Privacy Policy
​
Last updated: December 12, 2025
​
This Privacy Policy describes how Abraham-Nilsen Clinic SL (“the Company”, “We”, “Us”, or “Our”) collects, uses, stores, and protects personal data when You use Our website and when You interact with Us as a patient or prospective patient.
As a medical clinic, We process special categories of personal data, including health data, in accordance with the EU General Data Protection Regulation (GDPR), the Spanish Organic Law 3/2018 (LOPDGDD), and applicable healthcare regulations.
By using Our Service or by providing Us with Your personal data, You acknowledge that Your data will be processed in accordance with this Privacy Policy.
Interpretation and Definitions
Interpretation
Words with capitalized initial letters have meanings defined below, whether used in singular or plural.
​
Definitions
-
Account means a unique account created for You to access parts of Our Service.
-
Company refers to Abraham-Nilsen Clinic SL, C.C. Elviria, Oficina 1-2, Spain.
-
Cookies are small files placed on Your Device by a website.
-
Country refers to Spain.
-
Device means any device that can access the Service.
-
Personal Data means any information relating to an identified or identifiable individual.
-
Health Data means personal data related to physical or mental health, medical history, diagnoses, treatments, or clinical information, considered special category data under Article 9 GDPR.
-
Service refers to the Website.
-
Service Provider means any third party processing data on behalf of the Company.
-
Usage Data means data collected automatically through use of the Service.
-
Website refers to Clinica NorMed, accessible at https://www.clinicanormed.com/
-
You means the individual using the Service or receiving medical services from the Clinic.
​
​
Collecting and Using Your Personal Data
Types of Data Collected
1. Personal and Identification Data
-
First and last name
-
Date of birth
-
Identification details (when legally required)
-
Email address
-
Phone number
-
Postal address​
​
2. Health and Medical Data
When You receive medical or aesthetic treatments, We may process:
-
Medical history and anamnesis
-
Diagnoses and treatment plans
-
Clinical notes, photographs (with consent), and treatment records
-
Information relevant to patient safety and continuity of care
This data is processed only by authorized healthcare professionals and subject to medical confidentiality.
​​​
3. Usage Data
Automatically collected data may include:
-
IP address
-
Browser type and version
-
Pages visited and time spent
-
Device identifiers
-
Diagnostic and performance data
​
​
Lawful Basis for Processing
We process Your Personal Data based on one or more of the following legal grounds:
-
Performance of a contract (medical services requested by You)
-
Compliance with legal obligations (healthcare, tax, and record-keeping laws)
-
Protection of vital interests (patient safety)
-
Explicit consent (Article 9 GDPR) for processing health data where required
-
Legitimate interests, provided they do not override Your fundamental rights
​
​
Use of Your Personal Data
We use Your data to:
-
Provide medical, aesthetic, and healthcare services
-
Manage appointments, treatments, and patient records
-
Communicate with You regarding care, follow-ups, or administrative matters
-
Maintain legally required medical documentation
-
Improve the quality and safety of Our services
-
Send marketing communications only with Your explicit consent
-
Comply with regulatory and legal obligations
​
​
Sharing Your Personal Data
Your data may be shared only when necessary and under strict confidentiality:
-
With Service Providers (e.g. IT systems, hosting, appointment software, laboratories), under Data Processing Agreements
-
With healthcare professionals involved in Your treatment
-
With public authorities when legally required
-
In business transfers, subject to continued GDPR protection
-
With Your explicit consent, where applicable
​
​
We never sell patient or health data.
​Retention of Your Personal Data
-
Medical records are retained for the period required by Spanish healthcare law (generally minimum 5 years, often longer depending on treatment type).
-
Administrative and billing data is retained as required by tax and accounting laws.
-
Usage Data is retained for shorter periods unless needed for security or legal compliance.
​
​
International Data Transfers
​Your data is primarily processed within the European Economic Area (EEA).
If data is transferred outside the EEA, We ensure appropriate safeguards, such as:
-
EU Standard Contractual Clauses (SCCs)
-
Adequacy decisions by the European Commission
​
​
Security of Your Personal Data
​We apply appropriate technical and organizational measures, including:
-
Restricted access to medical data
-
Secure systems and encrypted communications where appropriate
-
Staff confidentiality obligations
Despite these measures, no system can be guaranteed 100% secure.
​
​
Your Data Protection Rights (GDPR)
​You have the right to:
-
Access Your personal data
-
Rectify inaccurate or incomplete data
-
Request erasure (where legally possible)
-
Restrict or object to processing
-
Data portability
-
Withdraw consent at any time
-
Lodge a complaint with the Spanish Data Protection Authority (AEPD)
Some rights may be limited due to medical record retention obligations.
​
Children’s Privacy
Our services are not directed at children under 14 years of age without parental or legal guardian consent, in accordance with Spanish law.
​
Cookies and Tracking Technologies
We use Cookies and similar technologies to operate and improve Our Website.
You can manage Cookies through Your browser settings. For more details, see Our Cookies Policy.
​
Links to Other Websites
Our Website may contain links to third-party sites. We are not responsible for their privacy practices and recommend reviewing their policies.
​
Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
Updates will be published on this page with a revised “Last updated” date.
​
Contact Us
If You have any questions or wish to exercise Your data protection rights, contact Us at:
​
Abraham-Nilsen Clinic SL
C.C. Elviria, Oficina 1-2
Email: info@clinicanormed.com
Phone: +34 952 836 377
Website: https://www.clinicanormed.com/
