Privacy Policy & Data Protection
Last updated: 10 September 2026
How Dr. Pedro Oscar Yelamo Vera collects, processes, and safeguards your personal and medical data under the GDPR and Spanish data protection law.
1. Commitment to Privacy (GDPR Compliance)
The protection of confidentiality, professional medical secrecy, and the lawful processing of personal data constitute unwavering pillars in the practice of Dr. Pedro Oscar Yelamo Vera. This Privacy Policy transparently and comprehensively describes how patients' personal data is collected, processed, safeguarded, and protected within the framework of providing medical, ultrasound, and telemedicine services, in strict compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).
2. Identity of the Data Controller
The Data Controller of the personal data is Dr. Pedro Oscar Yelamo Vera, holding NIF/NIE Z2589067P and with professional address located at Calle Arbolantxa 2, Piso 1 Izquierda, Bilbao, 48001, Vizcaya, Spain.
For any management, exercise of rights, or query regarding data protection, the user can contact the official email: drpedroyelamo@drpedroyelamo.com.
3. Categories of Data Processed
To ensure excellent medical care and comply with legal clinical documentation obligations, the Controller collects and processes the following types of data:
- General and Identification Data: First name, last name, date of birth, gender, place of residence, National Identity Document/Passport, telephone number, and email address.
- Transaction and Billing Data: Bank account or credit/debit card number for collection and billing management. (Note: Card payments are processed through secure external gateways; the Controller does not store full card numbers).
- Special Categories of Data (Health/Sensitive Data): With a reinforced level of protection, critical information is collected such as family and personal history, previous and current illnesses, symptoms, pharmacological treatments, diagnostic tests, clinical images (such as ultrasounds), medical reports, and any information the patient reveals during the in-person or telematic consultation.
4. Legal Basis for Processing
The processing of personal data is carried out under the strictest legal protection, based on the following GDPR legal bases:
- Performance of a Contract: For the provision of telemedicine services requested by the patient (Art. 6.1.b GDPR).
- Legal Obligation: For compliance with tax, accounting, and healthcare legislation applicable to the creation and maintenance of the Medical Record (Art. 6.1.c GDPR).
- Legitimate Interest: For the proper administrative management, scheduling, and operability of the clinic (Art. 6.1.f GDPR).
- Processing of Health Data (Special Category): Processed under the protection of the provision of healthcare, preventive medicine, medical diagnosis, and treatment, under the responsibility of a registered professional legally and deontologically subject to the duty of professional secrecy (Art. 9.2.h GDPR) and through the patient's explicit consent (Art. 9.2.a GDPR).
5. Specific Purposes of Processing
The data collected will be used solely and exclusively for the following purposes:
- Creation, updating, custody, and maintenance of the electronic and physical Medical Record of the patient.
- Direct provision of medical, ultrasound, and telemedicine services.
- Transactional communications with the patient for appointment management, clinical follow-up, and issuance of medical prescriptions or referrals.
- Regulatory compliance of a tax, accounting, commercial, and administrative nature.
- Issuance of informative or commercial communications (exclusively if the patient has granted granular, explicit, and revocable authorization for such purpose).
The Controller categorically declares that patients' data is not subjected to automated individual decisions or commercial profiling.
6. Data Processors and Third-Party Transfers
Your medical and personal data will never be sold or marketed. They will only be communicated to health or judicial authorities when there is an imperative legal mandate.
In order to offer modern, efficient, and digitized medical care, Dr. Pedro Oscar Yelamo Vera relies on highly prestigious technological platforms that act as "Data Processors". These providers operate under binding confidentiality agreements and end-to-end security measures. The services used are:
- Doctoralia Internet S.L. (Spain): Platform used for the comprehensive management of bookings, medical schedule control, and communications with patients.
- Rempe (Spain): Approved computer system for the issuance, validation, and secure management of electronic private medical prescriptions.
- Butterfly Cloud / Butterfly Network (USA / Europe): Clinical cloud environment used for the secure storage, processing, viewing, and high-resolution management of ultrasound diagnostic images.
- B2Brouter (Spain): Technological tool for the legal issuance, control, and management of the patient's electronic billing.
- Tukonta.com (Spain): Software used for the professional accounting and tax management of the medical practice.
Any international data transfer arising from the use of these providers has the appropriate legal guarantees established in Chapter V of the GDPR (Standard Contractual Clauses or European Commission adequacy decisions).
7. Retention and Custody Criteria (Legal Deadlines)
The Controller will retain personal data applying a principle of minimization, blocking them when they are no longer necessary for the collected purpose, but keeping them available to the competent authorities.
- Medical Record and Health Data: Retained by legal imperative for a minimum period of five (5) years counted from the date of discharge of the patient's last care process, in strict compliance with Law 41/2002, the basic law regulating patient autonomy.
- Billing, Accounting, and Tax Data: Maintained for a period of five (5) years after the termination of the service, to comply with the requirements of the Tax Agency and the Commercial Code.
8. Information Security Measures
The processing of medical information is carried out implementing rigorous technical and organizational security measures. All transmission of health data through the website is carried out using robust encryption protocols (SSL/TLS) and encrypted cloud storage. Access to Medical Records is restricted exclusively to authorized medical personnel, guaranteeing invulnerability against loss, alteration, or unauthorized access, always prioritizing the strictest medical secrecy.
9. Exercise of Data Subjects' Rights (ARCO+ Rights)
The GDPR grants patients absolute control over their information. At any time, the user, upon proof of identity, has the right to:
- Access their data and request a copy of their Medical Record.
- Rectify any inaccurate or outdated data.
- Erase their data (right to be forgotten), provided that health or tax legislation does not require its retention.
- Request the Restriction of or Object to the processing.
- Request the Portability of their file in a structured and commonly used format.
- Withdraw the consent previously granted, without retroactive effect.
To exercise these rights, the patient must send a written request to: drpedroyelamo@drpedroyelamo.com. If the patient considers that the processing of their data infringes applicable regulations or does not obtain satisfaction in the exercise of their rights, they are entitled to file a formal complaint with the Spanish Data Protection Agency (AEPD) (C/ Jorge Juan, 6. 28001 - Madrid; www.aepd.es).