Privacy Policy

1. Introduction

a. What is the applicable legislation on the protection of personal data?

In the European Union (EU), the main legal act governing the protection of personal data is Regulation (EU) 2016/679 on the protection of individuals with regard to data processing with personal data and the free movement of such data (General Data Protection Regulation - GDPR) [1] . It contributes to the modernization and unification of European data protection legislation enabling companies processing such data to reduce red tape and enjoy a increased consumer confidence. To this end, the GDPR strengthens the rights of EU citizens with regard to the processing of their personal data, provides new rights for them and them gives greater control over this data by giving:

In Romania, an EU member state, GDPR is applied directly, as well as through Law no. 190 of July 18th 2018 on measures to implement Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of data with personal data and on the free movement of such data [3] .

In this context, the role of this Privacy Policy is to introduce you to how Medic Chat, in his quality of Personal Data Operator, complies with the legislative acts mentioned above.

b. Who are we?

Medic Chat is a Telemedicine Site and Application that aims to simplify people's access to specialists.

Until 2017, in Romania there were only two options for obtaining specific medical information and truthful: traditional doctor visits, which often involve a long and complicated process, and self-diagnosis by conducting research on the Internet, which is not characterized by accuracy and often nor by fairness. Launched in 2017 , Medic Chat aims to offer a solution alternative to the two previously presented, for obtaining personalized medical information from reliable sources. Thus, they were laid the foundations for providing Telemedicine services in Romania with the advent of Medic Chat, starting in the Innovation Labs programs and continuing their development through Y Combinator Startup School.

The importance of Telemedicine services comes from many specialized studies. The most conclusive in this meaning is a study conducted by the American Medical Association in the United States, which attests to the fact that 70% of medical visits are informational, while only 30% of them need one physical consultation. This means that a significant portion of medical questions can receive a response to an online discussion or consultation, avoiding going to a clinic or office medical.

This is the context in which Medic Chat was born, an innovative Telemedicine solution that allows offering of remote medical advice and counseling, online, via messaging with doctors registered in the Application or in a virtual medical office of the doctors registered in Application.

c. How can we be contacted?

According to art. 24 of the GDPR , Medic Chat has the role of Data Operator [5] personal, while doctors registered in the Medic Chat Application have, according to art. 28 of the GDPR , the role of Empowered by Medic Chat [6] process such data.

For any comments, suggestions, questions or concerns regarding the information contained herein Privacy Policy or any other matter relating to the processing of Character Data by Medic Chat and / or by Medic Chat Authorized Persons, we may be contacted at any time based on the following contact details :

2. Definitions

The definitions contained in this section are complementary to the definitions given by the GDPR to the similar. Also, the terms of this Privacy Policy that are found in the GDPR, but are not found in this list of definitions, have the same meaning as given to those notions in the GDPR.

3. Purpose

a. What services does this Privacy Policy cover?

This Privacy Policy with Terms and Conditions using Medic Chat Services , se applies to Users who visit and / or use the following services provided by Medic Chat, named in continued generically as Medic Chat Services :

b. What is Medic Chat pursuing through this Privacy Policy?

This Privacy Policy sets out the rules under which Medic Chat and Powers of Attorney by Medic Chat obtains and processes the Personal Data of the Users. Thus, through this Policy Privacy Chat follows: w

Medic Chat reserves the right to periodically update this Privacy Policy to reflect any changes to the way in which the personal Data of the Users is processed or any changes in legal requirements. In case of any update, on the Medic Chat Site and in the Medic Chat Application the modified version of the Privacy Policy will be displayed, which is why the Users of the Services Medic Chat are asked to periodically check the contents of this document. In addition, Users registered in The Medic Chat application will be notified at the email address associated with the User Account each time This document is being updated.

c. On what basis does Medic Chat process Users' personal data?

According to art. 9 of the GDPR , Personal health data is a special category of data with personal data, and as such can only be processed in certain situations. By the nature of the services they provide offers, Medic Chat and / or Medic Chat Authorized Processors both Personal Data considered common (for example: name and surname, age, telephone number, etc.) and Special categories personal data. In the following we will present the legal bases that make the processing both categories of data by Medic Chat and / or by Medic Chat Authorized Persons to be legal.

The grounds on which Medic Chat processes Personal data considered common (ie other data other than health data) are as follows:

The grounds on which Medic Chat processes Special categories of character data personal (ie data health) are as follows:

Hereinafter, the notions of personal data considered common and special categories of data with personal data will be referred to generically as Personal Data.

In terms of Marketing Communications , Medic Chat processes Personal Data Based users their consent to the processing of data for this specific purpose.

Medic Chat and Empowered Persons may also process certain Personal Data in the following purposes:

4. Complaints about this Privacy Policy

Medic Chat users can file a complaint or complaint with the appropriate authorities in the following situations:

Such complaints or grievances may be addressed to the National Data Processing Supervisory Authority. with Personal Character (ANSPDCP). Below you will find useful information on how to file a complaint or a complaint to this authority.

However, Medic Chat encourages Users to, before making a complaint or grievance in to contact the competent authority to contact Medic Chat so that they can answer any questions they may have. observation or request regarding compliance with the rules on the protection of personal data. This will not in any way affect the right of Users to contact the competent authorities at any time, including if they consider the response from Medic Chat unsatisfactory. Doctor Chat is committed to making every effort to resolve any issues amicably.

a. Complaints filed with ANSPDCP

ANSPDCP is the Romanian authority competent to solve the complaints regarding the violation of the processing rules of personal data by data controllers. The contact details of this authority are the following:

For details on the steps to follow to file a complaint with ANSPDCP, Users are asked to consult this website .

5. Commitment

Both the Medic Chat Team, in its capacity as Personal Data Operator, and the Authorized Persons by Medic Chat to process such data, pay special attention to compliance with the legal conditions of processing of the Personal Data of the Users. Compliance with data protection legislation staff and good practices in the field, as well as ensuring a climate of transparency, security and trust for Users is a priority for Medic Chat.

As transparency is one of the core values ​​of Medic Chat, Users will be informed in How Medic Chat and Medic Chat Authorized Persons Process and Protect Data with their personal character. That's why Medic Chat offers the following guarantees:

Medic Chat also wishes to inform Users that in order to make payments, use Stripe payment processor services.

Medic Chat thanks you for your trust in the Services provided and the way in which the processing takes place Personal data.

6. Cookies

a. Purpose of Cookies

Medic Chat uses Cookies to distinguish between Users of Medic Chat Services. The use of cookies is useful for the following purposes:

b. What are Cookies?

Cookies are small files, consisting of letters and numbers, that will be stored on your computer, mobile terminal or other equipment through which a User accesses web pages. Cookies contain information which, at the request of a web server of a website, is transferred from the web environment storage of used equipment to the browser used (such as Mozilla Firefox, Google Chrome, Internet Explorer, Microsoft Edge, Safari).

Cookies do not contain software, viruses, spyware, malware or the like and cannot access information located locally, on the User's equipment.

c. What is the connection between Cookies and Personal Data?

By their nature, cookies do not require personal data to be used. This means that by using Cookies it will not be possible to find out the identity of each User who has accessed the Medical Services Chat. When, however, certain information related to the User and / or the equipment is processed used by it through Cookies, the purpose of that processing is to personalize the experience To users, by facilitating certain functionalities specific to Medic Chat Services.

d. What types of cookies do we use and how do we use them?

Medic Chat services use the following types of cookies:

The data obtained through these cookies allows Medic Chat to display content that is as relevant as possible to Users. For this purpose, it is possible for Medic Chat to transmit certain data obtained through Cookies to Third Parties.

By continuing to browse the Site and / or the Medic Chat Application, Users agree to about how Medic Chat uses cookies.

e. Deleting and Discarding Cookies

Typically, browsers used to access web pages have default settings that allow the use of Cookies. These settings may be changed so that the automatic administration of cookies is blocked by the browser or the user is informed each time cookies are used. Detailed information about Cookies administration capabilities and methods can be found in the settings area of ​​your browser.

The browser should also allow users to delete any cookies that no longer exist desired.

Medic Chat allows Users to select which types of Cookies to enable, by selecting one or several of the 3 options presented in the previous section (Essential Cookies, Analytical Cookies, Cookies Marketing) when they first visit the Medic Chat Web App or Website.

7. Personal data processed

Personal data processed by Medic Chat and / or Medic Chat Authorized Persons is, in principle, User identification data and Personal health data , the latter being necessary for the performance of medical counseling through Medic Chat application.

Depending on how these main categories of data are obtained and, where appropriate, transmitted. to Medic Chat and / or Medic Chat Authorized Persons, they can be divided into:

* Third-party means third-party entities that Medic Chat works with to provide services quality services for its Users, and to which it transmits or retrieves data which it may have personal character. The main third parties that fall into this category are:

In the following we present to you what are in concrete the Personal data obtained, processed and, there where applicable, transmitted by Medic Chat, as well as details of when each of them takes place the above operations.

a. Data provided

i. Data provided by the Patient User

At the moment of registration of the Patient User in the Medic Chat Application, Medic Chat obtains the following information about the User concerned:

At the time of authentication of the Patient User in the Medic Chat Application, Medic Chat obtains the following information about the User concerned:

When editing the profile created by the Patient User on the Medic Chat application in In order to use it, Medic Chat may obtain the following information regarding the User concerned, only if the User wishes to provide them:

Regarding settings for receiving notifications about Medic Chat Services , available to the Patient User, Medic Chat may obtain the following information regarding The user in question only if the User wishes to provide them:

At the time of asking a question to a Medical User by the Patient User on Medic Chat app, Medic Chat obtains the following information about the User concerned:

At the time of payment of a question by the Patient User on the App Medic Chat, Medic Chat obtains the following information about the User in question:

Upon receipt of a response to a question from a Medical User by The Patient User on the Medic Chat Application, Medic Chat obtains the following information about the User concerned:

  • The answer provided by the Medical User to the question asked;
  • Images attached by the Medical User to the answer provided.

At the time the Patient User performs an evaluation of the response received from User Medic on the Medic Chat Application, Medic Chat obtains the Patient User's opinion on how which the Medical User answered the question.

Regarding Patient Users' correspondence with the Medic Chat Team through some channels of external communication (for example, via email, phone, or the official Medic Chat Facebook page) in to get general information about Medic Chat Services (for example: to receive support technical or other guidance), Medic Chat may obtain the following information regarding the User in cause:

  • Email address;
  • Name and surname;
  • Phone number;
  • Age;
  • The medical problem the user is referring to;
  • Images related to the medical problem;
  • Medical analysis.

For news subscription, marketing communications and account activity notifications User Guide and / or Medic Chat Services , Medic Chat obtains the following information regarding The user in cause:

  • Email address (for receiving regular news and marketing communications related to the activity Medic Chat);
  • Email address and / or telephone number (one of the two, at the User's choice, for receiving of notifications regarding the activity of the user account on the Medic Chat Application).

Medical users have the opportunity to offer patients medical advice and advice in an office virtually, via email and / or SMS. For this purpose, the Medic User can enter in the Medic Chat Application the telephone number and / or e-mail address of the patient concerned. Thus, at the time of sending by Medic user gets an invitation to the virtual office , Medic Chat gets the phone number and / or adress of Patient email [16] .

ii. Data provided by the Medical User

At the time of registration of the Medic User in the Medic Chat Application, Medic Chat obtains the following information about the User concerned:

  • Name and surname;
  • Email address;
  • Password (not stored in clear, but encrypted);
  • Agreement on the Terms and Conditions of Use of Medic Chat Services;
  • The agreement to receive marketing communications and notifications from Medic Chat (the agreement is optional and may be withdrawn later);
  • Location;
  • Personal phone number;
  • Professional title (for example: resident doctor, specialist doctor, primary care doctor, etc.);
  • Specialization (eg epidemiology, infectious diseases, dermatology, etc.);
  • Number of years of experience;
  • Current job;
  • Graduate university and year of graduation.

After registering the Medical User in the Medic Chat App, Medic Chat gets, within Medic Chat Services, collaboration agreement between Medic Chat and the Medic User in question. This contract is different depending on the form of legal organization in which the Medical User exercises his profession (and namely, PF, PFA, PFI, CMI or SRL) and must include the date of signing and the signature of the contracting parties.

Through the collaboration agreement between the Medic User and Medic Chat also establishes the quality of the Medical User of the Person empowered by the Medical Chat to process Data with personal character, in accordance with the provisions of art. 28, para. (3) of the GDPR . As provided by art. 28, para. (1) from GDPR , Medic Chat ensures that Medical Users provide sufficient guarantees for the implementation of some appropriate technical and organizational measures so that the processing of personal data by the latter to comply with the requirements set out in the GDPR and ensure the protection of the rights of the Users whose Data they make object of processing. To this end, the collaboration agreement shall set out the following elements:

  • the purpose and duration of the processing of the data by the person authorized by Medic Chat;
  • the nature and purpose of the processing of the Data by the Person Authorized by the Medical Chat;
  • the type of personal data that can be processed by the Medic Chat Authorized Person;
  • Types of Users whose Personal Data is subject to processing by the Data Authorized Medic Chat;
  • obligations and rights of the Medic Chat Authorized Person (including, but not limited to, the obligation of the Person authorized by the Medical Chat not to recruit another person to deal with the processing Personal Data of Medic Chat Users than with the prior written permission of Medic Chat, in its capacity as Data Operator, obligation provided at art. 28, para. (3) of the GDPR ).

After registering the Medic User on the Medic Chat application, Medic Chat gets, through via an email sent by the Medical User to team@medic.chat , next information about the User in question:

  • Identity card;
  • IBAN;
  • Fiscal registration certificate (for PFA, PFI, CMI or SRL);
  • Certificate of membership in the College of Physicians or in the College of Psychologists, as the case may be;
  • Resident card;
  • Other documents equivalent to those listed above (in the case of Foreign Physicians).

After registering the Medic user on the Medic Chat application, Medic Chat gets annually , via an email sent by the Medical User to ekipa@medic.chat , the annual free practice notice or certificate of User Medic.

After registering the Medic User on the Medic Chat application, Medic Chat can get through via an email sent by the Medical User to team@medic.chat , the following information regarding the User in question, only if the Medical User sends it on his own initiative:

  • Malpractice insurance;
  • Specialist certificate;
  • Doctorate in medicine;
  • Bachelor's degree.

At the time of authentication by the Medic User in the Medic Chat Application, Medic Chat obtain the following information about the User in question:

  • Email address;
  • Password (not stored in clear, but encrypted).

When editing the profile created by the Medic User on the Medic Chat application in In order to use it, Medic Chat may obtain the following information regarding the User concerned, only if the User wishes to provide them:

  • Phone number;
  • Profile picture;
  • Academic title (for example: academician, associate professor, lecturer, etc.);
  • Overspecializations (eg sexology, audiology, etc.);
  • Presentation of the Medical User (ie a self-description of the Medical User);
  • Link to LinkedIn profile;
  • Link to personal site;
  • Details of current jobs: their name, address, website (e.g. website the hospital or clinic where the Medical User practices);
  • Details of the level of education completed: name of the institution of education completed, title diploma (for example: bachelor's, master's, doctorate), year of enrollment, year of graduation;
  • Details of previous work experience: name of previous job, position / position previous year of employment, year of resignation;
  • Attended conferences;
  • Certifications obtained;
  • Written scientific articles;
  • Membership in other entities (for example: associations, organizations, bodies, etc.).

Regarding settings for receiving notifications about Medic Chat Services , available to the Medic User, Medic Chat can obtain the following information regarding The user in question only if the User wishes to provide them:

  • Agreement to receive, by email and / or SMS, notifications regarding the activity of the User Account;
  • Agreement to receive Marketing Communications by e-mail and / or SMS;
  • Agreement to receive, via e-mail and / or SMS, news related to Medic Chat Services.

Regarding the settings for interpreting analyzes available to the User Medic , Medic Chat can get the following information about this User:

At the time of providing an answer by the Medical User to the question addressed to him by to a Patient User on the Medic Chat Application, Medic Chat obtains the following information:

At the time the Patient User performs an evaluation of the response received from User Medic on the Medic Chat Application, Medic Chat obtains the Patient User's opinion on how which the Medical User answered the question. This opinion may include data likely to allow identification of the Medical User, as well as data likely to allow the identification of the Patient User.

Regarding Medical Users' correspondence with the Medic Chat Team through channels of external communication (for example, by email, on the phone, on the official Facebook page of Medic Chat etc.) in to get general information about Medic Chat Services (for example: to receive support Technical Chat or other guidance), Medic Chat may obtain the following information regarding the Medic User in cause:

Regarding News Subscription, Marketing Communications and Account Activity Notifications of Medic Chat User and / or Services , Medic Chat obtains the following information regarding User Physician concerned:

Regarding the possibility for Medical Users to offer patients recommendations and advice physician In a virtual office , Medic Chat obtains the following information about the Medic User in cause:

The Medic user can provide patients with recommendations and medical advice in the virtual office through via a link sent by email or SMS. For this purpose, the Medical User may enter in Medic Chat application the telephone number and / or e-mail address of the target patient, in which case the User The physician must obtain at least prior express verbal consent from the patient in order transmission and processing of such data by Medic Chat. The Medic user fully assumes responsibility for obtaining the prior consent of the patient regarding the use of the number of telephone number and / or e-mail address of the patient (s), strictly in the case described.

b. Data collected

Every time a User visits or uses the Medic Chat Site or Application, there are certain categories of information about the User and the device used by him that are automatically collected by Medic Chat. The main categories of data that Medic Chat automatically collects are presented in the following.

Technical data , such as:

User web session data , such as:

Data on Users' Use of Site or Application Features Doctor Chat , such as:

Patient User Payments , such as the token received from payment processor following a successful payment and the User's decision to save payment information in the User account.

Data related to User Communication with the Medic Chat Team (for example: to obtain technical support, for clarifying general questions regarding Medic Chat Services, etc.), such as:

c. Location data

i. How and why Medic Chat obtains User Location data

User location information is provided by the web browser used by the user at when accessing and / or using the Medic Chat Website or Web Application.

This data helps identify the server closest to where the User is located in order to provide the content of the Medic Chat Web Application or Site in the most efficient way possible. Location data is also used to perform user demographics Medic Chat Web site and application and to more easily investigate certain technical issues in order constantly improving the services offered by Medic Chat.

ii. How to obtain and withdraw User consent to the collection and use of data on location

The user can agree to the collection and use of Medic Chat data user location through existing settings in the web browser being accessed Medic Chat Web Application or Website. For most web browsers, consent to collect, the use and transmission of data on the location of the User may be withdrawn at any time, also by via existing settings in the web browser used.

d. Data collected by and Data provided to Medic Chat transmitted to Third Parties

Automatically data collected by Medic Chat that may be transmitted to third parties counts the following:

Among Data provided to Medic Chat by Users and which may be transmitted to Third parties include:

e. Data collected by Medic Chat from third parties

This section lists data that Medic Chat may obtain from third parties at certain times. for specific purposes, in order to provide services efficiently to Users.

If Users choose to sign in to the Medic Chat App via Facebook, Google or Apple, at the time of each login , Medic Chat gets from Facebook, Google or Apple, where applicable, the following information about the User:

If Users choose to be notified via SMS in connection with Medic activity Chat or for Receiving Marketing Communications, Medic Chat obtains from Amazon, at the time of sending each SMS to Users, details regarding the delivery of SMS, such as: SMS delivery status, delivery date SMS, alerts, errors, etc.

If users choose to be notified by email about the activity Medic Chat or for receiving Marketing Communications, Medic Chat get from Amazon or Mailgun, after case:

At the time of payment, Stripe Payment Processor will send Medic Chat information about the status of that payment (for example, whether or not the payment was made successfully) and, if so The user wants to save the payment details for subsequent payments, an authentication token that will be used for this purpose. Medic Chat does not save the payment details of the User, but only that token. Card data or other confidential payment information cannot be deducted from this token.

8. Purpose of Data Processing

Medic Chat may process the personal data of the Users pursuant to art. 6, para. (1), lit. a), b), c) and / or f) of the GDPR . Thus, Medic Chat's right to process this information is granted by the presence of at least one of the following:

Whether it is Data provided directly by Users, Data automatically collected by the Physician Chat or data obtained from Third Parties, Medic Chat processes the Personal Data regarding the Users legally, equitably and transparently, only for well-defined and disclosed purposes Users. Medic Chat guarantees that all personal data processing operations you performs them in connection with the facilitation, improvement and efficiency of the provision of Medic Chat Services to Users.

In addition, all Personal Health Information [17] is processed by Medic Chat only with consent User Advice, which they explicitly provide when creating a User Account in the Medic Chat application by checking a box stating that they have read the information in this Privacy Policy.

In the following we will present the purposes for which Medic Chat processes the Personal Data described in section 7.

a. Purpose of Processing Provided Data

The data provided by Users directly to Medic Chat is mainly used in the following purposes:

b. Purpose of processing the Data collected

The data automatically collected by Medic Chat is used primarily for the following purposes:

c. Purpose of Processing Location Data

User location data when visiting and / or using the Web Application or Site Medic Chat are mainly used for the following purposes:

d. The purpose of the transmission of data to third parties and / or the collection of data from third parties

Medic Chat may transmit to or collect from third parties Personal Data about Users in the following purposes:

e. Transmission of Data to other entities, under special conditions

In the course of the Medic Chat activity, there may be situations in which the transmission of data to other entities with The personal nature of the Users is required either by the nature of the circumstances in question or by law in force. In such cases Medic Chat will notify Users of the circumstances, so that they can make an informed decision if they want to allow Medic Chat to continue to use their personal data.

Such exceptional circumstances in which Medic Chat may be required to provide Information on Users to other entities may appear in the following contexts:

9. Aggregation of Personal Data of Medical Users

a. What involves the aggregation of personal data of Medical Users

In the case of Medical Users, Medic Chat may create correlations and / or associations between Personal Data provided by them and other information related to Medical Users that the Medic Chat Team obtains from external sources. The aggregate data thus obtained shall be deemed to be also Personal Data and, in consequently, they will be processed in accordance with this Privacy Policy.

b. The purpose for which it is aggregated to the Personal Data of Medical Users

Medic Chat is also informed by external sources regarding the Personal Data provided by Users Doctors and aggregates the data they provide with information obtained from research conducted by Medic Chat to verify the veracity of the Data provided by Medical Users. The purpose for which Medic Chat achieves These checks are to ensure that only competent doctors have access to the Medic Chat Application they practice their profession legally and in accordance with the standards corresponding to their field of activity. In this way, Medic Chat aims to provide Patient Users with quality telemedicine services and to prevent fraud in the practice of the medical profession through the Medic Chat Application.

10. Purpose of Marketing Communications and Disclaimer

For Medic Chat it is important that its users are fully aware of the manner and purposes for which Medic Chat processes their Personal Data. Transmission of Marketing communications to Users is not part of the main business of Medic Chat and, like nor for the main purposes for which Medic Chat processes personal data. That's why we want that In this section we present both the purposes for which Medic Chat transmits Marketing Communications and how Users can prevent receiving them.

a. Purpose of Marketing Communications

Medic Chat can send Marketing Communications to its Users through various channels communication , such as:

The main purposes of which Medic Chat sends Marketing Communications to its Users are the following:

All of these goals are related to the constant improvement of Medic Chat Services, as well as interest Medic Chat team to promote and develop its business.

b. Disclaimer of Marketing Communications

Medic Chat uses Users' Personal Data only on the basis of express and prior consent offered by them. Therefore, Users have the option to opt out of receiving Communications at any time marketing by withdrawing consent in one of the following ways:

11. Disclosure of Personal Data of Some Users to Other Users

In order to fulfill its contractual obligations (more specifically, the provision of telemedicine services high quality to Users), Medic Chat reveals the personal data of some Users to other Users, either from the same category or from different categories. In the following we present to you about what It is personal data, to which Users are disclosed and at what times, as well as the purpose of the disclosure of this Information.

a. Disclosure of Patient User Data to Medical Users

i. Disclosed data

The personal data of Patient Users disclosed to Medical Users are the following:

ii. Time to reveal

Patient Users' personal information is disclosed to Medical Users on during the interaction between the Patient User and the chosen Medical User, as follows:

iii. Purpose of Disclosure

Doctor Chat Reveals to Patient Users Patient User Personal Data Mentioned Above so that the Patient User can receive pertinent medical recommendations and advice, adapted to the needs and his ailments. This operation of transmitting the Personal Data of the Patient User it is thus performed exclusively in the interest of the Patient User. The Patient user gives his consent for this way of processing your Personal Data by accepting the Terms and Conditions of use of Medic Chat Services and this Privacy Policy at the time of creating an Account User in the Medic Chat Application.

Regarding the reviews and evaluations provided by Patient Users following the interaction with a particular Medic User, the purposes of their disclosure to all Users of the Medic Chat Application are the following:

b. Disclosure of Patient User Data to Other Patient Users

i. Disclosed data

Patient Users' personal data disclosed to other Patient Users is the following:

ii. Time to reveal

Patient Users' first names are disclosed to other Patient Users at the time of publication by these of a review or evaluation of a Medical User.

Reviews and Ratings Provided by the Patient User Following Interaction with a Specific User Medic are disclosed to all Users of the Medic Chat Application at the time of review or evaluation provided by the Patient User is approved by the Medic Chat Team.

iii. Purpose of Disclosure

Medic Chat reveals to other Patient Users the first name, reviews and ratings provided by certain Patient Users Following Interaction with a Specific Medical User, Where Patient Users choose to provide such reviews or ratings. The purposes of their disclosure to all other Users are Medic Chat are as follows:

c. Disclosure of Medical User Data to Patient Users

i. Disclosed data

The personal data of Medical Users disclosed to Patient Users are the following:

ii. Time to reveal

Some of the Personal Data mentioned in the previous point that the Medical User provides within Its User Account are disclosed as soon as it includes and saves that information in his User Account. This data is available to all Users of the Medic Chat Application and may be modified by the Medical User at any time.

The answers provided by the Medical User to the questions asked by the Patient User, as well as, if as the case may be, subsequent messages by which the Medical User requests the Patient User for more details in related to his state of health are disclosed to the Patient User at the time the User The doctor gives her an answer or sends her an extra message. This statement is also valid for any files attached by the Medical User to the reply or message sent to the User Patient.

Reviews and Ratings Provided by the Patient User Following Interaction with a Specific User Medic are disclosed to all Users of the Medic Chat Application at the time the Patient User provides such a review or evaluation.

iii. Purpose of Disclosure

The personal data that the Medical User provides in his User Account are disclosed to Patient Users to allow them to choose to address a corresponding Medical User with their needs, desires, expectations and interests, in full knowledge of the facts.

The answers provided by the Medical User to the questions asked by the Patient User, as well as, if as the case may be, subsequent messages by which the Medical User requests the Patient User for more details in in connection with his state of health are disclosed to the Patient User for the purpose of fulfilling the obligations Medic Chat Agreement with Patient Users (namely, Providing Telemedicine Services high quality). This statement also applies to any files attached by the Medical User response or message sent to the Patient User.

Regarding the reviews and evaluations provided by Patient Users following the interaction with a particular Medic User, the purposes of their disclosure to all other Users of the Medic Chat Application are the following:

d. Disclosure of Medical User Data to Other Medical Users

i. Disclosed data

The personal data of Medical Users disclosed to other Medical Users are the following:

ii. Time to reveal

Some of the Personal Data mentioned in the previous point that the Medical User provides within Its User Account are disclosed as soon as it includes and saves that information in his User Account. This data is available to all Users of the Medic Chat Application and may be modified by the Medical User at any time.

Reviews and Ratings Provided by a Patient User Following Interaction with a Specific User Medic are disclosed to all Users of the Medic Chat Application at the time the Patient User provides such a review or evaluation.

iii. Purpose of Disclosure

Both the Personal Data that the Medical User provides in his User Account and the reviews and the ratings of a Medical User are disclosed to other Medical Users for the following purposes:

e. Disclosure of User Data to the Medic Chat Team

The Medic Chat Team means the developers who develop and maintain Medic Chat Services and those who responsible for the technical assistance of Users.

i. Disclosed data

The Medic Chat team has access to all the Personal Data of all Users, as they were presented above.

ii. Time to reveal

The personal data of all Users is currently being disclosed to the Medic Chat Team transmission of that data to Medic Chat servers.

iii. Purpose of Disclosure

The main purposes for which the Personal Data of all Users are disclosed to the Team Medic Chat are as follows:

12. Users' Rights to the Processing of their Personal Data by Medic Chat

According to Chapter III of the GDPR [19] the processing of their personal data, in this case, Medic Chat Users, have the following rights in connection with Medic Chat's Personal Information Processing:

Medic Chat undertakes to respond promptly to requests within the applicable legal provisions. formulated by Users regarding the aforementioned rights. Thus, Medic Chat will do everything possible the resolution of such requests shall have the following characteristics:

In the following we will show you the contents of the respective rights (ie what actions are possible under that right) and how those rights may be exercised in practice in within the Application Medic Chat (ie how these actions can be implemented by Medic Chat Users).

a. Content of rights

As we mentioned, by rights content we mean the actions that Users have taken. handy in on the basis of those rights. Specifically, the content of the rights refers to what users can do ask Medic Chat to link to their Personal Data.

i. Right to access Personal Data

According to art. 15 of the GDPR , Users have the right to request Medic Chat:

ii. The right to rectification of data

According to art. 16 of the GDPR , Users can request Medic Chat to make the following changes:

Medic Chat will notify the User that the Personal Data in question has been rectified or completed according to the instructions received from it. There may also be situations where Medic Chat did public or transmitted to Third Parties the Data of the User requesting their rectification or completion. In the In these cases, Medic Chat communicates to those Third Parties the changes requested by the User.

iii. The right to delete data ("the right to be forgotten")

According to art. 17, para. (1) of the GDPR , Users may request Medic Chat to delete their Data with personal only if:

There may be situations where Medic Chat has made public or transmitted to third parties the User's Data requests their deletion. In this case, according to art. 17 para. (2) of the GDPR, Medic Chat will take action reasonable measures, including technical measures, to inform operators who process personal data that The user has requested that these operators delete any links to such data or any copies or reproductions of this Personal Data.

According to art. 17, para. (3) of the GDPR , Medic Chat has no obligation to delete Personal Data of the User who has made a request to this effect, insofar as the processing of this Data is required:

We would like to inform you that art. 17, para. (3) of the GDPR provides two more hypotheses in which Medic Chat does not have the obligation to delete the personal data of the User following his request, but the three presented above are the most likely circumstances in which Medic Chat could refuse such a request.

Medic Chat will notify the User that his / her personal data has been deleted.

iv. Right to Restrict Data Processing

According to art. 18, para. (1) of the GDPR , Users may obtain a restriction on the processing of their Data personal information by Medic Chat:

According to art. 18, para. (2) of the GDPR , Medic Chat may continue to process Personal Data of the User even following a restriction request, if:

Before lifting the processing restriction Medic Chat will inform the User who obtained the restriction processing about this fact.

v. Right to Data Portability

According to art. 20, para. (1) of the GDPR , Users may exercise their right to data portability in the following forms:

Both forms of exercising the right to data portability are possible only if they are fulfilled cumulatively the following conditions:

According to art. 20, para. (4) of the GDPR Medic Chat may refuse requests for data porting To the extent that this infringes the rights and freedoms of others.

vi. The right to object to the processing of data

According to art. 21, para. (1) of the GDPR , Users may object to the processing of their Data by Medic Chat at any time, for reasons related to the particular situation in which they find themselves, in the following cases:

In such a case, Medic Chat will no longer process the User's Personal Data. With all Medic Chat will continue to process the Personal Data of the opposing User processing if:

vii. Automatic decision-making rights, including profiling

According to art. 22, para. (1) of the GDPR , Users may request Medic Chat not to be subject to a decision based exclusively on automatic processing, including profiling, if this has legal effect regarding the User or if it affects him in a similar way to a significant extent.

However, Medic Chat may continue, in relation to Users who have opposed automatic decision making, automatic processing:

b. Exercising rights

As stated, by exercising the rights we mean the ways in which Users may, in particular, address to Medic Chat various requests regarding their personal data that are subject to processing by Medic Chat.

Users can make the above requests in the following ways:

13. Storing Personal Data

a. How long will we store Users' Personal Data?

Medic Chat will store Users' personal data for as long as this is necessary achieving the goal of Medic Chat, which is to provide high quality telemedicine services to Its users. Thus, in principle, Medic Chat will store the Personal Data of the Users as much as long as they have a User Account in the Medic Chat Application. Users can request deletion at any time or closing your account [23] and Medic Chat will these requests, subject to retention certain Information including after the closure of the User Account, in situations where the legislation applicable or the legitimate interests [24] of Medic Chat require it. Data like that will be archived. They will not be used by Medic Chat, except as required by law for the purpose of proving contractual relations.

Medic Chat undertakes to review at regular intervals the personal data stored to ensure that this data is not kept longer than necessary. In each review, if you will consider that the retention of certain personal data is no longer of interest, Medic Chat will permanently delete it this information.

b. Where and how do we store Personal Data?

All personal data is stored on the servers of the cloud service providers with which Medic Chat work. These include: Amazon Web Services, Microsoft Azure, Google Cloud Services, and Atlas Mongodb. In principle, the data is stored on servers in the European Union, but if any of the The cloud services used are not valid in the European Union, we reserve the right to store certain data on a personal basis and on servers outside the Member States.

Although Medic Chat works with cloud service providers, they do not have access to Data personal data of Medic Chat Users, and the data processing processes are done in a way secure, using state-of-the-art cryptographic techniques.

Backups of all Personal Data are backed up daily to avoid any kind compromise of Medic Chat User Data in the event of adverse technical incidents. Copies of that were created at least a year ago will be deleted.

14. Security of Personal Data Processed

One of the principles related to the processing of personal data provided in art. 5 to the GDPR it is about maintaining the integrity and confidentiality of data. According to this principle, character data must be “processed in a way that ensures adequate security of personal data, including protection against unauthorized or unlawful processing and against loss, destruction or accidental damage, by taking appropriate technical or organizational measures ”.

Thus, Medic Chat undertakes to implement and maintain, throughout processing, technical measures and appropriate organizational arrangements to ensure the protection of the security, confidentiality and integrity of the Data with personal in accordance with the provisions art. 32 of the GDPR and industry standards. In addition, Medic Chat undertakes to evaluate and regularly review these measures in relation to potential risks, as well as constantly monitor them compliance with the measures taken with the legislation in force, in order to maintain a high level of data protection processed.

Specifically, among the measures implemented by Medic Chat to ensure the protection of data personally includes the following:

Despite the measures taken to protect the Personal Data of Users, we point out that the transmission of information over the Internet is not completely secure, and there is a risk that the Data will be viewed and used by unauthorized third parties. Therefore, we cannot be held responsible for such vulnerabilities of systems that are not under the control of Medic Chat.

15. Security incidents

a. Definition

By Security Incident we mean any act of destruction, loss, alteration or access or disclosure. unauthorized, culpable or intentional production of personal data processed in any way by to Medic Chat, if that action is likely to pose a high risk to your rights and Users' freedoms. The severity of this risk is assessed on the basis of elements such as:

b. Notification procedure

Following a Security Incident, Medic Chat undertakes to notify you, as appropriate, of any all Users, or only the affected Users, by communicating the occurrence of the Security Incident and a its circumstances, as well as the procedure established by Medic Chat to minimize harm The incident. Communication will be done by e-mail and, therefore, Users are solely responsible for themselves ensure that their contact details provided to Medic Chat are accurate and up to date.

Medic Chat will inform Users about the occurrence and circumstances of the Security Incident to the extent which is likely to pose a high risk to the rights and freedoms of Users. The information will be:

The information will include details of the circumstances of the Security Incident, such as the type Security Incident, Scope of Incident, Data Categories Affected, Measures Planned or Implemented application to remedy the effects of the Incident and the like.

16. Data Transfer Abroad

Medic Chat stores personal data on servers in the European Union, but if any of the Cloud services used is not valid in the EU, Medic Chat reserves the right to store certain Personal data and on servers outside EU Member States. We will always take action ensure that any international transfer of personal data is carefully managed in order to protect the rights and interests of our Users. Transfers to service providers and other third parties will always be protected by contractual commitments and, where appropriate, by other guarantees, such as standard contractual contracts issued by the European Commission or various certification schemes.

17. Management of Personal Data by the Medic Chat Team

a. Medic Chat Team Access to Users' Personal Data

In order to provide Users with access to the telemedicine services that Medic Chat undertakes to provide and, implicitly, to ensure that Medic Chat's contractual obligations to Users are met, The Medic Chat team has access to all the Personal Data of the Users to which Medic Chat has access according to section 7 of this Privacy Policy. Also the ways and purposes in which the Team Medic Chat processes User Data is identical to that used, respectively tracked by Medic Chat, so as described in Section 7.

b. Measures taken to ensure the protection of personal data

To ensure that the Medic Chat Team complies exactly with the terms of this Policy Privacy, Medic Chat implements measures such as:


[1] GDPR can be viewed here .

[2] For more details on the purpose of GDPR, you can visit this page .

[3] Law no. 190/2018 can be consulted by accessing this page .

[4] Note: In this Privacy Policy, you will notice that certain notions are written with uppercase character. This means that those concepts have a specific meaning to this Privacy Policy, which is explained in section 2. Therefore, in order to see the definitions of capitalized terms, please please refer to section 2 “Definitions” of this Privacy Policy.

[5] In English, this notion is known as Data Controller.

[6] In English, this notion is known as Data Processor.

[7] According to Art. 4, point 1 of the GDPR.

[8] According to Art. 4, point 15 of the GDPR.

[9] According to recitals 47 and 49 of the GDPR.

[10] According to Art. 4, point 7 of the GDPR.

[11] According to Art. 4, point 8 of the GDPR.

[12] According to Art. 4, point 2 of the GDPR.

[13] According to Art. 30, para. (2) of GEO no. 196 of 18 November 2020 for the modification and the completion of Law no. 95/2006 on health care reform, published in the Official Gazette no. 1108 of 19 November 2020.

[14] Some Patient Users may be surprised at images / photos provided with the question posed to the Medical User, features which may lead to the visual identification of the Users concerned. Medic Chat is committed to gives such images / photos the same level of protection and privacy as granted any other Personal Data, as set out in this Privacy Policy.

[15] This data is not stored by Medic Chat. Medic Chat only stores one token associated with the card, obtained from the payment processor after the payment is successfully made. If The Patient User chooses to save the payment information, that token will be used to make future payments, not the credit or debit card details with which the payment was made.

[16] If at the time of receiving such an invitation the patient concerned does not is among the Patient Users of Medic Chat Services, they will need to create a User on the Medic Chat application to receive access to the consultations in the virtual office within Medic Chat Services.

[17] According to Art. 9, para. (1) of the GDPR health data can only be processed if the data subjects have given their prior consent to the processing of such data for a specific purpose, such as establishing a medical diagnosis.

[18] In accordance with Art. 30, para. (1) of the GDPR.

[19] Chapter on the rights of data subject to data processing personal, accessible to this link .

[20] In exceptional cases we mean, for example: situations where the request The user has a complicated process to solve, situations in which the user has done more simultaneous requests, situations in which the Medic Chat Team faces a very large number of requests simultaneous from Users etc.

[21] Please read point vi. "The right to oppose processing data ” in this section.

[22] Please read point vi. "The right to oppose processing data ” in this section.

[23] According to Section 11.

[24] By legitimate interests we mean, for example, the use of personal data to justify the execution of a contract by Medic Chat or to establish, exercise or defend a Medic Chat right in court.