Legal

Privacy Policy

Last updated: May 2026

1. Introduction

Clinitrace ("we", "our", or "us") is a Spain-based healthcare compliance platform committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform and website at clinitrace.com, in accordance with the EU General Data Protection Regulation (GDPR) and Spain's Organic Law 3/2018 (LOPDGDD).

By accessing or using our services, you agree to the terms of this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.

2. Information We Collect

We collect information that you provide directly to us, including:

  • Contact information (name, email address, phone number)
  • Organisation and institution details, including Ministry of Health/Spanish healthcare licensing information
  • Account credentials
  • Communication preferences
  • Compliance activity logs and documentation
  • Operational data synced from your integrated EMR and HRIS systems (such as staff records, credentials, and service configurations)
  • Any other information you choose to provide

Zero patient health data retention: Clinitrace is a compliance platform, not a clinical record system. We do not collect, store, or retain patient medical records or personal health information. Our platform is engineered to manage institutional compliance activities only. Where an integration briefly surfaces operational data, we access the minimum necessary information on a read-only basis and never persist patient records to our systems.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our compliance services
  • Send you regulatory updates and compliance notifications
  • Process transactions and send related information
  • Respond to your enquiries and provide customer support
  • Send promotional communications (with your consent)
  • Monitor and analyse usage patterns and trends
  • Protect against fraud and unauthorised access

4. Data Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

  • Service Providers: With third-party vendors who assist in providing our services
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • With Your Consent: When you have given us permission to share

5. Data Security & Localisation

Data is hosted on secure infrastructure within the European Economic Area where practicable. We implement enterprise-grade technical and organisational measures to protect your information, including AES-256 encryption at rest, TLS 1.2+ encryption in transit, role-based access controls, network isolation, and continuous security monitoring.

Our data localisation approach ensures your compliance data remains subject to Spain law and GDPR protections at all times. We conduct regular security assessments and penetration testing to maintain these standards.

While no method of electronic transmission or storage is completely secure, we use commercially reasonable and industry-leading means to protect your information.

6. Data Retention

We retain your personal information for as long as necessary to fulfil the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. When we no longer need your information, we will securely delete or anonymise it.

7. Your Rights Under the GDPR and LOPDGDD

Under the GDPR and LOPDGDD, you have the following rights in relation to your personal data:

  • Access: Request access to the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Withdrawal of Consent: Withdraw consent to the collection, use, or disclosure of your data
  • Data Portability: Request transfer of your data to another organisation, where applicable
  • Deletion: Request deletion of your personal data where retention is no longer required

To exercise any of these rights, or to reach our Data Protection Officer, please contact us at privacy@clinitrace.com. We will respond in accordance with GDPR timelines.

8. Cookies

We use cookies and similar tracking technologies to collect and track information about your use of our website. You can control the use of cookies through your browser settings. For more information, please see our Cookie Policy.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.

10. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Clinitrace - Data Protection Office

Email: privacy@clinitrace.com