Sanistay Privacy Policy
Version v1.2 - 2026-06-10 - EN
Organisation: COALPL GROUP SL (trading as "Sanistay"). Version: v1.2. Effective date: 10 June 2026. Last updated: 10 June 2026. Applicable law: GDPR (EU 2016/679), Spanish LOPDGDD (Organic Law 3/2018), LSSI (Law 34/2002), ePrivacy Directive (2002/58/EC).
This Privacy Policy describes how COALPL GROUP SL, operating under the trade name Sanistay, processes the personal data of those who access, register for, or use the Sanistay platform, including guest users, hosts, healthcare professionals who request verification, website visitors, and persons who communicate with Sanistay.
The information is provided in a transparent, concise, and intelligible manner, without prejudice to the fact that certain processing activities may be set out in specific privacy notices where necessary given the context of the service.
1. Data controller
The data controller is COALPL GROUP SL, a company operating under the trade name Sanistay.
- Corporate name: COALPL GROUP SL
- Trade name: Sanistay
- Tax identification number (NIF): B26999623
- Registered office: Avenida Pérez Galdós 129, 48, 46018 Valencia, Valencia (Spain)
- Commercial register entry: Registro Mercantil de Valencia, Sheet V-233911, Entry 1, EUID ES46030.000968702
- Privacy email: legal@sanistay.es
- Website: https://sanistay.es
The preferred channel for data protection enquiries is legal@sanistay.es. Communications may also be sent by post to the registered office indicated above, with the reference "Data protection".
The processing of your personal data shall be governed by the following legislation:
- GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
- LOPDGDD: Organic Law 3/2018 of 5 December on the Protection of Personal Data and guarantee of digital rights
- LSSI: Law 34/2002 of 11 July on Information Society Services and Electronic Commerce
- ePrivacy Directive: Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector
2. Scope of application
This Policy applies to the processing of personal data carried out by Sanistay in connection with the platform, the website, the mobile application if available, booking and accommodation services, the messaging system, support, professional verifications, and communications associated with the service.
Where a user interacts directly with third parties acting as independent controllers, for example payment providers, hosts, or external service providers, such third parties may process personal data in accordance with their own privacy policies and legal obligations.
3. Categories of personal data processed
| Category | Main data | Minimisation notes |
|---|---|---|
| Registration and account | First and last name, email address, hashed password, telephone number if provided, country, language, date of birth, and records of legal acceptance. | The password is not stored in plain text. Date of birth is limited to age verification and, where applicable, compliance with obligations linked to the service. |
| Usage and activity | Searches, clicks, interactions, bookings, usage events, date and time, session duration, and features used. | Used to provide the service, security, improvement, and fraud prevention, subject to proportionality criteria. |
| Technical data | IP address, browser, operating system, language, device type, technical identifiers, and security logs. | Processed for security, diagnostics, service continuity, and legal traceability. |
| Analytics | Aggregated or pseudonymised browsing and product data via Vercel Analytics and PostHog, depending on configuration and consent. | PostHog is activated only where valid consent exists for non-essential analytics. |
| Professional verification and identity | Identity document, selfie, biometric verification, professional registration or licence number, issuing authority, province, specialty, verification status, and timestamps. | The document, selfie, and biometric template are processed by the verification provider. Sanistay retains the session identifier, result, and necessary professional credentials. |
| Host and payments | Address, date of birth, tax data, IBAN or tokenised bank account, Stripe Connect identifiers, verification statuses, and acceptance of Stripe terms. | Part of this information is processed by Stripe as an independent controller or, depending on the flow, as a processor. |
| Accommodations | Accommodation address, coordinates, photographs, description, house rules, price, availability, and data linked to the listing. | Coordinates are used for map and distance features. |
| Communications | Chat messages, tickets, forms, emails, attachments, and date and time of communication. | Internal access is limited to support, moderation, security, regulatory compliance, or legal requirements. |
| Optional profile | Photograph, biography, preferences, and any information the user chooses to provide. | Users are advised not to include health data or other sensitive data in free-text fields. |
Sanistay does not request information relating to the user's state of health. However, if the user voluntarily enters sensitive data in free-text fields, Sanistay may process it incidentally to manage the service or the relevant request, applying the principle of data minimisation and, where possible, deleting or restricting it.
4. Processing that may involve special categories of data
Identity verification may involve the processing of biometric data where facial comparison techniques are used to uniquely verify the identity of a natural person. In such cases, the processing is subject to Article 9 of the GDPR and requires a specific enabling condition, in addition to a legal basis under Article 6 of the GDPR.
For this processing, Sanistay shall document and reflect in the user flow: (i) specific prior information; (ii) explicit consent where that is the applicable enabling condition; (iii) a reasonable alternative or human review where appropriate; (iv) strict limitation of retention; and (v) enhanced security and audit measures. Where the provider acts as a processor, a processing agreement compliant with Article 28 of the GDPR must be in place; where it acts as an independent controller, this must be clearly disclosed.
Data relating to professional registration, licensing, or specialty are processed as professional credentials. They should not be classified as the data subject's health data unless, by their context or content, they reveal information about their own state of health.
5. Purposes and legal bases
| Purpose | Data affected | Legal basis |
|---|---|---|
| Creating and managing the account | Registration, authentication, profile, and acceptance of legal texts. | Performance of a contract or application of pre-contractual measures, Art. 6(1)(b) GDPR. |
| Providing the platform service | Bookings, accommodations, messaging, reviews, support, and coordination between users. | Performance of a contract, Art. 6(1)(b) GDPR. |
| "Verified healthcare professional" verification | Identity, professional credentials, verification status, and associated evidence. | Performance of a contract, Art. 6(1)(b); legitimate interest in fraud prevention, Art. 6(1)(f); and, for biometrics if applicable, Art. 9(2)(a) or another duly documented enabling condition. |
| Processing payments, charges, refunds, and payouts to hosts | Transactional data, invoicing, tax data, tokenised payment data, and Stripe statuses. | Performance of a contract, Art. 6(1)(b); legal obligation (tax/accounting), Art. 6(1)(c). |
| Security, fraud prevention, and abuse | IP, logs, events, rate limiting, auditing, and anti-fraud signals. | Legitimate interest, Art. 6(1)(f); and legal obligation where applicable, Art. 6(1)(c). |
| Strictly necessary or aggregated technical analytics | Aggregated or non-identifying operational data. | Legitimate interest, Art. 6(1)(f), provided it does not involve access to terminal equipment subject to consent. |
| Non-essential product analytics | Pseudonymised events and cookies/storage associated with PostHog. | Consent, Art. 6(1)(a) GDPR and Art. 22(2) LSSI. |
| Administrative and legal communications | Email, service notices, changes to terms, security, and incidents. | Performance of a contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c); legitimate interest, Art. 6(1)(f). |
| Direct marketing, surveys, or non-essential commercial communications | Email, preferences, and consents. | Consent, Art. 6(1)(a) GDPR, except where legally permitted under the LSSI for communications about similar products or services. |
| Handling requests and legal defence | Data necessary to respond to authorities, claims, or litigation. | Legal obligation, Art. 6(1)(c); legitimate interest in legal defence, Art. 6(1)(f). |
6. Legitimate interest and balancing test
Where Sanistay relies on legitimate interest as the legal basis for processing, it shall carry out a balancing test that takes into account the purpose pursued, the necessity of the processing, the user's reasonable expectations, the impact on their rights, and the safeguards applied. The user may object to such processing on the terms set out in the rights section.
7. Consent
Where processing is based on consent, it shall be freely given, specific, informed, and unambiguous. For processing that requires explicit consent, such as certain biometric uses, consent shall be obtained through a reinforced and documentable affirmative action.
- Consent checkboxes or controls shall not be pre-ticked.
- Accepting and rejecting cookies or non-essential technologies shall be presented with equal ease and prominence.
- The user may withdraw consent at any time without affecting the lawfulness of prior processing.
- Sanistay shall retain evidence of the granting or withdrawal of consent, including the applicable privacy notice version, date, time, and mechanism used.
8. Recipients and providers
Sanistay may disclose data to technology, payment, verification, support, hosting, analytics, security, and communications providers, to the extent necessary to provide the service and subject to applicable contractual safeguards. The classification of each provider as a data processor or independent controller depends on its specific function and the contract in force.
| Provider | Service | Recommended role to verify | Data processed | Location/safeguards |
|---|---|---|---|---|
| Vercel Inc. | Hosting, CDN, edge functions, cookieless analytics, and Vercel Blob. | Processor, except for services where it determines its own purposes. | Technical data, activity, IP, and files such as profile photos. | US/EU regions depending on configuration; DPA, SCCs, and supplementary measures. |
| Supabase Inc. | PostgreSQL database and authentication infrastructure. | Processor. | Persistent user data and authentication data. | EU region Frankfurt if so configured; DPA and SCCs where applicable. |
| Stripe Payments Europe Ltd. | Payments and Stripe Connect. | Independent controller for payment regulatory obligations; possible processor for certain technical services. | Payment data, invoicing, host KYC, and account statuses. | Ireland/EEA with possible transfers; Stripe safeguards and PCI-DSS. |
| Didit | Identity verification, document, and facial comparison. | Processor. | Document, selfie, biometric template, verification session, and professional credentials. | EU residence if configured; DPA, limited retention, and enhanced measures. |
| Resend Inc. | Transactional email. | Processor. | Email, message content, and attachments. | US; DPA, SCCs, and supplementary measures. |
| PostHog Inc. | Product analytics subject to consent. | Processor. | Pseudonymised identifier and usage events. | EU Frankfurt if configured; DPA, limited retention, and opt-out by default. |
| Sentry / Functional Software Inc. | Error monitoring. | Processor. | Traces, errors, internal identifiers, and technical data. | US; DPA, SCCs, payload minimisation. |
| Upstash Inc. | Rate limiting and Redis. | Processor. | IP, user identifier, and temporary counters. | EU region if configured; DPA and reduced TTL. |
| Google LLC - OAuth | Sign in with Google, if the user chooses it. | Independent controller for the Google account; possible processor in specific integrations. | Google identifier, name, email, and photo. | US; user actively initiates the flow. |
| Google LLC - Maps Platform | Geocoding and distance calculation. | Provider/processor depending on applicable contract. | Accommodation coordinates and technical query data. | US; SCCs/DPF if applicable and server-to-server queries where possible. |
9. International transfers
Some providers may process data outside the European Economic Area. Where an applicable adequacy decision exists, Sanistay may rely on that decision in respect of certified or covered entities. In other cases, Standard Contractual Clauses, transfer impact assessments where appropriate, and supplementary technical and organisational measures shall be used.
Reference to the EU-US Data Privacy Framework should be maintained only for providers that are actually certified and in respect of activities covered by that certification. Otherwise, the SCC mechanism and documented supplementary measures shall prevail.
10. Retention periods
| Data or processing | Indicative period | Legal criterion and deletion |
|---|---|---|
| Account and profile | While the account is active and up to 3 years from closure, unless longer obligations apply. | Handling of contractual liabilities; restriction and progressive deletion/anonymisation. |
| Acceptance of Terms and Conditions, policy, and consents | For the duration of the relationship and up to 3 years from the last acceptance or withdrawal, unless a claim arises. | Proof of compliance and information; deletion at end of period. |
| Professional verification retained by Sanistay | For the duration of the account and up to 3 years from closure or withdrawal of the badge. | Fraud prevention and accreditation of status; deletion of encrypted credentials and status. |
| Biometric data or documents processed by Didit | 6 months (Didit Console retention for Sanistay production and preview apps). | Automatic deletion by provider and possibility of early erasure where appropriate. |
| Payments, invoicing, and accounting | 6 years for commercial purposes and up to 4 years for tax purposes; retention of 6 years is recommended unless specific tax criteria apply. | Legal obligations; restriction and limited retention. |
| Internal chat and support | During the relationship and up to 3 years from account closure or incident, unless defence requires otherwise. | Contractual traceability and dispute resolution; restricted access and subsequent deletion. |
| Reviews | While relevant to service reputation; anonymisation after closure where appropriate. | Legitimate interest, information to other users, and freedom of expression; moderation and deletion in legally required cases. |
| Accommodation listings | While the listing is active and up to 3 years after removal. | Contractual traceability and liabilities; deletion or anonymisation. |
| Technical logs and IP | Period proportionate to the purpose; recommendation: 12 months unless logs linked to legal evidence or security. | Security and traceability; anonymisation or deletion on completion. |
| PostHog analytics | 90 days or the period configured with the provider. | Consent; automatic deletion and opt-out. |
| Consent cookies | Up to 24 months as maximum recommended to remember the choice, unless material changes occur. | Proof of consent and ease of management. |
During retention periods required by law or for the defence of claims, data may be restricted such that it is processed only to meet liabilities, administrative or judicial requirements, or defence against claims.
11. Security
Sanistay shall apply technical and organisational measures appropriate to the risk, including:
- Encryption in transit via TLS and encryption at rest where provided by the infrastructure.
- Application-level encryption for professional credentials where necessary, with separate key management.
- Passwords stored using robust hashing and salting.
- Session cookies with httpOnly, secure, and SameSite attributes where technically appropriate.
- Role-based access control, principle of least privilege, and audit logs.
- Rate limiting, error monitoring, backups, permission reviews, and incident response procedures.
- Minimisation of data sent to analytics, error, and map providers.
In the event of a personal data breach, Sanistay shall assess the risk and, where appropriate, notify the competent supervisory authority within 72 hours of becoming aware of it, as well as affected data subjects where the breach is likely to result in a high risk to their rights and freedoms.
12. Data subject rights
Users may exercise the rights of access, rectification, erasure, objection, restriction of processing, portability, and not to be subject to decisions based solely on automated processing, as well as withdraw consent where processing is based on consent.
Requests may be sent to legal@sanistay.es, indicating the right exercised, the data necessary to identify the account, and, where essential, documentation to verify the identity of the requester. Sanistay shall respond within one month of receipt of the request. That period may be extended by a further two months where necessary due to complexity or number of requests, informing the data subject within the first month.
The exercise of rights is free of charge. Reasonable fees may be charged or action refused only where the request is manifestly unfounded or excessive, in particular because of its repetitive character, in accordance with Article 12(5) of the GDPR.
| Right | Scope |
|---|---|
| Access | Confirm whether personal data are processed and obtain a copy of the data and information about the processing. |
| Rectification | Request correction of inaccurate data or completion of incomplete data. |
| Erasure | Request deletion of data where a legal ground applies, without prejudice to restrictions or retention obligations. |
| Restriction | Request that processing be restricted in the cases provided for by the GDPR. |
| Portability | Receive data provided in a structured, commonly used, machine-readable format, where applicable. |
| Objection | Object to processing based on legitimate interest on grounds relating to the particular situation. |
| Automated decisions | Not be subject to decisions based solely on automated processing with legal or similarly significant effects, except as legally permitted. |
| Withdrawal of consent | Withdraw consents without affecting the lawfulness of prior processing. |
The user has the right to lodge a complaint with the Spanish Data Protection Agency, especially where they consider that they have not obtained satisfaction in the exercise of their rights. Contact details: Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid, electronic office https://sedeagpd.gob.es and website https://www.aepd.es.
13. Minors
Sanistay is not directed at persons under 18 years of age. If Sanistay detects that a person under 18 has registered, it shall take reasonable measures to cancel the account and delete or restrict the data, unless a legal obligation to retain applies.
No commercial communications specifically directed at minors shall be sent, nor shall their data be processed for advertising profiling.
14. Cookies and similar technologies
Sanistay uses cookies and similar technologies to enable the service to function, maintain the session, remember preferences, and, where the user consents, obtain product analytics.
| Type | Purpose | Basis/consent | Examples |
|---|---|---|---|
| Strictly necessary | Authentication, security, CSRF, retention of essential preferences, and consent recording. | Consent not required where necessary to provide a service expressly requested or to enable communication. | session, refresh_token, csrf_token, sanistay_consent_v1. |
| Non-essential preferences | Remembering interface options that are not strictly necessary. | Consent if they involve non-essential storage. | Advanced experience preferences. |
| Analytics | Usage measurement and product improvement. | Prior consent except for strictly aggregated, non-invasive analytics that do not access terminal equipment in a non-exempt manner. | PostHog when activated; Vercel Analytics depending on configuration. |
| Marketing | Advertising, cross-site tracking, or social media pixels. | Prior consent. | Sanistay currently states that it does not use advertising cookies or social media pixels. |
The cookie panel shall allow users to accept, reject, and configure non-essential cookies with equal ease. Rejection must not prevent access to the service except in respect of features that technically depend on strictly necessary cookies.
The user may change their choice via the "Cookie preferences" link or equivalent mechanism. Cookies may also be blocked or deleted from the browser, although disabling necessary cookies may prevent normal operation of the platform.
15. Commercial communications
Sanistay shall not send commercial communications by electronic means without a valid legal basis. Where consent is requested, it shall be specific and withdrawable. If Sanistay were to send communications about similar services to existing customers under the LSSI, it shall in any event offer a simple, free, and visible opt-out mechanism in each communication.
16. Automated decisions and profiling
Sanistay does not currently make decisions based solely on automated processing that produce legal effects concerning the user or similarly significantly affect them. Relevant decisions, such as professional verification, account suspension, or incident resolution, shall include human review where they may significantly affect the user.
If relevant automated decisions or profiling are implemented in the future, Sanistay shall provide prior information on the logic applied, significance, and envisaged consequences, and shall ensure the rights recognised by the GDPR.
17. Changes to the Policy
Sanistay may update this Policy to reflect regulatory, technical, organisational, or provider changes. Where changes are material, Sanistay shall inform the user by reasonable means, such as a notice on the platform or by email, and shall request fresh acceptance where the nature of the change requires it.
Material changes include, among others, the addition of new purposes, new categories of data, new providers involving relevant international transfers, changes of legal basis, significant automated decisions, or processing of special categories of data not previously envisaged.
18. Contact
For any enquiry relating to this Policy or the processing of personal data, the user may contact Sanistay at legal@sanistay.es or by post at COALPL GROUP SL, Avenida Pérez Galdós 129, 48, 46018 Valencia, Valencia (Spain), with the reference "Data protection".
If a Data Protection Officer is appointed in the future, Sanistay shall update this Policy and notify the competent supervisory authority of the appointment where required.
COALPL GROUP SL (Sanistay) — Privacy Policy v1.2 — effective 10 June 2026.