Privacy Policy
1. INTRODUCTION
At stinotice.com and in the STI notice app we process personal data belonging to two distinct groups of people: those who use the service to send a notification (the USER) and those who receive that notification (the RECIPIENT). This Privacy Policy explains what data we process about each of them, for what purpose, on what legal basis and for how long. We are established in Spain and apply Regulation (EU) 2016/679 (GDPR) as our baseline standard worldwide. Section 16 contains country-specific information and section 17 contains additional rights for people in the United States. If you have received a notification from STI notice and do not know why, the information that concerns you is in section 7.
2. DATA CONTROLLER
Controller: SOLUCIONEC
Represented by: David Rodríguez Sánchez
Spanish tax ID (NIF): 45774319H
Address: Avenida Touroperador Air Marin, 2. 35100 San Bartolomé de Tirajana (Las Palmas – Spain)
Email: info@stinotice.com
3. DATA WE PROCESS
About the USER:
- Identification and contact: email address and any data you provide when you write to support.
- Account and use of the service: account identifier, language, notifications available and sent, and app settings.
- Health data (special category under Article 9 GDPR): the STI or STD you select when preparing a notification. This data reveals information about your health and your sex life and receives reinforced protection. It is used to draft the message and is kept for 30 days linked to the contact notified, for two purposes only: so that the recipient can view the notification when they open the link they receive, and to prevent duplicate alerts being sent to them during that period. After 30 days it is deleted.
- Data about the person you wish to notify: the phone number and/or email address you enter in the form.
- Payments: purchases of notification packs are processed through Stripe and Google Play. We do not store your full card number; we keep the transaction identifier and the data required by tax and accounting legislation.
- Technical and browsing data: IP address, device identifiers, operating system, browser, date and time of access and actions performed, obtained through cookies and similar technologies where you have given your consent.
About the RECIPIENT:
- The phone number and/or email address provided by the USER.
- The STI or STD notified to them, linked to that contact for 30 days.
- The technical delivery status of the notification.
We do not process their name, their address or any other data about them, we do not cross-reference their contact details with any other database and we do not build any profile.
4. PURPOSES
- Providing the service: managing your account, generating and sending the notification to the contact indicated, and confirming delivery.
- Allowing the recipient to view the notification for 30 days when they open the link they receive, and preventing them from receiving duplicate alerts during that same period.
- Managing payments, invoicing and accounting for notification packs.
- Handling enquiries, incidents and support requests.
- Preventing abusive use of the service, in particular false, bulk or harassing notifications, and dealing with the reports we receive on that ground.
- Analysing use of the website and the app in aggregate form in order to improve how they work.
- Displaying third-party advertising on the pages and screens where it is permitted, under the terms of section 8.
- Complying with legal obligations and responding to requests from competent authorities.
We never use the content of notifications or the STI selected to build commercial profiles, to target advertising or to train automated systems.
5. LEGAL BASES
In relation to the USER:
- Performance of a contract (Art. 6.1.b GDPR): account management, sending notifications and processing payments.
- Explicit consent (Art. 9.2.a GDPR): processing of the STI you select, since it is health data. It is collected separately before each send and you may withdraw it at any time, without affecting the lawfulness of processing carried out beforehand.
- Consent (Art. 6.1.a GDPR): cookies and similar technologies that are not strictly necessary, and personalised advertising.
- Legitimate interest (Art. 6.1.f GDPR): platform security and the prevention of fraud and abuse, following a documented balancing test that you may request from us.
- Compliance with legal obligations (Art. 6.1.c GDPR): tax, accounting and data protection obligations.
In relation to the RECIPIENT:
- Legitimate interest (Art. 6.1.f GDPR) in enabling them to learn of a possible exposure to an STI so that they can obtain early diagnosis and treatment. We have documented the balance between that interest and their rights. For 30 days we keep their contact details together with the STI notified, for the sole purpose of allowing them to view the notification when they open their link and of not sending them duplicate alerts during that period; once that period has elapsed both items are deleted. During that time we do not display advertising on the notification page, we do not pass their contact details to third parties for marketing purposes and we do not build any profile. They have an immediate and free objection mechanism.
- They may object at any time and with immediate effect at stinotice.com/unsubscribe.
6. CONSENT FOR HEALTH DATA
The STI you select in order to notify someone is health data. Before each send we ask for your express and separate consent to process it for the sole purpose of drafting and sending that specific notification. It is not requested for any other purpose and it is not shared with advertisers, analytics providers or any third party unconnected with the send. You may withdraw your consent by writing to info@stinotice.com, although withdrawal does not affect notifications that have already been sent.
7. INFORMATION FOR THE PERSON WHO RECEIVES A NOTIFICATION
If you have received an SMS or an email from STI notice without having requested it, this section brings together all the information we are required to give you under Article 14 GDPR.
- Who processes your data: SOLUCIONEC, Spanish tax ID (NIF) 45774319H, registered at Avenida Touroperador Air Marin, 2. 35100 San Bartolomé de Tirajana (Las Palmas – Spain). You can write to us at info@stinotice.com.
- Where we obtained your contact details: they were given to us by a user of the service who declared that they had sexual contact with you.
- What data about you we process: the phone number or email address to which the message was sent, the infection notified to you, and the technical delivery result. We do not know your name or anything else about you.
- Why: to send you a single alert allowing you to consider whether to get tested. We will not send you any commercial or promotional communication, we do not build profiles about you and we do not pass your contact details to advertisers or to any third party for marketing purposes.
- On what legal basis: our legitimate interest in enabling you to learn of a possible exposure to an STI and obtain early diagnosis (Art. 6.1.f GDPR). You may ask us for the balancing test we carried out and you may object at any time.
- How long we keep your data: for 30 days we keep the contact the message was sent to together with the infection notified to you. We do this for two reasons: so that you can view the notification when you open the link, and so that you do not receive duplicate alerts if someone else tries to notify you during that same period. After 30 days we delete both items and the link stops working.
- About the link you received: the page it opens displays the infection notified to you. Anyone who has that link can see it, so do not forward it and do not leave it accessible on a shared device. That page is not indexed by search engines and displays no advertising.
- Your rights: you may request access to, rectification of, erasure of, restriction of and portability of your data, and object to the processing. The fastest route for objection and erasure is the form at stinotice.com/unsubscribe, which is free and takes effect immediately. You can also write to info@stinotice.com.
- About who sent the message: we cannot reveal their identity, because it is also protected personal data and disclosing it could expose that person to risk. If you believe the message is false, amounts to harassment or forms part of a situation of violence, you can report it through the link in the notification and write to us at info@stinotice.com so that the account is blocked and the evidence preserved for any authority that lawfully requests it.
- Complaints: you may lodge a complaint with the Spanish Data Protection Agency (AEPD), with the supervisory authority of your country of residence, or with the authorities named in section 16.
- What to do with the information: the notification is not a diagnosis and does not come from a healthcare professional. If you have any doubts, contact your doctor or a sexual health service.
8. THIRD-PARTY ADVERTISING
We display third-party advertising on certain pages of stinotice.com and on certain screens of the STI notice app. The providers we work with are Google AdMob (Google Ireland Limited), ADMEDIA LLC FZ (United Arab Emirates), EXOCLICK, S.L. (Spain) and Propeller Ads Limited (Cyprus).
These providers may access information from your device (advertising identifier, IP address, device type, browser, operating system and pages visited) and use it to select, display and measure adverts, including personalised advertising and real-time programmatic bidding. They only do so if you have given your consent; if you refuse, their technologies are not loaded.
As regards the collection and transmission of data that takes place from our pages, we act as joint controllers with these providers within the meaning of Article 26 GDPR; they act as independent controllers as regards their subsequent use of that data. You can consult their policies here: https://adsterra.com/privacy-policy-managed/ https://www.exoclick.com/privacy-policy/ and https://monetag.com/privacy/.
When you confirm a send, and only if you have accepted advertising cookies, the tab you were browsing in may be redirected to a page belonging to one of our advertising providers while the service continues in a new tab. We have configured the site so that the address of the originating page is not transmitted to that provider. That provider never receives the infection selected, the content of the notification, the recipient's contact details or any data from which your health status could be inferred.
Some notifications are made available at no charge in the advertising-supported mode of the service. This is a financial incentive within the meaning of Californian law: the value of that incentive corresponds to the advertising revenue we obtain from a user session, which we estimate in good faith at less than two US cent per session, calculated as our total net advertising revenue divided by the number of sessions in which advertising was served. You are free to decline it, in which case notifications may be purchased individually, and you may withdraw your acceptance at any time from the Cookie Policy.
You can change or withdraw your advertising consent at any time using the link available in the Cookie Policy.
9. PROVIDERS AND RECIPIENTS OF THE DATA
We do not sell your personal data. We disclose it only to the providers we need in order to deliver the service and in the cases required by law:
- Hosting and infrastructure: IONOS CLOUD, S.L.U. (Spain). Processor. Email notifications are sent from our own infrastructure at this provider.
- SMS delivery: Bird (Netherlands). Processor.
- Payments: Stripe Payments Europe Ltd. (Ireland) and Google Commerce Limited (Irland). Independent controller as regards payment data.
- Analytics: Google Ireland Limited (Firebase, Google Analytics 4 and Google Tag Manager). Processor.
- Advertising: the providers listed in section 8.
- App distribution: Google Ireland Limited (Google Play).
- Public authorities and courts, where there is a legal obligation or a valid request.
We have entered into the contract required by Article 28 GDPR with all processors.
10. INTERNATIONAL TRANSFERS
Your data is stored and processed in the European Economic Area. Some of the providers listed process data outside that area. Where this occurs, the transfer relies on an adequacy decision of the European Commission or on the Standard Contractual Clauses approved by the Commission, together with any supplementary measures found necessary following the corresponding transfer impact assessment.
11. RETENTION PERIODS
- Recipient's contact details and the STI notified: 30 days from the send, so that the recipient can view the notification when they open their link and so that they do not receive duplicate alerts during that period. Once the period has elapsed both items are deleted and the link stops working.
- User account: for as long as it remains active.
- Invoicing and accounting: for the periods required by commercial and tax legislation.
- Support requests and requests to exercise rights: 3 years from resolution, as evidence that they were handled.
- Cookies and browsing data: the periods indicated in the Cookie Policy.
12. YOUR RIGHTS
You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw any consent you have given. If you are outside Spain, see also sections 16 and 17.
To do so, write to info@stinotice.com stating the right you wish to exercise. If you have received a notification and want to stop receiving them, the form at stinotice.com/unsubscribe is the fastest route.
Exercising these rights is free of charge. If you believe we have not dealt with your request properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD) or with the supervisory authority of your country of residence.
13. MINORS
The service is intended exclusively for people aged 18 or over and we do not knowingly collect data from minors. If we detect, or are told, that an account belongs to a minor, we will block it and delete their data without delay. We do not knowingly sell or share the personal information of anyone under 18. If you are a parent or guardian and believe that a minor in your care has used the service, write to us at info@stinotice.com.
14. SECURITY AND DATA BREACHES
We apply encryption in transit and at rest, role-based access control, pseudonymisation of notified contacts, access logging and backups. Because we process health data, we review the measures applied on a regular basis.
In the event of a security breach we will notify the Spanish Data Protection Agency within 72 hours and, where the breach poses a high risk to your rights, we will inform you directly and without undue delay.
15. CHANGES TO THIS POLICY
We may update this Privacy Policy to reflect legal or technical changes or changes in how the service is provided. We will publish the updated version at stinotice.com stating the date of the last amendment and, where the change is substantial, we will inform you through the contact details we hold.
16. COUNTRY-SPECIFIC INFORMATION AND OTHER COUNTRIES
We are established in Spain and apply Regulation (EU) 2016/679 (GDPR) as our worldwide baseline, together with any mandatory rule of your own country that applies to you. Wherever you are: we process your health data only with your express and separate consent; we do not sell your personal data; we do not use it for advertising or profiling; we store and process it in the European Economic Area; we delete the infection notified and the recipient's contact details after 30 days; and you may exercise the rights described in section 12 free of charge by writing to info@stinotice.com.
- Designated contacts: for the purposes of the Act respecting the protection of personal information in the private sector of Quebec and of the Protection of Personal Information Act of South Africa, the person in charge of the protection of personal information and the Information Officer is David Rodríguez Sánchez, reachable at info@stinotice.com.
- United Kingdom: we process your data under the UK GDPR and the Data Protection Act 2018. Transfers originating in the United Kingdom rely on the UK International Data Transfer Agreement or the UK Addendum to the Standard Contractual Clauses. The cookie consent panel is also how we obtain the consent required by the Privacy and Electronic Communications Regulations 2003.
- Transfers outside your country: your personal information is stored and processed in the European Economic Area and may be disclosed to the providers listed in section 9, located in the European Economic Area, Ireland, the Netherlands, Cyprus and the United Arab Emirates. We take reasonable steps to require those providers to protect it, but accountability rules such as Australian Privacy Principle 8.1 may not apply to overseas recipients in the same way. The European Economic Area provides a level of protection substantially similar to the conditions for lawful processing required by section 72 of POPIA.
- Sensitive and health information: the infection you select is health information, and therefore sensitive information under the Australian Privacy Act 1988, special personal information under section 26 of POPIA and sensitive information under Canadian and other national laws. We collect it only with your express consent, as described in section 6.
- Complaints: you may complain to the data protection authority of your own country, where one exists, and in any case to the Spanish Data Protection Agency (AEPD), which is our lead supervisory authority. In the United Kingdom, the Information Commissioner's Office at ico.org.uk; in Australia, the Office of the Australian Information Commissioner at oaic.gov.au; in Canada, the Office of the Privacy Commissioner at priv.gc.ca or, in Quebec, the Commission d'accès à l'information at cai.gouv.qc.ca; in South Africa, the Information Regulator at inforegulator.org.za; in the United States, the authority named in section 17.
- Breaches: where a breach is likely to result in serious harm we will notify you and the competent authority, including under the Australian Notifiable Data Breaches scheme, section 22 of POPIA, and Canadian confidentiality incident rules, of which we keep a register.
- Countries we do not serve: some countries require an operator established abroad to appoint a local representative, to register with a national authority or to store data locally. We do not offer the service in those countries. If you are in one of them and have received a notification, sections 7 and 12 apply to you in full.
17. ADDITIONAL INFORMATION FOR THE UNITED STATES
This section applies if you are a resident of a US state with a comprehensive consumer privacy law or a consumer health data law. It supplements, and does not replace, the rest of this policy.
- Sensitive and consumer health data: the STI you select, the fact that you have used the service, and the fact that you have received a notification are treated by us as sensitive personal information and as consumer health data. We use them only to provide the service as described in sections 3 to 7. We do not use them to infer characteristics about you, we do not use them for advertising, and we do not disclose them to advertisers. Our dedicated Consumer Health Data Privacy Policy describes this processing in the terms required by Washington State law.
- Sale and sharing: we do not sell personal information for money. However, the third-party advertising technology described in section 8 may amount to a "sale" or to "sharing" for cross-context behavioural advertising under some state laws. Rejecting advertising cookies in our consent panel opts you out of that processing across our website and app, and is the mechanism referred to by the Do Not Sell or Share My Personal Information link in our footer.
- Consumer health data: we do not sell consumer health data, and we will not do so. Under the Washington My Health My Data Act and the Nevada consumer health data law, a sale of consumer health data requires your separate valid authorisation, which we do not seek because we do not engage in that practice. You may withdraw any consent relating to consumer health data and request its deletion by writing to info@stinotice.com; we will action the withdrawal and instruct our processors accordingly.
- Financial incentive: the advertising-supported mode described in section 8 is offered as a financial incentive and requires your opt-in, which you may revoke at any time without penalty beyond the loss of the free notifications themselves.
- Your rights: depending on your state of residence, you may have the right to know what personal information we hold about you and how we use it; to obtain a copy of it; to correct it; to delete it; to opt out of its sale, sharing or use for targeted advertising; to limit the use and disclosure of sensitive personal information; and not to be discriminated against for exercising these rights. Where your state provides for it, you may also appeal a decision we make on your request.
- How to exercise them: write to info@stinotice.com stating your state of residence and the right you wish to exercise. We will verify your request through the contact details we already hold; we will not ask you for more information than is necessary to do so. You may use an authorised agent, in which case we may ask for evidence of their authority. We will respond within 45 days and may extend that period once where permitted, informing you of the extension.
- Location of the data: we are established in Spain and your data is processed in the European Economic Area, which applies a higher standard of protection than most US state laws.
Last updated: 29/08/2026
