DATA PROTECTION
Privacy Policy
This operational template must be reviewed against the clinic’s actual processing, retention and legal obligations before the public registration link is advertised.
Policy version: 2026-07-26
1. Information collected
The portal may store identity and contact details, profile preferences, appointment and vacation requests, comments, consent history, security logs and medical information voluntarily supplied for safer care.
2. Why information is used
Information is used to operate the member account, manage appointments, assess treatment safety, respond to requests, keep records, protect the service and meet applicable clinic obligations.
3. Medical information
Complete medical details are restricted to authorized clinical administration. Reception users receive limited safety flags rather than the full medical text.
4. Access and security
Access is role-based and important actions are logged. Passwords are stored as cryptographic hashes. No internet service can guarantee absolute security, so members should use a unique password and enable two-step verification when available.
5. Sharing
Information should only be shared with authorized clinic personnel and service providers required to operate the portal, subject to suitable confidentiality and data-protection controls. It is not intended for sale to advertisers.
6. Retention and requests
Retention periods must be defined by the clinic according to medical, legal and operational requirements. Members can export account data from the portal and may submit access, correction or deletion requests, subject to records the clinic must lawfully retain.
7. Photographs and communications
Treatment photographs and appointment communications use separate consent choices. Marketing use requires separate approval and should not be inferred from account creation.
8. Contact
Privacy questions and data requests should be sent through the clinic’s published contact channels.
