Building in health technology in Spain means navigating a regulatory landscape that would intimidate most founders. GDPR applies to all user data, but health data is classified as "special category" data requiring even stricter protections. Any feature that could be interpreted as medical advice potentially triggers medical device regulations (MDR) under EU law. Healthcare professionals must have verified credentials. Insurance coverage for teleconsultations varies by specialty and autonomous community.
Flamaid's founders chose to over-invest in compliance from day one — which added €30,000-€50,000 to their initial development cost compared to ignoring compliance until forced to address it. This decision proved correct: when Spanish regulators increased enforcement around teleconsultation platforms in 2021, competitors who had cut corners faced forced shutdowns and emergency retrofits. Flamaid had to do nothing.
Their technical architecture reflected the compliance requirements: all health data encrypted end-to-end, professional credential verification integrated with official medical college registries (Colegios de Médicos), consultation recordings with specific retention and deletion policies, and an audit trail for every patient-professional interaction.