AiON

Privacy Policy

At AiON we process particularly sensitive personal data — health data — and we take that responsibility with the utmost rigour. This Privacy Policy describes what data we process, for what purposes, on what legal bases, and what rights you have, in accordance with Regulation (EU) 2016/679 ("GDPR") and Organic Law 3/2018 ("LOPDGDD").

1. Data controller

AION MEDTECH, S.L. ("AiON"), with registered office at Carretera de Mendavia 11, Pabellón 16, 26009 Logroño (La Rioja), España. You can contact us regarding any data protection matter at the email address indicated at the end of this policy.

2. Data we process

Depending on the services you use, we process the following categories of data:

  • Identification and contact data: full name, national ID (DNI/NIE), date of birth, postal address, email address and telephone number.
  • Health data: the information you provide in the assessment questionnaires, medical history, measurements (for example, weight), treatments, prescriptions and the clinical documentation generated during follow-up.
  • Identity verification data: identity document and facial image, where verification is required for the medical act.
  • Transaction data: products and programmes contracted and order history. Full payment details are processed directly by our payment gateways; AiON does not store your card details.
  • Browsing data: IP address, device identifiers and platform usage data, in accordance with the Cookie Policy.

3. Purposes and legal bases

We process your data for the following purposes:

  • Provision of the telemedicine service (medical assessment, prescription, follow-up and medical records): performance of the contract and, with regard to health data, your explicit consent and the purposes of preventive medicine, diagnosis and provision of healthcare set out in Article 9(2)(h) of the GDPR, under the responsibility of professionals subject to professional secrecy.
  • Administrative management, invoicing and customer service: performance of the contract and compliance with legal obligations.
  • Retention of medical records: compliance with the legal obligations set out in Law 41/2002 on patient autonomy.
  • Identity verification: compliance with legal obligations and safeguarding the security of the medical act.
  • Commercial communications about our products and services: your consent, which you may withdraw at any time. We never use your health data for advertising purposes.
  • Platform improvement and analytics: your consent (cookies) and our legitimate interest in improving the service, using aggregated or pseudonymised data wherever possible.

4. Recipients of the data

Your data may be disclosed, only to the extent necessary, to:

  • The registered physicians who assess and follow up your case, subject to professional secrecy.
  • Authorised pharmacies, where a prescription exists, for dispensing the treatment.
  • Providers acting as data processors: hosting and technology platform, payment gateways, identity verification, delivery of communications, logistics for physical shipments and analytics tools. All of them under contract in accordance with Article 28 of the GDPR.
  • Public administrations and authorities, where there is a legal obligation.

We do not sell your personal data to third parties.

5. International transfers

Some of our technology providers may be located outside the European Economic Area. In such cases, we ensure that transfers are covered by adequacy decisions of the European Commission or by standard contractual clauses, with any additional safeguards that may be required.

6. Retention periods

Data is retained for the duration of the contractual relationship and, thereafter, for the periods required by law. In particular, clinical documentation is retained for the minimum periods established by Law 41/2002 and the applicable regional legislation. Data processed on the basis of consent is retained until such consent is withdrawn.

7. Your rights

You may at any time exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, as well as withdraw any consent given, by writing to us at the email address indicated at the end of this policy and duly identifying yourself.

If you consider that the processing does not comply with the applicable legislation, you may lodge a complaint with the Spanish Data Protection Agency (AEPD) (www.aepd.es).

8. Security

We apply technical and organisational measures appropriate to the risk, including encryption of communications, access controls, pseudonymisation where appropriate and staff training. Access to health data is restricted to healthcare personnel and strictly authorised staff.

9. Minors

Our services are aimed exclusively at persons over 18 years of age. We do not knowingly process data relating to minors; if we detect that a minor has registered, we will delete the data.

10. Updates to this policy

We may update this Privacy Policy to reflect regulatory or operational changes. We will publish the current version on this page and, if the changes are substantial, we will notify you.

Contact

For any questions about this policy or about the processing of your data:

AION MEDTECH, S.L.
Carretera de Mendavia 11, Pabellón 16
26009 Logroño (La Rioja), España
[email protected]