Your data at Smalta
Privacy policy
Information about the website, user accounts, support enquiries and the WhatsApp Business connection.Updated on 7 Sept 2026.
1. Who processes your data
Tanjiren Labs, S.L. owns Smalta. You can contact us about privacy at privacidad@smalta.es. The postal address is in the rights and contact section; tax and registration details are in the legal notice.
Tanjiren acts as controller of the data needed to manage its website, accounts and relationships with users and customers. When a practice uses Smalta to manage communications with its patients, the practice is the controller of that data and Tanjiren processes it on the practice’s behalf, following its instructions and the data processing agreement. This policy does not replace the information the practice must provide.
2. What data we use and why
- Enquiries and requests: name, professional contact details, organisation and the contents of the request, to respond and prepare the requested commercial relationship.
- Account and support: identity, email, authentication data, organisation, permissions and enquiries or issues, to provide access and assistance. If you choose to sign in with Google or Microsoft, we receive the identification data authorised from that provider.
- Security: technical access and activity data needed to protect the service, prevent abuse and resolve incidents.
The legal bases are performance of a contract or requested pre-contractual steps (GDPR Article 6(1)(b)), legitimate interests in handling professional contacts, providing support and protecting the service (Article 6(1)(f)), and applicable legal obligations (Article 6(1)(c)). Where processing requires consent, it will be requested separately and may be withdrawn.
Required fields are identified in each form; without them we cannot process the request. Do not include patient data or health information in commercial or support enquiries. We do not sell personal data or use these channels to make solely automated decisions producing legal or similar effects.
3. WhatsApp connection and messages
When an authorised person connects WhatsApp Business, we receive from Meta the business account and phone number identifiers, permissions and connection credentials needed to link them to their organisation. Facebook Login for Business is used to authorise this integration.
The integration processes phone numbers, message content, dates, replies and delivery statuses to send administrative reminders, manage appointment confirmations or changes and enable authorised staff to handle conversations. The data comes from the practice, its contacts and Meta. Reminders must be limited to administrative information; do not include diagnoses, treatments or clinical documentation.
The practice determines the purpose and legal basis of its communications and informs recipients. Messages must comply with the applicable consent requirements and WhatsApp rules. Data received from Meta is used to provide and protect the authorised integration, not for Tanjiren’s own advertising.
The administrator can remove the connection. To request deletion of the associated data, see the deletion instructions.
4. Providers and transfers
Hosting and backup, authentication and email, maintenance and technical monitoring providers may access data to the extent necessary. Processors must handle data in accordance with our instructions and the applicable contractual terms. Authorities may receive data that must be disclosed under a legal obligation.
WhatsApp/Meta is involved in authorising the connection and transporting messages under its data processing terms. Our primary hosting is in the European Union; using external services may involve processing outside the European Economic Area. WhatsApp provides for transfers to the United States, among other destinations, with the safeguards described in its data transfer addendum.
Transfers require an adequacy decision or applicable safeguards, such as standard contractual clauses. You can obtain the list of providers involved in processing your data and a copy of or reference to the safeguards through the privacy contact. Information about the service’s subprocessors is also provided to the practice as part of its contractual relationship.
5. How long data is kept
Enquiries and requests that do not proceed will generally be deleted or anonymised 12 months after the last interaction. Account and support data is kept for as long as necessary to provide the service and handle incidents. Data processed on behalf of a practice follows its instructions and the periods set out in the data processing agreement.
Disconnecting WhatsApp stops use of the connection. Deletion of credentials and other data is handled through the stated deletion procedure; disconnecting does not automatically erase the practice’s conversations or its assets on Meta. Data needed for legal obligations or claims is retained with restricted access for the applicable period.
6. Your rights and contact details
You may request access, rectification, erasure, restriction, objection and portability where applicable, and withdraw consent without affecting previous processing. We will only ask for additional information to verify your identity if there are reasonable doubts; do not send identity documents initially.
Write to privacidad@smalta.es or by post to Carrer de l'Escola Pia, 99 BIS, planta 1, 08201 Sabadell (Barcelona), España. We will respond within one month, subject to legally permitted extensions where applicable.
If your request concerns data managed by a practice, address it to that practice; Tanjiren will assist it in accordance with its contract. You may lodge a complaint with the Spanish Data Protection Agency.
7. Security and changes
We apply security measures appropriate to the processing, including access controls and protection of communications. We will publish changes to this policy with their update date and provide information about new purposes before using data for them.