MeDate

MeDate Privacy Policy

Last updated: [LAST UPDATED DATE] · Version 0.1-draft

Draft document: this text is provisional and will be reviewed and finalised by a Cyprus-qualified lawyer / GDPR professional before launch. Highlighted items in [brackets] are still to be confirmed.

1. Who we are

Controller(s) responsible for processing:

  • [LEGAL COMPANY NAME]
  • [REGISTERED COMPANY ADDRESS]
  • Registration number: [COMPANY REGISTRATION NUMBER]
  • Country of establishment: [COUNTRY OF ESTABLISHMENT]
  • Contact email: [CONTACT EMAIL]
  • Privacy email: [PRIVACY EMAIL]

Data Protection Officer (DPO), if applicable:

  • [DPO NAME OR "No DPO appointed"]
  • [DPO EMAIL]

[LEGAL ADVISOR TO CONFIRM WHETHER A DPO IS REQUIRED OR APPOINTED]

2. What data we collect

Not every category of data is collected from every user. The data depends on your role and on the information you choose to provide.

Patients with a MeDate account:

  • first name, last name and email (at registration)
  • account and sign-in details
  • optional profile details: phone number, date of birth, gender, address
  • appointment details (doctor, date, time, status)
  • reason for visit / appointment description, if you provide one
  • your choices on accepting terms and on receiving marketing messages

Doctors (professional accounts):

  • name, email and account details
  • professional details: specialty, clinic name and address, area, languages, biography and photo, if provided
  • availability and appointments
  • account and subscription status details (e.g. Standard/Premium, payment status)

Patients created manually by a doctor (who may not have a MeDate account):

  • first and last name
  • optionally: date of birth, gender, email, phone, address
  • appointments and information entered by the doctor in connection with providing their service (e.g. history notes, visit notes, treatment/outcome)

All users:

  • technical data necessary for the security and operation of the platform (e.g. sign-in session data)
  • records of administrative and support actions, where needed for security and accountability

3. Why we use the data

  • creating and managing accounts
  • searching for doctors
  • booking and managing appointments
  • sending necessary updates about appointments
  • operating and securing the platform
  • user support
  • preventing fraud and misuse
  • complying with legal obligations
  • managing doctors' professional accounts
  • informational and promotional messages, only where a valid legal basis exists (e.g. your optional consent)

4. Legal basis

There is no single legal basis for every processing activity. The table below is a draft and the final legal basis for each activity must be confirmed by the legal advisor.

PurposeData categoryPossible legal basisNotes
Account creation and managementIdentity, contact and account dataPerformance of a contract (Art. 6(1)(b) GDPR)[TO BE CONFIRMED]
Searching for doctorsDoctors' professional detailsPerformance of a contract / legitimate interests[TO BE CONFIRMED]
Booking and managing appointmentsContact data, appointment data, reason for visitPerformance of a contract (Art. 6(1)(b)); health data also requires an Article 9 condition[ARTICLE 9 CONDITION TO BE CONFIRMED]
Appointment updates and remindersEmail, appointment detailsPerformance of a contract / legitimate interests[TO BE CONFIRMED]
Information entered by doctors (manual patients, visit notes)Patient details, possibly health data[LEGAL BASIS TO BE CONFIRMED]Depends on the controller/processor allocation
Security, fraud and misuse preventionTechnical data, action recordsLegitimate interests (Art. 6(1)(f))[TO BE CONFIRMED]
User supportContact and account dataPerformance of a contract / legitimate interests[TO BE CONFIRMED]
Legal complianceAs required by lawLegal obligation (Art. 6(1)(c))[TO BE CONFIRMED]
Managing doctor accounts and subscriptionsDoctor details, subscription detailsPerformance of a contract (Art. 6(1)(b))[TO BE CONFIRMED]
Informational and promotional messagesName, emailConsent (Art. 6(1)(a)), where requiredOptional, separate checkbox; can be withdrawn at any time

Health data may constitute special-category personal data under Article 9 GDPR. The applicable Article 9 condition must be determined based on the actual role of MeDate, the healthcare professional, the processing purpose and applicable EU/Cyprus law.

Processing of health data is not necessarily based on consent; the appropriate condition will be determined as described above.

5. Health data

Information concerning health (for example a reason for visit or notes entered by a doctor) may receive enhanced protection under the GDPR.

MeDate only processes such information for defined and legitimate purposes and subject to the applicable legal requirements.

MeDate is not itself a healthcare provider; healthcare services are provided by the relevant healthcare professionals.

6. Doctors and patient data

Doctors may process patient information in connection with healthcare services and appointment management. Each doctor can only access their own patients and appointments.

The final allocation of controller/processor responsibilities between MeDate and individual healthcare professionals must be legally confirmed before production launch.

[CONTROLLER / PROCESSOR ALLOCATION TO BE CONFIRMED]

7. Who we share data with

Depending on how the service is used, data may be shared with the following categories of recipients:

  • the healthcare professional selected by the patient
  • service providers necessary to operate the platform
  • hosting and database providers
  • email providers
  • security / technical providers
  • authorities, where legally required

[FINAL LIST OF SUBPROCESSORS TO BE CONFIRMED]

8. International transfers

Where personal data is transferred outside the European Economic Area, MeDate will apply the safeguards required by applicable data protection law.

[FINAL LIST OF INTERNATIONAL TRANSFERS AND SAFEGUARDS TO BE CONFIRMED]

9. Data retention

Data typePurposeRetention periodReason
Account detailsAccount management[RETENTION PERIOD TO BE CONFIRMED][TO BE CONFIRMED]
Appointment detailsBooking and managing appointments[RETENTION PERIOD TO BE CONFIRMED][TO BE CONFIRMED]
Information entered by doctorsProviding healthcare services[RETENTION PERIOD TO BE CONFIRMED][TO BE CONFIRMED]
Doctor professional accounts and subscriptionsManaging accounts and subscriptions[RETENTION PERIOD TO BE CONFIRMED][TO BE CONFIRMED]
Terms acceptance and consent recordsProof of acceptance / consent[RETENTION PERIOD TO BE CONFIRMED][TO BE CONFIRMED]
Security and administrative action recordsSecurity and accountability[RETENTION PERIOD TO BE CONFIRMED][TO BE CONFIRMED]

10. Security

MeDate uses technical and organisational measures appropriate to the risks, including access controls, authentication, role-based permissions, security monitoring and other safeguards appropriate to the system.

No system can guarantee absolute security, but we make reasonable efforts to protect your data.

11. Your rights

  • right to be informed
  • right of access
  • right to rectification
  • right to erasure, where applicable
  • right to restriction of processing
  • right to data portability, where applicable
  • right to object, where applicable
  • right to withdraw consent, where processing is based on consent
  • rights concerning automated decision-making, where applicable

These rights are subject to the limitations provided by applicable law.

12. How to exercise your rights

Contact us at: [PRIVACY EMAIL]

We may need to verify your identity where reasonably necessary to protect your data.

You can also withdraw your consent to marketing messages at any time from the “Legal & Privacy” section of your profile.

13. Complaints

You may first contact MeDate at [PRIVACY EMAIL].

You may also have the right to lodge a complaint with the competent data protection supervisory authority. For Cyprus: the Office of the Commissioner for Personal Data Protection.

[VERIFY CURRENT OFFICIAL CONTACT DETAILS BEFORE PRODUCTION]

14. Children

[MINIMUM USER AGE / CHILD POLICY TO BE CONFIRMED]

15. Automated decision-making

MeDate does not currently intend to make decisions producing legal or similarly significant effects about users solely through automated processing.

If this changes in the future, this Privacy Policy will be updated.

16. Changes to this Privacy Policy

This policy may be updated. Where required, material changes will be communicated to users.

Last updated: [LAST UPDATED DATE]