Privacy Policy
How Clynalia handles personal data: yours as a visitor or as a user of the app, and your patients' as a clinic that uses it.
This document is only available in English for now. The rest of the site is available in your language.
1. Who we are
Miguel Monllau Monfort (NIF ES73383415Y), Calle Doctor Coca 1, planta 1, puerta 1, 08700 Igualada, Barcelona, Spain — trading as “Clynalia” — operates clynalia.com and the Clynalia app. Contact: privacy@clynalia.com.
This policy covers three situations. For visitors of clynalia.com and for the professionals who use the app, Clynalia is the data controller. For the patients whose records a clinic keeps in Clynalia, the clinic is the controller and Clynalia is its processor, under the Data Processing Agreement signed with each clinic.
2. Data we collect from visitors
We run no analytics on this site. No cookies, no tracking pixels, no third-party scripts, and no profiling of you across other sites. If that ever changes, it will be stated here before it does.
- The name and email address you submit to the launch notification form. Nothing else.
3. Data about you as a user of the app
If your clinic gives you access to Clynalia, we process the data needed to run your account and keep it secure:
- Your name, email address and role in the clinic, and your professional registration number if the clinic records it.
- Your password, stored only as a hash. If you add a passkey, its public key. If you link your Apple account, the identifier Apple assigns to you for Clynalia.
- The date, time and IP address of each sign-in, and — on Apple devices that support it — a device attestation, so that the account can only be used from the app.
- A log of each patient record you open. Clinics are legally required to know who accessed a clinical record, so this log is kept for the clinic and cannot be switched off.
The app contains no analytics, advertising or tracking SDKs. Nothing you do in the app is shared with third parties for their own purposes.
4. Patient data (for clinics)
When a clinic uses Clynalia, the clinic is the controller of its patients' data and Clynalia is the processor.
- We process patient data only on documented instructions from the clinic.
- Categories: identification and contact details; tax identification number and address when the clinic invoices the patient; health data (anamnesis, examination, treatment, progress, recommendations, allergies, history and medication); and documents or images the patient provides.
- Clinical content is stored encrypted with a key per clinic, each clinic's data is isolated at the database level, and every access to a record is logged.
- If the clinic turns on AI document reading, the text of a document is organised by a model run on Amazon Bedrock in a European Union region. The model does not diagnose, and no model is ever trained on patient records.
- We do not sell data.
- Patients exercise their rights with the clinic, not with Clynalia. We assist the clinic in responding.
5. Invoicing and the Spanish Tax Agency
Clynalia is an invoicing system that complies with the Spanish VERI*FACTU rules (Royal Decree 1007/2023). When a clinic issues an invoice, a billing record is created with the recipient's name, tax identification number and address, the date, number and concept of the invoice, and its amounts. The clinic submits that record to the Spanish Tax Agency (AEAT) from its own computer, with its own digital certificate. The legal basis is compliance with a legal obligation.
Billing records contain no health data: the concept is the clinic's tariff (for example, “physiotherapy session”), never the content of the visit.
6. Legal basis
- Launch notification list: your consent.
- Your account as a professional: performance of the contract with your clinic, and our legitimate interest in keeping the service secure. The access log: a legal obligation of the clinic.
- Patient data: performance of the contract with the clinic, under the terms of the DPA.
- Billing records: compliance with a legal obligation (tax and invoicing law).
7. Retention
- Launch notification contacts: until you unsubscribe.
- Professional accounts and sign-in logs: while the clinic is a customer, and afterwards for as long as needed to answer for legal liabilities.
- Patient records: as instructed by the clinic, within the legal retention periods for clinical records — at least five years from discharge from each care process under Spanish Law 41/2002, and the longer periods set by regional law, such as the fifteen years that apply to the clinical course in Catalonia. When a clinic leaves, its data is exported to the clinic and deleted under the DPA.
- Invoices and billing records: the tax limitation period of four years and the six-year commercial period, whichever applies to the clinic.
8. Sub-processors
The providers we rely on to run Clynalia:
- Amazon Web Services (Stockholm region, Sweden): hosting, database, encryption keys, backups and — for AI document reading — Amazon Bedrock, run in a European Union region.
- Resend (United States): transactional email, such as password reset links. We never send clinical content by email. Transfers are covered by Standard Contractual Clauses.
- Cloudflare: authoritative DNS and inbound email routing for clynalia.com, under its Data Processing Addendum.
Apple (Sign in with Apple, passkeys, device attestation and the App Store) acts as an independent controller under its own privacy policy. We give clinics notice before adding a new sub-processor.
9. International transfers
Patient records and account data are stored in the European Union. Resend and Cloudflare may process the data described above outside the European Economic Area, under Standard Contractual Clauses. Submitting billing records to the Spanish Tax Agency is not a transfer.
10. Your rights
You may request access, rectification, erasure, portability, or object to processing, by writing to privacy@clynalia.com. If you are a patient, address your request to your clinic, which is the controller of your record. You also have the right to lodge a complaint with your data protection authority — in Spain, the AEPD.
11. Changes
Last updated: 6 September 2026.