Skip to content
Análisis Médicos

Privacy policy

Last updated: 30 August 2026

This is an English translation, provided so you can understand the terms. The legally binding version is the Spanish original, and if the two differ, the Spanish version prevails.

This website sells blood tests and processes personal data in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

Four details are requested, no laboratory results enter this website, and this website does not set a single cookie. The sections on results and cookies explain how those three statements hold up.

Contents (15 sections)
  1. 1. Who processes your data
  2. 2. What data is requested, and what is not
  3. 3. No laboratory results enter this website
  4. 4. Which health data is processed, and on what basis
  5. 5. What it is processed for and on what legal basis
  6. 6. Who else sees your data
  7. 7. Transfers outside the European Union
  8. 8. How long data is kept
  9. 9. Why this website has no cookie banner
  10. 10. No profiling or automated decisions
  11. 11. Your rights, and how to exercise them
  12. 12. If there were a security breach
  13. 13. Accuracy of data, and data about another person
  14. 14. Changes to this policy
  15. 15. The other legal documents

1. Who processes your data

Controller
Antonio Mas Lorenzo
Tax ID (NIF)
74231831K
Address
Passatge Sistres 7, local 12, 08320 El Masnou (Barcelona)
Trading name
Análisis Médicos

Data relating to your health is processed by Dr. Antonio Mas, medical registration no. 08-46289, the doctor who designs and signs the test request, who is bound by professional secrecy. That is not decoration: it is the condition article 9.3 of the GDPR requires in order to process health data, and the section on health data explains what that data is here.

No data protection officer has been appointed, because none of the three cases in article 37.1 of the GDPR applies: we are not a public authority, we do not carry out regular and large-scale monitoring of people, and the health data processing we do is not large-scale. For any data protection matter, write to the address above.

2. What data is requested, and what is not

The order form has four fields, and three of them are required:

  • Full name and ID document (DNI, NIE or passport), because the test request is personal and the laboratory has to identify the person at the desk and label the sample with their name.
  • Email address, which is where the test request and the invoice arrive.
  • Phone, optional, and only to let you know if there is a problem with the order.

You can also choose a preferred centre to be printed on the test request, and indicate that the order is for someone else.

We do not ask for date of birth, sex, symptoms, medication or medical history. There is no clinical questionnaire on any screen, and there will not be: a questionnaire that changed what is requested would turn this into a simulated consultation, and it is not one. The laboratory collects age and sex itself, as it needs them to print the correct reference ranges.

When you pay, the three confirmations ticked at the last step are also stored, with their date: that the person tested is of legal age, that you understand this is not a medical consultation, and that you accept the terms and this policy. They are stored because they prove what was accepted and when, and they serve both parties.

Payment is processed by Stripe on its own screen. Card details never pass through this website and are not stored here.

3. No laboratory results enter this website

It is the decision that best protects buyers, so it is worth explaining in full and plainly.

This website has no table in which to store a result, and it is not an oversight: it does not exist and will not be created. The database stores who ordered what, when and for how much. It does not store what came back.

Results are delivered by the laboratory, and two people receive them. You, through the laboratory's own secure channel. And the doctor who signs the test request, because they request the test, are responsible for it and are the one the laboratory alerts if a critical value appears. The doctor receives them through the laboratory's channel, subject to professional secrecy, and outside this website's systems.

What does not happen is routine review or interpretation. There is no clinical history, no trend charts, and no panel where anyone can look up someone else's blood test. That is what keeps this service outside the custody of medical records, and why the list of data in the previous section is so short.

4. Which health data is processed, and on what basis

There is one item, and saying so is more honest than hiding it: which blood test profile has been ordered. Knowing that someone has requested a thyroid assessment or a hormone profile is data concerning health within the meaning of article 9.1 of the GDPR, even though it says nothing about their results.

It is processed on two bases, and both are needed:

  • Article 9.2.h) of the GDPR, which lifts the prohibition when processing is necessary for the provision of health care under a contract with a health professional. The contract is the one entered into when ordering, and the professional is the doctor who signs the test request.
  • Article 9.3 of the GDPR, which requires it to be done by a professional subject to professional secrecy or someone under their responsibility. That is the case.

The practical consequence, which is what matters: that data does not leave here. The laboratory receives it because it has to carry out the test. The payment gateway receives an amount and a generic description, not the name of the profile. And no advertising or analytics third party receives anything, because there are none.

The invoice also carries a generic description instead of the name of the profile, so that passing through an accountant's books does not turn the list of invoices into a record of what each customer had done.

5. What it is processed for and on what legal basis

PurposeLegal basis
Issuing the test request, sending it by email, handling the order and its incidentsPerformance of the contract (art. 6.1.b GDPR), together with arts. 9.2.h) and 9.3
Charging, issuing the invoice and keeping itLegal obligation (art. 6.1.c GDPR): Spanish VAT Law 37/1992, Royal Decree 1619/2012 and art. 30 of the Commercial Code
Sending the reminder to repeat the blood test, if an interval was chosenConsent (art. 6.1.a GDPR), which can be withdrawn in one click
Preventing abuse and fraud, limiting attempts and measuring website traffic in aggregateLegitimate interest (art. 6.1.f GDPR)
Defending or handling a complaintLegitimate interest (art. 6.1.f) and art. 9.2.f) GDPR

Providing the name, document and email is a requirement for issuing the test request. Without them a personal document cannot be signed or delivered, so without them no contract is possible. The phone number is voluntary and not providing it has no consequence.

6. Who else sees your data

Laboratorio Echevarne, acting on its own account

It receives the name and document because it has to identify the person and label the sample. It is not our processor: it is an independent controller for the processing it carries out, with its own privacy policy, its own obligations as a clinical laboratory and its own channel for delivering results. What happens within its circuit is not governed by this website.

The providers that run the website

These are processors within the meaning of article 28 of the GDPR: they process the data solely on our behalf, following our instructions, under a processing agreement and without using it for anything of their own.

ProviderWhat forWhere
Stripe Payments Europe, Ltd.Charging. Card details are received by Stripe directly on its screen and we never see them.Ireland
Supabase, Inc.The database where the order lives and the encrypted storage where the test request PDF lives.Paris
Vercel, Inc.Hosting of the website and the functions that process the order.Paris
Resend, Inc.Sending the order emails.United States

The payment gateway does not receive which test was ordered. It sees an amount and a generic description, because nothing more is needed to charge. The laboratory does receive it, because it has to carry out the test.

The email provider does receive it, and it is worth saying plainly: the message delivering your test request contains your name and what you ordered, so that provider sees it when sending. There is no way to send you your test request without saying what it is for.

What has been avoided is that it sees the document: the test request is not attached to the email, but sent as a download link. The PDF also carries your ID document and the full list of tests, and that file stays in the European Union.

Beyond this list, data is only disclosed to public authorities, courts or law enforcement when a rule requires it.

7. Transfers outside the European Union

The database, the documents and the functions that process an order are in Paris. This was chosen deliberately: otherwise, the functions would have run in the United States against a European database.

Email sending does leave the European Union, because Resend processes and stores in the United States. It sees the address, the subject, which is neutral, and the body of the message, which contains your name and the test ordered. It does not see the document, which is sent as a link and stays in the European Union.

And we say stores deliberately. Resend lets you choose to send email from Ireland, but that only changes where it is sent from: the message content and delivery logs are stored in the United States anyway. Saying here that email «stays in Europe» because that region was chosen would be one of those sentences that sound good and are not true.

Supabase, Vercel and Stripe are companies with a parent in the United States, so there may occasionally be access from there for technical support.

Those transfers rely on the mechanisms in chapter V of the GDPR:

  • The adequacy decision for the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023), for providers certified under it. The General Court of the European Union confirmed its validity on 3 September 2025. Resend is certified under it, and that list is public and can be checked at dataprivacyframework.gov.
  • The standard contractual clauses approved by the European Commission (art. 46.2.c GDPR), which are included in the processing agreements.

We say this and not «Privacy Shield», which is still found in many copied policies: that framework was annulled by the Court of Justice in 2020 and has not existed for years.

8. How long data is kept

Six years from the order, and we did not choose that period: it comes from adding up three obligations and keeping the longest.

WhatHow longWhy
The invoice and order records6 yearsArt. 30 of the Spanish Commercial Code
What the tax authorities can check4 yearsArt. 66 of Law 58/2003, General Tax Law
A possible claim under the contract5 yearsArt. 1964.2 of the Spanish Civil Code
The test request, which is healthcare documentationAt least 5 yearsArts. 17.1 and 17.5 of Law 41/2002

When the period ends, the data is deleted or anonymised. In the meantime it is blocked if its deletion is requested earlier: article 32 of the LOPDGDD requires it to be kept aside, without being accessible, exclusively available to judges, courts and authorities while liability lasts. When that period ends, it is destroyed.

Consent for the reminder ends sooner. Just unsubscribe from the link in the email and no more are sent.

9. Why this website has no cookie banner

Because it sets no cookies for visitors, and that is the whole answer. Article 22.2 of the LSSI-CE only requires permission to store or retrieve data on the user's device. If nothing is stored or retrieved, there is nothing to consent to.

This website writes nothing in your browser: no cookies, no local storage, no other marker. And it loads nothing from outside: no external fonts, no embedded maps, no videos, no Google Analytics, no advertising pixels, no social media buttons. The centre maps are our own drawings.

So how are visits counted?

With our own measurement, stored in the same database as the order. A new random key is generated every day, and for each visit an irreversible fingerprint is calculated combining that day's key, the IP address and the browser. The IP address is not stored anywhere: it goes into the calculation and is not kept. As the key changes every day, yesterday's fingerprints cannot be recalculated or matched with today's, so nobody is tracked from one day to the next.

For each visit we record the page, without anything after the question mark, and the referring site, domain only. The search term, the IP and the full browser are not stored.

The only cookies on the site

The session cookies of the administration panel, which keep whoever logs in to manage orders identified. They are strictly necessary within the meaning of article 22.2 and exempt from consent. Shop visitors never receive them.

10. No profiling or automated decisions

Although the product is called a «blood test profile», no profile of anyone is built here within the meaning of article 4.4 of the GDPR, and no automated decision of the kind in article 22 is taken. No algorithm changes what is requested depending on who buys it, and the price does not change from one person to another. Everyone who orders the same profile receives exactly the same profile, and sees it written on the profile page before paying.

11. Your rights, and how to exercise them

Articles 15 to 22 of the GDPR grant these rights:

  • Access: to know what data is held and obtain a copy.
  • Rectification: to correct anything that is wrong or incomplete. If the name or document on the test request has a typo, it is corrected and another is issued at no cost.
  • Erasure: to ask for it to be deleted, within the limits of the legal retention periods.
  • Restriction: to ask for it to be kept without being used while a disagreement is resolved.
  • Objection: to object to processing based on legitimate interest.
  • Portability: to receive the data in a machine-readable format, or have it sent to another controller.
  • Withdrawing consent at any time, without affecting what was processed before.

They are exercised by writing to the contact address, from the order email or proving your identity in another way. The law allows one month to reply (art. 12.3 GDPR); we reply sooner. Exercising a right is free.

If the reply does not satisfy you, or does not arrive, you can complain to the Spanish Data Protection Agency (art. 77 GDPR): aepd.es, or to the supervisory authority of the EU country where you live. You do not have to complain here first, although it is usually quicker.

12. If there were a security breach

A security breach affecting personal data is notified to the Spanish Data Protection Agency within 72 hours of becoming aware of it, unless it is unlikely to pose a risk (art. 33 GDPR). And if the risk to the rights of the people affected is high, they are also informed, without undue delay, explaining what has happened and what they should do (art. 34). None has occurred up to the date of this policy.

13. Accuracy of data, and data about another person

The details written in the form end up printed on a clinical document shown at a reception desk, so they must be accurate and up to date. Whoever provides them is responsible for their truthfulness, and if something changes or there is a typo, just write to correct it.

Buying for someone else is expected and normal, but whoever does so confirms that the person knows and agrees, and undertakes to inform them of this policy. The test request is issued in their name and only they can use it, showing their own document.

Minors. The service is aimed at adults, and at the last step of the order you confirm that the person having the test is one. As a general rule, article 7 of the LOPDGDD sets fourteen as the age for consenting to processing oneself; below that, the consent of whoever holds parental authority or guardianship is needed. That route is not offered here: for a minor, the right course is their paediatrician or doctor.

14. Changes to this policy

This policy may change if the service or the law changes. The date of the current version is at the very top, and what applies to an order is the version published on the day it was placed. If a change substantially affected data already collected, you are notified by email before it is applied.

15. The other legal documents

What you order, what it costs and what happens if you want to cancel is in the terms and conditions.