GDPR · LOPDGDD
Privacy Policy
At Nutrición Energética y Salud, S.L. we process the personal data you entrust to us in order to provide you with the Nutrición Energética service. This policy describes what we process, for what purposes, the legal basis on which we rely, and how you can exercise your rights.
1. Data controller
- Nutrición Energética y Salud, S.L. (Tax ID No. B65410813).
- Registered office: Calle Muntaner 438, 3.º 1.ª, 08006 Barcelona (Spain).
- Channel for GDPR rights:
[email protected](response within one month, which may be extended by two further months in complex cases, Art. 12 GDPR).
2. Data we process and purposes
Account and authentication
- Email: required to create your account and send you the access link (magic link). Legal basis: performance of the contract.
- IP address and user agent: logged in the sessions table for security purposes and to detect anomalous access. Legal basis: legitimate interest.
Subscription and payment
- Stripe identifier for your customer record and subscription, status and period end date. Legal basis: performance of the contract and compliance with accounting obligations.
- Card data is processed directly by Stripe Payments Europe, Ltd. We do not process or store it on our servers.
Individual recipe purchases
- If you purchase a recipe without an account, we store the email used in Stripe, the recipe identifier, the amount and the technical payment identifiers required to evidence access and prevent duplicates. Legal basis: performance of the contract and compliance with accounting obligations.
- When you log in with that same email, we may associate the purchase with your account so that you can regain access without paying again.
Courtesy codes
- When you redeem a code issued by the practice, we store the redemption date and the resulting validity period. Legal basis: performance of the contract.
Sign in with your Google account (OAuth)
- If you choose to sign in with Google, we receive from Google, via the OAuth protocol, your email address and a unique identifier for your Google account (the sub field) in order to create or link your account and authenticate you. We do not receive your Google password. Legal basis: performance of the contract (provision of the service you request) and your consent when you authorize access. You may continue to use access by link (magic link) as an alternative.
Analytics and campaign measurement
- With your consent, we use Google Analytics 4 to measure use of the platform on an aggregated basis (with anonymized IP) and Google Ads to measure the effectiveness of our advertising campaigns. These cookies start from a denied state by default (Google Consent Mode v2) and are only activated if you accept them. Legal basis: consent (Art. 6(1)(a) GDPR). Further details are available in our cookie policy.
3. The platform does NOT create any medical record
This platform is audiovisual educational content. We do not collect any clinical data about you, nor do we maintain any medical record. The recipes are for guidance only, intended for nutritional and wellness purposes, and are not a substitute for consultation with a healthcare professional.
If you are a patient of Dr. Pérez-Calvo, your medical record resides at his independent practice (jorgeperezcalvo.com), not on this platform. Redeeming a courtesy code issued at his practice only allows us to activate your subscription; it does not transfer any of your medical data to us.
4. Data processors
To provide you with the service we rely on the following providers. All of them comply with the GDPR, and data processing agreements are in place where applicable:
- Contabo GmbH (Germany) — hosting of the server and the database.
- Cloudflare, Inc. (United States, DPF) — DNS, CDN and edge TLS certification.
- Stripe Payments Europe, Ltd. (Ireland) — payment gateway.
- Resend, Inc. (United States · DPF · eu-west-1 Frankfurt processing region) — sending of the email containing the access link (magic link) and transactional communications (payment receipt, subscription-end notice).
- Vimeo, Inc. (United States, DPF) — hosting and playback of the videos (unlisted embed with domain whitelist).
- Google Ireland Limited / Google LLC (Ireland / United States, DPF) — usage analytics (Google Analytics 4), advertising campaign measurement (Google Ads) and social authentication when you sign in with Google (Google OAuth). Analytics and campaign measurement operate only if you give your consent.
5. International transfers
The providers we rely on that are based or that process data outside the European Economic Area are Resend, Inc., Vimeo, Inc., Cloudflare, Inc. and Google LLC, in the United States. The international transfer is covered by the European adequacy framework EU-US Data Privacy Framework (DPF) and, failing that, by the Standard Contractual Clauses (SCC) approved by the European Commission (Art. 46(2)(c) GDPR). Resend processes emails from its European region (eu-west-1, Frankfurt), minimizing the actual transfer of data outside the EEA.
The remaining processors handle data exclusively within the European Economic Area.
6. Retention period
- Account data: for as long as your account remains active. When you request cancellation, we immediately anonymize your personal data (name and email are replaced by an internal identifier) and retain only the minimum records required by accounting and tax obligations under the law.
- Accounting and payment data: 6 years from the last transaction (Art. 30 Commercial Code + General Tax Act (LGT)).
- Guest recipe purchases: retained for as long as access must remain available and, at a minimum, for the applicable statutory accounting retention periods. You may exercise your rights by writing from the same email used for the purchase.
- Technical session logs: 90 days.
7. Your rights
You may exercise at any time your rights of access, rectification, erasure, objection, restriction of processing and portability. The fastest way is:
- Iniciar sesión en tu cuenta y pulsar “Cancelar mi cuenta” (provoca la supresión de tu usuario y datos asociados, salvo los que debamos conservar por obligación legal).
- O enviar un email a [email protected] indicando el derecho que quieres ejercer y adjuntando copia del documento de identidad si lo solicitamos para acreditar la titularidad.
[email protected]
Tienes también derecho a presentar una reclamación ante la Agencia Española de Protección de Datos (aepd.es) si consideras que tu derecho no ha sido atendido correctamente. aepd.es
8. Aviso médico
El contenido editorial de la plataforma tiene carácter divulgativo. No constituye prescripción médica individualizada ni sustituye la consulta con un profesional sanitario. Las recomendaciones están indicadas para objetivos nutricionales y de bienestar, nunca como tratamiento de patologías diagnosticadas.
Last updated: 31 de mayo de 2026.