⚠️ Provisional draft pending legal review.
Data processing agreement
Last updated: September 26, 2026
Parties and subject matter
The customer (controller) engages [RAZÓN SOCIAL] (processor) to process the personal data of its end customers as needed to provide Recepta, in accordance with Article 28 GDPR.
Data and purpose
Categories: name, phone, email, messaging identifiers, conversation content, transcripts and, if enabled, recordings; appointment data. Purpose: handle communications, manage appointments and produce summaries for the customer.
No special categories of data (e.g. health) will be processed: the assistant only manages appointments and must not collect clinical information.
Processor obligations
Process data only on the customer's documented instructions; ensure confidentiality; apply appropriate security measures (encryption, access control, per-customer isolation); assist with data subject requests; notify breaches without undue delay; delete or return data when the service ends.
Sub-processors
The customer authorises the sub-processors listed in the Privacy policy (hosting, AI, telephony, messaging, payments, email). Changes will be notified in advance so the customer can object.
Location
Data is hosted in the EU. Any international transfer relies on appropriate GDPR safeguards.