Privacy Policy

Last Updated: December 2024

This Privacy Policy explains how Kechuadvca collects, uses, and protects your personal information when you visit our website or use our services.

Data Controller

Kechuadvca B.V. (registration number B62031458) is the data controller responsible for your personal data. We are located at Kastanjelaan 288, 3575 MO Utrecht, Netherlands. For privacy-related questions, please contact us at privacy@kechuadvca.top or call +31 404026829.

Data Collection

The data we collect includes personal information such as your name, email address, phone number, and any health information you provide for treatment purposes. We also collect technical information about your use of our website, including IP address, browser type, and pages visited. This information is collected when you book appointments, fill out forms, or interact with our website and services.

How We Use Your Information

We explain how we use your information in this section. Your personal data is used to provide spa services, process bookings, communicate about appointments, send service updates, and improve our offerings. We use health information solely for providing appropriate treatments and ensuring your safety. Technical data helps us improve website functionality and user experience. All use of your data is based on legitimate interests, contract performance, or your explicit consent as required by GDPR.

Legal Basis for Processing

Under GDPR, we process your personal data based on the following legal grounds: performance of a contract (for service delivery), legitimate interests (for business operations and communication), consent (for marketing communications), and legal obligations (for health and safety requirements). You have the right to withdraw consent at any time where processing is based on consent.

Data Sharing

We do not sell or rent your personal information to third parties. We may share your data with trusted service providers who assist with appointment scheduling, payment processing, or website maintenance, but only under strict confidentiality agreements. We may also disclose information if required by law or to protect our rights and safety.

Data Retention

We retain your personal data only as long as necessary for the purposes outlined in this policy. Appointment and treatment records are kept for 7 years as required by healthcare regulations. Marketing preferences are retained until you unsubscribe. Website analytics data is typically retained for 26 months. Health information is securely destroyed after the required retention period unless ongoing treatment requires longer retention.

Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

  • Right of Access: Request copies of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your data under certain conditions
  • Right to Restrict Processing: Request limitation of data processing
  • Right to Data Portability: Receive your data in a structured format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent for consent-based processing

Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. This includes encryption of sensitive data, secure storage systems, access controls, and regular security assessments. Our staff receives regular training on data protection and confidentiality.

International Data Transfers

Your personal data is primarily processed within the European Union. If we transfer data outside the EU, we ensure appropriate safeguards are in place, such as adequacy decisions or standard contractual clauses approved by the European Commission.

Cookies and Tracking

Our website uses cookies to improve functionality and analyze usage. Essential cookies are necessary for website operation, while analytical cookies help us understand visitor behavior. You can manage cookie preferences through our cookie banner or browser settings. For detailed information, please see our Cookie Policy.

Marketing Communications

With your consent, we may send promotional emails about our services, special offers, and wellness tips. You can unsubscribe at any time using the link in our emails or by contacting us directly. We respect your communication preferences and will not send unwanted marketing messages.

Children's Privacy

Our services are intended for adults. We do not knowingly collect personal information from children under 16 without parental consent. If we become aware that we have collected data from a child without proper consent, we will delete it promptly.

Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will notify you of significant changes by posting the updated policy on our website and updating the "Last Updated" date. Your continued use of our services after changes indicates acceptance of the updated policy.

Data Breach Notification

In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay, as required by GDPR.

Contact Us

If you have questions about this Privacy Policy, wish to exercise your rights, or need to contact us regarding privacy matters, please reach out using the following contact information:

Kechuadvca B.V.

Kastanjelaan 288

3575 MO Utrecht, Netherlands

Privacy Officer: privacy@kechuadvca.top

Phone: +31 404026829

You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if you believe your data protection rights have been violated.