Privacy policy
This policy explains in plain language what data Medicostop processes, why it uses it, and how you can exercise your rights.
Last updated: August 30, 2026.
1. Controller
Medicostop is a technology platform operated from Chile. The data controller is Ricardo Yánez.
2. Data we process
- Bookings: name, identity document, email, phone, and appointment details such as professional, clinic, date, time, and status.
- Accounts: email, protected credentials, roles, permissions, and activity needed to manage access.
- Professionals and clinics: profile, contact, specialty, availability, and verification information published through the service.
- Operations and security: technical logs, session identifiers, administrative audit records, and data needed to prevent abuse and diagnose failures.
Medicostop does not request symptoms, diagnoses, medical records, or payment data in the MVP booking flow. Appointment details may indirectly reveal a health interest and are handled with restricted access. Do not include clinical information in contact fields.
3. Why we use data
- Create, confirm, remind, retrieve, and cancel appointments.
- Create and protect accounts, authenticate users, and enforce permissions.
- Maintain the service's security, continuity, support, and traceability.
- Meet applicable obligations and handle requests or claims.
We do not sell personal data or use booking data for advertising or marketing. If this changes, we will provide notice and request any authorization that may be required.
4. Legal bases
For public bookings, we request your informed authorization before confirmation. We also process data needed to fulfill the requested relationship, meet applicable obligations, and protect the service's legitimate security and operation. You may withdraw consent for future processing where applicable. We do not conduct advertising, profiling, or automated decisions with significant effects.
5. Who receives data
We share only what is necessary with the selected clinic or professional and with providers that operate hosting, security, and transactional email, such as MailerSend. These providers act to deliver the service, not for their own commercial purposes.
Some providers may process data outside Chile. In those cases, we require contractual and security measures appropriate to the nature of the processing.
6. Retention and deletion
We keep data only as long as needed to provide and protect the service and meet applicable obligations. Our initial rule is: bookings for 24 months after their date; completed transactional messages for 90 days; accounts and profiles while active and for up to 24 months after closure; audit records for 24 months; and rotating local backups for 7 days. We then delete or anonymize the data unless an obligation or claim justifies longer retention.
7. Your rights
You may request information about and access to your data, and its correction, deletion, objection, blocking, or portability where applicable. We may request reasonable information to verify your identity. If we must retain certain data because of an obligation or claim, we will explain why.
8. Cookies
We use technical cookies required for sessions, security, and language preferences. The MVP does not use advertising or third-party analytics cookies.
9. Security
We apply reasonable technical and organizational controls, including permission-based access, encryption in transit, audit records, and backups. No system can guarantee absolute security; we will investigate and manage incidents as required.
10. Contact and requests
For questions or to exercise your rights, use our contact channel.
