• castellano
  • german
  • portuguese
  • brazil

Consumer Health Data Privacy Policy

This policy is published by SOLUCIONEC, the operator of stinotice.com and of the STI notice app, in accordance with the Washington My Health My Data Act, the Nevada consumer health data law and equivalent US state laws. It supplements our Privacy Policy and prevails over it in the event of any conflict, for the data described here.

1. WHO THIS APPLIES TO
This policy applies to you if you are a resident of Washington State, of Nevada, or of any other US state whose law gives you specific rights over consumer health data, and you use STI notice or receive a notification from it. If you are elsewhere, our Privacy Policy is the document that governs.

2. WHAT WE TREAT AS CONSUMER HEALTH DATA
We treat the following as consumer health data, whether or not a given state law would require it:
- The fact that you have created an account on, or used, a service whose sole purpose is to notify a sexual partner of a possible exposure to a sexually transmitted infection. This on its own says something about your sexual and reproductive health, and we handle it accordingly.
- The infection you select when preparing a notification.
- The fact that you have received a notification, and the infection stated in it.
- The phone number or email address to which a notification was sent, when linked to any of the above.

3. WHAT WE COLLECT, WHY, AND HOW WE USE IT
- The infection selected. Purpose: to draft the text of the notification, to allow the person you notify to view it for 30 days through the link they receive, and to avoid sending them duplicate alerts in that period. Use: no other. It is not used for advertising, for profiling, for research, or to train automated systems.
- The contact details of the person notified. Purpose: to deliver the message and to operate the 30-day duplicate check. Use: no other.
- Account and usage records (account identifier, language, notifications available and sent, dates and times). Purpose: to operate your account, to process payment and to detect abusive use of the service such as false, bulk or harassing notifications.
- Technical data (IP address, device identifiers, browser, operating system). Purpose: security, fraud prevention and, where you have consented, analytics.
We do not collect any category of consumer health data, and do not use it for any purpose, beyond what is listed here. If that ever changes we will obtain your consent first.

4. WHERE THE DATA COMES FROM
- Directly from you, when you create an account, select an infection and enter the contact details of the person you wish to notify.
- From another user of the service, if that person has entered your phone number or email address in order to notify you. That is the only way we obtain data about a recipient.
- Automatically from your device, through cookies and similar technologies, and only where you have consented.
We do not buy consumer health data, we do not obtain it from data brokers, public records, social networks or advertising networks, and we do not infer it from your browsing elsewhere.

5. WHAT WE SHARE AND WITH WHOM
Categories of consumer health data shared: the infection stated in a notification and the contact details of the person notified. Nothing else in section 2 is shared.
Categories of third parties with whom it is shared:
- The person you notify. The message we deliver contains the infection you selected. That is the purpose of the service.
- Public authorities and courts, where there is a legal obligation or a valid legal request.
We have no affiliates and share no consumer health data with any affiliate.
We do not share consumer health data with our payment processor, with our analytics provider or with any advertising provider. The advertising providers listed in our Privacy Policy never receive the infection selected, the content of a notification, the contact details of a recipient, or any data from which your health status could be inferred.
On request we will give you the identity of each third party with which your consumer health data has been shared, together with an active means of contacting it.

6. WE DO NOT SELL CONSUMER HEALTH DATA
We do not sell consumer health data and we have never sold it. Under the Washington My Health My Data Act and the Nevada consumer health data law, a sale would require your separate written authorisation containing the specific items those laws prescribe. We do not seek such an authorisation because we do not engage in that practice. If that ever changed, we would ask you for a valid authorisation first, and you would be free to refuse and to revoke it later.

7. WE DO NOT USE GEOFENCING
We do not operate, and will not operate, any geofence around a healthcare facility, a clinic, a testing centre or any other place that provides in-person health care services, and we do not use location data to identify, track, collect data from, or send notifications or advertising to anyone based on their proximity to such a place.

8. YOUR RIGHTS
- To confirm and access: to know whether we collect, share or sell your consumer health data, and to obtain a copy of it, together with the list of third parties described in section 5.
- To withdraw consent: to withdraw your consent to the collection and to the sharing of your consumer health data, at any time and without giving a reason.
- To delete: to have your consumer health data deleted from our records, including from our backups. When we receive a deletion request we act on it within 30 days, we instruct every processor and third party that holds the data on our behalf to do the same, and we notify you when it is done.
- To appeal: if we refuse a request, we will tell you why and how to appeal, in a clearly accessible way. If we deny your appeal, you may complain to the Washington State Attorney General at atg.wa.gov, to the Nevada Attorney General at ag.nv.gov, or to the authority of your own state.
- Not to be penalised: exercising any of these rights is free and does not affect the price or the quality of the service.

9. HOW TO EXERCISE THEM
Write to info@stinotice.com stating your state of residence and which right you wish to exercise. If you have received a notification and simply want it deleted and no further messages, the fastest route is the form at stinotice.com/unsubscribe, which is free and takes effect immediately.
We verify requests using the contact details we already hold and will not ask you for more information than is necessary to do so. You may use an authorised agent, in which case we may ask for evidence of their authority. We respond within 45 days and may extend that period once where the law permits, telling you why.

10. HOW LONG WE KEEP IT
The infection selected and the contact details of the person notified are deleted 30 days after the notification is sent, after which the viewing link stops working. Account records are kept while the account is active. Invoicing records are kept for the periods required by Spanish tax and commercial law. Nothing in this section prevents you from asking for earlier deletion under section 8.

11. WHERE YOUR DATA IS PROCESSED
We are established in Spain. Your consumer health data is stored and processed in the European Economic Area, under the European Union General Data Protection Regulation, which applies to it in addition to the US state laws described here.

12. CHANGES TO THIS POLICY
We will not collect, use or share categories of consumer health data beyond those disclosed here without obtaining your consent first. If we update this policy we will publish the new version at this address, state the new effective date, and keep the link to it on our home page.

13. CONTACT
SOLUCIONEC
Represented by: David Rodríguez Sánchez
Spanish tax ID (NIF): 45774319H
Avenida Touroperador Air Marin, 2. 35100 San Bartolomé de Tirajana (Las Palmas – Spain)
info@stinotice.com

Last updated: 29/08/2026

STI noticeAvailable on Google Play
DOWNLOAD
×