How we protect your data
Last updated:
Language version notice
These legal documents were drafted in Polish. Other language versions may be machine translations and are provided for convenience only. In case of discrepancies, the Polish version prevails.
Our principles
This page explains in plain language what we do with data. The legally binding version is the Privacy Policy.
We collect only what is needed
You do not need an account, or to tell us anything about your health, in order to browse. Data appears only when you ask for something: booking an appointment, creating an account, writing to us.
We do not sell data
We neither sell nor rent data. We do not share it with advertisers beyond measuring campaign performance, which needs your separate consent and which you can withdraw at any time.
Tracking is off by default
Until you click consent, neither analytics nor campaign measurement runs. On health-related pages, such as the booking wizard, third-party scripts do not load at all, regardless of consent.
Only those who must, have access
Data is separated between providers at the database level, and access is role-based on a least-privilege basis. One provider cannot see another provider's patients.
Who is responsible for your data
It depends where you are in the service, and it decides who to address your questions to.
- Browsing the site, holding a patient account, writing to us - the controller is Medova (EPKO sp. z o.o.). Ask us.
- Booking an appointment, attending a visit, corresponding with the front desk - the controller is the healthcare provider. We are only the tool it uses, acting on its instructions.
If you write to us about something the provider is responsible for, we forward your request to it and tell you where it went.
Health data
Information about vaccinations, illnesses and treatment is special category data under Article 9 GDPR. We protect it more strictly than the rest.
Medova does not keep a health record of its own. The feature that collected health declarations (pregnancy, immunosuppression, chronic conditions, allergies, blood type) was switched off in July 2026, and the data collected was irreversibly deleted together with the table that held it.
The only health data we process as controller is the vaccine your enquiry concerns. We collect it on the basis of explicit consent and delete it automatically after 90 days.
Records of a visit are created by the provider, are governed by medical records legislation, and the provider decides who may access them.
Automation and artificial intelligence
We take no decisions about you by automated means alone. We do not refuse service, set prices or score you with an algorithm.
Where we use language models (translation, country health summaries, the demonstration voice assistant) we label it, and you can always ask to speak to a person. The details are in AI Transparency.
We do not use patient data or provider content to train models.
Who we entrust data to
These are the companies that process data on our behalf under data processing agreements. The table is generated from the supplier register kept in the service's source code, so it cannot name a provider we no longer use.
| Processor | What they process for us | Where the data sits | Transfer basis |
|---|---|---|---|
| Supabase Inc. | Database, authentication, file storage | AWS eu-central-1 (Frankfurt, Germany) | Data stays in the EU; standard contractual clauses for technical support |
| Hetzner Online GmbH | Application hosting (dedicated server) | Germany | No transfer outside the EEA |
| Cloudflare, Inc. | CDN, attack protection, TLS termination | Global network, EU points of presence | Standard contractual clauses |
| Stripe Payments Europe, Ltd. | Payments and settlement | Ireland | Standard contractual clauses; EU-US Data Privacy Framework |
| Resend, Inc. | Transactional email (confirmations, reminders) | United States | Standard contractual clauses |
| Upstash, Inc. | Rate limiting (stores a hashed IP address only) | European Union | Standard contractual clauses |
| SMSAPI Sp. z o.o. | SMS delivery to patients in Poland (confirmations, reminders) | Poland | No transfer outside the EEA |
| Twilio Inc. | SMS delivery to patients outside Poland (confirmations, reminders) | United States | Standard contractual clauses; EU-US Data Privacy Framework |
| Anthropic PBC | Language-model features (translations, support handling) | United States | Standard contractual clauses; zero-retention mode, no training on the data |
| Google LLC | Analytics (GA4, with consent), maps and geocoding, fonts, Tag Manager | United States | Standard contractual clauses; EU-US Data Privacy Framework |
| Meta Platforms Ireland Limited | Conversion pixel (Meta Pixel) for paid Meta/Instagram campaigns, with marketing consent | Ireland / global network | Standard contractual clauses; EU-US Data Privacy Framework |
| ElevenLabs Inc. | AI receptionist demo widget on the clinics landing page | United States | Standard contractual clauses; EU-US Data Privacy Framework |
Your rights
You have the right to access your data and receive a copy, to have it corrected, erased or its processing restricted, to data portability, to object to processing based on our legitimate interest, and to withdraw consent at any time.
The fastest route: sign in and go to Settings → Privacy. Downloading a copy of your data and deleting your account work immediately, without waiting for us. Cookie consent is changed in the site footer.
Anything more complex goes to dpo@medova.health. We answer within one month at the latest, and for complex matters we may extend that by two months, telling you in advance.
How we secure data
- The application runs on a server in Germany, the database in the European Union.
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- Data separated between providers at the database level.
- Two-factor sign-in available for every account.
- Logging of access to sensitive data and of administrative actions.
- Backups with regularly tested restores.
Found a vulnerability? Write to security@medova.health. We do not pursue good-faith researchers.
Data Protection Officer
You can write directly to our Data Protection Officer about anything concerning your data. It costs nothing and the correspondence is confidential.
Email: dpo@medova.health
EPKO sp. z o.o., ul. Podleśna 2, 05-270 Marki, Poland
