Terms of Service & Privacy Policy
Your trust, privacy, and data security are our top priorities
Terms of Service
Legal Information
Website Owner and Data Controller:
- Owner: Asociación CRC Warriors — Apoyo Integral a Pacientes de Cáncer Colorrectal
- Tax ID (CIF): [PENDING]
- Registry: [PENDING — Registration in progress]
- Registered address: [PENDING]
- Contact: contacto@crcwarriors.com
CRC Warriors is a non-profit association established under Spanish Organic Law 1/2002 on the Right of Association. This website does not constitute a commercial activity and does not offer paid services. Its purpose is to provide comprehensive support to colorectal cancer patients and their families.
1. Acceptance of Terms
By accessing, browsing, or using CRC Warriors ("the Platform," "Service," "we," "us," or "our"), you acknowledge that you have read, understood, and agree to be bound by these Terms of Service ("Terms"), our Privacy Policy, and any additional terms and conditions that may apply to specific sections or features of the Platform.
If you do not agree to these Terms, you must not access or use the Platform. Your continued use of the Platform following the posting of any changes to these Terms constitutes acceptance of those changes.
2. Description of Service
CRC Warriors is an AI-powered informational platform designed to support colorectal cancer patients, caregivers, healthcare providers, and researchers. Our services include:
- Clinical Trial Matching: AI-assisted matching of patient profiles with relevant clinical trials based on genetic mutations, treatment history, and eligibility criteria
- Treatment Information: Educational resources about medications, therapies, and treatment options
- Genetic Profile Management: Tools to store and manage genetic mutation data for personalized recommendations
- Community Support: Forums and discussion areas for patients and caregivers to share experiences
- Researcher Tools: Features enabling clinical researchers to connect with potentially eligible patients
- AI-Powered Insights: Personalized treatment recommendations and scientific news summaries
- Doctor-Patient Communication: Tools for healthcare providers to recommend trials to their patients
Critical Medical Disclaimer
CRC Warriors is NOT a medical service and does NOT provide medical advice, diagnosis, or treatment. The information provided on this Platform is for educational and informational purposes only. It is not intended to be a substitute for professional medical advice, diagnosis, or treatment.
ALWAYS seek the advice of your physician, oncologist, or other qualified healthcare provider with any questions you may have regarding your medical condition, treatment options, or clinical trial eligibility. NEVER disregard professional medical advice or delay seeking it because of something you have read on this Platform.
3. Eligibility and Registration
To use our Platform, you must:
- Be at least 18 years of age (or the age of majority in your jurisdiction)
- Have the legal capacity to enter into a binding agreement
- Provide accurate, current, and complete registration information
- Not be prohibited from using the Platform under applicable laws
By registering an account, you agree to:
- Maintain the confidentiality of your password and account credentials
- Immediately notify us of any unauthorized access or security breach
- Accept full responsibility for all activities conducted under your account
- Not share your account credentials with any third party
- Keep your profile information accurate and up-to-date
4. User Types and Roles
Our Platform supports different user types with specific responsibilities:
| User Type | Description | Responsibilities |
|---|---|---|
| Patients | Individuals diagnosed with colorectal cancer | Provide accurate medical information; consult healthcare providers before making decisions |
| Caregivers | Family members or supporters of patients | Respect patient privacy; obtain consent before sharing information |
| Healthcare Providers | Licensed physicians and medical professionals | Verify credentials; maintain professional standards; obtain patient consent |
| Researchers | Clinical trial investigators and research staff | Comply with ethical protocols; respect patient privacy; follow contact request procedures |
5. AI-Generated Content and Recommendations
Our Platform uses artificial intelligence and machine learning algorithms to provide personalized recommendations and insights. You acknowledge and understand that:
- AI-generated content is based on algorithms and available data, not human medical judgment
- AI recommendations should never replace consultation with qualified healthcare providers
- Match scores and compatibility assessments are estimates and may not reflect actual eligibility
- AI systems may produce errors, inaccuracies, or outdated information
- The quality of recommendations depends on the accuracy of information you provide
AI Limitations
Our AI systems are designed to assist, not replace, human decision-making. Clinical trial eligibility is ultimately determined by the trial's medical team. Always verify AI-generated information with your healthcare provider before making any medical decisions.
6. Clinical Trial Information
Clinical trial information displayed on our Platform is sourced from publicly available databases including ClinicalTrials.gov and other registries. We strive to maintain accurate and current information, however:
- Trial information may become outdated as trials progress or close
- Eligibility criteria may change without immediate reflection on our Platform
- Contact information and locations may not be current
- We do not control or guarantee the accuracy of third-party trial data
- Listing on our Platform does not constitute endorsement of any trial
7. Researcher Contact Requests
Clinical researchers may request to contact patients who have opted into our researcher visibility program. By enabling researcher visibility:
- Your anonymized medical profile may be visible to verified researchers
- Researchers may send contact requests through our platform
- You control which information is shared (country, age, mutations, treatments)
- Your personal contact information is never shared without explicit acceptance
- You may accept, decline, or ignore any contact request
- Accepting a request only shares your email address with the requesting researcher
8. Community Guidelines
Our community forums are designed to provide peer support. When participating, you agree to:
- Treat all members with respect and compassion
- Share experiences without providing medical advice
- Respect the privacy and anonymity of other members
- Not share false, misleading, or harmful medical information
- Not promote products, services, or unproven treatments
- Not harass, bully, or discriminate against other members
- Report inappropriate content to moderators
9. Prohibited Conduct
You agree NOT to:
- Use the Platform for any unlawful purpose or in violation of these Terms
- Impersonate any person, patient, or healthcare provider
- Provide false credentials or misrepresent your qualifications
- Upload, transmit, or distribute malicious code, viruses, or harmful content
- Attempt to gain unauthorized access to any portion of the Platform
- Harvest, scrape, or collect user data without authorization
- Interfere with or disrupt the Platform's operation or security
- Use automated systems (bots, scrapers) without written permission
- Sell, transfer, or sublicense your account or any Platform content
- Use the Platform to promote commercial products or services without authorization
10. Intellectual Property Rights
All content on CRC Warriors, including but not limited to text, graphics, logos, icons, images, audio clips, digital downloads, data compilations, and software, is the property of CRC Warriors or its content suppliers and is protected by international copyright, trademark, and other intellectual property laws.
You may:
- View and print content for personal, non-commercial use
- Share links to our content
You may NOT:
- Reproduce, distribute, or modify our content without permission
- Use our trademarks or branding without authorization
- Remove copyright or proprietary notices
11. User-Generated Content
By submitting content to our Platform (forum posts, comments, experiences, etc.), you:
- Grant us a non-exclusive, worldwide, royalty-free license to use, display, and distribute your content
- Represent that you own or have rights to the content you submit
- Agree that your content does not violate any third-party rights
- Understand that we may remove content that violates our policies
12. Disclaimer of Warranties
THE PLATFORM IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED. TO THE FULLEST EXTENT PERMITTED BY LAW, WE DISCLAIM ALL WARRANTIES, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
We do not warrant that:
- The Platform will meet your specific requirements
- The Platform will be uninterrupted, timely, secure, or error-free
- Information obtained through the Platform will be accurate or reliable
- Any errors in the Platform will be corrected
13. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, CRC WARRIORS AND ITS OWNER SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING:
- Loss of profits, data, or goodwill
- Service interruption or system failure
- Personal injury or property damage
- Any damages arising from medical decisions made based on Platform information
- Unauthorized access to or alteration of your data
This Platform is provided free of charge as an informational resource. Given the non-commercial nature of this project, liability is limited to the maximum extent permitted by Spanish and EU law.
14. Indemnification
You agree to indemnify, defend, and hold harmless CRC Warriors and its owner from any claims, damages, losses, liabilities, costs, and expenses (including reasonable legal fees) arising from:
- Your use of the Platform
- Your violation of these Terms
- Your violation of any third-party rights
- Any content you submit or share on the Platform
15. Termination
We reserve the right to suspend or terminate your account and access to the Platform at any time, with or without cause, and with or without notice. Grounds for termination include:
- Violation of these Terms or any applicable policies
- Suspected fraudulent, abusive, or illegal activity
- Request by law enforcement or government agencies
- Extended periods of inactivity
You may terminate your account at any time through your account settings or by contacting us. Upon termination, you may request deletion of your personal data in accordance with applicable law.
16. Modifications to Terms
We reserve the right to modify these Terms at any time. Material changes will be communicated via:
- Email notification to registered users
- Prominent notice on the Platform
- Update to the "Last Updated" date at the top of this document
Continued use of the Platform after changes are posted constitutes acceptance of the modified Terms.
17. Governing Law and Jurisdiction
These Terms shall be governed by and construed in accordance with the laws of Spain and applicable European Union regulations, including but not limited to:
- General Data Protection Regulation (GDPR - Regulation EU 2016/679)
- Spanish Organic Law 3/2018 on Personal Data Protection (LOPDGDD)
- Law 34/2002 on Information Society Services (LSSI-CE)
Any legal action or proceeding arising out of these Terms shall be subject to the exclusive jurisdiction of the courts of Orihuela, Spain.
18. Dispute Resolution
Any dispute arising from these Terms or your use of the Platform shall first be attempted to be resolved through good-faith negotiation. If negotiation fails within 30 days:
- For EU consumers: You may use the European Commission's Online Dispute Resolution platform at https://ec.europa.eu/consumers/odr
- Disputes shall be resolved in the courts of Murcia, Spain
19. Severability
If any provision of these Terms is found to be unenforceable or invalid under applicable law, that provision shall be limited or eliminated to the minimum extent necessary, and the remaining provisions shall remain in full force and effect.
20. Entire Agreement
These Terms, together with our Privacy Policy and Cookie Policy, constitute the entire agreement between you and CRC Warriors regarding the use of the Platform, superseding any prior agreements or understandings.
Contact Information
If you have questions about these Terms of Service:
- Owner: Asociación CRC Warriors — CIF: [PENDING]
- Email: contacto@crcwarriors.com
- Location: Spain, European Union
We aim to respond to all inquiries within 30 days.
Privacy Policy
Data Controller Information
In accordance with the General Data Protection Regulation (GDPR) and Spanish LOPDGDD:
- Data Controller: Asociación CRC Warriors
- Location: Spain, European Union
- Contact Email: privacidad@crcwarriors.com
CRC Warriors ("we," "us," or "our") is committed to protecting your privacy and ensuring the security of your personal and health information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Platform, in compliance with the General Data Protection Regulation (GDPR) and Spanish data protection law (LOPDGDD).
Our Privacy Commitment
We treat your health information with the highest level of care and security. We implement industry-standard security measures and never sell your personal data to third parties.
1. Information We Collect
1.1 Information You Provide Directly:
- Account Information: Name, email address, password, country, and user type (patient, caregiver, doctor, researcher)
- Medical Profile: Cancer diagnosis, stage, genetic mutations, MSI/MMR status, ECOG performance status, metastasis locations
- Treatment History: Previous and current treatments, medications, clinical trial participation, response to treatments
- Genetic Information: Gene mutations (KRAS, BRAF, HER2, TP53, etc.), specific alterations, testing dates and methods
- Demographics: Date of birth, gender, location (city, country)
- Communications: Forum posts, messages, contact requests, support inquiries
- Documents: Medical reports, test results, and other uploaded files
1.2 Information Collected Automatically:
- Device Information: IP address, browser type and version, operating system, device identifiers
- Usage Data: Pages visited, features used, search queries, time spent on pages, click patterns
- Log Data: Access times, error logs, referring URLs
- Cookies and Tracking: Session cookies, preference cookies, analytics cookies (see Cookie Policy)
Special Category Data (Health Data)
Medical and genetic information is classified as "special category data" under GDPR Article 9. We process this data only with your explicit consent and implement enhanced security measures to protect it.
2. Legal Basis for Processing (GDPR Article 6 & 9)
| Purpose | Legal Basis |
|---|---|
| Account creation and management | Contract performance (Art. 6.1.b) |
| Clinical trial matching | Explicit consent (Art. 9.2.a) |
| Processing health data | Explicit consent (Art. 9.2.a) |
| Researcher contact requests | Explicit consent (Art. 6.1.a) |
| Platform security | Legitimate interest (Art. 6.1.f) |
| Analytics and improvement | Consent (Art. 6.1.a) |
| Legal compliance | Legal obligation (Art. 6.1.c) |
3. How We Use Your Information
- Provide Services: Match you with clinical trials, generate personalized recommendations
- Communication: Send notifications, alerts about new trials, respond to inquiries
- Improve Platform: Analyze usage patterns to enhance features and user experience
- Research Connections: Enable researchers to find eligible patients (with your explicit consent)
- Security: Protect against fraud, abuse, and unauthorized access
- Legal Compliance: Comply with applicable laws and regulations
4. Data Sharing and Disclosure
We may share your information with:
- Researchers: Only with your explicit consent and only the data you choose to share
- Healthcare Providers: If you accept a doctor's invitation to connect
- Service Providers: Hosting, email, and technical services (with data processing agreements)
- Anti-Fraud Security Providers: Bot-verification services that process your IP address and technical browser data solely to prevent automated abuse (see 4.1)
- Legal Authorities: When required by law or to protect rights and safety
We NEVER:
- Sell your personal data to third parties
- Share your data for marketing purposes without consent
- Disclose your identity to researchers without your explicit acceptance
4.1 Data Processors
In compliance with Article 28 of the GDPR, below we list the main data processors with whom we have signed the corresponding processor agreement and, where applicable, Standard Contractual Clauses (SCCs) approved by the European Commission for transfers outside the EEA:
| Processor | Purpose | Data processed | Location / Policy |
|---|---|---|---|
| Cloudflare, Inc. (Turnstile) |
Anti-bot verification on registration and login forms to prevent automated abuse | IP address, user-agent, technical browser data (non-persistent telemetry fingerprint) | USA — transfer covered by SCCs Privacy policy |
| Google LLC (reCAPTCHA on contact) |
Anti-bot verification on the contact form | IP address, user interactions, technical cookies | USA — transfer covered by SCCs Privacy policy |
| Google LLC (Analytics) |
Aggregated usage statistics | Anonymized IP address, session identifiers, browsing data | USA — transfer covered by SCCs Privacy policy |
| Stripe Payments Europe, Ltd. | Donation and membership-fee processing | Payment data (tokenized), email, name, amount | Ireland (EU) Privacy policy |
About Cloudflare Turnstile specifically: unlike other CAPTCHA systems, Turnstile is designed not to track the user. It does not install persistent cookies nor build a cross-site visitor profile. The token issued is single-use and discarded after verification. Cloudflare acts exclusively as a data processor, without using the data for its own purposes.
5. International Data Transfers
Our servers are located in the European Union. If any data transfer outside the EU/EEA is necessary (e.g., for certain technical services), we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Data processing agreements with all service providers
6. Your Rights Under GDPR
Under the General Data Protection Regulation and Spanish LOPDGDD, you have the following rights:
| Right | Description |
|---|---|
| Access | Request a copy of all personal data we hold about you |
| Rectification | Correct inaccurate or incomplete personal data |
| Erasure ("Right to be Forgotten") | Request deletion of your personal data |
| Restriction | Limit how we process your data in certain circumstances |
| Data Portability | Receive your data in a structured, machine-readable format |
| Objection | Object to processing based on legitimate interest |
| Withdraw Consent | Withdraw consent at any time (without affecting prior processing) |
To exercise any of these rights, contact us at privacidad@crcwarriors.com. We will respond within 30 days as required by GDPR.
7. Data Retention
- Active accounts: Data retained while your account is active
- Inactive accounts: Data may be deleted after 3 years of inactivity (with prior notice)
- Deleted accounts: Data deleted within 30 days, except where legal retention is required
- Anonymized analytics: May be retained indefinitely as it no longer identifies you
- Legal requirements: Some data may be retained longer if required by law
8. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption: SSL/TLS for data in transit, encryption at rest for sensitive data
- Access Controls: Role-based access, strong authentication requirements
- Monitoring: Security logging and intrusion detection
- Backups: Regular encrypted backups with secure storage
- Passwords: Secure hashing (bcrypt) for all passwords
9. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the Spanish Data Protection Agency (AEPD) within 72 hours
- Inform affected users without undue delay if there is high risk
- Document all breaches and remediation actions taken
10. Children's Privacy
Our Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that we have collected personal information from a child under 18, we will take immediate steps to delete that information.
11. Third-Party Links
Our Platform may contain links to third-party websites, including ClinicalTrials.gov, research institutions, and pharmaceutical companies. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
12. Right to Lodge a Complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the supervisory authority:
Spanish Data Protection Agency (AEPD)
- Website: www.aepd.es
- Address: C/ Jorge Juan, 6, 28001 Madrid, Spain
- Phone: +34 901 100 099
13. Changes to Privacy Policy
We may update this Privacy Policy periodically. Material changes will be notified via email and/or prominent notice on the Platform at least 30 days before taking effect. Your continued use after changes indicates acceptance.
Privacy Contact Information
For questions, concerns, or requests regarding your privacy or this policy:
- Data Controller: Asociación CRC Warriors
- Privacy Email: privacidad@crcwarriors.com
- General Contact: contacto@crcwarriors.com
We aim to respond to all privacy inquiries within 30 days as required by GDPR.
Cookie Policy
This Cookie Policy explains how CRC Warriors uses cookies and similar tracking technologies when you visit our Platform, in compliance with EU Directive 2009/136/EC and Spanish LSSI-CE.
1. What Are Cookies?
Cookies are small text files placed on your device when you visit a website. They help websites remember your preferences, understand how you use the site, and improve your experience.
2. Types of Cookies We Use
| Category | Purpose | Duration | Consent Required |
|---|---|---|---|
| Strictly Necessary | Authentication, security, basic functionality | Session / 30 days | No (exempt) |
| Functional | Remember preferences, language, display settings | 1 year | Yes |
| Analytics | Understand usage patterns, improve services | 2 years | Yes |
| Performance | Page load times, error tracking | 1 year | Yes |
3. Specific Cookies We Use
Strictly Necessary Cookies (No consent required):
- PHPSESSID: Session management (Session)
- csrf_token: Security protection (Session)
- auth_token: Authentication (30 days)
Functional Cookies (Consent required):
- theme_preference: Light/dark mode (1 year)
- notification_settings: Alert preferences (1 year)
- language: Language preference (1 year)
Analytics Cookies (Consent required):
- _ga, _gid: Google Analytics (2 years / 24 hours)
- _gat: Google Analytics rate limiting (1 minute)
4. Managing Cookie Consent
When you first visit our site, you will see a cookie consent banner where you can:
- Accept All: Enable all cookie categories
- Reject Non-Essential: Only allow strictly necessary cookies
- Customize: Choose which categories to enable
You can change your preferences at any time through:
- Cookie Settings: Link in website footer
- Browser Settings: Most browsers allow you to block or delete cookies
- Account Settings: Manage analytics preferences in your profile
Important Note
Blocking strictly necessary cookies may prevent you from using certain features of the Platform, including logging into your account.
5. Third-Party Cookies
Some cookies or technical tokens are placed by third-party services we use:
- Google Analytics: Usage statistics (with IP anonymization enabled)
- Google reCAPTCHA: Anti-bot verification on the contact form
- Cloudflare Turnstile: Anti-bot verification on registration and login forms. Does not install persistent tracking cookies; uses only temporary technical storage required for verification
These third parties have their own privacy policies. We recommend reviewing them:
- Google: https://policies.google.com/privacy
- Cloudflare: https://www.cloudflare.com/privacypolicy/
6. Do Not Track
We respect Do Not Track (DNT) browser signals. When DNT is enabled, we limit data collection to strictly necessary cookies only and disable analytics tracking.
7. Updates to This Policy
We may update this Cookie Policy to reflect changes in our practices or applicable laws. The "Last Updated" date will be revised accordingly.
8. Active Cookie Declaration
Below is the complete list of cookies used on our website. You can change or withdraw your consent at any time from the "Cookie Settings" link in the page footer.
Strictly Necessary Cookies (no consent required):
| Cookie | Purpose | Duration |
|---|---|---|
| PHPSESSID | Server session management (authentication, language, CSRF) | Session |
| crc_cookie_consent | Store your cookie preferences | 12 months |
| google_oauth_state | Security protection during Google sign-in | Session |
| crcw_bypass | Admin access during maintenance | 24 hours |
Functional Cookies (consent required):
| Cookie | Purpose | Duration |
|---|---|---|
| google_login_token | Remember Google sign-in | 30 days |
| trusted_device | Remember trusted device (two-factor authentication) | 30 days |
| rv_* / recent_report_* | Access verification for generated medical reports | 24 hours |
Analytics Cookies (consent required):
| Cookie | Purpose | Duration |
|---|---|---|
| _ga / _ga_* | Google Analytics — anonymous site usage statistics | 2 years |
| _gid | Google Analytics — distinguish unique users | 24 hours |