Privacy Policy
OkDoctor Terms, Conditions and Privacy
Protection of privacy and legitimate use of personal data is a priority; absolutely for OkDoctor (us or OkDoctor). We are committed to ensuring your privacy. This Privacy Policy (Policy) explains how we collect, use, store and disclose your personal data in the context of our site (Site), mobile application (; App), Software-as-a platform. -Specialist and Clinical Services (Platform) and the provision of any other related services (collectively, Services)
We suggest that you read this Policy carefully before using the Services or the Site or opening an account on the Platform (Account).
OkDoctor reserves the right to change this Policy, especially if the changes are due to changes in our procedures; operational or legislative or regulatory changes.
I. Information applicable to all users
OkDoctor AD Ultra Limited Service S.r.l. headquartered in Bucharest, 42 Roma Street 011775. We manage the site www.OkDoctor.it and other sites connected to it. We are part of the Ultra Business Group, a group of companies operating in different countries in Europe and America.
For the purposes of European Union data protection laws, in particular the General Data Protection Regulation (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data personally, hereinafter referred to as GDPR), OkDoctor, together with the following companies The OkDoctor partner where our technical management team (OkDoctor Tech) is located, are the controllers of your personal data.
Strategic decisions about the purposes and means of processing personal data of patients are always made by our team OkDoctor Tech.
OkDoctor Tech also plays an important role in the decision-making process regarding data processing, mainly in relation to the processing of physicians 'and specialists' data processing.
If you are a physician or healthcare professional who uses the Platform and Services in a professional capacity and
(a) you have entered into a contract to receive our Premium / Paid Services (Service Agreement) or
(b) you work in, for or with a clinic or center that has entered into a Service Agreement, OkDoctor Tech Group companies may be co-controllers of the processing of your personal data in connection with the provision of specific Services, as indicated in the Service Agreement which may be entered into with us.You can contact our Data Protection Officer (DPO) by sending an email to privacy@okdoctor.ro at the OkDoctor offices.
What kind of personal data do we collect and use, for what purposes; and on what legal grounds
The nature of the personal data we collect and use, so for purposes; of the processing and the related legal basis on which the processing is based depends on the type of user and the different use of the Platform, Site, Application or Services by the latter. In particular:
- If you are a patient or user of our Site or Application looking for information about health professionals or using one or more; of our Services, the provisions of Section II of this Notice apply;
- If you are a physician or healthcare professional using the Platform and Services in a professional manner and you have registered on the Platform by creating your Account (a Registered Professional), possibly having and concluded in a Service Agreement, it applies the provisions of Section III of this Information; and
- if you are a physician or healthcare professional whose personal data appears on the Platform, but you are never registered on the Platform (and therefore do not have an Account or are subject to a Service Agreement: a Unregistered Professional ), the provisions of Section IV of this notice shall apply.
If OkDoctor processes your personal data on the basis of its legitimate interest under Art. 6.1 (f) of the GDPR, OkDoctor will have; performed a test on the balance between your interests and your sound rights to ensure that the latter are not harmed or endangered by our legitimate interest. Please note that you may contact us at any time to express your opposition to our processing (see paragraph What are your rights?regarding the processing of personal data (below).
Sharing data with third parties
We may disclose your personal information to other OkDoctor Tech Group companies solely for the purpose of providing you with the requested Services.
We may also share your personal data with external providers, again for the sole purpose of providing you with the requested Services. Unless otherwise notified and requested to transfer data to another controller, each of these third parties acts as a data controller to our instructions and has entered into an agreement to appoint the controller with us in accordance with the art. 28 GDPR. These include:
- Cloud hosting and server maintenance service provider,
- Providers of telephone or digital communication tools,
- Providers of customer support tools,
- External consultants, auditors or advisers,
- Payment service providers, banks, credit reference and fraud prevention agencies and insurance companies,
- IT company that provides us with similar software or services
- Third parties with whom procurement, merger, investment or corporate reorganization procedures are ongoing or planned.
Some of the third parties mentioned above are located outside the European Union. In this case, we are under our obligation to ensure that the legal requirements for the transfer of the data are met in a secure manner and we will remain responsible in any case for respecting your legal rights and obligations in relation to the personal data transferred.
Finally, we may disclose your data in order to comply with any legal or regulatory requirements or dictations, to enforce our policies or conditions of use or the Service Agreement, to contact the authorities; judicial or other authorities; to comply with their legitimate demands or to protect our rights. We may also share your personal information with other entities; companies, in the event of a merger, acquisition or investment in such an entity; company or in the event of a corporate reorganization.
Except as noted above, we will not transfer your personal information to third parties without your consent.
What are your rights regarding the processing of personal data
In accordance with the GDPR and regardless of your use of the Platform and Services, you have the following rights:
- You have the right to be informed about the processing of your personal data (ie for what purposes, what type of personal data, whose recipients are communicated, retention periods, any third party sources from which they were obtained , checking automatic decisions, including profiling, logic used, and the importance and consequences expected). This information, as well as (where applicable) the provisions of the Service Agreement or any other information or notifications regarding the processing of personal data provided by OkDoctor Tech Group, fulfills your right to be informed;
- You are entitled to:
- Request a copy of the personal data we process; you will delete (if you believe we have no right to keep them) or rectify (if you believe they are inaccurate) your personal data;
- oppose and therefore limit the processing of your data by us (in which case, you will only have access to those features of the Services that do not require the type of processing you have objected to);
- revoke any consent to the processing of data previously given by you (revocation of consent does not affect the legitimacy of the treatments implemented before the actual revocation, or on the basis of legal conditions other than consent);
- requires portability of your data stored by us in digital format (ie to receive your personal data in a structured, commonly used and machine-readable format to transfer to another data controller or to obtain such a direct transfer, if technically feasible);
contact us preferably in the ways; indicated in the Contacts section of this notification;
- You have the right to lodge a complaint with our DPO (preferably by contacting us in the indi as in the Contact section of this notification) or, if your complaint is not satisfactorily resolved by us, Authorities; Guarantor for the protection of personal data (accessible through the website www.garanteprivacy.it/) if you consider that we process your personal data in a manner contrary to the law;
We will always comply with our legal obligations regarding your rights as a person; of stakeholders, to allow you to fully exercise them. We will try to respond to you within a reasonable time and, in any case, within one month (or within the timeframe that we will notify you immediately in the event of complex or numerous requests). We reserve the right to charge a reasonable fee (which reflects the cost of providing information) or to refuse to respond when requests are manifestly unfounded or excessive: in which case we will explain the situation to you and inform you of your rights. We also reserve the right to verify the identity of the applicant in order to avoid sharing your personal data with unauthorized third parties.
Our goal is; make sure the information we hold about you is always accurate. To help us keep your information up to date, you will need to be careful to notify us of any changes to your personal information. Following a report or request from you, we will do our best to ensure that your personal information in our possession is accurate and up to date.
Automatic decision and profiling
We do not process personal data that results in decisions based entirely and solely on the automatic processing of your personal data. We do not use any profiling system or tool to process your data, fully automated decision-making processes based on your personal data.
Links to other websites
Our site and our Application may contain links to other sites, applications or platforms, including through the "social" buttons. While we do our best to ensure that such links are always directed to sites, applications or platforms that share our high standards of privacy, we are in no way responsible for the content, security or privacy policies of other sites. Websites and a link to our site do not constitute an endorsement of the site in question. Once transferred to another site, application or platform, the user is subject to the latter's terms and conditions (including the relevant privacy policy and underlying practices). We encourage you to review the terms of service and privacy policies or policies applicable to such sites, applications or platforms before sharing your personal data.
How we protect your data
OkDoctor and Doctor Tech Group take appropriate technical, physical, electronic, operational and administrative security measures to protect your personal data from unauthorized access. We comply with industry-accepted standards to protect the personal information you provide to us, both during transmission and after receipt: for example, periodic tests on the security of the Platform, segmentation and control of access to data within the organization and the use of pseudonymization techniques. , anonymization or encryption. Unfortunately, the transmission of information via the Internet (including e-mail) is not; always completely safe. Despite our constant commitment to ensuring the maximum protection of your personal data, we cannot guarantee the security of your data when it is transmitted to our Site, Application or Platform, especially if the transmission takes place in a modal way; Uncertain. Therefore, the user assumes the risk arising from that transmission. Once we receive your information, we will use strict procedures and appropriate security features to prevent any unauthorized access or sharing.
Contact us
For any questions regarding your personal information, you can contact us:
- via our Contact Form on the Site,
- by e-mail to: privacy@okdoctor.ro
- If you are a registered professional who has signed a service agreement, please contact our Customer Service and other questions regarding your Account.
II. Dedicated sectionusers of the Platform (patients)
If you are a patient or user of our site or application looking for information about healthcare professionals or facilities, this section applies to you.
A) What personal data do we process; how we collect them; for what purposes and on what legal basis do we treat them
1. Create an account and register to use our Services
We collect your personal data directly when you register on our Site or Application, for your use of the Services, or when you book a visit or meeting through the Platform. When registering or booking, please provide basic details, including email address and telephone number. You can also register using social platforms such as Facebook or Google, in which case it will come to you; requested to allow these companies to share some of your personal information with us (as indicated on the registration page). You can also add additional information, such as your last name, first name, gender, or phone number. We save this information in our systems to enable you to use the Services.
Our services allow you, among other things, to: book visits, send messages and / or chat with specialists, save your personal information in your OkDoctor Account, and post your opinion about your site experience. during the visit. You can also check your visit history and manage your account.
From your in-app user account, you can manage automatic and system notifications (for example, pop-ups).
When you register to use our Services, or book a visit or appointment, you agree to the Terms and Conditions by clicking the appropriate box and then enter into a legally binding agreement. The need on our part to perform the obligations under this contract and to allow you to access the Services is a valid legal basis for the processing of your personal data, as specified in Article 6.1 (b) of the GDPR.
2. Using the Services
Reservations: When you book a visit or appointment with a specialist or clinic, or when you request a diagnostic test, through the Site or Application, we will obtain additional data from you, including , for example:
- Name and surname,
- Phone number,
- Email address,
- Visit date and time,
- the reason and type of visit / appointment, exam or test you are requesting,
- Any additional information you decide to share (for example, answers to questionnaires; additional instructions for the specialist; description of symptoms) during the appointment booking process.
We will store this data within the Platform and pass it on to the specialist or clinic. After the transmission of your personal data, the specialist or clinic will become independent data controllers for the purposes determined by them (for example, to provide you with medical services). This treatment will be; subject to the specialist's or clinic's personal data processing and retention policy.
In addition, we may send you (by phone or e-mail) a booking confirmation and / or a reminder before your visit date; and we will notify you in case of cancellation. After the visit, we may contact you to request that you write a review of your experience on the Site. Before the visit, the specialist may decide to send you, through the Platform, a questionnaire about your symptoms and the reason for your visit. The answer to the optional questionnaire, but will help the specialist to prepare for the visit. The specialist will send you the questionnaire and only he / she will receive the answers, unless you expressly agree to the storage of your answers in the OkDoctor account, for review or further use by you
Account History: One of the Services we provide to users is; to save your data (booking and scheduling history; health data provided to specialists, etc.) in your Account There allows you to, among other things,:
- Keep your data in one place and
- You always have data about, for example, your medical history, the treatments you take into account, your allergies, and your health.
Doctor chat or private message: through our platform you can also start a chat with a specialist or pwill send you a private message: we will keep you informed, but we will not access it, and the content of such conversations will remain private between you and the specialist.
You can always review the history and content of your chats or messages.
Our need to perform the Terms of Service and to allow you to access the Services is a valid legal basis for the processing of your personal data, as specified in Article 6.1 (b) of the GDPR.
However, some of the personal data that you share with us during the booking process is or may be considered (individually or jointly) data relating to your health and therefore deserves specific protection. according to GDPR. For more information on the legal basis for the processing of this data, please refer to Section II (B) of this statement ( Do we process your health data? ).
3. Write a review or a public question
When you decide to post a review on the Site about your experience with a specialist or medical unit, or to post a question to professionals on the Platform, we may collect some of your personal data (for example, if you include identification data and / or describe the reason for your visit or details about your medical history). For this reason, we will ask for your consent for the processing of health data. The processing of personal health data on the basis of consent is; according to Article 9.2 (a) of the GDPR.
Please note that your reviews will be made public. We advise you not to enter any private or sensitive information, as is the case. as audiences will be visible to all users of the Site.
4. Communications
As a user of the Services with your own Account, you will receive communications from us regarding topics that may be of interest to you (i.e., strictly related to the Services that you use): for example, communications regarding new features, new products, additional or ancillary services, promotions, news and other topics related to services or news; about Docplanner group initiatives that might be of interest to you
The legal basis for sending such communications (by telephone or e-mail) is; legitimate interest in accordance with Article 6.1 (f) of the GDPR. However, as these are potentially commercial communications, you will always have the right to object to the receipt, in which case we will not contact you again, except for (a) service communications sent by your doctor through our Visiting Platform. or appointments reserved by you through the Platform (e.g. reminders, cancellations, specialist requests, invitations to review), which come from your doctor (who uses our Services) and not from us (see Section II (D) of this Disclosure We also act as data processors on behalf of specialists and clinics ); and / or (b) other non-commercial service communications relating to your Account or the Services (for example: changes to the terms of the contract, notices of failure, messages of a legal or regulatory nature).
Other data and purposes of treatment
As part of your use of the Site, Application or Platform, we may obtain other types of data, including, for example, information about your device (computer or mobile phone), IP address, time zone and language, or the browser you are using. We will also collect information on timing, modalities; and the duration of your use of the Services (first and last use, session duration in the Account). If you use the app, we may also get GPS location data (you'll always have the option to turn off this feature directly on your mobile device).
We will process these datasets of a technical nature ("metadata") for:
- Respond to and defend against any complaints (from you or third parties) regarding the Services and their use by you and / or
- Manage and plan our business. (for example, how our users will use our Services in the future and estimate trends for their needs and preferences). In this case, in most cases the data used will be anonymized (for example, the way you browse our site), but in some cases the data, if read in conjunction with other data, may reveal your identity. >
We process this information on the basis of our legitimate interests, which constitute a legal basis for the processing of personal data in accordance with Article 6.1 (f) of the GDPR. Please note that you have the right to object to the processing of this data at any time.
B) Do we process data about your health?
In some of the following cases:
- When booking a visit or meeting with a specialist or clinic using the Platform
- If you choose to save your personal data in your Account
- if you write a review on the Site that includes personal health data
- If, through the Platform, you start a chat conversation with a specialist or send one or more to the latter; communications by sharing information about your health
- If you use the functionality; o Services similar to those listed above
We may gain access to personal data about your health, which deserves specific protection under the GDPR.
Therefore, we will need your prior consent to process this data, which we will ask you from time to time. Your consent is, in this case, required in order to use the Services mentioned above; in fact, we could not provide them without being able to process this data. The processing of your health data based on your consent is; according to Article 9.2 (a) of the GDPR. You may withdraw your consent at any time, in which case we will not be able to continue to provide you with the Services for which it is sharing such data; necessary.
C) Is it possible to provide other people's personal data?
If you book a visit or meeting on behalf of another person (for example, for a minor family member), you authorize us to collect that person's personal data. We will process your personal data for the same purposes; for which we treat yours, applying the same security policies and measures.
D) We also act in quality; of data processors given on behalf of specialists and clinics
We offer various services to doctors and clinics. Our services allow our clients 'physicians and clinics, among other things, to upload and save patients' personal data, information about patient visits, and information about their health. They also allow them to send communications and text messages or emails to patients through our Platform and manage their work commitments.
When we process your data on the instructions of the doctor or clinic of our client whom you have contacted (and not because you have used our services directly or created an Account with us), and your patient data is transmitted to us from him. the latter, we simply act as quality; of data processors (according to Article 28 of the GDPR), in the name and on behalf of our customers, and always and only on the basis of their instructions and instructions; never for our purposes; independent.
There it also applies to specialists and clinics who send you headlines, emails, advertising campaigns or similar communications through our platform: they, and not us, decide whether or not to send them to you. We do not take responsibility; from these communications, the processing of your personal data by specialists or clinics or the existence of an appropriate legal basis for this.
If you do not wish to receive such messages, or you wish to exercise your rights to your personal data processed by your specialist or clinic, we suggest that you contact the physician or clinic who sent you the message asking them not to be contacted.
E) Storing and deleting your data
With regard to the personal data you provide in accordance with Sections II (A), (B) and (C) above, which we process as quality; of data controllers (according to GDPR) based on our direct relationship with you, we will store them in our systems only as long as necessary for the purposes mentioned above or if necessary to comply with the legal obligations to which we are subject. .
The time we keep your data will vary; depending on the type of information and purposes; for which we use them. In general, we will keep our records for up to 6 years after the end of your relationship with us, in order to comply with our legal obligations. See the trail for more informationtor table:
Typology |
Retention period |
|
---|---|---|
Book a visit or meeting, create an Account, and use the Services |
We will store the personal data you provide in our systems to create an Account and / or book a visit or appointment with a specialist or clinic for as long as your Account is; active (to be able to provide you with our Services) and for another 6 years (only to comply with our legal obligations). |
|
Account medical history |
We will keep in our systems the health data regarding your medical history, which you have saved in your Account, for as long as your Account is; active. |
|
Talk to your doctor |
We will keep the chat content in our system for a period of 2 years from the date of the conversation. |
|
Reviews |
Reviews posted by you on the Platform will only be deleted at your express request. |
|
Metadata |
Your Account metadata will be retained by us for as long as your Account is; active (to be able to provide you with our Services) and for another 6 years (only to comply with our legal obligations). |
|
Complaints |
We will process your personal data provided in connection with the filing of a complaint for 6 years from the closing date of the complaint, only to protect us in the event of any legal action. |
Purpose of treatment |
Retention period |
|
---|---|---|
Account creation or signing of the Service Agreement |
We will process your data as long as you have an active Account or Service Agreement. If you delete your user account or terminate your service agreement, we will retain your personal data for a period of 6 years. |
|
Metadata |
Your Account metadata will be retained by us for as long as your Account is; active (to be able to provide you with our Services) and for another 6 years (only to comply with our legal obligations). |
|
Complaints |
We will process your personal data provided in connection with the filing of a complaint for 6 years from the closing date of the complaint, only to protect us in the event of any legal action. |
Browser |
Link to Settings |
How to manage cookies |
Google Chrome |
https://support.google.com/chrome/answer/95647?hl=en-US&p=cpn_cookies |
Click the three dots in the upper right corner and open `` settings ''. In the site settings, click "security and privacy"; to manage cookies. |
Safari |
https://support.apple.com/it-it/HT201265 |
Go to the preferences settings page and click "security". In the security section you can manage your cookies. |
Microsoft Edge |
https://support.microsoft.com/it-it/search?query=enable%20cookies%20in%20edge |
Click the three dots in the upper right corner and open `` settings ''. In the site settings, click on privacy, search, and services to manage cookies. |
Mozilla Firefox |
https://support.mozilla.org/it/kb/Siti%20web%20e%20avviso%20di%20blocco%20dei%20cookie |
Click the three bars in the upper right corner and open options. In the site options, click on "security and privacy" to manage cookies. |