This legal document is only available in Spanish. The Spanish version is the only one with legal validity under Spanish law.
1. Data Controller
The controller responsible for the processing of your personal data is 6Profiles Consulting, S.L., a limited liability company incorporated under the laws of the Kingdom of Spain, operating commercially under the Booka brand.
- Company name: 6Profiles Consulting, S.L.
- CIF: B09885815
- Jurisdiction of incorporation: Spain
- Registered office: Calle de Silvia Munt 6, Madrid, Spain
- Operating offices: Madrid (Spain), Bogotá (Colombia), Riyadh (Saudi Arabia)
- Privacy email: privacy@usebooka.com
- Legal email: legal@usebooka.com
- Website: usebooka.com
6Profiles Consulting, S.L. is subject to the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Organic Law 3/2018 on the Protection of Personal Data and guarantee of digital rights (LOPDGDD) of Spain, Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE), and Regulation (EU) 2024/1689 (EU AI Act). We also comply with the applicable data protection regulations in the other jurisdictions in which we operate, including, without limitation: UK GDPR (United Kingdom), CCPA/CPRA (California), Law 1581/2012 (Colombia), LFPDPPP (Mexico), LGPD (Brazil), PDPL (Saudi Arabia, Royal Decree M/19/2021), Federal Decree-Law 45/2021 (United Arab Emirates) and Law 13/2016 (Qatar).
2. Data Protection Officer
As of the date of this policy, 6Profiles Consulting, S.L. is not required to designate a Data Protection Officer (DPO) under Article 37 of the GDPR, as it does not carry out systematic, large-scale monitoring of data subjects nor process special categories of data as a core activity. Nevertheless, all data protection queries may be directed to privacy@usebooka.com. We undertake to respond within a maximum of 30 calendar days. Should it become necessary to designate a DPO in the future, this policy will be updated with their contact details.
3. Categories of Personal Data We Collect
We collect and process the following categories of personal data depending on the service you use:
3.1. Personal identification data
- Full name, date of birth, nationality and country of residence
- Email address and phone number
- Profile photo and copy of identity document (passport, national ID or equivalent)
- Postal address (where necessary for sending documentation)
3.2. Professional and academic data
- University degrees, academic certificates, transcripts and diplomas (including digitized documents)
- Professional licenses and registrations (registration with professional bodies, registration number, specialization)
- Professional specialties and supplementary certifications in any regulated profession: medicine, nursing, engineering (all branches), architecture, teaching, psychology, veterinary medicine, law, pharmacy, accounting and others
- Work experience, employment history and professional references
- Curriculum vitae (original and AI-generated)
- Language information and language certifications
- Good Standing letters and professional records
3.3. Financial and payment data
- Payment information processed by Stripe (tokenized; Booka does not store full card data)
- Transaction history and invoices
- Billing data (name, tax address, NIF/CIF where applicable)
3.4. B2B user data
- Identity of the contracting officer (name, position, professional contact details)
- Identity of the client organization's authorized users
- Institution information (name, address, sector, estimated usage volume)
- API keys, technical configurations and integration data
3.5. Technical and usage data
- IP address, browser type, operating system and device
- Web and app browsing data: pages visited, time spent, click flow
- Approximate geolocation data (country/city level, derived from IP)
- Cookie identifiers and tracking technologies (see our Cookie Policy)
- Anonymized session recordings (Microsoft Clarity) and analytics events (PostHog)
- In the mobile app: device identifiers, push notification tokens, app usage data
4. Purposes of Processing
4.1. Provision of contracted B2C services
- Credential Analysis: Receipt of your academic and professional documents, analysis using artificial intelligence (Claude, by Anthropic) and generation of a personalized report with the available homologation, equivalence or recognition options by country and profession.
- Credential Validation Management: Collection of documentation, preparation of files, communication with regulatory bodies (Ministry of Universities, ANECA, SCFHS, SCE, SOCPA, DHA, DOH, GMC, NMC, QCHP and others) and follow-up of the process on behalf of the User.
- International CV Pro: Extraction of data from your CV using AI, generation of optimized versions adapted to the standards of the destination country and sector.
- Mobile app: Account management, push notifications, file status updates, messaging with the team.
- Comparators and simulators: Providing comparative information on requirements, timelines and conditions between countries and professions.
4.2. Provision of B2B services
- Self-serve: Access to the control panel and the AI agents so the client organization can manage its credentialing files.
- Managed: End-to-end management of each file by a dedicated Case Manager.
- API & Embedded: Provision of services through technical integration with third-party systems (HRIS, ATS, university platforms, admissions software, staffing systems).
4.3. Communications
- Sending transactional emails related to the contracted services (confirmations, status updates, invoices, file progress alerts).
- Push notifications in the mobile app.
- Sending commercial and promotional communications, only with your prior consent (you may withdraw your consent at any time).
- Customer support via email, WhatsApp and web forms.
4.4. Service analysis and improvement
- Analysis of platform usage via PostHog and Microsoft Clarity to improve the user experience.
- A/B testing to optimize the interface and conversion flows.
- Automated lead scoring to prioritize commercial attention.
4.5. Legal compliance and security
- Compliance with tax, accounting and legal obligations.
- Prevention of document fraud, detection of falsified credentials and protection of platform security.
- Handling of complaints and exercise of rights by Users.
5. Legal Basis for Processing (Art. 6 GDPR)
| Purpose | Legal basis |
|---|
| Provision of contracted B2C services (analysis, management, CV Pro) | Performance of a contract (Art. 6.1.b) |
| B2B services contracted by institutions | Performance of a contract (Art. 6.1.b) |
| Commercial communications and marketing | Consent (Art. 6.1.a) |
| Usage analysis, A/B testing, lead scoring | Legitimate interest (Art. 6.1.f) — service improvement and commercial efficiency |
| Tax, accounting and legal compliance | Legal obligation (Art. 6.1.c) |
| Sharing profile with employing institutions or universities | Explicit consent (Art. 6.1.a) |
| Fraud prevention and platform security | Legitimate interest (Art. 6.1.f) |
| AI processing (Verifier, Regulator, Trust agents) | Performance of a contract (Art. 6.1.b) + informed consent (Art. 6.1.a) |
Where processing is based on your consent, you have the right to withdraw it at any time without affecting the lawfulness of processing based on consent before its withdrawal. You can withdraw your consent by contacting us at privacy@usebooka.com.
6. Use of Artificial Intelligence and Automated Decisions
Booka is a platform with agentic AI at the core of the product. It is essential that the User understands how and when AI is used in the processing of their data.
6.1. Booka's three Agents
- Verifier Agent: verifies credentials against the primary source, connecting directly with universities, professional bodies and government databases to confirm the authenticity and validity of the document.
- Regulator Agent: knows the protocols, formats and requirements of each regulatory body in the destination country (SCFHS in Saudi Arabia, GMC and NMC in the United Kingdom, DHA and HAAD in the Emirates, Ministry of Universities and ANECA in Spain, Saudi Council of Engineers, MEFP, MOHESR and others) and adapts the file to the required standard.
- Trust Agent: monitors visa deadlines, prepares consular documentation and manages renewals when the User contracts this additional service.
6.2. Underlying technology
All agents are built on Claude, a language model developed by Anthropic, Inc. (San Francisco, USA), with proprietary orchestration technologies developed by 6Profiles Consulting, S.L. Your documents are processed via the Anthropic API and are not used to train the AI models.
6.3. Credential Analysis
The documents you upload (degrees, certificates, transcripts) are analyzed by the Verifier Agent to extract relevant information (issuing institution, profession, specialty, date of issue) and cross-reference it with our database of regulatory requirements for each country and profession. The resulting report is delivered as guidance output and not as a professional opinion.
6.4. International CV Pro
The CV Pro service uses AI to (a) extract the information from your original CV, (b) restructure and optimize the content according to the standards of the destination country and sector, and (c) generate a professional version of the document. Your CV data is processed exclusively for the provision of this service.
6.5. Automated lead scoring
We use an automated scoring system (lead scoring) that evaluates the level of interest and the likelihood of conversion of Users based on their interactions with the platform. This score is used solely to prioritize commercial attention and produces no legal effects on the User nor significantly affects them in a similar way.
6.6. Safeguards under Art. 22 GDPR and the EU AI Act
In accordance with Article 22 of the GDPR and Regulation (EU) 2024/1689 (EU AI Act):
- No fully automated decision-making process produces significant legal effects on you. The final decision on the homologation, equivalence or recognition of credentials always rests with the competent regulatory body.
- The outputs generated by Booka's Agents are reviewed by our human team (in Managed and B2B plans) or are subject to subsequent confirmation by the regulatory body.
- You have the right to request human intervention, express your point of view and contest any result generated by the AI.
- Where Booka acts as a provider of an AI system used by a public body (high-risk use under Annex III of the EU AI Act), we comply with all applicable requirements: risk management, data quality, technical documentation, human oversight, technical robustness, cybersecurity and registration in the EU database.
7. Data Retention Periods
| Data category | Retention period | Justification |
|---|
| Account and profile data | Duration of the relationship + 5 years after deletion request | Limitation period for legal actions |
| Financial data and invoices | 6 years from the last transaction | Tax and accounting obligation (Art. 30 Spanish Commercial Code) |
| Credential validation files | Duration of the process + 5 years after completion | Possible claims and subsequent verifications |
| AI-generated CVs | 1 year from generation | Reasonable period of document use |
| Analytics data and analytical cookies | 2 years | Trend analysis and service improvement |
| Commercial communications (consent) | Until consent is withdrawn | Legal basis: consent |
| Security records and logs | 1 year | Incident detection and regulatory compliance |
| B2B contracts and institutional data | Duration of the contract + 6 years | Contractual and tax obligation |
| Internal denial list (document fraud) | 10 years | Legitimate interest in fraud prevention |
Once the indicated periods have elapsed, your data will be deleted or irreversibly anonymized, unless a legal obligation requires their retention for an additional period.
8. International Data Transfers
| Recipient | Country | Purpose | Safeguard |
|---|
| Anthropic, Inc. | USA | AI analysis of documents and agents (Verifier, Regulator, Trust) | SCC + DPF |
| Stripe, Inc. / Stripe Payments Europe Ltd. | USA / Ireland | Payment processing | DPF + SCC |
| Vercel, Inc. | USA | Web hosting and content delivery | DPF + SCC |
| Neon, Inc. | EU (Germany) | Main database | Within the EEA — no additional safeguards required |
| Twilio/SendGrid | USA | Sending transactional emails | DPF + SCC |
| PostHog, Inc. | USA / EU | Web and app analytics | SCC |
| Microsoft (Clarity) | USA / EU | Behavioral analysis (session recordings) | DPF + SCC |
| Google Cloud | USA / EU | Auxiliary cloud services and Speech-to-Text | DPF + SCC |
| HubSpot, Inc. | USA / EU | CRM and lead management | DPF + SCC |
| GoHighLevel / Centralize | USA | Auxiliary CRM | SCC |
| DataFlow Group | UAE / Multi-jurisdiction | Primary source verification (PSV) of healthcare and engineering credentials | Partnership agreement + SCC |
Additionally, within the framework of the validation services, your documents may be shared with regulatory bodies in the destination countries (Ministry of Universities in Spain, ANECA, SCFHS in Saudi Arabia, GMC in the United Kingdom, DHA in the United Arab Emirates, Saudi Council of Engineers, SOCPA, QCHP in Qatar, DREETS in France, among others). These transfers are made only when you have contracted the corresponding service and are necessary for the performance of the contract.
9. Sharing Data with Third Parties
We do not sell your personal data. We share your data only in the following circumstances:
- Regulatory bodies: On your behalf and as part of the contracted validation service (ministries, professional bodies, health councils, engineering councils, education authorities).
- Employing institutions and universities: Exclusively with your prior explicit consent, within the framework of the contracted services.
- Payment processors: Stripe processes your payments securely under PCI-DSS Level 1 standards.
- Technology service providers: The providers listed in section 8 act as data processors under contracts that guarantee the protection of your data.
- DataFlow Group: Verifying partner for healthcare and engineering credentials in the Gulf, where applicable.
- Bookahospi (8Hospi Inc.): If you contract complementary healthcare services (placement, visa, shifts) that require management by Bookahospi, a specific transfer applies with your explicit consent.
- Legal obligation: When required by law, court order or competent administrative authority.
- Protection of rights: To protect our legitimate rights, including fraud prevention.
10. Your Rights as a Data Subject
In accordance with the GDPR and applicable law, you have the following rights:
- Right of access (Art. 15 GDPR): Obtain confirmation of whether we process your data and access a copy of it.
- Right of rectification (Art. 16 GDPR): Request the correction of inaccurate or incomplete data.
- Right of erasure (Art. 17 GDPR): Request the deletion of your data when it is no longer necessary, you withdraw your consent or you object to the processing (“right to be forgotten”).
- Right to portability (Art. 20 GDPR): Receive your data in a structured, commonly used and machine-readable format, and transmit it to another controller.
- Right to restriction (Art. 18 GDPR): Request that the processing of your data be restricted in certain circumstances.
- Right to object (Art. 21 GDPR): Object to the processing of your data based on legitimate interest or for direct marketing purposes.
- Right to withdraw consent: Withdraw your consent at any time, without affecting the lawfulness of prior processing.
- Right not to be subject to automated decisions (Art. 22 GDPR): Not be subject to decisions based solely on automated processing that produce legal effects on you.
- Right to lodge a complaint: Lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es) or with the data protection authority of your country of residence (ICO in the UK, INAI in Mexico, SIC in Colombia, ANPD in Brazil, SDAIA in Saudi Arabia, among others).
To exercise any of these rights, send an email to privacy@usebooka.com indicating the right you wish to exercise and enclosing a copy of your identity document. We will respond within a maximum of 30 calendar days, extendable by a further two months in cases of particular complexity, with prior notice.
10.1. Deleting your account and associated data
If you want to delete your account and associated data from Booka, please follow these steps:
- Open the Booka app.
- Go to Profile → Personal Information → Delete account.
- Select Delete Account, or contact us at privacy@usebooka.com.
- Include the email address or phone number linked to your account.
After receiving your request, we will delete your account and associated personal data, including your profile information and app-related account data.
Some data may be retained where required for legal, security, fraud prevention, billing, or compliance purposes. Any retained data will be kept only for the required retention period and then deleted.
For account deletion requests, contact: privacy@usebooka.com and sebastian@bookahospi.com.
11. Minors' Data
Booka's services are intended exclusively for professionals over 18 years of age. We do not deliberately collect personal data from minors. If we become aware that we have collected data from a minor without appropriate parental consent, we will proceed to delete such data without delay. If you believe we have collected data from a minor, please notify us at privacy@usebooka.com.
12. Security Measures
We implement appropriate technical and organizational measures to protect your personal data:
- Encryption in transit: All communications are carried out via TLS 1.2+ (HTTPS).
- Encryption at rest: Data stored in our database is encrypted (Neon PostgreSQL with AES-256 encryption).
- Access control: Role-based access with the principle of least privilege. Multi-factor authentication for the internal team and mandatory for B2B accounts.
- Certified providers: Our main providers (Stripe, Vercel, Neon, Anthropic, Google Cloud) maintain SOC 2 Type II and/or ISO 27001 certifications.
- Secure payments: Stripe maintains PCI-DSS Level 1 certification. Booka never stores full payment card data.
- Data sovereignty: European data in European infrastructure (Neon AWS Frankfurt). Saudi data in PDPL-compliant infrastructure where applicable.
- Booka: ISO 27001 and SOC 2 Type II in the certification process, with expected completion in Q3 2026.
- Monitoring: Continuous monitoring of infrastructure and access logs.
- Mobile app: Authentication tokens stored in Keychain (iOS) and Keystore (Android), never in insecure storage.
- Training: Staff with access to personal data receive regular data protection training.
13. Cookies and Tracking Technologies
We use cookies and similar technologies for the operation of our platform, usage analysis and personalization. For detailed information about the cookies we use, their purposes, duration and how to manage them, please consult our Cookie Policy.
14. Data Breach Notification
In the event of a security breach affecting your personal data, we will comply with the notification obligations set out in Articles 33 and 34 of the GDPR:
- We will notify the competent supervisory authority (AEPD) within a maximum of 72 hours from becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
- Where the breach entails a high risk to your rights and freedoms, we will communicate the breach to you without undue delay, indicating the nature of the breach, the possible consequences and the measures taken.
15. Changes to this Policy
We reserve the right to update this Privacy Policy to adapt it to legislative, jurisprudential or data processing practice developments. In the event of substantial changes:
- We will publish the updated version on this same page with the new date of last update.
- We will notify you by email (if we have your address) at least 30 days in advance of the changes taking effect.
- If the changes affect processing based on your consent, we will request new consent where necessary.
16. Contact
For any query relating to this Privacy Policy or to the processing of your personal data:
- Controller: 6Profiles Consulting, S.L. (Booka)
- CIF: B09885815
- Registered office: Calle de Silvia Munt 6, Madrid, Spain
- Email: privacy@usebooka.com
- Website: usebooka.com
Booka Privacy Policy · 6Profiles Consulting, S.L. · June 9, 2026