Legal
Privacy Policy
Draft translation · pending legal review.
Data controller
- Identity: Orkestra System SL
- Email: informacion@orkestrasystem.com
- Website: www.orkestrasystem.com
Scope of this policy
This policy applies to processing carried out through orkestrasystem.com and associated forms, as well as to the care relationship with patients.
Data we process
- Identification and contact: first name, surname, email, phone, city.
- Appointment and attendance data: schedule, assigned professional, reason for consultation as stated by the user.
- Billing and transaction data (where applicable).
- Browsing and analytics data (cookies; see the Cookie Policy).
- Job applications (CV).
- Marketing preferences and segmentation.
Purposes and legal bases
- Provision of care and management of appointments / medical records.
Basis: art. 6.1.b GDPR (performance of a contract/service) and art. 9.2.h GDPR (healthcare). - Handling enquiries (forms, email, phone).
Basis: 6.1.b and/or 6.1.f (legitimate interest). - Compliance with legal obligations (health, tax, accounting, claims).
Basis: 6.1.c GDPR. - Informational and commercial communications (newsletter, reviews) about our own services.
Basis: 6.1.a (consent) and art. 21.2 of the Spanish LSSI (prior relationship). You may object freely at any time. - Analytics and advertising/remarketing (via cookies).
Basis: 6.1.a GDPR (consent). - Recruitment processes (job applications).
Basis: 6.1.a and 6.1.b (pre-contractual measures). - Basic marketing profiling (express consent). No automated decisions with legal effects.
Recipients and processors
- HubSpot (forms) · Google Analytics / Tag Manager (analytics)
- Doctoralia (patient scheduling and CRM) · GoDaddy (hosting)
- Google Workspace (office software) · Square and Caixabank (payments)
- WhatsApp Business (customer support) · Adobe Sign (electronic signatures)
- Public authorities, judges and courts where there is a legal obligation.
International transfers: none are currently envisaged; all providers operate within the EEA. Should any be necessary, Standard Contractual Clauses would apply.
Retention periods
- Medical records: minimum 5 years (or the legal period applicable by autonomous community).
- Customer and billing data: 6 years (commercial) / 4 years (tax).
- Leads and enquiries: up to 24 months from the last contact or revocation.
- Marketing: until you object or withdraw consent.
- Job applications: up to 24 months unless revoked.
Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction, portability and not to be subject to automated decisions by writing to informacion@orkestrasystem.com (subject: "GDPR – Rights") attaching an identity document. You may also lodge a complaint with the Spanish Data Protection Agency.
Minors
Our services are intended for people over 14 years of age.
Security
We apply appropriate technical and organizational measures (encryption in transit, access controls, backups, access logging, etc.). In the event of a notifiable breach, we will act in accordance with the GDPR.
Social media
Your interaction with our profiles is governed by this policy and the terms of each platform. We do not use private messages for incompatible purposes.
TikTok integration
Orkestra System SL uses the TikTok API to publish content on our official account. Through this integration:
- Data we collect: username, account identifier and TikTok post metrics.
- Purpose: management and publication of content on our TikTok account for communication and marketing purposes.
- Legal basis: legitimate interest in communicating with our community.
- Retention: access data is kept while the integration remains active and is deleted when permissions are revoked.
- Rights: you can revoke our application's access at any time from your TikTok account privacy settings at tiktok.com/setting.
- More information: see TikTok's privacy policy at tiktok.com/legal/privacy-policy.
Cookies
See the Cookie Policy for more information.
Changes to this policy
We may update this policy for legal or operational reasons and will publish the date of the last update.
Last updated: February 2026
Last updated: 2026-04-23