Privacy Policy

Version: 5 — April 2026
Legal references: GDPR (EU) 2016/679 · LOPDGDD 3/2018 · Spanish Biomedical Research Act 14/2007 · Patient Autonomy Act 41/2002

1. Data Controller

FieldValue
Full nameDr. Pascal MENSAH
Trading nameYmmunoledge
AddressCalle Solleric 3, 07340 Alaró, Balearic Islands, Spain
Emaildrpascalmensah@proton.me
Tax IDY4159702M
Medical Registration No.070710746
Websitehttps://drpascalmensah.com

2. Categories of Data Processed

2.1 Browsing data (automatic)

IP address, browser type, pages visited, session duration. Used exclusively for technical operation and aggregated statistics.

2.2 Booking data

Full name, email, phone, country of residence and voluntarily provided health information.

2.3 Health data (Art. 9 GDPR)

Medical history, biological markers, GlycanAge biological age profile, personalised clinical report.

2.4 Genetic data

Laboratory analysis is performed exclusively by N-Gene (Mallorca, Spain), acting as an independent data controller under its own consent framework. Dr. Mensah receives raw genetic data and the results report for clinical interpretation.

Variants processed: MTHFR, VDR, IL6, TNF, FADS1/2, CYP1A2, GSTT1, TCF7L2 and others.

2.5 Genetic interpretation methodology

Interpretation carried out entirely by Dr. Mensah using reference scientific literature (PubMed, ClinVar, OMIM, clinical practice guidelines). No external AI tools are used for identifiable patient genetic data.

2.6 Communication data

Emails and WhatsApp messages (+34 626 175 546) processed exclusively to respond to enquiries.

3. Purposes and Legal Basis

PurposeLegal basisRegulation
Booking managementArt. 6.1(b) + 6.1(a)Act 41/2002
Clinical consultationArt. 6.1(b) + 9.2(h)LOPS; Act 41/2002
Genetic interpretation (from N-Gene)Art. 9.2(a) + 9.2(h)Act 14/2007 Art. 45–47
GlycanAge profileArt. 9.2(h) + 9.2(a)Act 41/2002
Clinical report and therapeutic strategyArt. 6.1(b) + 9.2(h)Act 41/2002
Website statistics (anonymised)Art. 6.1(a) cookiesePrivacy; LOPDGDD
Responding to enquiriesArt. 6.1(b) + 6.1(a)

4. DPIA — Art. 35 GDPR

Processing of raw genetic data constitutes special processing. A Data Protection Impact Assessment (DPIA) is mandatory before continuing. Specialist data protection advice is strongly recommended.

5. Data Retention

  • Clinical and genetic data: minimum 5 years from last consultation (Act 41/2002)
  • Contact data and communications: 3 years from last interaction
  • Browsing data: according to cookie type
  • Invoicing data: 6 years (Spanish commercial law)

6. Recipients

6.1 N-Gene — Independent data controller

N-Gene (Mallorca) acts as independent data controller for laboratory analysis. For questions about sample processing, the patient should contact N-Gene directly.

6.2 GlycanAge (if applicable)

GlycanAge Ltd. (United Kingdom) — independent data controller for glycan profile analysis. [Verify post-Brexit international transfer safeguards.]

6.3 Other service providers (processors)

ProviderPurposeLocation
Booking system Topdoctors.esAppointment managementBarcelona, Spain.
WordPress hosting. Digital Business Lounge LtdWebsite hostingFarnborough, Hampshire, United Kingdom
Complianz BVCookie consent managementEU (Netherlands)
DeepL Pro (DeepL SE)Translation of de-identified clinical documentsEU (Germany) — DPA signed

7. Your Rights

RightDescription
AccessCopy of raw genetic, clinical data and reports
RectificationCorrection of inaccurate data
ErasureDeletion when no longer necessary
RestrictionTemporary suspension of processing
PortabilityData in structured format
ObjectionObject to processing based on legitimate interest
Withdrawal of consentWithout retroactive effect
Right not to be informed (genetics)Act 14/2007 Art. 4; Act 41/2002

Contact: drpascalmensah@proton.me
Supervisory authority: AEPDwww.aepd.es

8. Security Measures

  • HTTPS/TLS encrypted transmission
  • Access to raw genetic data restricted exclusively to Dr. Mensah
  • Identifiable raw genetic data not transmitted to external platforms
  • Regular backups and incident recovery procedures
  • Breach notification to AEPD (Art. 33 GDPR) within legal timeframes

9. Affiliate Programmes and Commercial References

Dr. Mensah may participate in paid affiliate programmes. Where an active affiliate relationship exists, it will be clearly labelled [Affiliate link] or [Paid partnership]. Unlabelled references are independent clinical recommendations.

10. Minors

Services directed exclusively at persons aged 18 and over.

11. Updates

Policy available at https://drpascalmensah.com. Last revised: April 2026.

12. DPO and Contact

Processing of raw genetic data may require designation of a DPO (Art. 37.1(c) GDPR). Consult a specialist data protection adviser.

FieldValue
Data ControllerDr. Pascal MENSAH
Emaildrpascalmensah@proton.me
AddressCalle Solleric 3, 07340 Alaró, Balearic Islands, Spain
DPOappointment in progress
Scroll to Top