At QuHealthy, we consider the privacy of your health information a fundamental right. This Privacy Notice (Aviso de Privacidad) details our practices regarding how we collect, process, and safeguard your personal and clinical data across Mexico, Latin America, and the United States.
1. Introduction and Scope
This Privacy Notice applies to all QuHealthy platform users — patients, doctors, clinics, and website visitors. It describes what personal data we collect, how we use it, and the rights available to you. Creating an account or booking an appointment means you've had the opportunity to review this notice. For sensitive health information specifically, we ask for your separate, explicit consent at the point you provide it, as described in Section 7.
2. Information We Collect
We collect different categories of information to operate the platform:
- Identity Data: Name, email, date of birth, and ID document. Nombre completo, correo electrónico, teléfono y dirección.
- Health Information: Medical history, lab results, consultation notes, and prescriptions, entered by you or your healthcare provider. Under Mexican law, this is classified as sensitive personal data (datos personales sensibles); in a U.S. HIPAA-covered context, the equivalent term is Protected Health Information. Either way, it receives our highest level of protection and requires your express consent. Cédula profesional, especialidad y comprobante de ejercicio clínico.
- Technical Data: IP address, browser type, operating system, and device identifiers, collected through cookies subject to your consent — see our Cookie Policy for details. Historial clínico, notas de evolución, diagnósticos, recetas y antecedentes biomédicos.
3. How We Use Your Information
We use your health data exclusively to facilitate medical care. QuHealthy never sells medical history to third parties, pharmaceutical companies, or insurance companies, under any circumstances. Technical data is used, with your consent, for performance analytics and platform improvements.
5. Security and Standards
The platform is built under strict cybersecurity standards. Sensitive data, including medical records and media (X-rays, photos), is stored with AES-256 encryption at rest and TLS 1.3 in transit. We host on cloud infrastructure that offers HIPAA-eligible services. As we formalize healthcare relationships in the United States, we will pursue and clearly disclose any additional compliance certifications we obtain.
6. Cross-Border Transfers and Data Retention
Some of our service providers — for example, payment processing and cloud infrastructure — may process data outside Mexico, including in the United States. Where this happens, we put contractual safeguards in place to protect your information to the standard described in this notice. We retain personal data only as long as necessary to provide the service, meet legal record-keeping obligations, or resolve disputes; once that period ends, data is securely deleted or anonymized.
7. Your Rights
Depending on your location, you have rights over your personal data under Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), the California Consumer Privacy Act (CCPA), the EU's GDPR, or other applicable local law. In Mexico and most of Latin America, these are known as ARCO rights:
- Acceso (Access): Request a complete copy of the personal data we hold about you, in a machine-readable format.
- Rectificación (Rectification): Request correction of inaccurate or outdated information.
- Cancelación (Cancellation): Request deletion of your account and associated data — comparable to the 'right to be forgotten' — where there's no legal reason for us to keep it.
- Oposición (Objection): Object to certain uses of your data, and revoke access you've previously granted to doctors or clinics.
If you're in Mexico and believe your rights haven't been respected, you can file a complaint with the Secretaría Anticorrupción y Buen Gobierno (Dirección General de Datos Personales en el Sector Privado), Mexico's data protection authority.
8. Children's Privacy
QuHealthy is not directed at, and we do not knowingly collect personal information directly from, individuals under 18. If a minor receives care booked through QuHealthy, this occurs under the account, supervision, and consent of a parent or legal guardian.
To exercise your privacy rights (ARCO, CCPA, or otherwise) or for questions about our security practices, contact our privacy team at privacy@quhealthy.org. Data controller: [QuHealthy legal entity name and registered address — to be completed upon RFC registration].
Contactar a Soporte