Data Protection (GDPR)
Roles in data processing
Understanding the roles correctly is essential for compliance:
| Role | Who | Meaning |
|---|---|---|
| Controller | The clinic or medical practice | Decides what data is collected, for what purpose and how long it is kept. Answers to patients and to the supervisory authority. |
| Processor | Sfetcu Adrian Marius P.F.A. | Processes data exclusively on the clinic's instructions, by providing the technical platform. |
| Sub-processor | Hostico SRL, Romania (European Union) | Provides the infrastructure on which the application runs and stores the data. |
Mandatory before processing real patient data: a Data Processing Agreement under Art. 28 GDPR must be signed between the clinic and the platform provider. Without it, both parties are non-compliant.
Where data is stored
All data is hosted by Hostico SRL, Romania (European Union). Data does not leave the European Union, so no third-country transfer safeguards under Chapter V GDPR are required.
Technical measures implemented
- Access control — role-based permissions; doctors see only their own patients
- Two-factor authentication — available for accounts with extended privileges
- Access log — records who opened each record, when, and from which IP address
- Encryption in transit — HTTPS with HSTS enforced
- Encryption at rest — uploaded documents encrypted with AES-256-GCM using envelope encryption, where enabled
- Attack protection — login rate limiting, CSRF protection, upload content validation, anti-robot verification on public forms
- Data separation — each clinic's data is logically isolated at query level
- Backups — regular, with full export available to the controller at any time
- Session expiry — after 30 minutes of inactivity
What each clinic must do
The platform provides the technical means, but full compliance also requires organisational measures:
- Inform patients about the processing of their data (privacy notice)
- Maintain a record of processing activities (Art. 30(1))
- Define an internal retention and deletion policy
- Have a procedure for notifying breaches within 72 hours
- Appoint a Data Protection Officer, where required
- Train staff on confidentiality
Breach notification
If we become aware of a security incident affecting a clinic's data, we will inform them without undue delay and in any case within 24 hours, so the clinic can meet its own 72-hour notification obligation to the supervisory authority.
Contact
For any question regarding data protection in relation to the platform, write to office@itrepair.ro. For your own medical data, please contact the clinic where you are registered.
Note: This document was drafted to cover the usual situations of a medical platform and reflects the measures actually implemented. It does not constitute legal advice.