Practitioner acts as data controller and CLEQUI S.L acts as data processor. The DPA in Annex I forms an integral part of these Terms and governs that processing.
For the Practitioner’s own account data, CLEQUI S.L is the controller per the Privacy Policy.
4. Practitioner responsibilities
- Make clinical decisions and sign protocols. The Platform offers technological and AI assistance, but all recommendations require the Practitioner’s review and validation.
- Comply with the applicable code of ethics and health legislation.
- Treat each patient’s information confidentially.
- Obtain explicit consent from patients to process their health data when working outside the Platform or where applicable.
- Address data-subject rights of their patients; the Platform provides export, rectification and erasure tools.
- Comply with their tax, employment and commercial obligations. The Platform facilitates invoicing but does not replace the Practitioner’s accounting responsibility.
5. Fees
Current fees are published on the Platform. Plans may include AI usage measured in tokens; usage is shown in the Practitioner’s admin panel. CLEQUI S.L may change fees with at least 30 days’ notice.
6. Intellectual property
The Platform’s software, brand and content are owned by CLEQUI S.L. Templates, protocols and materials the Practitioner creates within the Platform belong to the Practitioner; you grant us a limited licence to host, process and display them to your patients as part of the service.
7. Limitation of liability
To the maximum extent permitted by law, CLEQUI S.L’s aggregate liability to the Practitioner for all claims arising from these Terms is limited to the amounts actually paid by the Practitioner during the 12 months preceding the event giving rise to the claim. We are not liable for lost profits or indirect damages. This limitation does not apply to damages caused by wilful misconduct, gross negligence or data-protection breaches attributable to CLEQUI S.L.
8. Indemnity
The Practitioner shall hold CLEQUI S.L harmless against claims by patients or third parties arising from (i) clinical or nutritional decisions, (ii) breach of professional duty or health legislation, or (iii) misuse of the Platform by the Practitioner.
9. Suspension and termination
Either party may terminate the contract with 30 days’ notice. CLEQUI S.L may immediately suspend or cancel the account in case of material breach, fraud, risk to patients or to Platform security. The Practitioner may download their data in an exportable format for 30 days after termination; thereafter data will be deleted, except where legal retention obligations apply.
10. Changes
We may update these Terms to reflect legal or service changes. Material modifications will be notified at least 30 days in advance. If the Practitioner does not accept the new terms, they may terminate without penalty before they enter into force.
11. Governing law and jurisdiction
These Terms are governed by Spanish law. For any dispute the parties submit, expressly waiving any other forum, to the Courts and Tribunals of [pendiente — configúralo en Admin → Legal].
Annex I — Data Processing Agreement (DPA)
This Annex complies with GDPR art. 28 and governs the processing by CLEQUI S.L (the “Processor”) of personal data for which the Practitioner is the controller (the “Controller”).
A. Subject, nature and purpose
The processing is for the provision of the CLEQUI S.L Platform: hosting, storage, backup, transmission, AI analysis and communication of the personal data that the Controller and their patients enter.
B. Duration
For the term of the contract and, thereafter, during the return or deletion period set out in these Terms.
C. Categories of data subjects and data
- Data subjects: the Controller’s patients, their contacts and, where applicable, the Controller’s employees or collaborators.
- Data: identification, contact, demographic, health data (special category), lifestyle, non-identifying biometric, usage data and communications.
D. Processor obligations
- Process data only on documented instructions from the Controller. These Terms, the Platform and its configurations constitute documented instructions. Any additional instruction shall be issued in writing.
- Ensure that authorised personnel commit to confidentiality and receive appropriate training.
- Implement the technical and organisational measures described in the Security Annex (Annex II): field-level AES-256-GCM encryption for sensitive data, per-column key derivation, HMAC blind indexes for searches without decryption, TLS, MFA for administrators, RLS, periodic testing and audits.
- Assist the Controller, by appropriate technical and organisational measures, in responding to data-subject rights requests.
- Assist the Controller in compliance with arts. 32-36 GDPR (security, breach notifications, impact assessments and prior consultations).
- At the Controller’s choice, return or delete data at the end of the contract, subject to legal retention obligations.
- Make available to the Controller the information necessary to demonstrate compliance with these obligations and allow reasonable audits, with notice and subject to confidentiality.
E. Security breaches
The Processor shall notify the Controller, without undue delay and in any event within 48 hours of becoming aware, of any security breach affecting Controller data, with the information necessary for the Controller to comply, where applicable, with their notification obligations to the supervisory authority and to data subjects (arts. 33 and 34 GDPR).
F. Sub-processors
The Controller grants general authorisation for the engagement of the sub-processors listed below. CLEQUI S.L will give at least 30 days’ notice of any addition or replacement, giving the Controller the opportunity to object on reasoned grounds.
- Supabase Inc. — database, authentication, storage.
- Anthropic, PBC — language model (with prior pseudonymisation).
- Stripe Payments Europe — payment processing.
- Resend — transactional email.
- Google LLC — Calendar API and Meet.
- Twilio Ireland — WhatsApp messaging.
- Cloudflare — anti-bot protection and CDN.
- Upstash — rate limiting.
G. International transfers
Transfers outside the EEA rely on European Commission Standard Contractual Clauses (Decision 2021/914) or on an adequacy decision, supplemented by additional measures (encryption, pseudonymisation, access control).
H. Liability
Each party is liable for damage caused where it has not complied with its directly applicable GDPR obligations, in accordance with art. 82 GDPR.
Annex II — Technical and organisational measures (summary)
- Encryption at rest: AES-256-GCM at field level for clinical data and PII; HKDF for per-table per-column key derivation.
- Encryption in transit: TLS 1.2+ required on all connections.
- Pseudonymisation: direct patient identifiers are replaced with generic placeholders before any data is sent to the AI model.
- Access control: database row-level security, least privilege, MFA required for administrators.
- Activity logging: security and access event logs retained for 12 months.
- Backups: automated, encrypted and periodically tested.
- Vulnerability management: dependency reviews and pre-deployment security checks.
- Continuity and recovery: service-restoration procedures.