Skip to content
Recepta

⚠️ Provisional draft pending legal review.

Data processing agreement

Last updated: September 26, 2026

Parties and subject matter

The customer (controller) engages [RAZÓN SOCIAL] (processor) to process the personal data of its end customers as needed to provide Recepta, in accordance with Article 28 GDPR.

Data and purpose

Categories: name, phone, email, messaging identifiers, conversation content, transcripts and, if enabled, recordings; appointment data. Purpose: handle communications, manage appointments and produce summaries for the customer.

No special categories of data (e.g. health) will be processed: the assistant only manages appointments and must not collect clinical information.

Processor obligations

Process data only on the customer's documented instructions; ensure confidentiality; apply appropriate security measures (encryption, access control, per-customer isolation); assist with data subject requests; notify breaches without undue delay; delete or return data when the service ends.

Sub-processors

The customer authorises the sub-processors listed in the Privacy policy (hosting, AI, telephony, messaging, payments, email). Changes will be notified in advance so the customer can object.

Location

Data is hosted in the EU. Any international transfer relies on appropriate GDPR safeguards.