2026-08
Privacy policy
What we process, why, on what legal basis, for how long, and what you can do about it. Written to be read, not to tick a box.
Controller
HEMORA (pending incorporation of the company). Data protection contact: privacidad@hemora.es.
What we process
Account data: email address, hashed password, your name if you give one, country of residence and language.
Health data: the documents you upload and what is extracted from them — dates, clinics, measured values, summaries — together with what you record in your medical profile: date of birth, sex, height, weight, blood group, allergies, treatments and past conditions.
Technical data: a log of sign-ins and account actions, with the IP address truncated to its first three groups. We use no analytics or advertising cookies.
Why, and on what basis
To run the service — storing, reading and ordering your record — on the explicit consent you give at sign-up (Article 9(2)(a) GDPR, as this is health data) and on performance of the contract (Article 6(1)(b)).
For AI reading, on a separate consent you can withdraw at any time. If you withdraw it we stop sending documents to the model provider; your record keeps working and you can enter values by hand.
For the security of the service — spotting access attempts, preventing abuse — on our legitimate interest (Article 6(1)(f)).
There are no automated decisions with legal effects and no commercial profiling. We do not sell or share data for advertising, with no exceptions.
Who else sees it
Hosting and the database, on servers located in Frankfurt, Germany. The files, in a European object store. All of it encrypted before it leaves our process.
The AI provider that reads the documents, based and hosted in France, with zero retention: it receives the document text in order to file it, and neither keeps nor trains on it. It does not receive your account name.
The transactional email provider, based in France, which receives only your address and the message we send you.
The payment gateway, if you subscribe. It receives your email and billing details; never any of your health data. Your card never passes through our servers.
A processor agreement under Article 28 GDPR is in place with each of them.
Said precisely, because it matters: **your data is stored and processed in the European Union**, but some of these providers are companies with a United States parent. Their support staff may, exceptionally and to resolve a technical problem, access it from outside the European Economic Area. That access is a transfer within the meaning of the GDPR, and it is covered by the European Commission's standard contractual clauses (Article 46) or by the EU–US Data Privacy Framework. We would rather write it this way than promise it does not happen.
How we protect it
Every file, and the text extracted from it, is stored encrypted with AES-256-GCM. The key is not stored alongside the data.
Passwords are stored derived with scrypt, never in clear. Session identifiers are stored only as a hash, so a database dump grants access to no account.
Technical access to a user's data is logged and only happens at that person's request, to resolve a problem.
For how long
For as long as your account is open. When you close it we offer you the full export of your record in the same step, and then destroy the content.
Access logs are kept for twelve months, for security. Proof of consent is kept for as long as needed to demonstrate it against a claim.
Your rights
Access, rectification, erasure, portability, restriction and objection, and withdrawal of consent at any time. Write to privacidad@hemora.es: we answer within one month at the latest.
Export is free and in open formats, always. If our answer does not satisfy you, you may complain to the Agencia Espanola de Proteccion de Datos (AEPD), www.aepd.es.
Minors
You cannot create your own account under the age of fourteen. An adult may keep the record of a child in their care under a family plan, and is responsible for that processing.