1. Controller and Data Protection Officer
Controller: ASKABIDE KLINIKA S.L., tax ID B20864211, Easo kalea 79, 20006 Donostia, 943 444 792, askabide@askabide.com.
DPO: Previsión Sanitaria, Servicios y Consultoría, S.L.U., tax ID B82663188, C/ Génova 26, 28004 Madrid, 914 311 244, protecciondedatos@grupopsn.es.
2. Data categories
- Identity and contact details.
- Appointment, billing, insurance and referral data.
- Health data: indication, relevant history, pregnancy, medication, specimen, results and reports.
- Genetic or biometric data when required by the ordered test.
- Consent, traceability and chain-of-custody records.
- Minimal technical browsing and language/cookie preferences.
Data minimisation applies. Clinical information that needs a secure healthcare channel should not be sent through WhatsApp.
3. Purposes and legal bases
| Purpose | Main legal basis |
|---|---|
| Answer enquiries, estimates and appointments. | Pre-contractual steps, care relationship or consent where required. |
| Identify the patient, collect and handle samples, perform or refer tests and deliver results. | Healthcare/diagnosis; GDPR Arts. 6(1)(b)/(c) and 9(2)(h), healthcare law and professional secrecy. |
| Clinical records, quality, safety, billing and retention duties. | Legal obligation, public-health interest and care provision. |
| Transfer data to the requesting professional or necessary partner laboratory. | Healthcare provision, service performance and confidentiality safeguards. |
| Optional marketing. | Specific, withdrawable consent; care is never conditional on it. |
4. Data source
Data may come from the person, an authorised representative, the requesting professional or centre, the payer/insurer when involved and partner laboratories returning results. Anyone providing another person’s data must have sufficient authority.
Delivery of results by email: Askabide normally sends reports by email after review and validation, using the address supplied or confirmed by the patient. The public website does not store or display clinical reports; delivery takes place through the email channel agreed with the centre.
5. Recipients and processors
Access is restricted to authorised staff who need it. Data may be disclosed to partner laboratories for genetics, confirmation, microbiology, pathology or specialist testing; contracted IT, hosting, maintenance, security, sample transport and confidential-destruction suppliers; requesting professionals, payers and authorities where legally justified. Personal data are not sold.
6. International transfers and WhatsApp
The website does not embed Meta pixels or send information to WhatsApp before the user clicks the link. Opening WhatsApp also subjects processing to WhatsApp/Meta terms and may involve international transfers.
WhatsApp is for administrative information and appointments only. Do not send reports, intimate images, identity documents, genetic results or urgent information. Askabide will provide a secure alternative when needed.
7. Retention
Enquiries not leading to care are kept only as necessary to respond and meet liabilities. Clinical documentation, reports and traceability are retained for applicable healthcare, tax, quality and limitation periods. Erasure cannot remove records that must legally be kept.
8. Rights
You may request access, rectification, erasure where applicable, restriction, objection, portability and withdrawal of consent. Contact askabide@askabide.com or the controller’s address, marking the request “Data protection” and proving identity proportionately. You may also contact the DPO.
You may complain to the Spanish Data Protection Agency: www.aepd.es.
9. Minors and representation
Testing minors or represented persons requires the documentation and involvement set by law and by the test type. Genetics and kinship tests use specific consent; covert or unauthorised specimens are not accepted.
10. Security
Askabide applies access controls, traceability, backups, appropriate encryption or equivalent measures, training, professional secrecy and incident management. No system eliminates all risk; incidents are assessed and notified where GDPR requires.
11. Version
Last reviewed: 17 August 2026. This policy will be updated if contact channels, email delivery of results, providers or partner laboratories change.