Privacy Policy
1. Who we are
The MedicalApp platform is developed and operated by Sfetcu Adrian Marius P.F.A., VAT ID 51442597, based in Voluntari, judetul Ilfov, Romania. You can reach us at office@itrepair.ro or by phone at 0750.219.216.
Important distinction: for patient data entered into the platform, the clinic is the data controller and we act as a data processor. The clinic decides what data is collected and for what purpose; we merely provide the technical means.
This means that requests concerning your medical data should be addressed directly to your clinic, not to us.
2. What data is processed
| Category | Examples | Entered by |
|---|---|---|
| Identification | Name, surname, national ID number or passport, date of birth, sex, citizenship | Patient or clinic staff |
| Contact | Phone, email, address | Patient or clinic staff |
| Health data | Consultations, diagnoses, measurements, prescriptions, uploaded documents | Medical staff |
| Appointments | Date, time, service, doctor, reason for visit | Patient or reception |
| Technical | IP address, access time, actions performed in the application | Collected automatically, for security |
3. Legal basis and purpose
- Performance of a contract (Art. 6(1)(b) GDPR) — for booking and providing the requested medical services.
- Healthcare purposes (Art. 9(2)(h) GDPR) — for health data processed for medical assistance.
- Explicit consent (Art. 9(2)(a) GDPR) — for data you voluntarily provide in the online booking form.
- Legal obligations (Art. 6(1)(c) GDPR) — retention of medical records under healthcare legislation.
- Legitimate interest (Art. 6(1)(f) GDPR) — platform security, access logging and abuse prevention.
4. Retention periods
Medical data is retained for the period required by healthcare legislation. Appointment data and access logs are retained for the duration of the contract between the clinic and the provider, plus any period required to meet legal obligations. Upon termination, the clinic receives a full copy of the data, which is then deleted from our systems.
5. Where the data is stored
All data is stored on servers provided by Hostico SRL, Romania (European Union). Data does not leave the European Union. No transfer to third countries takes place.
The hosting provider acts as a sub-processor and has access to the infrastructure, not to the content of the data in a usable form when encryption at rest is enabled.
6. Who else has access
We do not sell or rent personal data. Data may be accessible to:
- authorised staff of your clinic, limited to their assigned role;
- the hosting provider, which maintains the technical infrastructure;
- public authorities, where a legal obligation exists.
Our technical staff access clinic data only at the clinic's express request, solely to resolve a technical issue, and every such access is logged.
7. Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability and objection. You also have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP).
To exercise rights concerning your medical data, please contact the clinic where you are registered, as it is the data controller.
8. Security measures
- Encrypted connection (HTTPS) for all traffic
- Role-based access, with permissions limited per user type
- Optional two-factor authentication for accounts with extended privileges
- Access log recording every opening of a patient record
- Passwords stored irreversibly hashed; protection against password-guessing attacks
- Encryption at rest for uploaded documents, where enabled by the platform administrator
- Regular backups of the database and documents
Note: This document was drafted to cover the usual situations of a medical platform and reflects the measures actually implemented. It does not constitute legal advice.