Privacy policy
This policy explains what personal data we process, why, on what legal basis, who we share it with, how long we keep it and how you can exercise your rights, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).
Last updated: 28 September 2026
1. Data controller
- Cloud Cost Control SL
- Tax ID (NIF): B19340702
- Registered in the Mercantile Register, sheet B-620287
- Email: damian@contigobot.com
ContigoBot, Contigo Clínica and the other trade names shown on this site are brands of Cloud Cost Control SL.
2. Controller and processor: who decides about your data
Cloud Cost Control SL acts in two different roles:
- As controller, for the data of people who visit this website or contact us, for the data of our customers and their users, and for conversations held with a WhatsApp number that belongs to ContigoBot.
- As processor, for the data that clinics manage with Contigo Clínica: data about their clients (the animals' owners), their patients and their staff, including the WhatsApp messages exchanged with the clinic's number. In these cases the clinic is the controller, and we process the data only on the clinic's instructions and to provide the service, in accordance with Article 28 GDPR.
If you are a client of a clinic that uses Contigo Clínica, the clinic is responsible for informing you about the processing of your data and for handling your rights. If you send a request to us, we will pass it on to the clinic without delay.
3. What data we process, why, and on what legal basis
a) Visits to this website. This site (www.contigobot.com) is a static site hosted on Cloudflare Pages. It has no forms that send data to our servers and uses no analytics or advertising tools. To serve the pages and protect the site against abuse, Cloudflare processes technical connection data such as your IP address, browser and the page requested.
- Purpose: to display the site and keep it available and secure.
- Legal basis: our legitimate interest in providing an available and secure website (Art. 6(1)(f) GDPR).
b) Contact and meetings. The site's forms do not send any data themselves: pressing the button opens your email program with a message addressed to us, and we only receive your data if you choose to send it. If you email us or book a meeting through our Cal.com link, we process the data you provide (name, email address, company, phone number and the content of your message).
- Purpose: to answer your enquiry, arrange the meeting you requested and, where appropriate, prepare a proposal.
- Legal basis: taking steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR) and our legitimate interest in handling the communications we receive (Art. 6(1)(f) GDPR).
- We do not use this data to send you marketing communications.
c) Customers and users of our applications. When a clinic or another business subscribes to our services, we process the data of its contact persons and of the users who access the application (name, email address, role and login credentials), as well as the data needed to invoice the service.
- Purpose: to provide the contracted service, give support and manage invoicing.
- Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and compliance with our legal obligations, in particular tax and accounting obligations (Art. 6(1)(c) GDPR).
d) WhatsApp messages. Our applications use Meta's WhatsApp Business Platform (WhatsApp Business Cloud API) to receive the messages sent to the connected number and to send replies, appointment confirmations and changes, reminders and post-visit information. We process the sender's phone number, the profile name provided by WhatsApp, the content of the messages and their date and time. Messages are stored in the service's database so that the relevant team can read them and continue the conversation.
- If the number belongs to a clinic, we process this data as a processor on the clinic's behalf (section 2), and the legal basis is determined by the clinic.
- If you write to a WhatsApp number that belongs to ContigoBot, we are the controller. Purpose: to answer your message and handle your request. Legal basis: taking steps prior to entering into a contract, or performing a contract, at your request (Art. 6(1)(b) GDPR) and our legitimate interest in answering the messages we receive (Art. 6(1)(f) GDPR).
e) Automatic replies generated with artificial intelligence. When a WhatsApp message is written as free text, the application sends the text of the message to the xAI API (Grok model), together with the configuration and information the clinic has uploaded, to understand the enquiry and generate the automatic reply. The message may contain data the sender chooses to write, such as their name, their animal's name or a description of symptoms. Options chosen from WhatsApp menus are not sent to xAI. The assistant does not give diagnoses and refers cases that need it to the clinic's team. The legal basis is that of the WhatsApp processing it forms part of (point d).
f) Clinic management (Contigo Clínica). On behalf of each clinic, and depending on the modules it has switched on, the application processes: owners' data (name, phone number, email address and the clinic's notes); data about the animals and their care (name, species, breed, alerts, clinical history, vaccinations, treatments, visit images and laboratory results); appointments, reminders, online bookings and access to the client portal; invoices, payments and invoicing records (Veri*Factu); and staff working-time records. The clinic can receive laboratory results at a dedicated email address, which is processed by Cloudflare's email service. Legal basis: the one determined by the clinic as controller; we process the data under the data processing agreement (Art. 28 GDPR).
Invoicing records. The application generates Veri*Factu invoicing records with their chained hash. The application does not currently send these records to the Spanish Tax Agency (AEAT).
Consent. None of the processing described here is based on your consent. If we ever ask for your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before you withdraw it.
4. Recipients and processors
We do not sell personal data. We only disclose it to third parties when the law requires us to (for example, to the tax authorities, courts or law enforcement).
To provide our services we use the following providers, which process data as processors (or sub-processors, for clinic data):
- Cloudflare, Inc. (United States): hosting of the website and applications (Cloudflare Pages and Workers), database (Cloudflare D1), file storage such as visit images and laboratory attachments (Cloudflare R2), and receipt of email.
- Meta (Meta Platforms Ireland Limited and its group companies, including Meta Platforms, Inc. and WhatsApp LLC in the United States): transmission of WhatsApp messages through the WhatsApp Business Cloud API. Meta may also act as an independent controller for the safety and integrity of its platform, under its own terms.
- xAI (United States), Grok model: generation of automatic replies to free-text WhatsApp messages.
- Cal.com, Inc. (United States): meeting booking, when you use our booking link.
- Our corporate email provider: receipt of the emails you send us.
5. International transfers
Cloudflare, Meta, xAI and Cal.com are US companies or part of US groups, so data may be processed outside the European Economic Area. These transfers rely on the safeguards in Chapter V GDPR: the provider's participation in the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023) or, where that does not apply, the Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914) included in each provider's data processing agreement.
You can check which organisations participate in the Data Privacy Framework at www.dataprivacyframework.gov, and ask us about the safeguards applied by writing to damian@contigobot.com.
6. How long we keep data
We keep data for as long as it is needed for the purpose for which it was collected. After that, we keep it blocked for the periods during which legal liabilities may arise and then delete it.
- Enquiries and contacts: as long as needed to handle your enquiry and any relationship that results from it.
- Customer and invoicing data: for the duration of the contract and afterwards for the periods required by tax and commercial law (generally four years under the Spanish General Tax Law and six years under the Commercial Code).
- Data processed on behalf of clinics, including WhatsApp messages: while the contract with the clinic is in force. When it ends, we return or delete the data as the clinic instructs, unless the law requires us to keep it. Working-time records are kept for at least four years, as employment law requires.
- Technical data from website visits: Cloudflare keeps it for limited periods, under its terms.
7. Automated decisions
We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). The WhatsApp assistant answers enquiries and handles appointments, and the clinic's team can step into the conversation at any time.
8. Your rights
You can at any time exercise your rights of access, rectification, erasure, objection, restriction of processing and data portability, and withdraw any consent you have given us.
To exercise them, email us at damian@contigobot.com stating which right you wish to exercise. If we have reasonable doubts about your identity, we may ask for the information needed to confirm it. We will reply within one month, which may be extended in the cases provided for in the GDPR.
If we process your data on behalf of a clinic (section 2), we recommend contacting that clinic; if you write to us, we will pass your request on.
9. Complaints to the AEPD
If you believe we have not processed your data properly, you can lodge a complaint with the Spanish Data Protection Agency (AEPD) through its website, www.aepd.es. We would appreciate the chance to resolve the matter first, so please contact us beforehand.
10. Security
We apply technical and organisational measures appropriate to the risk, including:
- All communication with the site and the applications is encrypted (HTTPS).
- Each clinic's data is kept separate from other clinics' data and can only be accessed by that clinic's authorised users, according to their role.
- Passwords are stored protected by a hash function, never in plain text, and failed sign-in attempts are limited.
- Notifications we receive from WhatsApp are verified by their signature before they are processed.
11. Cookies
This website (www.contigobot.com) sets no cookies and stores nothing in your browser's local storage, and it uses no analytics, advertising or social media content. Fonts are served from our own site.
The Contigo Clínica applications use only technical cookies needed to start and keep a session secure: the session and cross-site request forgery protection cookies for clinic staff who sign in, and the contigo_portal_session cookie for the client portal, which expires after seven days at most. As they are exempt under Article 22(2) of the Spanish Information Society Services Act (LSSI-CE), they do not require consent. We do not use analytics or advertising cookies.
12. Changes to this policy
We may update this policy to reflect changes in our services or in the law. The current version, with its last-updated date, will always be published on this page.
