Clínica Ferrer

Privacy Policy

Last updated: 26 August 2026.

1. Data controller

Controller: Vicente Ferrer Pérez (Clínica Ferrer). Spanish tax ID: 29175170S. Address: C. de la Cruz, 2, Mezzanine, 30820 Alcantarilla (Murcia), Spain. Privacy email: info@clinicaferrer.com. Telephone: +34 968 808 536. Website: https://clinicaferrer.com. Health Register: 2920008.

This Policy primarily governs data processed through the Website and initial communications. Patient clinical information is supplemented by the data-protection notices and consent documents provided during healthcare delivery.

2. Scope and principles

Clínica Ferrer processes data lawfully, fairly and transparently and applies purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality. Only data reasonably necessary for each purpose will be requested.

3. Data processed and sources

Data normally comes from the user or patient, their legal representative or authorised persons, insurers or care networks when the user asks to apply coverage, and technology providers that generate technical usage information.

  • Identity and contact data: name, surname, telephone, email, language and, where relevant, identification document.
  • Request data: preferred date, general reason, treatment of interest, messages and communications.
  • Insurance data: insurer, policy or card number, beneficiary status and applicable services.
  • Health data: only where necessary to provide care or voluntarily communicated by the user.
  • Technical data: IP address, browser, device, security logs, cookie consent, browsing and interactions.
  • Image, voice or testimonial: only where specific permission exists for collection or publication.

4. Purposes, legal bases and retention

The principal processing activities are summarised below. Retention may be extended where necessary to comply with legal obligations, respond to official requests or establish, exercise or defend legal claims.

PurposeDataLegal basisRetention
Enquiries and appointment requestsIdentity, contact details, message, availabilityPre-contractual steps requested by the user; legitimate interest in respondingUp to 12 months after the last interaction, unless a later relationship or claim arises
Healthcare managementIdentity, contact details, health data and clinical recordProvision of healthcare; legal obligations; Article 9(2)(h) GDPRMandatory healthcare and liability periods; at least 5 years after discharge from each care process
Insurers and care networksIdentity, policy or membership, services and billingPerformance of the requested relationship; legal obligations; legitimate interest in managing coverageFor the management period and applicable statutory, tax and limitation periods
Marketing communicationsContact details and preferencesExplicit consentUntil consent is withdrawn or an opt-out is requested
Testimonials and imagesImage, voice, testimonial and, where relevant, clinical informationSpecific, explicit and separate consentUntil consent is withdrawn, without retroactive effect on prior lawful use
Analytics and digital advertisingOnline identifiers, device, browsing and interactionsConsent through the cookie settings panelAs stated in the Cookie Policy
Security and legal defenceTechnical logs, IP address, activity and evidenceLegitimate interests; legal compliance; establishment or defence of claimsFor the necessary period and applicable limitation periods

5. Health data and communication channels

Health data is special-category data. Where it must be processed for diagnosis, care or healthcare management, the basis is Article 9(2)(h) GDPR, healthcare law and professional secrecy, together with the relevant Article 6 GDPR basis. Non-care uses, such as publishing an identifiable clinical testimonial or image, require explicit, specific and separate consent.

Please do not send detailed clinical information, radiographs or images through general forms, email or WhatsApp unless expressly requested by the clinic. If unsolicited health data is received, access will be restricted and it will be retained only where necessary to handle the request or meet legal obligations.

6. Required data

Fields marked as required are necessary to respond or manage an appointment. Without them, the request may not be processed. Users warrant that data is accurate and that they are authorised to communicate third-party data. A person requesting an appointment for someone else must inform that person or act as an authorised representative.

7. Recipients and processors

Personal data is not sold. Providers acting on behalf of Clínica Ferrer may access it, including hosting, maintenance, email, appointment management, clinical software, backup, security, analytics and professional advisers, under contract and confidentiality obligations.

Where necessary and legally justified, data may also be disclosed to healthcare professionals involved in care; laboratories or diagnostic centres; insurers and care networks requested by the patient; banks or payment providers; advisers and professional liability insurers; health, tax, judicial or administrative authorities; and law-enforcement bodies where provided by law.

8. International transfers

Some global providers, particularly Google, Meta, Vimeo or support services, may process data outside the European Economic Area. Clínica Ferrer will use providers covered by an applicable adequacy decision, including the EU-U.S. Data Privacy Framework where appropriate, or safeguards such as Standard Contractual Clauses, transfer assessments and supplementary measures. Current provider information is available in their policies and the cookie settings.

9. Rights

Data subjects may request access, rectification, erasure, objection, restriction and portability; withdraw consent at any time; and not be subject to solely automated decisions producing legal or similarly significant effects, where applicable. Withdrawal does not affect prior lawful processing or mandatory retention.

Requests may be sent to info@clinicaferrer.com or to the stated postal address, marked ‘Data protection’. Reasonable information may be requested to verify identity. A response will be provided within statutory time limits. Complaints may be lodged with the Spanish Data Protection Agency, www.aepd.es.

10. Children and representatives

The Website is not intended for children to independently arrange healthcare or submit clinical data. Requests concerning minors should be made by parents, guardians or representatives, without prejudice to healthcare rules on maturity, information and consent. Data sent without sufficient authority may be erased or evidence of authority may be requested.

11. Automated decision-making

Clínica Ferrer does not use the Website to make solely automated decisions producing legal or similarly significant effects. Analytics or advertising tools, if consented to, may create segments or measurements but do not decide diagnosis, access to treatment or clinical conditions.

12. Security and confidentiality

Technical and organisational measures proportionate to risk are applied, including access control, confidentiality duties, backups, maintenance, encryption where appropriate, incident management and provider selection. No system is infallible, so ordinary channels should not be used for extensive clinical information.

13. Cookies and external services

Non-essential cookies, pixels and external content are activated only with consent managed through the cookie panel. Links to WhatsApp, insurers, social networks or other sites are also subject to their owners' policies once opened by the user.

14. Changes to this Policy

This Policy may be updated for legal, technical or service changes. The latest update date will be published and, where a change requires fresh consent, it will be requested appropriately.

15. Language

This Policy is provided in Spanish and English with the same informational purpose. In the event of discrepancy, the Spanish version prevails to the extent permitted by law, without limiting mandatory rights.

Principal legal framework

  • Regulation (EU) 2016/679, General Data Protection Regulation (GDPR).
  • Spanish Organic Law 3/2018 on personal data protection and digital rights.
  • Spanish Law 41/2002 on patient autonomy and Region of Murcia Law 3/2009 on healthcare users' rights and duties.
  • Spanish Law 34/2002 on information society services and electronic commerce.