Privacy Policy
Last updated: 10 April 2026
The Spanish version of this document is the only legally binding one. This translation is provided for informational purposes only.
1. Data controller
Wavaily's role depends on the type of data. Wavaily (hereinafter, the “Platform”), accessible from www.wavaily.com, is the data controller of the data of registered clinics and professionals and of the visitors of this website:
- Identity: Wavaily (hereinafter, the “Controller”)
- Contact email: privacidad@wavaily.com
- Website: www.wavaily.com
With regard to the data of the patients who book appointments through a clinic's portal, the data controller is the relevant clinic, and Wavaily acts as a data processor on behalf of that clinic (Art. 28 GDPR). Each patient can consult their clinic's privacy notice on the booking portal itself.
2. Personal data we collect
Depending on the relationship you have with the Platform, we may process the following categories of personal data:
2.1 Clinics and professionals (registered users)
- Identifying data: first name, surname, email address, telephone number.
- Professional data: clinic name, address, professional registration number (if provided), specialties.
- Access data: email address and encrypted password.
2.2 Patients (users of the clinics)
- Identifying data: first name, surname, email address, telephone number.
- Health data: only that which is strictly necessary for appointment management (requested service, reason for consultation if the clinic enables it). Wavaily does not access or store complete medical records.
- Browsing data: IP address, browser type, cookies.
3. Purposes of the processing
We process personal data for the following purposes:
- Provision of the service: management of user accounts, management of appointments and bookings, sending of confirmations and reminders.
- Transactional communications: sending of appointment confirmation, cancellation, rescheduling and reminder emails by email, SMS or WhatsApp.
- Improvement of the Platform: aggregated and anonymized statistical analysis of the use of the Platform.
- Legal compliance: handling of complaints and exercise of rights, compliance with tax and commercial obligations.
4. Legal basis for the processing
- Performance of a contract (Article 6.1.b GDPR): the processing is necessary for the provision of the service contracted by the clinics and the management of patients' appointments.
- Consent (Article 6.1.a GDPR): for the sending of commercial communications, where applicable.
- Legitimate interest (Article 6.1.f GDPR): for the improvement of the Platform and the prevention of fraud.
- Legal obligation (Article 6.1.c GDPR): for compliance with applicable tax and commercial obligations.
5. Recipients of the data
Personal data may be communicated to the following recipients, exclusively for the purposes indicated:
- Supabase, Inc. (United States): database hosting and authentication. It has standard contractual clauses approved by the European Commission for international transfers.
- Vercel, Inc. (United States): hosting of the Platform. It has standard contractual clauses.
- Resend, Inc. (United States): sending of transactional emails. It has standard contractual clauses.
- Stripe, Inc. (United States): payment processing, if the clinic enables online payment. It has standard contractual clauses.
- Twilio, Inc. (United States): sending of SMS and WhatsApp messages, if the clinic enables reminders. It has standard contractual clauses.
Data will not be disclosed to third parties other than those indicated, except by legal obligation.
6. International transfers
The providers indicated in the previous section are located in the United States. In all cases, the Standard Contractual Clauses approved by the European Commission (Implementing Decision 2021/914) have been signed as an adequate safeguard for the international transfer of data, in accordance with Article 46.2.c GDPR.
7. Retention period
- Data of registered users (clinics): for as long as the contractual relationship is maintained and, after its termination, for the legally required periods (a minimum of 5 years in accordance with the Spanish Commercial Code).
- Patient data: Wavaily processes it solely on behalf of the clinic, which is the data controller, and keeps it for as long as the contract with them is in force. On termination it is returned or deleted according to the clinic's decision (GDPR art. 28.3.g). It is the clinic that sets the retention periods required of it by healthcare law: at least 5 years from the discharge of each episode of care (Ley 41/2002 art. 17), and 15 years in Catalonia (Ley 21/2000 art. 12).
- Browsing data: a maximum of 13 months from its collection.
8. Rights of the data subject
In accordance with the GDPR and Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales (Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and guarantee of digital rights, LOPD-GDD), the data subject has the right to:
- Access: to know what personal data of theirs is being processed.
- Rectification: to request the correction of inaccurate or incomplete data.
- Erasure: to request the deletion of their data when it is no longer necessary for the purpose for which it was collected.
- Objection: to object to the processing of their data in certain circumstances.
- Restriction of processing: to request that the processing of their data be restricted.
- Portability: to receive the data provided in a structured, commonly used and machine-readable format.
To exercise these rights, the data subject may contact privacidad@wavaily.com, indicating their identity and the right they wish to exercise. The request will be handled within a maximum period of one month.
Likewise, the data subject has the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) (www.aepd.es) if they consider that their rights have not been duly addressed.
9. Security measures
Wavaily applies appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of passwords and sensitive data in transit (TLS) and at rest.
- Row Level Security policies in the database, ensuring that each clinic only accesses its own data.
- HTTP security headers (HSTS, CSP, X-Frame-Options).
- Secure authentication using JWT tokens with controlled expiration.
10. Cookies
The Platform uses cookies that are strictly necessary for the operation of the service (session authentication). No cookies are used for advertising or third-party tracking purposes.
For more information about the cookies used, you can consult your browser settings.
11. Relationship between Wavaily and the clinics
For the purposes of the GDPR, Wavaily acts as a data processor with respect to the patient data that the clinics manage through the Platform. Each clinic is the data controller of its patients' data and must have its own legal basis for such processing (patient consent, performance of a healthcare service contract, etc.).
The conditions of this data processing relationship are governed by the service provision contract signed between Wavaily and each clinic.
12. Amendments
Wavaily reserves the right to amend this Privacy Policy to adapt it to legislative or case-law developments. In the event of substantial changes, registered users will be notified by email with a minimum of 15 days' prior notice.