Privacy and data protection policy
Last updated: 30 September 2026
In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (hereinafter, GDPR), Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) and Spanish Law 34/2002 of 11 July on Information Society Services and Electronic Commerce (LSSI-CE), ANKORA HEALTH CARE SL explains how it processes personal data on its website, its web portal and its Android and iOS applications (hereinafter, together, "Ankora").
Ankora is a platform used by psychology centres and therapists to manage the care of their patients. This policy is based on the principle of accountability: we apply the measures required by law and can demonstrate so to the supervisory authorities.
This English version is provided for information. In the event of any discrepancy, the Spanish version prevails.
1. Data controller: who are we?
| Company name | ANKORA HEALTH CARE SL |
|---|---|
| Tax ID (NIF) | B93905933 |
| Registered office | Avenida del Tibidabo 38-40, Ático, 08022 Barcelona, Spain |
| Registration details | Registered in the Barcelona Mercantile Registry (Registro Mercantil de Barcelona), volume/IRUS 1000478489810, folio 1, sheet B 662789, entry 1 |
| Contact email | soporte@ankorahc.com |
| Data protection officer | development@ankorahc.com |
2. Are we the controller or the processor of your data?
If you are a patient, the controller of your clinical record is not Ankora but the centre or therapist who treats you. Ankora provides the software they work with and processes your data solely on their instructions, as a data processor (Article 28 GDPR), and never for any purpose of its own. It is your centre that must inform you and to whom you should address any request to exercise your rights.
Ankora therefore acts in two different capacities:
| Capacity | Which data | Who informs you |
|---|---|---|
| Controller | People who contact us or visit the website, contact persons at client centres, invoicing of clients, support, and the security and technical operation of the platform and the applications. | This policy. |
| Processor | The clinical record and everything the centre processes about its patients: sessions, diary, emotion log, exercises, questionnaires, goals, appointments, messages, files and the centre's invoices to the patient. | The centre, through the information it gives you; Ankora acts under the data processing agreement signed with each centre. |
3. Purpose, legal basis and retention: what do we use your data for and for how long?
As controller, we process the following data:
| Processing | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Contact and information requests | Name, email, telephone and the content of the enquiry. | Responding to the request. | Consent or pre-contractual measures (Art. 6(1)(a) and 6(1)(b) GDPR). | As long as needed to respond. If the request leads to a contract, the data are then kept as client management data. |
| Client management | Identification and contact details of the centre and its representatives. | Providing the contracted service. | Performance of a contract (Art. 6(1)(b)). | For the term of the contract and, afterwards, for the limitation periods of any claims that may arise from it. |
| Client invoicing | The client's tax and billing details. | Complying with tax and commercial obligations. | Legal obligation (Art. 6(1)(c)). | Six years (Spanish Commercial Code) and at least four years (tax legislation). |
| Support | Name, email, profile, centre and the content of the enquiry. | Handling incidents and enquiries. | Performance of a contract (Art. 6(1)(b)). | Conversations with the support assistant are not stored: they disappear when you leave the screen. Enquiries sent through the contact form are kept for the term of the contract with the centre and, afterwards, for the limitation periods. Each submission is recorded in the audit log, without the text of the enquiry, for three years. |
| Platform security | Sign-in and access log, IP address, device identifier and technical error log. | Protecting accounts, preventing unauthorised access and detecting errors. | Legitimate interest (Art. 6(1)(f)) and the obligation to apply security measures (Art. 32 GDPR). | Sign-in log and error log: one year. Audit log: three years (five where it concerns health data, on behalf of the centre). |
| Operation of the mobile applications | The device's notification identifier and application crash reports (device model, operating system and app version, and the technical trace of the error), with no patient data or clinical record data. | Notifying the device that new information is available and fixing application errors. | Performance of a contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)). | The identifier, until you sign out on the device; crash reports, 90 days. |
| Service communications | Contact email. | Informing clients about the service. | Legitimate interest and Art. 21(2) LSSI-CE, or consent. | Until you unsubscribe. |
Once those periods have expired, or if erasure is requested while a legal obligation to keep the data still applies, the data are blocked: removed from all ordinary use and available only to courts and tribunals, the Public Prosecutor and the competent public authorities (Article 32 LOPDGDD) until they are destroyed.
4. Mobile applications: which permissions do they request and what do they store on your phone?
- Camera and microphone: only for video sessions with your therapist, and only while the video session is open. Video sessions run on Ankora's own servers, without third-party platforms.
- Notifications: to remind you of tasks, appointments and messages. The notification contains no clinical information: it only tells the app that new information is available.
- Data stored on the phone: so that it can work offline, the app keeps a copy of your information. That copy is excluded from the device's backups and is deleted when you sign out.
- We do not use your location, we show no advertising, we use no advertising analytics tools, and we do not sell or share data with third parties for commercial purposes.
5. Recipients: who do we share your data with?
We do not disclose data to third parties except where required by law: for example, to the Spanish Tax Agency, to courts and tribunals or to supervisory authorities.
To provide the service we rely on the following providers, which act as data processors under a contract that complies with Article 28 GDPR:
| Provider | Service | Location |
|---|---|---|
| Microsoft Ireland Operations Ltd. (Azure) | Hosting of the platform, database, file storage and email delivery. | European Union - Spain Central |
| Google Ireland Ltd. (Firebase) | Notifications to devices and application crash reports. | European Union and United States |
| Atlassian (Jira Service Management) | Handling of enquiries sent from the support screen. | European Union and United States |
The providers involved in processing patient data (hosting, email, notifications, speech transcription and language models) are disclosed to each centre in the data processing agreement, and each centre discloses them to its patients.
6. International transfers: does your data leave the European Union?
Some of the providers above may process data in the United States. In those cases the transfer is based on the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023) or, failing that, on the standard contractual clauses approved by the European Commission, in accordance with Chapter V GDPR.
7. Security: how do we protect your data?
We apply technical and organisational measures appropriate to the risk of processing health data (Article 32 GDPR), including:
- Encrypted connections for all communications, and encrypted stored data.
- Strong passwords, optional two-step verification and automatic sign-out after inactivity.
- Access to each clinical record limited to the professionals assigned to the patient, with a log of who viewed it and when.
- Service credentials kept in key vaults, no passwords in the code, and antivirus scanning of uploaded files.
- A duty of confidentiality for all staff and for providers with access to the data.
Even so, no security measure on the Internet is infallible. Please keep your password and recovery codes safe and sign out on shared devices.
8. Your rights: what rights do you have and how can you exercise them?
You may exercise the following rights free of charge:
- Access: to know which of your data we process and obtain a copy.
- Rectification: to correct inaccurate data.
- Erasure: to request deletion, with the blocking effect described in section 3 where there is an obligation to keep the data.
- Restriction of processing and objection to processing based on legitimate interest.
- Portability: to receive your data in a structured format.
- Withdrawal of consent at any time, where consent is the legal basis.
To exercise them, write to soporte@ankorahc.com stating which right you are exercising. Where necessary, we will ask you to verify your identity. We will reply within one month.
If you are a patient and wish to exercise your rights over your clinical record, contact your centre or your therapist. If you write to us instead, we will tell you who the controller is and forward your request without delay.
9. Complaints: where can you complain?
If you consider that we have not properly handled your rights, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos):
- Website: www.aepd.es
- Post: Agencia Española de Protección de Datos, C/ Jorge Juan, 6, 28001 Madrid, Spain
- Telephone: +34 901 100 099 and +34 912 663 517
Lodging a complaint with the Agency is free of charge and does not require a lawyer or legal representative.
10. Automated decision-making
Ankora does not take automated decisions with legal effects about the people whose data it processes as controller. The artificial intelligence tools that centres may enable help draft clinical documentation under the review of the professional, who makes the decisions; they are used on behalf of the centre, and it is the centre that informs its patients about them.
11. Minors
Ankora accounts cannot be created freely: they are created by the centre providing care. Where the patient is a minor, it is the centre's responsibility to obtain the authorisations required by law.
12. Changes to this policy
We may amend this policy to adapt it to changes in the law or in the service. The date of the last update appears at the top of this document and, if the change is significant, we will inform clients and users through the usual channels.