Legal document

Privacy Policy

Last updated: 22 July 2026

1. Data controller

Controller: MilOffers S.L.

Contact email: hola@miloffers.com

General purpose: platform management, clinic accounts, users, coupons, communications and support.

2. Data we process

  • Identification and contact data (name, email, phone, clinic address).
  • Account and authentication data.
  • Billing and payment data (processed by payment providers).
  • Browsing data, technical and analytics cookies.
  • Patient/end-user data in relation to coupons and forms.

3. Purposes and legal bases

  • Provision of contracted service (contract performance).
  • Registration, access and security management (legitimate interest / contract).
  • Billing and legal obligations (legal obligation).
  • Commercial communications about the service (legitimate interest or consent).
  • Platform improvement and aggregated analytics (legitimate interest).

4. Retention

We will retain data while a contractual relationship exists or as necessary for the stated purposes, and thereafter for applicable statutory limitation periods.

Billing data will be retained according to tax and commercial regulations.

5. Data subject rights

You may exercise rights of access, rectification, erasure, objection, restriction and portability, and withdraw consent where consent is the legal basis.

To exercise them, email hola@miloffers.com stating your request and proving your identity.

You have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) if you consider processing does not comply with regulations.

6. Processors and transfers

We use technology providers (hosting, email, payments, analytics) who process data on our behalf with contractual guarantees required by GDPR.

If international transfers occur, appropriate safeguards will be adopted (standard contractual clauses or other recognised measures).

7. Security

We apply reasonable technical and organisational measures to protect data against unauthorised access, loss or alteration.

No system is completely secure; users must safeguard credentials and report suspicious access.