Coren by da.care SA
Version 0.1 (draft), 22 July 2026
Draft for legal review. This document supports the legitimate-interest basis (GDPR Article 6(1)(f); equivalent Swiss FADP proportionality analysis) cited in the Coren Privacy Policy, Section 4 ("Operate the directory", "Tell practitioners they are listed") and Section 5. It should be revisited whenever the underlying processing changes materially, and specifically before Coren is ever extended to Germany or another jurisdiction flagged below.
This assessment covers two processing activities, evaluated together because the second depends entirely on the first:
It follows the standard three-part test: purpose, necessity, balancing.
What is the interest, and whose is it?
Coren's interest is commercial and operational: a directory with no listed practitioners has no value to Seekers, and no reason for a practitioner to ever hear that Coren exists. Populating the directory from public information, and then telling the practitioner it's been done, is how the product reaches the point where it can function at all. This is a genuine, present interest actively being pursued today, not a speculative future one.
There is also a third-party interest worth naming separately, GDPR permits relying on a third party's legitimate interest, not only the controller's own: Seekers have a real interest in a directory that is actually populated and useful, and practitioners who are findable have an interest in being found by people looking for exactly what they offer. Both of these are the reason the Terms describe Coren's purpose as connecting Seekers with Providers, not simply "growing the directory."
Is the interest lawful and clearly articulated? Yes: operating a professional directory is an ordinary, lawful commercial activity, and the purpose (data collection and use limited to enabling discovery of a professional service) is specific, not an open-ended "improve our business" justification.
(A) Creating profiles from public information.
Could the same purpose be achieved with a less intrusive method? The realistic alternative is a self-signup-only model, where Coren only lists practitioners who proactively register. That is less intrusive, but it does not achieve the purpose: it fails to solve the cold-start problem (an empty or near-empty directory has no value to Seekers, and gives practitioners no reason to ever learn Coren exists in the first place, since nothing prompts them to). Pre-populating from information the practitioner has already chosen to make public is, at this stage of the product, necessary to reach the point where the directory is useful at all.
Necessity also constrains scope, not just the decision to crawl in the first place. An Unclaimed Profile is deliberately limited to professional and business fields already listed in Terms Section 5 (name, practice name, specialisation, location, languages, working mode, years of experience, published contact details, and a generated summary), and Coren does not knowingly include private or sensitive information. This is the data-minimisation half of necessity: no more is collected or published than the purpose requires.
(B) Sending outreach e-mails.
Is e-mailing the practitioner necessary, or could disclosure happen some other way (e.g. a public notice, or none at all)? GDPR Article 14 specifically requires individual notice when the data was not collected from the data subject directly, "public notice" does not satisfy that requirement when direct contact is feasible, and e-mail is the only contact channel available at the point a Listing is created (no other relationship with the practitioner exists yet). Sending a small, capped number of notification e-mails (the current sequence: six e-mails over 27 days, see webpipe/docs/coren-outreach-health-wellness-en.md) is therefore necessary to satisfy a legal obligation this same processing activity creates, not merely a convenient marketing channel.