Privacy Policy
Last updated: 6 September 2026
This policy explains how BIO-SENSING SOLUTIONS, S.L., trading as DyCare, processes personal data relating to visitors to dycare.com, users of its forms and people who contact the company through its corporate channels.
It applies to DyCare’s corporate website. It does not govern patient or health data processed through ReHub. Such processing is governed by ReHub-specific information, agreements with healthcare organisations and the notices provided by the healthcare provider acting as controller.
1. Data controller
Controller: BIO-SENSING SOLUTIONS, S.L. (DyCare)
Tax ID: B66508912
Commercial Registry: Barcelona Commercial Registry, Volume 45087, Folio 42, Sheet B-465593
Address: Avenida Meridiana 354, 2nd floor, 08027 Barcelona, Spain
Telephone: +34 935 520 029
General email: info@dycare.com
Data Protection Officer: dpo@dycare.com
2. Personal data we may process
Depending on the interaction, we may process identification and contact data, organisation and professional details, form and correspondence data, marketing preferences, recruitment information, testimonials or images supplied with authorisation, and technical data such as IP address, device, browser, logs and cookie identifiers.
Please do not send health data through general corporate forms. If you need support concerning ReHub, use support@dycare.com and avoid including unnecessary clinical information.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Answer enquiries and support requests | Pre-contractual measures, performance of a contract or legitimate interest in handling enquiries |
| Manage commercial and contractual relationships | Pre-contractual measures, performance of a contract and legal obligations |
| Send marketing communications | Consent or legitimate interest where legally permitted |
| Manage recruitment | Pre-contractual measures and, for future opportunities, consent |
| Publish testimonials or images | Consent or another documented legal basis |
| Security, fraud prevention and website operation | Legitimate interest and legal obligations |
| Analytics and non-essential cookies | Consent, where required |
4. Required information
Fields marked as mandatory are required to deal with the request or provide the relevant service. Failure to provide them may prevent us from responding or entering into the requested relationship.
5. Recipients and service providers
Data may be disclosed when required by law and processed by providers acting on DyCare’s instructions, including Hostinger for web hosting and infrastructure, HubSpot for relationship and form management, and Google for configured analytics, productivity or website services. Primary hosting for this website is in Frankfurt, Germany, with backups in France. Providers are subject to contracts and security obligations.
6. International transfers
Some providers may process data outside the European Economic Area. Where this occurs, DyCare relies on an adequacy decision, Standard Contractual Clauses or another mechanism permitted by the GDPR, together with supplementary safeguards where appropriate.
7. Retention
- Enquiries: while handled and generally for up to one year after closure, unless a longer period is necessary.
- Contracts: for their duration and the applicable commercial, tax and limitation periods.
- Marketing: until consent is withdrawn or the person objects, retaining minimal suppression data.
- Recruitment: during the process and, if authorised for future opportunities, for up to two years.
- Testimonials and images: while authorised publication continues or until consent is withdrawn for future use.
- Cookies and security logs: for the periods stated in the cookie policy or required to investigate incidents.
8. Individual rights
You may request access, rectification, erasure, restriction, portability or objection, and withdraw consent at any time, by writing to dpo@dycare.com. We may request information necessary to verify identity. You may also lodge a complaint with the Spanish Data Protection Agency at www.aepd.es or with the competent supervisory authority.
9. Automated decisions
The corporate website does not make decisions producing legal or similarly significant effects based solely on automated processing. If this changes, the required information and safeguards will be provided.
10. Children
The corporate website is not intended to collect children’s data without appropriate authorisation. A parent or guardian who believes a child has provided data should contact dpo@dycare.com.
11. Security and confidentiality
DyCare applies appropriate technical and organisational measures based on risk. No Internet system is completely secure; suspected incidents should be reported to support@dycare.com.
12. Social networks and external links
Interactions on social networks are also subject to the provider’s terms and privacy policy. External websites are controlled by their respective operators.
13. Marketing communications
DyCare will not send electronic marketing without a valid legal basis. Every message will provide a simple, free opt-out method. Requests may also be sent to marketing@dycare.com.
14. Changes
DyCare may update this policy to reflect legal, technical or processing changes. The current version and update date will be published here, and material changes will be communicated appropriately.
15. Language
The Spanish version is the reference version. If a translation conflicts with it, the Spanish text prevails, without prejudice to rights granted by applicable law.
