Privacy Policy
Last updated: 23 September 2026 · version v2_2026-09-23
The Spanish version of this document is the only legally binding one. This translation is provided for informational purposes only.
1. Data controller
Wavaily's role depends on the type of data. Wavaily (hereinafter, the “Platform”), accessible from www.wavaily.com, is the data controller of the data of registered clinics and professionals and of the visitors of this website:
- Identity: Wavaily, tax ID pending (company being incorporated)
- Registered address: pending registration; for any enquiry, privacidad@wavaily.com
- Registry details: pending registration at the Commercial Registry
- Data protection contact: privacidad@wavaily.com
- Data protection officer: pending appointment; in the meantime, privacidad@wavaily.com
- Website: www.wavaily.com
With regard to the data of the patients who book appointments through a clinic's portal, the data controller is the relevant clinic, and Wavaily acts as a data processor on behalf of that clinic (Art. 28 GDPR). Each patient can consult their clinic's privacy notice on the booking portal itself.
2. Personal data we collect
Depending on the relationship you have with the Platform, we may process the following categories of personal data:
2.1 Clinics and professionals (registered users)
- Identifying data: first name, surname, email address, telephone number.
- Professional data: clinic name, address, professional registration number (if provided), specialties.
- Access data: email address and encrypted password, or the Google account identifier if the user signs in with Google.
- Integration data: if the professional connects Google Calendar, the data described in section 14.
2.2 Patients (users of the clinics)
- Identifying data: first name, surname, email address, telephone number and, where provided, identity document, date of birth and postal address.
- Health data (special category under Article 9 GDPR): the service booked, the reason for the visit where the clinic enables that field, and all clinical content the clinic records on the Platform (clinical history, assessments, scales, anatomical marks, attached documents, discharges and signed consents). Wavaily hosts and processes them solely on behalf of the clinic, which is the controller, and never for its own purposes.
- Browsing and evidence data: IP address, browser type and session cookies, and the IP address and date recorded with a consent.
3. Purposes of the processing
We process personal data for the following purposes:
- Provision of the service: management of user accounts, management of appointments and bookings, sending of confirmations and reminders.
- Transactional communications: sending of appointment confirmation, cancellation, rescheduling and reminder emails by email, SMS or WhatsApp.
- Improvement of the Platform: aggregated and anonymized statistical analysis of the use of the Platform.
- Legal compliance: handling of complaints and exercise of rights, compliance with tax and commercial obligations.
- Integrations chosen by the user: signing in with Google and sending appointments to Google Calendar (section 14).
4. Legal basis for the processing
- Performance of a contract (Article 6.1.b GDPR): the processing is necessary for the provision of the service contracted by the clinics and the management of patients' appointments.
- Consent (Article 6.1.a GDPR): for the sending of commercial communications, where applicable.
- Legitimate interest (Article 6.1.f GDPR): for the improvement of the Platform and the prevention of fraud.
- Legal obligation (Article 6.1.c GDPR): for compliance with applicable tax and commercial obligations.
5. Recipients of the data
Personal data may be communicated to the following recipients, exclusively for the purposes indicated:
- Supabase, Inc. (US company; data hosted in Ireland): database, authentication and file storage. Processing agreement with standard contractual clauses.
- Vercel, Inc. (US company; compute in Dublin, Ireland): hosting and execution of the Platform, plus cookieless aggregate usage and performance measurement.
- Resend, Inc. (United States): transactional email.
- Stripe: the clinic's subscription charge and, where the clinic enables prepayment, the patient's payment into the clinic's account.
- Twilio, Inc. (United States): SMS and WhatsApp messages, where the clinic enables those channels.
- Meta Platforms (United States): WhatsApp Business, where the clinic uses that channel.
- Functional Software, Inc. (Sentry): technical error monitoring, with personal data scrubbed beforehand.
- Google: sending appointments to Google Calendar, if a professional connects it; Google reviews, if the clinic connects its listing; and Google sign-in, if the user chooses it. Details in section 14.
- Spanish Tax Agency (AEAT): invoicing records where the clinic issues invoices under VERI*FACTU. A recipient by legal obligation, not a processor.
Data will not be disclosed to third parties other than those indicated, except by legal obligation.
6. International transfers
The database, the files and the Platform's compute are in Ireland (European Union). Some of the providers listed are US companies that may access the data from outside the European Economic Area to provide support. In those cases the transfer relies on the EU-US Data Privacy Framework (adequacy decision of 10 July 2023) where the provider is certified, and on the standard contractual clauses approved by the European Commission (Implementing Decision (EU) 2021/914) otherwise. You may request a copy of the applicable safeguards at privacidad@wavaily.com.
7. Retention period
- Data of registered users (clinics): for as long as the contractual relationship is maintained and, after its termination, for the legally required periods (a minimum of 5 years in accordance with the Spanish Commercial Code).
- Patient data: Wavaily processes it solely on behalf of the clinic, which is the data controller, and keeps it for as long as the contract with them is in force. On termination it is returned or deleted according to the clinic's decision (GDPR art. 28.3.g). It is the clinic that sets the retention periods required of it by healthcare law: at least 5 years from the discharge of each episode of care (Ley 41/2002 art. 17), and 15 years in Catalonia (Ley 21/2000 art. 12).
- Browsing data: 12 months from collection at most.
8. Rights of the data subject
In accordance with the GDPR and Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales (Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and guarantee of digital rights, LOPD-GDD), the data subject has the right to:
- Access: to know what personal data of theirs is being processed.
- Rectification: to request the correction of inaccurate or incomplete data.
- Erasure: to request the deletion of their data when it is no longer necessary for the purpose for which it was collected.
- Objection: to object to the processing of their data in certain circumstances.
- Restriction of processing: to request that the processing of their data be restricted.
- Portability: to receive the data provided in a structured, commonly used and machine-readable format.
To exercise these rights, the data subject may contact privacidad@wavaily.com, indicating their identity and the right they wish to exercise. The request will be handled within a maximum period of one month.
Likewise, the data subject has the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) (www.aepd.es) if they consider that their rights have not been duly addressed.
9. Security measures
Wavaily applies appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of passwords and sensitive data in transit (TLS) and at rest.
- Row Level Security policies in the database, ensuring that each clinic only accesses its own data.
- HTTP security headers (HSTS, CSP, X-Frame-Options).
- Secure authentication using JWT tokens with controlled expiration.
- Access tokens for third-party services, such as Google Calendar, stored encrypted.
10. Cookies
The Platform uses only first-party, strictly necessary cookies: the user's session, the active clinic where more than one is managed, the chosen language and, only if the user asks to save their details to their account when finishing a booking, those details, encrypted, for at most 24 hours and until they sign in. No advertising, social-network or cross-site tracking cookies are used, and none are shared with third parties for profiling.
To measure usage and performance we use Vercel Analytics and Speed Insights, which set no cookies or persistent identifiers and work on aggregate data; booking-funnel events expressly exclude name, phone, email and date of birth. Error monitoring (Sentry) sets no cookies either and scrubs personal data before sending; session recording is disabled.
You can delete or block cookies from your browser settings. Blocking the necessary ones prevents signing in and using the Platform.
11. Relationship between Wavaily and the clinics
For the purposes of the GDPR, Wavaily acts as a data processor with respect to the patient data that the clinics manage through the Platform. Each clinic is the data controller of its patients' data and must have its own legal basis for such processing (patient consent, performance of a healthcare service contract, etc.).
The conditions of this data processing relationship are governed by the service provision contract signed between Wavaily and each clinic.
12. Amendments
Wavaily reserves the right to amend this Privacy Policy to adapt it to legislative or case-law developments. In the event of substantial changes, registered users will be notified by email with a minimum of 15 days' prior notice.
13. Mandatory data and automated decisions
Fields marked as required on each form are necessary to create the account, book an appointment or issue an invoice; without them the service cannot be provided. The rest are optional and leaving them empty only prevents using the related feature.
No automated decisions producing legal effects or similarly significantly affecting individuals are taken within the meaning of Article 22 GDPR, nor is profiling carried out for that purpose.
14. Data obtained from Google
Two features of the Platform use data from the user's Google account: signing in with Google and the Google Calendar connection. Both are optional: they are only activated if the user chooses to, and can be deactivated at any time.
14.1 Sign in with Google
If the user signs in with their Google account, Google provides us with their name, email address, profile picture and an identifier for their account. We use them solely to create the account, identify the user and allow them to sign in. Wavaily has no access to the user's Google password.
14.2 Google Calendar
Each professional can connect their Google Calendar from “My settings” on the Platform. Wavaily then asks Google for three permissions, the narrowest that allow these features: the one Google describes as “see, create, change and delete events on Google calendars you own”, which Wavaily uses to send the professional's appointments to their calendar and to read their busy times; checking the availability of the calendars they have access to; and seeing the list of those calendars. It uses them exclusively to:
- Add their appointments to their primary calendar. For each appointment assigned to them in Wavaily, an event is created, which is updated or deleted when the appointment changes or is cancelled. The event contains the service, the patient's name, the date and time, the clinic's address, a link to the appointment in Wavaily (which requires signing in) and an internal identifier. Appointment notes are not sent to Google.
- Block the professional's busy times in Wavaily. Wavaily reads the busy times of the professional's primary calendar, which is ticked automatically when they connect (they can untick it), and of any other calendars they tick. From each event it reads only the start and end, whether it counts as busy or available, whether it is cancelled, whether it is part of a recurring series and, from the attendees, only whether and how they responded, without names or emails; of those responses it only uses the professional's own, so as not to block the invitations they have declined. It also reads the event's private technical data, of which it only uses the tag that identifies the events of the appointments Wavaily itself sends to Google (the internal identifier mentioned in the previous point). It does not request titles, descriptions or locations. In the schedule, those times are only shown as “Busy (Google)” and, if an appointment overlaps one of them, the professional is notified by email with the date, time and service of the appointment, without any patient data or details of the Google event.
- Keep only what is needed to maintain the connection: the access tokens issued by Google, stored encrypted; the identifier of each event created; the email of the connected Google account; the identifier and name of each calendar in that account's list (the identifier of a calendar someone else shares with the professional may be that person's email); and, for the ticked calendars, the start and end of each busy time with the identifier of its event and the sync status. Titles, descriptions and data from other apps are not stored.
The patient data contained in the events Wavaily creates is transferred to the professional's Google account and, from then on, Google processes it under its own terms.
14.3 Limited use of Google data
- We do not use data obtained from Google for advertising, to build profiles or to train artificial intelligence models.
- We do not sell it or disclose it to third parties. It is processed only by the providers listed in section 5, in order to provide the service.
- No one at Wavaily reads it, unless the user expressly authorises it, it is necessary for security reasons (for example, to investigate abuse) or it is required by law.
- Wavaily's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
14.4 Retention and withdrawal of access
Google Calendar data is kept while the connection is active. If the professional unticks a calendar, the busy times read from it are deleted immediately. When they disconnect Google Calendar from “My settings”, Wavaily revokes the access with Google and immediately deletes the tokens, the account email, the list of their calendars with their identifiers and names, the busy times read and the overlap notices; the identifiers of the events created by Wavaily are kept with each appointment for as long as it exists. While the connection is active, an overlap notice that has already been handled is deleted once the appointment has passed and 30 days have gone by since the notice. Events already created remain in the professional's calendar, and they can delete them from Google Calendar. The user can also withdraw Wavaily's access at any time from their Google account permissions page.