Privacy and data protection policy

Last updated: 30 September 2026

In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (hereinafter, GDPR), Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) and Spanish Law 34/2002 of 11 July on Information Society Services and Electronic Commerce (LSSI-CE), ANKORA HEALTH CARE SL explains how it processes personal data on its website, its web portal and its Android and iOS applications (hereinafter, together, "Ankora").

Ankora is a platform used by psychology centres and therapists to manage the care of their patients. This policy is based on the principle of accountability: we apply the measures required by law and can demonstrate so to the supervisory authorities.

This English version is provided for information. In the event of any discrepancy, the Spanish version prevails.

1. Data controller: who are we?

Company nameANKORA HEALTH CARE SL
Tax ID (NIF)B93905933
Registered officeAvenida del Tibidabo 38-40, Ático, 08022 Barcelona, Spain
Registration detailsRegistered in the Barcelona Mercantile Registry (Registro Mercantil de Barcelona), volume/IRUS 1000478489810, folio 1, sheet B 662789, entry 1
Contact emailsoporte@ankorahc.com
Data protection officerdevelopment@ankorahc.com

2. Are we the controller or the processor of your data?

If you are a patient, the controller of your clinical record is not Ankora but the centre or therapist who treats you. Ankora provides the software they work with and processes your data solely on their instructions, as a data processor (Article 28 GDPR), and never for any purpose of its own. It is your centre that must inform you and to whom you should address any request to exercise your rights.

Ankora therefore acts in two different capacities:

CapacityWhich dataWho informs you
ControllerPeople who contact us or visit the website, contact persons at client centres, invoicing of clients, support, and the security and technical operation of the platform and the applications.This policy.
ProcessorThe clinical record and everything the centre processes about its patients: sessions, diary, emotion log, exercises, questionnaires, goals, appointments, messages, files and the centre's invoices to the patient.The centre, through the information it gives you; Ankora acts under the data processing agreement signed with each centre.

3. Purpose, legal basis and retention: what do we use your data for and for how long?

As controller, we process the following data:

ProcessingDataPurposeLegal basisRetention
Contact and information requestsName, email, telephone and the content of the enquiry.Responding to the request.Consent or pre-contractual measures (Art. 6(1)(a) and 6(1)(b) GDPR).As long as needed to respond. If the request leads to a contract, the data are then kept as client management data.
Client managementIdentification and contact details of the centre and its representatives.Providing the contracted service.Performance of a contract (Art. 6(1)(b)).For the term of the contract and, afterwards, for the limitation periods of any claims that may arise from it.
Client invoicingThe client's tax and billing details.Complying with tax and commercial obligations.Legal obligation (Art. 6(1)(c)).Six years (Spanish Commercial Code) and at least four years (tax legislation).
SupportName, email, profile, centre and the content of the enquiry.Handling incidents and enquiries.Performance of a contract (Art. 6(1)(b)).Conversations with the support assistant are not stored: they disappear when you leave the screen. Enquiries sent through the contact form are kept for the term of the contract with the centre and, afterwards, for the limitation periods. Each submission is recorded in the audit log, without the text of the enquiry, for three years.
Platform securitySign-in and access log, IP address, device identifier and technical error log.Protecting accounts, preventing unauthorised access and detecting errors.Legitimate interest (Art. 6(1)(f)) and the obligation to apply security measures (Art. 32 GDPR).Sign-in log and error log: one year. Audit log: three years (five where it concerns health data, on behalf of the centre).
Operation of the mobile applicationsThe device's notification identifier and application crash reports (device model, operating system and app version, and the technical trace of the error), with no patient data or clinical record data.Notifying the device that new information is available and fixing application errors.Performance of a contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)).The identifier, until you sign out on the device; crash reports, 90 days.
Service communicationsContact email.Informing clients about the service.Legitimate interest and Art. 21(2) LSSI-CE, or consent.Until you unsubscribe.

Once those periods have expired, or if erasure is requested while a legal obligation to keep the data still applies, the data are blocked: removed from all ordinary use and available only to courts and tribunals, the Public Prosecutor and the competent public authorities (Article 32 LOPDGDD) until they are destroyed.

4. Mobile applications: which permissions do they request and what do they store on your phone?

5. Recipients: who do we share your data with?

We do not disclose data to third parties except where required by law: for example, to the Spanish Tax Agency, to courts and tribunals or to supervisory authorities.

To provide the service we rely on the following providers, which act as data processors under a contract that complies with Article 28 GDPR:

ProviderServiceLocation
Microsoft Ireland Operations Ltd. (Azure)Hosting of the platform, database, file storage and email delivery.European Union - Spain Central
Google Ireland Ltd. (Firebase)Notifications to devices and application crash reports.European Union and United States
Atlassian (Jira Service Management)Handling of enquiries sent from the support screen.European Union and United States

The providers involved in processing patient data (hosting, email, notifications, speech transcription and language models) are disclosed to each centre in the data processing agreement, and each centre discloses them to its patients.

6. International transfers: does your data leave the European Union?

Some of the providers above may process data in the United States. In those cases the transfer is based on the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023) or, failing that, on the standard contractual clauses approved by the European Commission, in accordance with Chapter V GDPR.

7. Security: how do we protect your data?

We apply technical and organisational measures appropriate to the risk of processing health data (Article 32 GDPR), including:

Even so, no security measure on the Internet is infallible. Please keep your password and recovery codes safe and sign out on shared devices.

8. Your rights: what rights do you have and how can you exercise them?

You may exercise the following rights free of charge:

To exercise them, write to soporte@ankorahc.com stating which right you are exercising. Where necessary, we will ask you to verify your identity. We will reply within one month.

If you are a patient and wish to exercise your rights over your clinical record, contact your centre or your therapist. If you write to us instead, we will tell you who the controller is and forward your request without delay.

9. Complaints: where can you complain?

If you consider that we have not properly handled your rights, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos):

Lodging a complaint with the Agency is free of charge and does not require a lawyer or legal representative.

10. Automated decision-making

Ankora does not take automated decisions with legal effects about the people whose data it processes as controller. The artificial intelligence tools that centres may enable help draft clinical documentation under the review of the professional, who makes the decisions; they are used on behalf of the centre, and it is the centre that informs its patients about them.

11. Minors

Ankora accounts cannot be created freely: they are created by the centre providing care. Where the patient is a minor, it is the centre's responsibility to obtain the authorisations required by law.

12. Changes to this policy

We may amend this policy to adapt it to changes in the law or in the service. The date of the last update appears at the top of this document and, if the change is significant, we will inform clients and users through the usual channels.