Privacy Policy
Version: 1.2.0 | Last updated: 2026-04-07
Privacy Policy
Last updated: April 8, 2026
This Privacy Policy describes how Thanic Capital SL ("Thanic", "we", "us") collects, uses, and protects personal data in connection with the Pymwin platform, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable national data protection laws.
1. Identity of the Data Controller
| Company name | Thanic Capital SL |
|---|---|
| Tax ID (NIF) | B72956204 |
| Registered address | Calle Gran Via de Don Diego Lopez de Haro, 45, 5º Dr., 48011 Bilbao (Bizkaia), Spain |
| General contact | info@pymwin.com |
| Legal / data protection | legal@pymwin.com |
Thanic Capital SL acts as Data Controller with respect to the personal data of website visitors and registered users of the Pymwin platform.
With respect to the personal data of patients and end clients managed by Pymwin subscribers within the platform, Thanic Capital SL acts exclusively as a Data Processor on behalf of each subscriber (who is the Data Controller), pursuant to a Data Processing Agreement (DPA).
2. Data Protection Officer (DPO)
Thanic Capital SL has not yet formally designated a Data Protection Officer. Until such designation is made, all data protection enquiries should be directed to legal@pymwin.com.
3. Categories of Personal Data Processed
3.1 Visitors to the Pymwin website
- Technical data: IP address (anonymised), browser type, operating system, referring URL, pages visited, session duration.
- Aggregated usage analytics: collected via Vercel Web Analytics — no cookies are set, no personal identifiers are stored, and no consent banner is required.
3.2 Registered users (Pymwin subscribers)
- Identification data: full name, email address, phone number.
- Professional data: profession, licence number, speciality.
- Business data: business name, tax identification number (NIF/CIF), invoicing address, VAT number (for intra-Community supplies).
- Account data: username, hashed password, subscription plan, account status, preferences, locale.
- Payment data: subscription status, last-four card digits, card brand, billing period. Full card numbers are never stored by Thanic — all payment processing is handled by Stripe under its own PCI-DSS certification.
- Communication data: transactional emails, in-app notifications, support correspondence.
- Audit and security data: login timestamps, IP addresses, device fingerprints, action logs.
3.3 Patients and end clients (Thanic as Processor)
When Pymwin subscribers use the platform to manage their own patients or clients, Thanic processes the following categories of data solely on behalf of the subscriber:
- Identification data: full name, date of birth, national ID number.
- Contact data: postal address, phone number, email address.
- Tax data: NIF/NIE (where required for official invoicing).
- Service-related data: appointment history, session notes, invoices, payments.
- Special category — health data (Art. 9 GDPR): clinical records, diagnoses, treatment plans, physiotherapy/podology notes.
The subscriber is the Data Controller for this data. Thanic does not access, use, or share patient data except as strictly necessary to provide the contracted service or as required by law.
4. Purposes and Legal Bases
4.1 Thanic as Data Controller
| Purpose | Legal basis (GDPR) | Retention |
|---|---|---|
| User registration and account management | Art. 6(1)(b) — performance of a contract | Duration of the account + 30 days after cancellation |
| Provision of the SaaS service (Pymwin) | Art. 6(1)(b) — performance of a contract | Duration of the subscription |
| Invoicing and tax compliance | Art. 6(1)(c) — legal obligation | 6 years from issue date |
| Customer support | Art. 6(1)(b) — performance of a contract | Resolution + 2 years |
| Sending transactional communications (receipts, alerts, notifications) | Art. 6(1)(b) — performance of a contract | Duration of the account |
| Sending commercial communications (newsletter, new features) | Art. 6(1)(f) — legitimate interest / Art. 6(1)(a) — consent (where required) | Until unsubscription or withdrawal of consent |
| Security, fraud prevention, and abuse detection | Art. 6(1)(f) — legitimate interest | Active logs: 12 months; security incident records: 5 years |
| Compliance with requests from competent authorities | Art. 6(1)(c) — legal obligation | As required by applicable law |
| Service improvement and analytics | Art. 6(1)(f) — legitimate interest | Indefinite (aggregated/anonymised data only) |
Summary of key retention periods: account data is deleted within 30 days of subscription cancellation; invoices and related financial records are retained for 6 years.
4.2 Thanic as Data Processor
Where Thanic processes patient data on behalf of a subscriber, purposes and retention periods are governed exclusively by the subscriber's instructions and the terms of the Data Processing Agreement (DPA) in force between Thanic and that subscriber.
5. Special Category Data: Health Information
5.1 Technical and organisational safeguards
- Encryption in transit: TLS 1.2 or higher for all data transfers.
- Encryption at rest: AES-256 for all stored data.
- Access control: Role-Based Access Control (RBAC) and Row-Level Security (RLS) at the database level; each subscriber can only access their own data.
- Audit logging: all read and write operations on health records are logged with user, timestamp, and action type.
- Data residency: health data is stored within the European Union (Supabase Ireland — eu-west-1 region).
- Thanic staff access: strictly limited to infrastructure maintenance; Thanic personnel cannot read patient clinical content in the normal course of operations.
5.2 Legal basis for processing health data
Thanic processes health data solely as a Data Processor. The applicable legal basis under Art. 9(2) GDPR (e.g., explicit consent of the data subject, or processing necessary for preventive or occupational medicine) is the exclusive responsibility of the subscriber (Data Controller).
6. Recipients of Personal Data
Personal data may be disclosed to the following categories of recipients:
- Sub-processors: technology providers that support the operation of the platform (see Section 8 for the full list).
- Competent authorities: tax agencies, supervisory authorities, courts, or law enforcement bodies, where disclosure is required by applicable law or a binding judicial order.
- Professional advisors: lawyers, auditors, and accountants acting under professional confidentiality obligations.
- Legal successors: in the event of a merger, acquisition, or asset transfer, data subjects will be notified in advance.
Personal data is never sold, rented, or traded to third parties.
7. International Data Transfers
7.1 Transfer safeguards
Thanic Capital SL is established in Spain, so the processing we carry out directly takes place within the European Economic Area and does not constitute an international transfer. However, some of our sub-processors are established in the United States or other third countries outside the EEA. Where personal data is transferred to such countries, Thanic ensures that appropriate safeguards are in place, specifically:
- Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914), incorporated into our DPAs with each sub-processor.
- EU–US Data Privacy Framework (DPF): where the sub-processor is certified under the DPF (or equivalent successor framework), we rely on the European Commission adequacy decision (pending confirmation for each provider).
- Supplementary technical measures: encryption, pseudonymisation, and data minimisation applied to reduce risk in the event of third-country access requests.
8. Sub-Processors
| Provider | Service | Location | Transfer safeguard |
|---|---|---|---|
| Supabase Inc. | Database, authentication, file storage | USA entity; EU data stored in Ireland (eu-west-1) | DPA + SCCs |
| Stripe Inc. | Payment processing | USA | DPA + SCCs |
| Resend Inc. | Transactional email delivery | USA | DPA + SCCs |
| Vercel Inc. | Application hosting and CDN | USA | DPA + SCCs |
| Vercel Web Analytics | Aggregated, cookie-free website analytics | USA | No personal data processed |
| Sentry (Functional Software Inc.) | Error monitoring and performance tracking | USA | DPA + SCCs |
| fiskaly GmbH — SIGN ES | Electronic invoicing (Verifactu / TicketBAI) — Pro plan only | EU (Germany) | DPA (no transfer outside EEA) |
| Twilio Inc. | SMS, WhatsApp, and multichannel notification delivery | USA | DPA + SCCs |
Thanic maintains an up-to-date sub-processor register and will notify subscribers of any new sub-processor at least 14 days before its appointment, in accordance with the DPA terms.
9. Retention Periods
Personal data is retained only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law. When data is no longer needed:
- Deletion: data is securely deleted from active systems and sub-processor storage.
- Blocking: where immediate deletion is not possible (e.g., backup cycles), data is blocked — access is restricted pending scheduled deletion.
- Anonymisation: in certain cases, data may be anonymised rather than deleted, so that it can no longer be attributed to an identified or identifiable individual. Anonymised data is not subject to GDPR.
Encrypted backups are retained for a maximum of 30 days, after which they are automatically overwritten. Specific retention periods per processing purpose are set out in Section 4.
10. Rights of the Data Subject
Under the GDPR, data subjects whose personal data is processed by Thanic as Data Controller have the following rights:
- Right of access (Art. 15): to obtain confirmation of whether your data is being processed and, if so, to receive a copy of it.
- Right to rectification (Art. 16): to have inaccurate or incomplete data corrected without undue delay.
- Right to erasure / 'right to be forgotten' (Art. 17): to request deletion of your data in the circumstances defined by the GDPR.
- Right to restriction of processing (Art. 18): to request that processing is limited in certain circumstances (e.g., while accuracy is contested).
- Right to data portability (Art. 20): to receive your data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.
- Right to object (Art. 21): to object to processing based on legitimate interests or for direct marketing purposes at any time.
- Right not to be subject to automated decision-making (Art. 22): not to be subject to decisions based solely on automated processing that produce significant effects on you.
- Right to withdraw consent: where processing is based on consent, to withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at legal@pymwin.com with a clear description of your request. We will respond within one month of receipt. In complex cases, this period may be extended by a further two months; you will be informed if an extension applies.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos — AEPD) at www.aepd.es, or with the supervisory authority of your country of residence within the EU/EEA.
11. Automated Decision-Making and Profiling
Thanic does not carry out any automated decision-making or profiling that produces legal effects or similarly significant impacts on data subjects, within the meaning of Article 22 GDPR.
12. Security Measures
Thanic implements appropriate technical and organisational security measures to protect personal data against accidental loss, unauthorised access, disclosure, alteration, or destruction. These measures include, but are not limited to:
- Encryption in transit: TLS for all communications between clients and servers.
- Encryption at rest: AES-256 for all stored data, including backups.
- Password hashing: user passwords are stored as bcrypt hashes; plaintext passwords are never stored.
- Least privilege principle: staff and system accounts are granted only the minimum permissions required to perform their function.
- Two-factor authentication (2FA): required for all internal Thanic administrative access.
- Row-Level Security (RLS): enforced at the database layer to prevent cross-tenant data access.
- Automated backups: encrypted backups with a 30-day retention cycle.
- Audit logging: access and mutation events are logged with actor, timestamp, and resource identifiers.
- Security incident management: documented internal procedures for detection, containment, and notification of personal data breaches.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, Thanic will notify the competent supervisory authority within 72 hours of becoming aware of the breach, in accordance with Art. 33 GDPR. Affected data subjects will also be notified without undue delay where required under Art. 34 GDPR.
13. Minors
The Pymwin platform is designed for use by healthcare and wellness professionals aged 18 or over. Thanic does not knowingly collect personal data from minors for its own controller purposes.
Where a subscriber uses the platform to manage records of minor patients, the subscriber, as Data Controller, is solely responsible for ensuring that an appropriate legal basis exists for processing the minor's data (e.g., parental or guardian consent) and for complying with any additional obligations applicable under national law.
14. Modifications to This Policy
Thanic reserves the right to update or modify this Privacy Policy at any time. When changes are made, the "Last updated" date at the top of this document will be revised accordingly.
For substantial changes — those that materially affect your rights or the way we process your data — Thanic will notify registered users by email at least 14 days before the changes take effect. Continued use of the platform after that date constitutes acceptance of the updated policy.
We encourage you to review this page periodically to stay informed of any updates.
15. Contact
For any questions, requests, or concerns regarding this Privacy Policy or the processing of your personal data, please contact us through any of the following channels:
- Email: legal@pymwin.com
- Data Controller (Thanic Capital SL): Calle Gran Via de Don Diego Lopez de Haro, 45, 5º Dr., 48011 Bilbao (Bizkaia), Spain