Privacy policy

Last updated: 1 October 2026

This Privacy Policy describes how the personal data of users of the blood donation registration application (hereinafter, the ‘App’) is collected, used and protected. Use of the App implies acceptance of this Privacy Policy.

1. Data controller

The controller responsible for processing personal data is:

  • Controller: Andrés Lara Mesa
  • Contact email: info@doaapp.es

2. Personal data collected

The App processes data concerning your health, which the General Data Protection Regulation (Article 9) treats as a special category. It processes it only with your consent, as described in section 4, and for the purposes in section 3.

This is the data the App collects:

  • From your Apple or Google account: your name and email address.
  • What you enter in your profile: first name, surname, date of birth, biological sex, blood type, weight and, if you choose, a photo.
  • The dates of the donations you record.
  • From the quick test: whether you passed and, if not, which group of questions stopped it (current health, medication, travel or sexual risk behaviour). Your individual answers are not stored.
  • The medicines and countries you type in the quick test, which are sent to the providers in section 6 to be checked, without your name or your account.
  • Your favourite donation points.
  • Crash reports and, only if you accept it, App usage data.

All data is provided by you voluntarily.

3. Purpose of processing

Personal data is processed for the following purposes:

  • To manage user registration in the App.
  • To facilitate personal monitoring of blood donations.
  • To send reminders or communications related to donation (if applicable).
  • To improve the functioning and user experience of the App.

Under no circumstances will the data be used for medical, diagnostic or clinical research purposes.

4. Legal basis for processing

The legal basis depends on what the data is used for:

  • Your account, what you keep in it and the quick test: your consent, given when you enter that data. The test is optional and the rest of the App works without it.
  • Usage data: your consent, asked for separately, which you can withdraw whenever you like in Settings › Privacy and data.
  • Crash reports and data about installing and updating the App: our legitimate interest in keeping the App working and secure. You can object by writing to the email address in section 1.
  • Disclosing data where the law requires it: legal obligation.

You can withdraw your consent at any time, without this affecting the lawfulness of the previous processing.

5. Data retention

We keep your data for these periods:

  • Your account and everything you keep in it: for as long as you keep it. If you delete it in the App (Profile › Delete account), it is deleted at that moment; if you ask by email, within 30 days at most.
  • The technical record of each quick-test check: unlinked from your account after 30 days.
  • Crash reports (Sentry): deleted after 30 days.
  • Usage data (PostHog): deleted when you delete your account, and otherwise after one year.

You can ask for your data to be deleted at any time.

6. Disclosure of data to third parties

We do not sell your data or pass it to third parties for their own purposes. To work, the App relies on these providers:

  • Supabase: hosts your account and everything you enter in the App.
  • Sentry: receives crash reports, without your IP address and without your account data.
  • PostHog: receives usage data, and only if you have accepted it.
  • Expo: distributes the App and its updates.
  • CIMA, the AEMPS public medicines search, which your device queries during the quick test.
  • Artificial intelligence providers (Anthropic, OpenAI, Google, Groq and Cerebras): they resolve the quick test checks. They receive the medication or the country, never your name, your email or your account.
  • Apple and Google: they verify your identity if you sign in with them.
  • Google Maps: draws the map.

Sentry and PostHog process the data in the European Union; Expo and the artificial intelligence providers, outside the European Economic Area. The legal basis for each use is the one in section 4.

Beyond this list, we will only disclose your data where the law requires it.

7. Data security

The data controller shall take the necessary technical and organisational measures to ensure the security and confidentiality of personal data, preventing its alteration, loss, unauthorised processing or access.

8. User rights

The user may exercise the following rights at any time:

  • Access to their personal data.
  • Rectification of inaccurate data.
  • Erasure of their data.
  • Restriction of processing.
  • Objection to processing.
  • Data portability.

To exercise these rights, the user may contact us via the email address indicated in section 1.

9. Changes to the privacy policy

The controller reserves the right to modify this Privacy Policy to adapt it to new legislation or changes in the App. In the event of significant changes, the user will be informed.

10. Contact

If you have any questions about this Privacy Policy or the processing of your data, you can contact us at:

  • Email: info@doaapp.es

11. Location

If you give permission, the App reads your device's location to centre the map on the donation points near you. That location is used at the time and is not stored, nor sent to our servers or our database. You can refuse the permission or withdraw it in your system settings: the map keeps working and shows the whole of Galicia.

12. Where the donation point data comes from

The donation points in Galicia and the mobile unit schedule shown in the App come from public information published by the Galician Health Service (SERGAS), through its Organ and Blood Donation Agency (ADOS), at ados.sergas.gal. We reuse it under the Xunta de Galicia's reuse conditions.

Doa is not affiliated with SERGAS or the Xunta de Galicia, which do not sponsor or endorse the App.

This website

This site uses no cookies and loads nothing from other domains. Vercel, the provider that hosts it, records IP addresses and the pages requested in order to serve the site and protect it from abuse. We also use Vercel Web Analytics to count visits: it stores nothing on your device and does not identify you, and it records only the page visited, the site you came from, your country, browser, operating system and device type. We do this on the basis of our legitimate interest in knowing how the site is used, and you can object by writing to us.