Privacy Policy
This notice explains how NeuroBehavior Clinic processes personal data through its public website, enquiry and recruitment channels, clinical administration, and research activities. Protocol-specific, clinical, forensic, or institutional notices provide additional information where relevant.
Data Controller
NeuroBehavior Clinic
Carrer de Villarroel 170, 08036 Barcelona, Spain
Data Protection Officer
privacy@neurobehaviorclinic.com
Contact the DPO regarding confidentiality, the use of personal data, or the exercise of data protection rights.
Current Version
Effective date: 21 May 2024
Version: 2.0
1. Scope and Layered Information
This policy covers ordinary public browsing, contact enquiries, professional or institutional correspondence, clinical referral enquiries, and employment applications submitted through this website.
Clinical care, research participation, forensic instructions, biological samples, and shared institutional projects may require a more specific notice. The activity-specific notice, consent form, protocol, or agreement supplements this policy and describes the applicable purpose, legal basis, recipients, and retention period.
2. Personal Data We Process
Website and enquiries: name, contact details, organisation, enquiry category, message content, language, technical request data, and limited security information.
Recruitment: application form responses, CV, education, qualifications, experience, language skills, availability, and information voluntarily included by the applicant.
Clinical administration: identity and contact data, referral information, appointments, relevant health history, assessment records, reports, and correspondence.
Research: eligibility, consent, study identifiers, questionnaires, behavioral and psychometric data, neuroimaging, electrophysiology, biometrics, biological or genetic data, and protocol records.
3. Purposes and Legal Bases
Website operation and security: delivery, integrity, misuse prevention, and incident response, based on our legitimate interests in operating a secure institutional website.
Enquiries and referrals: reviewing and responding to the request, taking requested pre-contractual steps where applicable, and managing legitimate professional or institutional correspondence.
Recruitment: assessing an application, taking steps before a possible employment relationship, meeting legal obligations, and retaining an application for other roles only where separate talent-pool consent has been given.
Clinical administration: managing accepted care or assessment, professional documentation, legal obligations, and the provision or management of health care under the applicable professional safeguards.
Research: the legal basis is determined for each approved study and may include consent, scientific research provisions, legitimate interests, legal obligations, or another basis permitted by applicable law. Special-category data also requires a corresponding condition under Article 9 GDPR or the applicable research and health-law framework.
4. How Public Website Forms Are Handled
Contact forms: submissions are delivered to the clinic mailbox selected for the enquiry category. The website uses a short-lived anti-abuse record derived from the email address and network address to limit repeated submissions; it expires after approximately five minutes.
Job applications: the completed form and CV are delivered to the recruitment mailbox. The local temporary copy of the CV is deleted after the delivery attempt; the delivered message and attachment remain in the controlled mailbox for the applicable recruitment period.
Please do not use a public form to send urgent information, full medical records, court files, identity documents, or other sensitive material unless the clinic has specifically instructed you to use that channel.
5. Cookies, Sessions, Maps, and External Resources
Ordinary public browsing does not require a clinic authentication session. Technical session cookies are used for the restricted staff login and operations portal and may also be used when necessary to secure a server-side request.
The contact page embeds Google Maps to display the Barcelona and Zürich locations. Loading that page may connect the visitor's browser to Google, which may receive technical information under its own privacy terms.
Public pages currently obtain presentation resources from an external content-delivery network. The provider may receive ordinary connection data, such as IP address and browser information, needed to deliver that resource. We do not currently use advertising cookies or public-site behavioral analytics.
6. Recipients, Processors, and Research Roles
Access is limited to personnel who require the information for the stated purpose. Recipients may include authorized clinical, research, coordination, recruitment, or administrative staff; hosting, email, secure storage, and IT service providers acting under appropriate arrangements; competent ethics or regulatory bodies; and professional advisers or public authorities where disclosure is lawful and necessary. Study-specific notices identify participating institutions, sponsors, laboratories, data-access bodies, and whether organisations act as separate controllers, joint controllers, or processors.
7. International Transfers
Research or technical processing may involve Switzerland, the EU/EEA, or another jurisdiction identified in the relevant notice. Where data is transferred outside the EU/EEA, we use an applicable adequacy decision or another lawful safeguard, such as standard contractual clauses, together with proportionate technical and organisational controls. Identifiable research data is not shared internationally merely because a collaboration exists.
8. Retention
Enquiries: normally retained while active and for up to 12 months after closure, unless an ongoing relationship, legal claim, or statutory duty requires longer retention.
Recruitment: retained during selection and normally for up to six months after closure. Where separate talent-pool consent is given, an application may be retained for up to 12 months.
Clinical records: core clinical documentation is retained for at least 15 years from discharge where Catalan health-record law requires it; other clinical documentation is generally retained for at least five years and may be kept longer where clinically, legally, judicially, or scientifically justified.
Research records: retained for the period specified by the approved protocol, participant information, ethics decision, funding conditions, scientific integrity requirements, and applicable law. Biological and genetic material follows its own consent and governance terms.
9. Security and Confidentiality
Access control: role- and purpose-based access to restricted systems.
Coding: separation of direct identifiers from research datasets where feasible.
Data quality: controlled records, change documentation, and review procedures.
Incident response: containment, assessment, documentation, and notification where legally required.
10. Your Rights and Complaints
Subject to the processing context and applicable law, you may request access, rectification, erasure, restriction, portability, or object to processing, and you may withdraw consent without affecting earlier lawful processing. Some rights may be limited where health-record, research-integrity, legal-claim, or public-interest requirements apply.
Send requests to the Data Protection Officer at privacy@neurobehaviorclinic.com. We may verify identity and the relevant processing context. You may also lodge a complaint with the Spanish Data Protection Agency (AEPD). For processing specifically subject to Swiss law, the Federal Data Protection and Information Commissioner (FDPIC) may also be relevant.
11. Automated Decision-Making
Website enquiry or recruitment data is not used for solely automated decisions producing legal or similarly significant effects. Statistical or computational systems may support research analysis, quality control, or professional review, but clinically or forensically relevant conclusions require qualified human assessment and the safeguards stated in the applicable protocol or professional process.
12. Changes to This Policy
We update this policy when our public data flows, clinical or research activities, service providers, or legal obligations materially change. The effective date and version shown above identify the current public notice.