Privacy policy
At Facilitra we process personal data every day, our customers', the technicians who use Field, the patients who book through Bookings. This policy explains what data we collect, what we use it for, and what control you have over it. We've written it without unnecessary jargon.
1. Data controller
The data controller is Manuel Raya Coello (NIF 49064506D), a sole trader operating under the Facilitra brand from Huelva, Spain. You can get in touch at hola@facilitra.com.
For specific privacy matters or to exercise your rights, write to privacy@facilitra.com.
2. What data we process
We process different categories of data depending on how you interact with us:
If you visit facilitra.com
Anonymous browsing data (page visited, rough device, country). We use analytics that don't require tracking cookies. We don't profile you.
If you write via the form or email
Name, email, company (optional), the language you wrote in and message content. We retain it for as long as the commercial conversation lasts and, if it doesn't convert to a customer, up to 24 months so we can pick it back up.
If you're a Facilitra Field or Bookings customer
Customer company data, authorised users, operational data you upload (end-customers, appointments, visits) and system usage logs. We process this data as a processor, not a controller, you decide what comes in and goes out. The signed DPA applies.
If you've subscribed to the newsletter
Your email address and the language you subscribed in, so we write to you in it. Nothing else: no name, no company, no open tracking. You leave in one click, no justification needed, and from then on we keep your address on an exclusion list, precisely so we never write to you again.
If you join the talent network
Name, email, the language you signed up in, area of interest, your LinkedIn profile if you give us one, and whatever you tell us about yourself. The legal basis is your consent, which we record with a timestamp and which you can withdraw at any time by writing to privacy@facilitra.com. We keep it for 12 months and then it is deleted automatically. We don't ask for a CV, there is no automated screening, and we only share it with the vendors we need to operate, listed in section 4.
3. Legal basis
The legal bases we apply are:
- Performance of a contract, when you're a Facilitra customer or in an active commercial conversation.
- Legitimate interest, for operational communications to existing customers and anonymous site usage measurement.
- Consent, for the newsletter, the talent network and any communication that isn't strictly contractual. You can withdraw at any time.
- Legal obligation, to retain invoicing and other documents required by tax and commercial law.
4. Who we share data with
We don't sell data. We share only with vendors we need to operate, all bound by processor agreements and EU residency:
- Cloud infrastructure (Hetzner, Germany, Finland).
- Transactional email (Postmark, EU).
- Messaging (Meta WhatsApp Business API, EU hosting).
- SMS (Iberian carriers via SMSAPI).
- Payment processor (Stripe, EEA).
If we ever bring on a vendor outside the EEA, we'll update this list and apply the additional safeguards required (European Commission's Standard Contractual Clauses).
5. Your rights
You have the following rights over your data:
- Access, request a copy of the data we hold about you.
- Rectification, correct inaccurate data.
- Erasure, ask us to delete it, within the periods the law allows.
- Objection, object to processing based on legitimate interest.
- Portability, receive your data in a structured format and take it with you.
- Restriction, ask us to pause a specific processing while a dispute is resolved.
- Complaint to the authority, AEPD in Spain (aepd.es), CNPD in Portugal (cnpd.pt).
Write to privacy@facilitra.com and we'll reply within 30 calendar days. If we reply within three business days, it isn't because we're rushing, it's because that's the reasonable thing to do.
6. Security
We run a security program proportionate to the risk of the data we process. Key measures:
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- Role-based access with multi-factor authentication for employees.
- Daily encrypted backups, retained for 35 days inside the EU.
- Annual external audit.
- Documented continuity plan and incident response procedure.
If we detect a breach affecting your data, we'll notify you within 72 hours of becoming aware, along with the measures we're taking.
7. Changes to this policy
If we update this policy, we'll announce it on this page and, if changes are material, we'll email you. The "last updated" date is always at the top of the document.