1. Who we are
Controller(s) responsible for processing:
- [LEGAL COMPANY NAME]
- [REGISTERED COMPANY ADDRESS]
- Registration number: [COMPANY REGISTRATION NUMBER]
- Country of establishment: [COUNTRY OF ESTABLISHMENT]
- Contact email: [CONTACT EMAIL]
- Privacy email: [PRIVACY EMAIL]
Data Protection Officer (DPO), if applicable:
- [DPO NAME OR "No DPO appointed"]
- [DPO EMAIL]
[LEGAL ADVISOR TO CONFIRM WHETHER A DPO IS REQUIRED OR APPOINTED]
2. What data we collect
Not every category of data is collected from every user. The data depends on your role and on the information you choose to provide.
Patients with a MeDate account:
- first name, last name and email (at registration)
- account and sign-in details
- optional profile details: phone number, date of birth, gender, address
- appointment details (doctor, date, time, status)
- reason for visit / appointment description, if you provide one
- your choices on accepting terms and on receiving marketing messages
Doctors (professional accounts):
- name, email and account details
- professional details: specialty, clinic name and address, area, languages, biography and photo, if provided
- availability and appointments
- account and subscription status details (e.g. Standard/Premium, payment status)
Patients created manually by a doctor (who may not have a MeDate account):
- first and last name
- optionally: date of birth, gender, email, phone, address
- appointments and information entered by the doctor in connection with providing their service (e.g. history notes, visit notes, treatment/outcome)
All users:
- technical data necessary for the security and operation of the platform (e.g. sign-in session data)
- records of administrative and support actions, where needed for security and accountability
3. Why we use the data
- creating and managing accounts
- searching for doctors
- booking and managing appointments
- sending necessary updates about appointments
- operating and securing the platform
- user support
- preventing fraud and misuse
- complying with legal obligations
- managing doctors' professional accounts
- informational and promotional messages, only where a valid legal basis exists (e.g. your optional consent)
4. Legal basis
There is no single legal basis for every processing activity. The table below is a draft and the final legal basis for each activity must be confirmed by the legal advisor.
| Purpose | Data category | Possible legal basis | Notes |
|---|---|---|---|
| Account creation and management | Identity, contact and account data | Performance of a contract (Art. 6(1)(b) GDPR) | [TO BE CONFIRMED] |
| Searching for doctors | Doctors' professional details | Performance of a contract / legitimate interests | [TO BE CONFIRMED] |
| Booking and managing appointments | Contact data, appointment data, reason for visit | Performance of a contract (Art. 6(1)(b)); health data also requires an Article 9 condition | [ARTICLE 9 CONDITION TO BE CONFIRMED] |
| Appointment updates and reminders | Email, appointment details | Performance of a contract / legitimate interests | [TO BE CONFIRMED] |
| Information entered by doctors (manual patients, visit notes) | Patient details, possibly health data | [LEGAL BASIS TO BE CONFIRMED] | Depends on the controller/processor allocation |
| Security, fraud and misuse prevention | Technical data, action records | Legitimate interests (Art. 6(1)(f)) | [TO BE CONFIRMED] |
| User support | Contact and account data | Performance of a contract / legitimate interests | [TO BE CONFIRMED] |
| Legal compliance | As required by law | Legal obligation (Art. 6(1)(c)) | [TO BE CONFIRMED] |
| Managing doctor accounts and subscriptions | Doctor details, subscription details | Performance of a contract (Art. 6(1)(b)) | [TO BE CONFIRMED] |
| Informational and promotional messages | Name, email | Consent (Art. 6(1)(a)), where required | Optional, separate checkbox; can be withdrawn at any time |
Health data may constitute special-category personal data under Article 9 GDPR. The applicable Article 9 condition must be determined based on the actual role of MeDate, the healthcare professional, the processing purpose and applicable EU/Cyprus law.
Processing of health data is not necessarily based on consent; the appropriate condition will be determined as described above.
5. Health data
Information concerning health (for example a reason for visit or notes entered by a doctor) may receive enhanced protection under the GDPR.
MeDate only processes such information for defined and legitimate purposes and subject to the applicable legal requirements.
MeDate is not itself a healthcare provider; healthcare services are provided by the relevant healthcare professionals.
6. Doctors and patient data
Doctors may process patient information in connection with healthcare services and appointment management. Each doctor can only access their own patients and appointments.
The final allocation of controller/processor responsibilities between MeDate and individual healthcare professionals must be legally confirmed before production launch.
[CONTROLLER / PROCESSOR ALLOCATION TO BE CONFIRMED]
7. Who we share data with
Depending on how the service is used, data may be shared with the following categories of recipients:
- the healthcare professional selected by the patient
- service providers necessary to operate the platform
- hosting and database providers
- email providers
- security / technical providers
- authorities, where legally required
[FINAL LIST OF SUBPROCESSORS TO BE CONFIRMED]
8. International transfers
Where personal data is transferred outside the European Economic Area, MeDate will apply the safeguards required by applicable data protection law.
[FINAL LIST OF INTERNATIONAL TRANSFERS AND SAFEGUARDS TO BE CONFIRMED]
9. Data retention
| Data type | Purpose | Retention period | Reason |
|---|---|---|---|
| Account details | Account management | [RETENTION PERIOD TO BE CONFIRMED] | [TO BE CONFIRMED] |
| Appointment details | Booking and managing appointments | [RETENTION PERIOD TO BE CONFIRMED] | [TO BE CONFIRMED] |
| Information entered by doctors | Providing healthcare services | [RETENTION PERIOD TO BE CONFIRMED] | [TO BE CONFIRMED] |
| Doctor professional accounts and subscriptions | Managing accounts and subscriptions | [RETENTION PERIOD TO BE CONFIRMED] | [TO BE CONFIRMED] |
| Terms acceptance and consent records | Proof of acceptance / consent | [RETENTION PERIOD TO BE CONFIRMED] | [TO BE CONFIRMED] |
| Security and administrative action records | Security and accountability | [RETENTION PERIOD TO BE CONFIRMED] | [TO BE CONFIRMED] |
10. Security
MeDate uses technical and organisational measures appropriate to the risks, including access controls, authentication, role-based permissions, security monitoring and other safeguards appropriate to the system.
No system can guarantee absolute security, but we make reasonable efforts to protect your data.
11. Your rights
- right to be informed
- right of access
- right to rectification
- right to erasure, where applicable
- right to restriction of processing
- right to data portability, where applicable
- right to object, where applicable
- right to withdraw consent, where processing is based on consent
- rights concerning automated decision-making, where applicable
These rights are subject to the limitations provided by applicable law.
12. How to exercise your rights
Contact us at: [PRIVACY EMAIL]
We may need to verify your identity where reasonably necessary to protect your data.
You can also withdraw your consent to marketing messages at any time from the “Legal & Privacy” section of your profile.
13. Complaints
You may first contact MeDate at [PRIVACY EMAIL].
You may also have the right to lodge a complaint with the competent data protection supervisory authority. For Cyprus: the Office of the Commissioner for Personal Data Protection.
[VERIFY CURRENT OFFICIAL CONTACT DETAILS BEFORE PRODUCTION]
14. Children
[MINIMUM USER AGE / CHILD POLICY TO BE CONFIRMED]
15. Automated decision-making
MeDate does not currently intend to make decisions producing legal or similarly significant effects about users solely through automated processing.
If this changes in the future, this Privacy Policy will be updated.
16. Changes to this Privacy Policy
This policy may be updated. Where required, material changes will be communicated to users.
Last updated: [LAST UPDATED DATE]