Legal document

Privacy Policy

Version 1.0 · Last updated: 1 September 2026

This English version is provided for convenience. In case of any discrepancy, the Spanish version prevails.

1. Data controller

The controller of the personal data collected through the EyeHub platform is Emmetropes 20 20 In Sight S.L., Spanish tax ID (NIF) B67586735, registered office at Calle Málaga 4 - 2D, 28770 Colmenar Viejo, España. Data protection contact: legal@emmetropes.com.

This policy applies in accordance with Regulation (EU) 2016/679 (“GDPR”) and Spanish Organic Law 3/2018 on Personal Data Protection and Digital Rights (“LOPDGDD”).

2. Data we process

  • Account data: email address and password (stored encrypted by our authentication provider), platform role and login data.
  • Professional profile data: name, photo, qualifications, speciality, experience, education, publications, institution and any other information you choose to include. Profiles are designed to be visible to other platform users.
  • Content and activity: posts, comments, reactions, mentions, Agora listings, job applications, course and event registrations, and documents you store in Vault.
  • Messaging: messages exchanged with other users and related metadata. Messages are not used for purposes other than providing the service.
  • Network and profile views: connections, followers and records of which users have viewed your profile. Note that, likewise, when you view another user’s profile they may see that you did.
  • Verification and KYC: documents evidencing identity, professional qualification or authority to represent an entity, where verification is requested.
  • Payment data: if you purchase paid services, payment is processed by external providers (such as Stripe); EyeHub does not store your full card details, only transaction references and billing data.
  • Technical data: IP address, device and browser type, activity and security logs (audit logs).

Third-party and patient data: the platform is not intended for processing patient data; publishing or storing it is prohibited (see the Terms & Conditions). If you enter personal data of third parties (for example, contacts or members of your institution), you warrant that you are entitled to do so.

3. Purposes and legal bases

  • Providing the service (account and profile management, professional network, messaging, Agora, Academy, events, Vault, notifications, profile statistics): performance of the contract (Art. 6(1)(b) GDPR).
  • Professional verification and KYC: performance of the contract and compliance with legal obligations, together with the legitimate interest in keeping a healthcare professional community reliable (Arts. 6(1)(b), (c) and (f) GDPR).
  • Payments and invoicing: performance of the contract and legal obligations, including tax obligations (Arts. 6(1)(b) and (c) GDPR).
  • Security, fraud and abuse prevention (including audit logs, rate limiting and content moderation): legitimate interest in protecting the platform and its users, and compliance with legal obligations (Arts. 6(1)(f) and (c) GDPR; LSSI-CE; Regulation (EU) 2022/2065).
  • Service improvement and performance metrics (aggregate, cookieless measurement): legitimate interest (Art. 6(1)(f) GDPR).
  • Service communications (operational notices, notifications): performance of the contract. Commercial communications only with your consent or under Art. 21.2 LSSI-CE for similar services, with the right to object at any time (Arts. 6(1)(a) and (f) GDPR).

We do not take decisions based solely on automated processing that produce legal effects on you. Content ordering follows the parameters described in the Terms & Conditions.

4. Recipients

  • Other users: according to the nature of the service and your visibility settings (profile, posts, listings, applications addressed to an employer, event attendance, profile views).
  • Processors: infrastructure providers under Art. 28 GDPR agreements: Supabase (database, authentication and storage), Vercel (hosting and performance metrics) and, where applicable, Stripe (payments) or other providers needed to deliver the service.
  • Employers and institutions: when you submit an application or interact with an institution, that entity processes your data as an independent controller.
  • Public authorities: where legally required.

We do not sell personal data.

5. International transfers

Our providers may process data outside the European Economic Area (for example, US providers). Such transfers rely on European Commission adequacy decisions (including the EU–US Data Privacy Framework for certified entities) or on standard contractual clauses, with supplementary measures where appropriate. You can request further information at legal@emmetropes.com.

6. Retention periods

  • Account and profile data: while the account is active. After closure, data is deleted or anonymised without undue delay, except data that must be kept blocked to meet legal responsibilities (Art. 32 LOPDGDD).
  • Published content: until you delete it or the account is closed, subject to temporary backups.
  • Billing data: for the periods required by tax and commercial law (generally 4–6 years).
  • Security and audit logs: for the time necessary and proportionate to the security purpose.
  • Profile view records: kept for a limited period and shown in aggregate or recent form.

7. Your rights

You may at any time exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw your consent, by writing to legal@emmetropes.com from the email linked to your account or otherwise evidencing your identity. You can also manage much of your data directly from the platform settings, including deleting your account.

If you consider that the processing breaches the law, you may lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es, C/ Jorge Juan 6, 28001 Madrid), although we would appreciate the chance to resolve it first.

8. Security

We apply technical and organisational measures appropriate to the risk (encryption in transit, access controls, managed authentication, audit logs and rate limiting) and review them periodically. No system is infallible; we recommend strong, unique passwords.

9. Minors

The platform targets professionals and entities of the sector and is not intended for persons under 18, whose registration is not permitted.

10. Changes to this policy

Any material change to this policy will be announced through the platform or by email before it takes effect, stating the new update date.

11. Contact

For any privacy matter: legal@emmetropes.com, or by post at Calle Málaga 4 - 2D, 28770 Colmenar Viejo, España.