PRIVACY POLICY
1. Data Controller
In accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and Organic Law 3/2018 on Personal Data Protection and Digital Rights (Spain), the following information is provided:
Data Controller: Dr. Lorena Olvera Moreno
Professional Activity: Sexology, Sex Therapy, and Couples Therapy Services
Professional Address: Alcalá de Henares, España
Contact Email: info@lorenaolvera.com
Website: www.lorenaolvera.com
2. Personal Data Collected
Through this website, the following categories of personal data may be collected:
-
Full name
-
Email address
-
Phone number
-
Availability for scheduling sessions
-
Information voluntarily provided through contact or booking forms, including the reason for consultation
The reason for consultation may involve the disclosure of special categories of personal data under Article 9 of the GDPR, including information relating to health, sexual life, or other highly sensitive personal matters.
Such data will be processed solely with the explicit consent of the data subject and under strict confidentiality and security measures in accordance with applicable data protection laws.
Data subjects guarantee that the personal data provided is accurate and truthful.
3. Purpose of Data Processing
Personal data will be processed for the following purposes:
-
Manage information requests submitted through the contact form.
-
Manage the booking of sessions and the provision of professional services.
-
Manage billing and compliance with legal obligations.
-
Maintain communications related to the provision of the service.
No automated decisions or profiling will be carried out.
4. Legal Basis for Processing
The processing of personal data is based on:
-
The explicit consent of the data subject when submitting a contact or booking form
-
The performance of a service contract
-
Compliance with applicable legal obligations
For special categories of personal data, processing is based on the explicit consent of the data subject pursuant to Article 9(2)(a) GDPR.
5. Data Retention
Personal data will be retained for as long as necessary to fulfill the purposes for which it was collected and in accordance with applicable legal requirements.
6. Data Recipients
Personal data will not be shared with third parties unless required by law.
However, data may be processed by service providers necessary for the operation of the website and payment processing, including:
-
Wix (website hosting and management platform)
-
Stripe (payment processing)
-
PayPal (payment processing)
These providers act as data processors and provide appropriate safeguards in accordance with the GDPR.
As some of these providers may be located outside the European Economic Area (EEA), international data transfers may occur. Such transfers will be carried out in compliance with applicable data protection laws and subject to appropriate safeguards, such as Standard Contractual Clauses (SCCs), where applicable.
7. Professional Confidentiality
Information shared within the professional relationship will be treated with the highest level of confidentiality and in accordance with applicable ethical and professional standards in sexology and couples therapy.
Special category data relating to health, intimate life, or personal matters will be handled with particular care and used exclusively for the provision of professional services.
Disclosure will only occur if legally required or mandated by judicial authority.
8. Data Subject Rights
Data subjects may exercise the following rights:
-
Right of access
-
Right to rectification
-
Right to erasure
-
Right to restriction of processing
-
Right to object
-
Right to data portability
To exercise these rights, you may send a request to the email address indicated above, attaching a copy of an identification document.
You also have the right to file a complaint with the Spanish Data Protection Agency (AEPD) (www.aepd.es).
9. Data Security
Appropriate technical and organizational measures are implemented to ensure the security and confidentiality of personal data and to prevent unauthorized access, alteration, loss, or misuse.
10. Updates to this Privacy Policy
This Privacy Policy may be updated to reflect legal, regulatory, or operational changes. Users are encouraged to review it periodically.