Legal
Privacy policy
How Tendfuls collects, uses and protects personal data.
Last updated: 1 September 2026
1. Who we are
Tendfuls ("Tendfuls", "we", "us") is a care coordination platform operated from Spain. This policy explains how we handle personal data when you visit tendfuls.com or use the Tendfuls service. Contact for privacy matters: privacy@tendfuls.com.
2. Two kinds of data
We handle personal data in two different roles.
- Account and website data, such as your name, email, billing details and how you use the site and app. For this data we are the controller.
- Record data, meaning everything entered into a care record: notes, goals, medical history, trackers, documents and contacts. This data is owned by the record owner. For this data we act as a processor (or, for HIPAA-covered customers, a business associate) and use it only to provide the service as instructed by the owner.
3. What we collect
Provided by you
- Account details: name, email address, password (hashed), role (family, provider, organization)
- Billing details: plan, payment status; card details are handled by our payment provider and never stored by us
- Messages you send to us
- Record data you or your team enter, as described in section 2
Collected automatically
- Device and browser type, IP address, approximate location derived from IP
- Usage events in the app (pages opened, features used) used for reliability and product improvement
- Access logs: which account viewed or changed which part of a record, and when. These are part of the record and visible to its owner
- Cookies as described in our cookie policy
4. Why we use it
- To provide the service: authentication, storing and displaying records, permissions, exports, billing
- To generate insights: pattern detection runs only on the record it belongs to and only where the owner's plan includes it; record data is never used to train models shared across customers
- To keep the service secure: fraud detection, abuse prevention, audit logging
- To support you and respond to messages
- To improve the product using aggregated, de-identified usage statistics
- To send service emails (receipts, security notices, changes to terms). Marketing emails are sent only with consent and can be stopped at any time
5. Legal bases (EU/UK)
| Purpose | Legal basis |
|---|---|
| Providing the service and billing | Performance of a contract |
| Security, audit logs, fraud prevention | Legitimate interests; legal obligation |
| Product analytics | Legitimate interests (de-identified) or consent |
| Marketing emails and non-essential cookies | Consent |
| Record data (special category health data) | Processed on the instructions of the owner, who relies on explicit consent or another Article 9 basis |
6. Sharing
We do not sell personal data. We share it only with:
- People the record owner invites. Within a record, data is visible only to team members and only for the categories the owner has granted
- Service providers under contract: cloud hosting, payment processing, email delivery, error monitoring. Each is bound to process data only for us and to appropriate security terms
- Authorities where required by law, after review, and with notice to you where legally permitted
- A successor in the event of a merger or acquisition, under this policy's terms and with notice
7. International transfers
Record data for EU and UK customers is stored in the EU. Where a service provider processes data outside the EEA or UK, we rely on adequacy decisions or Standard Contractual Clauses with additional safeguards.
8. Retention
- Record data is kept for as long as the record exists. Owners can delete individual entries or the whole record at any time; deleted data is removed from live systems immediately and from backups within 35 days
- Lifetime read access means we keep a record after a subscription ends unless the owner deletes it
- Account data is kept while the account is open and for up to 6 years afterwards where required for tax or legal purposes
- Access logs are kept for the life of the record
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or port your personal data, to object to certain processing, to withdraw consent, and to complain to a supervisory authority (in Spain, the Agencia Española de Protección de Datos). Record owners can exercise access, portability and deletion directly in the app via export and delete. Team members who need help with data held in a record should contact the record owner; we will assist where required by law. Email privacy@tendfuls.com for anything else. We respond within 30 days.
10. Security
Data is encrypted in transit and at rest, access is permission-controlled and logged server-side, two-factor authentication is available to all accounts and required for provider and organization accounts, and backups are encrypted. Details are on our security page. No system is perfectly secure; if we learn of a breach affecting your data we will notify you and the relevant authority as the law requires.
11. Children
Records are frequently about children, but accounts are held by adults: parents, guardians, providers and organizations. We do not knowingly allow people under 16 to open an account. Data about a child inside a record is controlled by the record owner.
12. Changes
We will post changes here and, for material changes, email account holders at least 14 days in advance.
13. Contact
Tendfuls, Spain. privacy@tendfuls.com. Other ways to reach us are on the contact page.