Privacy Policy

Effective date: 2026-07-09 · Version 1.1

What's new in this version: We are announcing, with 30 days' advance notice as promised in §11 below, that starting 2026-08-08 this site will begin showing advertising served by Google AdSense. This version explains what that means for cookies (§4), third-party processors (§5), and your rights under CCPA/CPRA and the Global Privacy Control signal (§6). Nothing in this update changes how provider data is sourced or presented (§3), and no advertising or cookies of any kind are active before 2026-08-08.

A Critical Distinction: Visitor Information vs. Provider Information

This policy concerns data about you (the visitor). Data about healthcare providers shown on profile pages is sourced from federal public records (NPPES, Open Payments, Medicare Provider Utilization, PECOS) and is governed by Section 3 below — it is not "personal data" that we "collect about you" in the privacy-law sense.

1. Data Controller

Data Controller: Yoel Castaño, Spain (contact: [email protected]).

Because the controller is established in the European Union, this site complies with the EU General Data Protection Regulation (GDPR) for all visitors regardless of location. EU/EEA/UK visitors have the right to access, rectify, erase, restrict, port, and object to processing of their personal data (GDPR Arts. 15–22), and to lodge a complaint with the Spanish AEPD (www.aepd.es) or their local supervisory authority.

2. What We Collect From Visitors

Our web server (nginx, hosted by Hetzner Online GmbH in Germany) automatically records standard access logs for each request:

  • IP address (categorized as personal data under GDPR Art. 4(1) and CCPA §1798.140(v)(1)(A))
  • User-agent (browser/OS string)
  • Referrer URL
  • Timestamp
  • Requested URL and HTTP method
  • HTTP response status and size

These logs are retained for 14 days and used solely for security, abuse detection, and aggregate traffic analysis. Lawful basis: legitimate interest under GDPR Art. 6(1)(f) — operating a secure public website.

We do not require accounts. There is no login, no registration, and no personal information form on this site (other than optional contact email if you write to us).

3. Provider Data Is Federal Public Record

All information displayed on provider profile pages — names, credentials, specialties, business addresses, payments received, and Medicare billing data — is sourced from federal government databases published by the Centers for Medicare & Medicaid Services (CMS): NPPES (Freedom of Information Act-released NPI registry), Open Payments (Sunshine Act §6002, 42 U.S.C. §1320a-7h), Medicare Provider Utilization, and PECOS. We present this information as-is; we do not add, fabricate, or editorialize any provider record.

This information is public record under federal statutory mandate and journalist-shield principles. The publication of this data is a constitutionally protected act of public-interest journalism (Bartnicki v. Vopper, 532 U.S. 514 (2001)).

4. Cookies

No cookies of any kind before 2026-08-08.

Starting 2026-08-08 (this notice is our 30-day advance disclosure, published 2026-07-09), this site will display advertising served by Google AdSense. Google AdSense uses cookies and similar technologies to serve and measure ads, which may include personalized advertising based on your visits to this and other sites.

From 2026-08-08:

  • EEA/UK visitors: you will be shown a consent management platform (CMP) prompt before any advertising cookie is set. Advertising cookies will only be set if you consent; you may withdraw consent at any time. This is our lawful basis for ad-related cookies under GDPR/ePrivacy — consent under GDPR Art. 6(1)(a), not legitimate interest.
  • California and other US-state residents: you have the right to opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising. We honor the Global Privacy Control (GPC) browser signal as a valid opt-out request, and we provide a "Do Not Sell or Share My Personal Information" mechanism (see §6).
  • Everyone else: ads may still be shown, but without the cross-context tracking cookie where you have not consented / have opted out.

If we separately add privacy-respecting analytics (e.g., Plausible, no cookies, no cross-site tracking), this policy will be updated and visibly announced 30 days before deployment, as with this change.

5. Service Providers / Third-Party Processors

The following processors handle visitor data on our behalf:

  • Hetzner Online GmbH (Germany — hosting and server logs). Data processed within the EU.
  • Cloudflare, Inc. (United States — DNS and DDoS protection, if applicable). Cloudflare relies on Standard Contractual Clauses for international transfers.
  • Email — incoming mail to our @doctransparency.com addresses is routed through our email provider.
  • Google LLC (Google AdSense) — United States. Starting 2026-08-08, Google serves advertising on this site and may process visitor data (such as cookie identifiers and browsing activity) for ad delivery and measurement, subject to the consent and opt-out mechanisms described in §4 and §6. Google acts as an independent controller for its advertising data processing; see Google's Privacy & Terms for how Google uses this data. Google relies on Standard Contractual Clauses / the EU-US Data Privacy Framework for international transfers, per Google's own disclosures.

We do not sell visitor data. Before 2026-08-08 we do not share visitor data with any other third party. From 2026-08-08, the only sharing is the AdSense processing described above, subject to your consent (EEA/UK) or opt-out (US, via GPC or the mechanism in §6).

6. California Residents (CCPA / CPRA) and Other US State Privacy Laws

In the past 12 months we have collected the following categories of personal information from visitors: identifiers (IP address) and internet activity (pages viewed, referrer, user-agent).

Through 2026-08-07: we do not sell or share personal information for cross-context behavioral advertising, and we have not done so historically.

Starting 2026-08-08: once Google AdSense begins serving ads on this site, personalized/behavioral advertising may constitute a "share" of personal information for cross-context behavioral advertising under CCPA/CPRA (Cal. Civ. Code §1798.140) and comparable state laws (e.g., Colorado, Connecticut, Virginia). Accordingly, from that date:

  • You have the right to opt out of the sale or sharing of your personal information. We will provide a "Do Not Sell or Share My Personal Information" link/mechanism site-wide.
  • We will honor the Global Privacy Control (GPC) signal sent by your browser as a valid, legally-binding opt-out request, applied automatically without requiring a separate account or login.
  • Opting out (via GPC or the site mechanism) disables ad personalization tied to your visits across sites; you may still see non-personalized advertising.

California residents may request access, deletion, correction, or opt-out of personal information by emailing [email protected], or by using the Global Privacy Control signal from 2026-08-08 onward. We respond within 45 days.

7. EU/EEA/UK Visitors (GDPR)

In addition to the rights listed in §1, you have the right to data portability and the right not to be subject to automated decision-making. To exercise any right, email [email protected]. We respond within 30 days.

8. Children

This site is not directed to children under 13. We do not knowingly collect personal information from children. Parents who believe their child has interacted with the site may contact [email protected] for removal.

9. Provider Takedown / Correction Requests

Providers who believe their NPPES, Open Payments, or Medicare record displayed on this site is incorrect, or who request review for removal, may email [email protected] with their NPI. While we cannot alter the underlying federal records, we will:

(a) display a correction notice within 7 business days where the inaccuracy is verifiable; (b) suppress a profile pending CMS correction in cases of verified identity theft or imminent safety concerns; (c) document our source dataset and retrieval date upon request.

10. Data Breach Notification

In the event of a personal data breach affecting visitor data, we will notify the AEPD within 72 hours per GDPR Art. 33, and affected users without undue delay where required under GDPR Art. 34 and applicable US state breach laws.

11. Changes to This Policy

We will revise the "Effective date" above and post material changes prominently for 30 days. Previous versions may be requested at [email protected].

Version history:

  • v1.1 (2026-07-09, effective 2026-08-08 for the advertising provisions): Added Google AdSense as a processor (§5); updated Cookies (§4) and California/US state rights (§6) to reflect advertising, consent management, and Global Privacy Control opt-out, announced 30 days ahead of the 2026-08-08 effective date.
  • v1.0 (2026-04-17): Initial policy.

12. Contact

For all privacy questions, requests, or complaints: [email protected] (45-day SLA for CCPA requests; 30-day SLA for GDPR requests).

Data Disclaimer — Data sourced from the Centers for Medicare & Medicaid Services (CMS): National Plan and Provider Enumeration System (NPPES), Open Payments program, Medicare Provider Utilization and Payment Data, and Provider Enrollment & Certification data (PECOS). Published under the Freedom of Information Act (FOIA). This website is not affiliated with, endorsed by, or authorized by CMS, HHS, or the U.S. Government. Data may contain errors as reported to CMS by providers and reporting entities. Payments from industry are legal and do not indicate wrongdoing. Medicare data reflects only patients aged 65+ or those with qualifying disabilities. For corrections, contact CMS directly. This information does not constitute medical advice and should not be used as the sole basis for choosing a healthcare provider. Procedure descriptions use plain language and do not reference CPT® codes, which are copyrighted by the American Medical Association. Full methodology → · Report a data error → · Privacy policy →