This Privacy Policy describes how CLEQUI S.L (“CLEQUI S.L”) collects, uses, protects and shares the personal data we process in relation to the CLEQUI S.L platform.
1. Data controller
- Legal name: CLEQUI S.L
- Tax ID (NIF/CIF): B000000
- Registered address: Calle del Espino, 9
- Contact email: hola@clequi.com
- Data Protection Officer (DPO): [pendiente — configúralo en Admin → Legal] — [pendiente — configúralo en Admin → Legal]
2. Data we process
2.1 Patients
- Identifiers: name, email, phone, ID/passport number, date of birth, address.
- Health data (special category, GDPR art. 9): medical history, allergies, current medication, supplementation, biometric measurements (weight, height, body composition), lab results and any test you upload, symptoms, practitioner notes, meal plans.
- Usage data: sign-in records, IP address, browser, pages visited, application events.
- Payment data: handled directly by Stripe; we only store the transaction identifier and billing metadata.
2.2 Nutritionists
- Identification & professional: name, email, phone, tax ID, professional license number, clinic address, billing bank details.
- Operational: calendars, templates, custom prompts, history of interactions with patients via the platform.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the service (account, authentication, consultations, plans) | Performance of contract (art. 6(1)(b) GDPR) |
| Processing health data for nutritional follow-up by your chosen practitioner | Explicit consent (art. 9(2)(a)) and preventive medicine / health-care purposes (art. 9(2)(h)) |
| AI-assisted protocol generation and summaries | Performance of contract and explicit consent for health data |
| Invoicing, accounting and tax obligations | Legal obligation (art. 6(1)(c)) |
| Marketing communications (nutrition tips, product news) | Consent (art. 6(1)(a)) — revocable at any time |
| Information security, fraud prevention, audit | Legitimate interest (art. 6(1)(f)) |
4. Recipients and processors
We do not sell your data. We share information only with processors strictly required to deliver the service, all under data-processing agreements (GDPR art. 28):
- Supabase Inc. (US / EU) — database, authentication and storage.
- Anthropic, PBC (US) — large language model that assists the practitioner. Direct identifiers (name, email, phone) are removed before any data is sent to the model. Anthropic does not train on your data.
- Stripe Payments Europe — payment gateway; card data never passes through our servers.
- Resend (US) — transactional email delivery.
- Google LLC (US) — Calendar API (when the nutritionist voluntarily connects it) and Meet for video consultations. Equilibra360's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Twilio Ireland — WhatsApp messaging (when the nutritionist enables it).
- Cloudflare — anti-bot protection and content delivery.
- Upstash — rate limiting.
- Public authorities where there is a legal obligation to disclose.
5. International transfers
Providers outside the EEA process data under (i) an adequacy decision (EU-US Data Privacy Framework where applicable) or (ii) European Commission Standard Contractual Clauses, together with additional technical measures (encryption in transit and at rest, minimisation and pseudonymisation before AI processing).
6. Retention
- Account data: while the account is active.
- Clinical history and plans: up to 5 years from the last interaction, per Spanish Law 41/2002 on patient autonomy for healthcare records. Longer retention where the patient requests it or legal obligations apply.
- Invoicing: 6 years (Spanish Commercial Code).
- Security logs: 12 months.
- Marketing: until you withdraw consent.
After these periods data is securely deleted or anonymised.
7. Encryption and security
We apply field-level AES-256-GCM encryption to stored personal and health data, per-table per-column key derivation via HKDF, HMAC-SHA256 blind indexes for searches without decryption, TLS for all traffic, multi-factor authentication for administrators, access logging, and row-level security policies. We periodically review providers and vulnerabilities.
8. Automated decisions and AI
We use language models to assist the practitioner in drafting protocols, consultation summaries and lab analyses. These outputs never constitute an automated decision under GDPR art. 22: the nutritionist personally reviews, edits and authorises any recommendation before communicating it to the patient. Direct patient identifiers (name, email, phone) are replaced by generic placeholders before any text is sent to the AI model.
9. Your rights
You may exercise the following rights at any time by emailing hola@clequi.com:
- Access to the data we process about you.
- Rectification of inaccurate data.
- Erasure (“right to be forgotten”).
- Restriction of or objection to processing.
- Portability in a structured, commonly-used format.
- Withdrawal of consent (without retroactive effect).
- Not to be subject to a decision based solely on automated processing.
If you believe your request was not properly addressed, you may file a complaint with the Spanish Data Protection Agency: https://www.aepd.es.
10. Minors
The service is not directed at children under 14. Users between 14 and 18 require express authorisation from a holder of parental authority or guardianship.
11. Cookies and similar technologies
We use only strictly-necessary cookies for authentication and security. We do not use third-party analytics or advertising cookies. If other technologies are introduced, a specific cookie policy will be published with a prior consent mechanism.
12. Changes to this policy
Any modification will be published on this page, indicating the version and the last-updated date. Material changes will be communicated by email or in-app, and a fresh acceptance will be requested where appropriate.