Privacy notice
Last updated: [UPDATE DATE]
1. Data controller
The controller of the data collected through this platform is [NAME OR LEGAL ENTITY OF THE CONTROLLER], with tax ID [TAX ID] and registered address at [FULL ADDRESS]. You can contact us at [PRIVACY CONTACT EMAIL].
When you use this platform as a patient of a clinic, that clinic acts as the controller of your health data and [NAME OR LEGAL ENTITY OF THE CONTROLLER] acts as the data processor, in accordance with Article 28 of the GDPR.
2. Data we process and purpose
- Contact data (name, email, phone): appointment management, communications about your treatment and access to the patient portal.
- Health data (reason for visit, pre-anamnesis notes collected by the virtual assistant, exercise plans and pain logs): provision of the physiotherapy service and monitoring of your progress.
- Data from clinic staff accounts (email, role): access to the management panel.
- Access logs we keep a log of staff access to patient records for security and auditing purposes (art. 32 GDPR).
3. Legal basis
- Performance of the care relationship (art. 6.1.b GDPR) for appointment management and treatment follow-up.
- Explicit consent (art. 6.1.a and 9.2.a GDPR) for the processing of health data collected through the booking website, the virtual assistant or Telegram. You may withdraw your consent at any time.
- Legitimate interest (art. 6.1.f GDPR) for the security of the service and access logging.
4. Data retention
Health data is retained for the period required by the health regulations applicable in the country where the clinic operates (for example, the minimum medical-record retention period under local law). Billing data is retained for the statutory tax periods. Access logs are retained for [PERIOD, e.g. 24 months].
5. Processors and recipients
- Mistral AI (France, EU): processes the virtual assistant's messages to generate responses, under a valid data processing agreement (DPA). Data does not leave the European Economic Area.
- Dodo Payments (merchant of record; verifiable at dodopayments.com/legal): management of clinic subscription payments. We never process patients' banking data.
- Telegram (only if you contact us through that channel): the conversation is also subject to Telegram's privacy policy.
- Hosting provider : [HOSTING PROVIDER AND SERVER LOCATION, preferably EU].
Data is not disclosed to third parties for advertising purposes and no international transfers are made beyond those described.
6. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability by contacting your clinic or [PRIVACY CONTACT EMAIL], attaching a document proving your identity. If you believe the processing does not comply with the regulations, you can lodge a complaint with the data protection supervisory authority in your country (in the EU/EEA, your national data protection authority).
7. Security
We apply appropriate technical and organisational measures: encryption of communications (HTTPS), access control by user and role, logging of access to patient data and encrypted backups [DESCRIBE BACKUP POLICY].