Skip to main content

Data Processing Agreement (DPA)

Last updated: 8 October 2026

1Parties

This Data Processing Agreement (the «Agreement») governs the personal data MiEspacio processes on behalf of your business when providing the Platform. It gives effect to Article 28 of Regulation (EU) 2016/679 (GDPR) and to Spanish Organic Law 3/2018 (LOPDGDD).

Controller: the business that owns the account («you»). You decide what data you put into the Platform and why.

Processor:

  • Name: Bohdan Hordiychuk
  • Tax ID: Y9939706V
  • Address: Alicante, España
  • Data protection contact: privacy@miespacio.app

This Agreement forms part of the Terms of Use and is accepted when the account is created. On anything concerning personal data, it prevails over the Terms.

2Scope

Subject matter: provision of the Platform for managing bookings, clients, staff, payments and communications.

Duration: for as long as the account is active, plus the retention period in clause 10.

Nature and purpose: to host, organise, retrieve, transmit and erase the personal data you enter, solely in order to provide the service and to meet the legal obligations that bind us.

We do not process your data for our own purposes. We do not sell it, we do not pass it to third parties for commercial purposes, and we do not use it to train artificial intelligence models.

3Instructions

We process personal data only on your documented instructions. Documented instructions comprise this Agreement, the Terms of Use, and the actions you take inside the Platform — creating a booking, sending a reminder, exporting your client book, anonymising a record.

If we consider an instruction of yours to infringe the GDPR or the LOPDGDD, we will tell you without delay and may suspend it until you confirm or amend it.

Where a legal obligation requires us to process the data otherwise, we will inform you before doing so unless the law itself prohibits that on public interest grounds.

4Confidentiality

The people authorised on our side to process personal data are bound by an express duty of confidentiality of indefinite duration, which survives the end of their engagement with us.

Internal access to a business's data is limited to what is strictly necessary to resolve a specific incident, and it is logged.

5Security

We apply at least the following technical and organisational measures:

  • Encryption in transit: TLS 1.2 or above on every connection.
  • Field-level encryption at rest for the most sensitive categories: client medical notes, chat content, SMS bodies, two-factor secrets, passkeys and device tokens.
  • Isolation between businesses: every record carries a company identifier and every query is filtered by it; an attempt to reach another business's data resolves as «not found».
  • Role-based access control with per-employee permissions, so each member of your team sees only what they need.
  • Immutable audit log: audit entries cannot be modified or deleted; the restriction is enforced in the database itself.
  • Daily backups kept for 30 days, followed by weekly and monthly copies, with the backup archive encrypted.
  • Rate limiting on authentication and on bulk export endpoints.

These measures may evolve; we will not lower the level of security provided.

6Sub-processors

You give us general authorisation to engage the sub-processors listed in Annex II. With each of them we maintain a contract imposing data protection obligations equivalent to those in this Agreement.

We will give you at least 30 days' notice before adding or replacing any sub-processor. Within that period you may object on reasonable data protection grounds; if we cannot offer an alternative, you may terminate the service without penalty.

We remain liable to you for our sub-processors' performance of their obligations.

7Transfers

Data is hosted in the European Union.

Some Annex II sub-processors are established outside the EEA. Where that is the case, the transfer relies on a European Commission adequacy decision or on the Standard Contractual Clauses, together with any supplementary measures required.

Artificial intelligence providers receive data only when you expressly enable an AI feature, and only the fragment that feature needs.

8Assistance

We assist you, through functions available in the Platform itself, so that you can meet data subject rights and your obligations under Articles 32 to 36 GDPR:

  • Access and portability: a full export of your client book and appointment history in machine-readable form, at any time and at no cost while your account access is active. When the service ends, you may request return of the data through our privacy contact, subject to the retention periods in clause 10.
  • Erasure: anonymisation of a client record, which removes identifying data and keeps only the accounting record required by tax law.
  • Withdrawal of consent and management of communication preferences.
  • Rectification and restriction: editing and deactivating records from the panel.

If a data subject of yours contacts us directly, we will not answer on our own account: we will pass the request to you without delay so that you, as controller, resolve it.

9Breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting data processed on your behalf.

The notification will include, so far as we hold it: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where we cannot provide everything at once, we will provide it in phases.

Notification to the supervisory authority and, where required, to data subjects is yours to make as controller.

10End of processing

When the service ends, at your choice we will return or delete the personal data processed on your behalf.

You can exercise the return yourself at any time using the export described in clause 8.

Unless you instruct otherwise:

  • Recycle bin: deleted items are kept for 30 days before permanent removal, so an accidental deletion can be undone.
  • Backups: data may persist in backups for the retention cycle described in clause 5; it is isolated there and removed when that cycle ends.
  • Legal retention: we keep data whose retention is required of us by Union or Spanish law — in particular records with tax effect — for the legally required period and with restricted access.

The general retention period is configurable by your business within the limits set by law.

11Audit

We will make available to you the information needed to demonstrate compliance with this Agreement and with Article 28 GDPR.

We will allow for and contribute to audits, including inspections, conducted by you or by an auditor you appoint who is not a competitor of ours, on reasonable notice, during business hours, no more than once a year — unless a supervisory authority or a personal data breach warrants otherwise — and subject to confidentiality.

12Annex I: data

Categories of data subjects: your business's clients; people who book without registering; members of your team with access to the Platform; where applicable, legal guardians of minors.

Categories of personal data:

  • Identification and contact: name, phone number in international format, email address, date of birth, address.
  • Activity: appointment history, services provided, attendance and no-shows, preferences, internal notes, tags, loyalty programme.
  • Communications: content and status of SMS, WhatsApp, email and chat messages exchanged through the Platform.
  • Images: photographs you upload against a client record or a service.
  • Transactional: amounts, line items, payment status and tax documents. We do not store full card details: the client enters them directly with the payment provider.
  • Team data: identification, access credentials, working time and time records, absences and leave (including sick leave), leave balances, employee documents and their signatures, onboarding and offboarding checklists, birthdays and work anniversaries each person chooses to share, answers to internal team surveys (deleted when each survey closes; the group report is kept for 24 months), permissions and, where you use it, commission and payroll data.

Special categories (Art. 9 GDPR). The Platform provides fields for allergies, contraindications, medical notes, patch-test history and consent forms. These are health data. They are processed only if you choose to enter them, and the legal basis — normally the data subject's explicit consent — is yours to establish. These fields are stored encrypted. Absences recorded as sick leave reveal health data about your team; their legal basis (normally Article 9(2)(b) GDPR, obligations in the field of employment law) is your responsibility.

Minors. If your activity involves minors, it is for you to obtain and keep the consent of the holder of parental responsibility or guardianship, under Article 7 LOPDGDD.

13Annex II: sub-processors

The following providers may process personal data on our behalf. Those marked optional are involved only if you enable the corresponding feature.

  • Infrastructure and storage (application hosting, database, files and backups) — European Union.
  • Transactional email (confirmations, reminders, notices).
  • SMS — Twilio, LabsMobile, SMSPubli (depending on the configured provider).
  • WhatsApp — Twilio or Meta Platforms (optional).
  • Video consultation — Twilio (optional).
  • Push notifications — Google Firebase (optional).
  • Calendar sync — Google Calendar, Microsoft Outlook (optional).
  • Business profile and reviews — Google (optional).
  • Artificial intelligence features — OpenAI, Anthropic (optional; only the fragment the enabled feature needs).
  • Geocoding — Geoapify (optional).
  • Wallet passes — Apple, Google (optional).
  • Error monitoring — Sentry, with personal data scrubbed from reports.

These are not our sub-processors:

  • Redsys and Stripe when you charge your clients. The payment settles into your own account and you are the merchant of record; we never receive that money. Your relationship with the payment provider is direct.
  • The Spanish tax agency (AEAT). Sending fiscal documentation is a legal obligation, not processing on your instruction.
  • The billing provider for your MiEspacio subscription, in respect of which we act as controller and not as processor.

The current list is published on this page. Any change is notified under clause 6.

14Governing law

This Agreement is governed by Spanish law and by the law of the European Union. For any dispute, the parties submit to the courts having jurisdiction under the applicable rules.

This document is published in several languages. In the event of any discrepancy, the Spanish version prevails.

If any clause is held void, the remainder stays in force.

Questions about how we process data?

Write to us and we will answer with whatever technical detail you need.