Privacy Policy
At Cita1 we take privacy seriously. This policy explains in clear terms what personal data we process, for what purposes, on what legal basis, for how long, who we share it with, and how you can exercise your rights, including the deletion of your data. Cita1 is a product of Paicla OÜ and, when we provide the service to a business, we process certain data on behalf of that business.
- Data controller
- Our roles: controller and processor
- What data we process
- Purposes
- Legal basis
- Retention periods
- Recipients and third parties
- International transfers
- Your rights and how to delete your data
- Security
- Cookies and similar technologies
- Minors
- Changes to this policy
- Contact and supervisory authority
1. Data controller
The controller of the data described in this policy (in the cases where we act as controller) is:
- Paicla OÜ (hereinafter, “Paicla”, “we” or “Cita1”).
- Company registration no.: 17483149 (Estonian Commercial Register).
- Registered office: Tartu mnt 67/1-13b, 10115 Tallinn, Estonia (European Union).
- Contact email: info@paicla.ai.
2. Our roles: data controller and data processor
Depending on the context, Paicla OÜ acts in two distinct roles under Regulation (EU) 2016/679 (GDPR):
- As data controller, when we process data for our own purposes: visitors to the cita1.es website, people who contact us, and the data of the businesses that subscribe to Cita1 (account and billing data).
- As data processor, when a business uses Cita1 to serve its customers. In that case, the client business is the controller of its end customers' data and Paicla processes that data following its instructions and on its behalf, under the corresponding data processing agreement (art. 28 GDPR). This includes messages exchanged via WhatsApp and Telegram, voice channel calls, and appointment data.
If you are an end customer of a business that uses Cita1 and you wish to exercise your rights over your data, you can contact that business (the controller) or contact us, and we will forward your request or help you route it to the right place.
3. What data we process
3.1. Website browsing data
When you visit cita1.es we process minimal technical data (IP address, browser and device type, pages visited) needed to serve the site and keep it secure. The site does not use tracking cookies or third-party analytics or advertising tools, and does not load external fonts that send your IP address to third parties.
3.2. Contact details
If you write to us (by email or through the Paicla OÜ contact form), we process the data you provide: name, contact details and the content of your message.
3.3. Client business account and billing data
For businesses that subscribe to Cita1, we process identification and contact data, account data and the data needed to bill the subscription.
3.4. Conversation data (WhatsApp, Telegram and voice)
When a business serves its customers with Cita1, we process — on behalf of the business — the data needed to manage the conversation and the appointment, including:
- The end customer's phone number and profile name.
- The content of the messages and files exchanged, including voice notes (which are transcribed so they can be handled) and any images or documents sent.
- Technical identifiers and metadata provided by Meta's WhatsApp Business Platform and/or by Telegram (for example, message identifiers and timestamps).
- On the voice channel: the caller's number, the call audio and its transcription, needed to handle the call and manage the appointment.
3.5. Appointment data
Requested service, assigned professional, date and time, appointment status, reminders and confirmations, and associated notes.
3.6. Payment data
Subscription payments are processed through Stripe. Paicla does not store your full card details; Stripe acts as the payment provider.
4. Purposes
- Providing the Cita1 service: handling conversations, booking, rescheduling and cancelling appointments, and sending reminders and confirmations.
- Managing the client business's account and the billing of the subscription.
- Handling your contact, support and sales enquiries.
- Ensuring security, preventing fraud and abuse, and complying with legal obligations.
- Improving and maintaining the service (in aggregated or pseudonymised form wherever possible).
5. Legal basis
- Performance of a contract (art. 6(1)(b) GDPR): provision of the service to the client business and, where applicable, management of the conversation with the end customer.
- Legitimate interest (art. 6(1)(f) GDPR): service security, abuse prevention and product improvement.
- Consent (art. 6(1)(a) GDPR): where applicable, for example for certain communications. You may withdraw it at any time.
- Legal obligation (art. 6(1)(c) GDPR): compliance with accounting, tax and other legal obligations.
For processing where we act as processor, the legal basis is determined by the client business (the controller), which must have a valid basis for communicating with its end customers via WhatsApp or Telegram.
6. Retention periods
- Contact data: for as long as needed to handle your request and, afterwards, for the applicable statutory period.
- Account, conversation and appointment data: for as long as the relationship with the client business remains in force and according to its instructions; upon termination, the data is deleted or returned within a reasonable period, unless there is a legal obligation to retain it.
- Billing data: for the periods required by accounting and tax regulations.
When data is no longer needed, we delete it or anonymise it.
7. Recipients and third parties
We do not sell your data. To provide the service, we share data with providers acting as processors or sub-processors, subject to confidentiality and security obligations:
- Meta Platforms Ireland Ltd. (WhatsApp Business Platform): sending and receiving WhatsApp messages on behalf of the business. See the WhatsApp privacy policy.
- Twilio Inc.: messaging connectivity (when the business chooses Twilio) and voice channel telephony. See the Twilio privacy policy.
- Voice channel providers, when the business enables the Voice Agent: speech recognition (Deepgram) and voice synthesis (ElevenLabs), acting as processors to transcribe and answer calls.
- Stripe Inc. / Stripe Payments Europe Ltd.: processing of subscription payments. See the Stripe privacy policy.
- Google Ireland Ltd. (Google Calendar): informational feed of appointments into the professional's calendar (one-way, view-only) when the business enables the integration. See the Google privacy policy.
- Infrastructure providers: website hosting (Netlify) and network/CDN and DNS services (Cloudflare), needed to serve the site securely.
We may also disclose data to public authorities where there is a legal obligation to do so.
8. International transfers
Some of these providers may process data outside the European Economic Area. In those cases, transfers are covered by valid mechanisms under the GDPR, such as adequacy decisions or the European Commission's Standard Contractual Clauses, together with additional safeguards where appropriate.
9. Your rights and how to delete your data
You may exercise the following rights at any time:
- Access to your personal data.
- Rectification of inaccurate data.
- Erasure (“right to be forgotten”): requesting the deletion of your data.
- Restriction of processing.
- Objection to processing based on legitimate interest.
- Portability of the data you have provided to us.
- Withdrawal of consent at any time, without affecting the lawfulness of any prior processing.
How to request the deletion of your data: write to us at info@paicla.ai stating “Data deletion request” and, if possible, the detail the business used to contact you (for example, your WhatsApp number). We will verify your identity and handle your request without undue delay and, at the latest, within one month. If you are an end customer of a business that uses Cita1, deletion will be carried out in coordination with that business, which is the controller of your data; in any case, we will help make sure your request reaches its destination.
10. Security
We apply appropriate technical and organisational measures to protect data: encryption in transit (HTTPS), access control, two-factor authentication (2FA), re-authentication for sensitive actions, activity logging, and data minimisation and anonymisation where possible.
11. Cookies and similar technologies
The cita1.es site uses only the cookies or technical storage strictly necessary for its operation and security. We do not use third-party analytics, advertising or tracking cookies, so no consent banner is required for those purposes. The Cita1 application (the management dashboards) may use technical storage needed to keep your session active.
12. Minors
Cita1 is aimed at businesses and adults. We do not knowingly collect data from minors without the involvement of those who hold parental authority or guardianship over them. If you believe a minor has provided us with data, please contact us so we can delete it.
13. Changes to this policy
We may update this policy to reflect changes in the law or in the service. We will publish the current version on this page and indicate the date of the last update.
14. Contact and supervisory authority
For any privacy question or to exercise your rights, write to us at info@paicla.ai, which is our point of contact for data protection matters. Given the nature and volume of our processing, we are not required to appoint a Data Protection Officer (DPO); if we appoint one in the future, we will indicate it here.
If you believe we have not handled your request properly, you have the right to lodge a complaint with a supervisory authority. In Spain, the Agencia Española de Protección de Datos (AEPD). In Estonia, the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).