MedicalApp

Data Protection (GDPR)

Last updated: 4 August 2026

Roles in data processing

Understanding the roles correctly is essential for compliance:

RoleWhoMeaning
ControllerThe clinic or medical practice Decides what data is collected, for what purpose and how long it is kept. Answers to patients and to the supervisory authority.
ProcessorSfetcu Adrian Marius P.F.A. Processes data exclusively on the clinic's instructions, by providing the technical platform.
Sub-processorHostico SRL, Romania (European Union) Provides the infrastructure on which the application runs and stores the data.

Mandatory before processing real patient data: a Data Processing Agreement under Art. 28 GDPR must be signed between the clinic and the platform provider. Without it, both parties are non-compliant.

Where data is stored

All data is hosted by Hostico SRL, Romania (European Union). Data does not leave the European Union, so no third-country transfer safeguards under Chapter V GDPR are required.

Technical measures implemented

What each clinic must do

The platform provides the technical means, but full compliance also requires organisational measures:

Breach notification

If we become aware of a security incident affecting a clinic's data, we will inform them without undue delay and in any case within 24 hours, so the clinic can meet its own 72-hour notification obligation to the supervisory authority.

Contact

For any question regarding data protection in relation to the platform, write to office@itrepair.ro. For your own medical data, please contact the clinic where you are registered.

Note: This document was drafted to cover the usual situations of a medical platform and reflects the measures actually implemented. It does not constitute legal advice.

Sfetcu Adrian Marius P.F.A. · CUI 51442597 · Voluntari, judetul Ilfov
© 2026 MedicalApp