Skip to content
SPSP-Health

Legal

Privacy Policy

Last updated August 1, 2026

This policy explains what personal data SPSP-Health collects through https://spsp-health.com, why we collect it, and what rights you have over it. We have written it to describe what this website actually does — nothing more.

Who is responsible for your data

The data controller for the processing described here is:

SPSP-Health

For any privacy question, or to exercise the rights listed below, contact us at [email protected].

Cookies and tracking

This website sets no cookies. It also stores nothing else on your device — no local storage, no session storage, no device fingerprinting. There is no advertising network, no marketing pixel, and no cross-site tracking of any kind. This is why you are not asked to dismiss a cookie banner: there is nothing to consent to.

We rely on the following third-party services to run the site. None of them places cookies:

  • Cloudflare hosts and delivers the site and protects it from attack. Aggregate, cookie-free traffic measurement (Cloudflare Web Analytics) tells us how many people visit which pages. It does not identify or profile individual visitors.
  • Cloudflare Turnstile protects the contact form from automated abuse. It replaces a traditional CAPTCHA and does not track you across websites.

You do not need to change any browser setting to browse this site privately. Should we ever introduce anything that does store data on your device, we will ask for your consent first.

What we collect, and why

When you use the contact form. We receive your name, email address, the type of request you selected, your message, and — if you applied through a job listing — which role you applied for. We use this solely to read and respond to your request.

The legal basis is Article 6(1)(b) GDPR, because handling your enquiry is a step taken at your own request before any agreement between us; for job applications this covers the recruitment process. Where your message is a general enquiry rather than a prospective relationship, we rely on our legitimate interest in responding to people who contact us, under Article 6(1)(f) GDPR.

We do not ask you to tick a consent box for this, because consent is not the correct basis for processing you have actively requested — and a box you must tick in order to send the form would not be freely given consent in any case.

When you simply visit. Our hosting provider records standard server log data — IP address, browser type, requested page, and timestamp — to keep the site available and to block malicious traffic. The legal basis is our legitimate interest in the security and stability of the site, under Article 6(1)(f) GDPR.

Who else sees your data

We do not sell your personal data, and we do not share it for advertising. It reaches only:

  • Cloudflare — website hosting, security, and cookie-free traffic measurement.
  • Resend — delivers your contact form submission to us as an email. Your message is not stored in a database; it lives in our mailbox.

Both act as our processors under contract and may process data outside the European Economic Area, including in the United States. Those transfers are covered by the European Commission's Standard Contractual Clauses and the providers' own safeguards.

How long we keep it

  • Contact form correspondence is kept while we deal with your request and for up to 12 months afterwards, so we have a record of what was discussed.
  • Job applications are kept for the duration of the recruitment process and for up to 6 months after the position is filled. We will ask you separately if we would like to keep your details on file for future openings.
  • Server logs are retained for a short period by our hosting provider for security purposes.

You can ask us to delete your data sooner at any time.

Your rights

Under the GDPR you have the right to:

  • Access — obtain a copy of the personal data we hold about you. The first copy is free of charge.
  • Rectification — have inaccurate data corrected or incomplete data completed.
  • Erasure — have your data deleted where we have no overriding reason to keep it.
  • Restriction — have us pause processing while a dispute about your data is resolved.
  • Object — object to processing based on our legitimate interests.
  • Portability — receive your data in a machine-readable format, or have it sent to another organisation.
  • Withdraw consent — where we ever rely on consent, withdraw it at any time without affecting processing already carried out.

Write to [email protected] to exercise any of these. We will respond within one month.

If you believe we have handled your data improperly, you may lodge a complaint with the data protection supervisory authority in your country of residence or work.

Children

This is a corporate website intended for a professional audience. We do not knowingly collect personal data from children. If you believe a child has sent us their details, contact us and we will delete them.

Changes to this policy

If we change how we handle personal data, we will update this page and revise the date shown at the top. Material changes will be described here rather than made silently.