Vita

Vita Systems

Privacy Policy

Effective date: 30 September 2026.

Last updated: 30 September 2026.

Version: 2.0.

This policy explains how Vita Systems processes personal data, and when it acts as controller or as processor. It applies to the Vita Systems website and to Vita Center, the SaaS platform used by clinics for appointment messaging (via WhatsApp), prescription management, staff scheduling, and billing.

1. Who we are

Controller: Joao Lucas Nóbrega Galdino, operating under the trade name Vita Systems (an unregistered trade name; Vita Systems is not a separate legal entity).

Address: 77 Avinguda d'Alacant, Elche, 03202, Spain.

NIF: Z3463352V.

Contact: info@vitasystems.app.

2. Our roles

2.1. As controller. Vita Systems is the controller of data it processes for its own purposes: website enquiries and sales communications, customer accounts, billing between Vita Systems and its clinic customers, and business administration.

2.2. As processor. When a clinic uses Vita Center to communicate with or manage its own patients or employees, the clinic is the data controller and Vita Systems acts as data processor. This relationship is governed by a separate Data Processing Agreement (DPA) between Vita Systems and the clinic. This policy does not replace that agreement.

In these cases, the clinic decides what data is sent and why. Individuals should contact the relevant clinic to exercise their rights over data the clinic controls (see section 10).

3. Data we process

3.1. Enquiries and business relationships. Name, email, professional information and enquiry content submitted via our website or WhatsApp; for customers, account details, contract and billing information, and service-related communications.

3.2. Clinic messaging (as processor). On the clinic's instructions, we may process: contact names and phone numbers, WhatsApp identifiers, message content, message attachments (images, documents, audio and similar files), delivery status and timestamps, and technical data needed to operate the service (message and API logs).

3.3. Prescriptions (as processor). Where a clinic uses this feature, we may process prescription content entered by clinic staff, which can include patient name, diagnosis, dosage and treatment information, and a generated PDF document. This is entered and controlled entirely by the clinic.

3.4. Staff and scheduling (as processor). Employee name, role, working schedule and related identifiers, entered and controlled by the clinic as employer.

3.5. Billing (as controller). Vita Systems bills clinics directly for the service through Stripe. We do not currently process patient billing or payment data.

4. Purposes and legal basis

As controller, we process data to respond to enquiries, prepare quotations, enter into and administer contracts, manage billing, and comply with legal obligations. The legal basis is, depending on the case, pre-contractual steps, performance of a contract, legal obligation, our legitimate interest in operating and marketing our business, or consent where required.

As processor, we process clinic data only to provide, maintain, secure and support the service, following the clinic's documented instructions and the applicable DPA. We do not use this data for advertising, analytics, AI training, or purposes unrelated to providing the service.

5. Health data and clinic responsibilities

Some features (for example, prescriptions and appointment messaging) can involve health-related data. Clinics are responsible for deciding what information they enter or send, and for complying with the GDPR, healthcare confidentiality, professional-secrecy rules, and any other obligations that apply to them.

Vita Center is not intended for emergencies. We recommend clinics avoid sending detailed clinical information over WhatsApp where it is not necessary for the purpose of the message. Vita Systems does not provide telemedicine or clinical care and is not responsible for the clinical content clinics choose to process.

6. WhatsApp and Meta

Vita Center uses the WhatsApp Business Platform (Cloud API), hosted by Meta. Clinics use their own WhatsApp Business Account and phone number; the clinic is responsible for obtaining valid opt-in from its patients before messaging them, including for any marketing template messages sent through the service.

Communications sent through WhatsApp are also processed by WhatsApp and Meta under their own terms and privacy notices, independently of Vita Systems. This may involve transfers of data outside the EEA. See:

7. Recipients and subprocessors

We use a limited number of technology providers:

  • Hosting and database: Hetzner (Germany), for the website and the application database.
  • Backups: stored on encrypted object storage on Hetzner (Germany), as full encrypted database dumps retained for 30 days.
  • Email delivery: Neo (neo.space), used to send account verification, password reset and login-alert emails.
  • Payments: Stripe, used to bill clinics.

These providers access data only as needed to provide their service. Where we act as processor for a clinic, subprocessors are engaged in accordance with the applicable DPA.

8. International data transfers

Data hosted with Hetzner is processed in Germany, within the EEA. Communications through WhatsApp and Meta may involve processing outside the EEA under Meta's own safeguards (see section 6). Where a transfer outside the EEA applies, it relies on the safeguards available under the GDPR, such as an adequacy decision or Standard Contractual Clauses, as applicable to that provider.

9. Retention

Data category Retention
Website/email enquiries 12 months
Customer/account data Duration of contract + 12 months
Clinic message content While the contract is active; deleted within 30 days of termination unless the clinic instructs otherwise
Application/infrastructure logs Currently retained without a fixed deletion period.
Backups 30 days (full encrypted database dump)
Legal and accounting records (invoices) 6 years, as required by Spanish commercial/tax law.

Retention of clinic messaging data may also depend on the clinic's own configuration and instructions under the DPA.

10. Your rights

You may exercise your rights of access, rectification, erasure, objection, restriction and portability where applicable.

  • For data we control (section 2.1): contact info@vitasystems.app.
  • For patient, client or employee data controlled by a clinic (section 2.2): contact the relevant clinic directly. Vita Systems will assist the clinic in responding where required by the DPA.

You may also lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD, www.aepd.es ), or with the supervisory authority of your place of residence or work.

11. Security

Access to clinic data is restricted to authenticated users of the same clinic, enforced through our API. Data at rest on our database is encrypted (LUKS). We do not currently hold any security certifications.

12. Changes to this policy

We may update this policy to reflect legal, technical or service changes. The effective date, last-updated date and version are shown at the top of this page.