Skip to main content
Ваша конфиденциальность

Как мы защищаем ваши данные

Последнее обновление:

Документ показан на английском языке

Этот документ недоступен на языке, на котором вы просматриваете сайт, поэтому мы показываем английскую версию. Это действующий текст, вступивший в силу с указанной выше даты. Юридически обязательной остаётся польская версия.

Our principles

This page explains in plain language what we do with data. The legally binding version is the Privacy Policy.

We collect only what is needed

You do not need an account, or to tell us anything about your health, in order to browse. Data appears only when you ask for something: booking an appointment, creating an account, writing to us.

We do not sell data

We neither sell nor rent data. We do not share it with advertisers beyond measuring campaign performance, which needs your separate consent and which you can withdraw at any time.

Tracking is off by default

Until you click consent, neither analytics nor campaign measurement runs. On health-related pages, such as the booking wizard, third-party scripts do not load at all, regardless of consent.

Only those who must, have access

Data is separated between providers at the database level, and access is role-based on a least-privilege basis. One provider cannot see another provider's patients.

Who is responsible for your data

It depends where you are in the service, and it decides who to address your questions to.

  • Browsing the site, holding a patient account, writing to us - the controller is Medova (EPKO sp. z o.o.). Ask us.
  • Booking an appointment, attending a visit, corresponding with the front desk - the controller is the healthcare provider. We are only the tool it uses, acting on its instructions.

If you write to us about something the provider is responsible for, we forward your request to it and tell you where it went.

Health data

Information about vaccinations, illnesses and treatment is special category data under Article 9 GDPR. We protect it more strictly than the rest.

Medova does not keep a health record of its own. The feature that collected health declarations (pregnancy, immunosuppression, chronic conditions, allergies, blood type) was switched off in July 2026, and the data collected was irreversibly deleted together with the table that held it.

The only health data we process as controller is the vaccine your enquiry concerns. We collect it on the basis of explicit consent and delete it automatically after 90 days.

Records of a visit are created by the provider, are governed by medical records legislation, and the provider decides who may access them.

Automation and artificial intelligence

We take no decisions about you by automated means alone. We do not refuse service, set prices or score you with an algorithm.

Where we use language models (translation, country health summaries, the demonstration voice assistant) we label it, and you can always ask to speak to a person. The details are in AI Transparency.

We do not use patient data or provider content to train models.

Who we entrust data to

These are the companies that process data on our behalf under data processing agreements. The table is generated from the supplier register kept in the service's source code, so it cannot name a provider we no longer use.

ProcessorWhat they process for usWhere the data sitsTransfer basis
Supabase Inc.Database, authentication, file storageAWS eu-central-1 (Frankfurt, Germany)Data stays in the EU; standard contractual clauses for technical support
Hetzner Online GmbHApplication hosting (dedicated server)GermanyNo transfer outside the EEA
Cloudflare, Inc.CDN, attack protection, TLS terminationGlobal network, EU points of presenceStandard contractual clauses
Stripe Payments Europe, Ltd.Payments and settlementIrelandStandard contractual clauses; EU-US Data Privacy Framework
Resend, Inc.Transactional email (confirmations, reminders)United StatesStandard contractual clauses
Upstash, Inc.Rate limiting (stores a hashed IP address only)European UnionStandard contractual clauses
SMSAPI Sp. z o.o.SMS delivery to patients in Poland (confirmations, reminders)PolandNo transfer outside the EEA
Twilio Inc.SMS delivery to patients outside Poland (confirmations, reminders)United StatesStandard contractual clauses; EU-US Data Privacy Framework
Anthropic PBCLanguage-model features (translations, support handling)United StatesStandard contractual clauses; zero-retention mode, no training on the data
Google LLCAnalytics (GA4, with consent), maps and geocoding, fonts, Tag ManagerUnited StatesStandard contractual clauses; EU-US Data Privacy Framework
Meta Platforms Ireland LimitedConversion pixel (Meta Pixel) for paid Meta/Instagram campaigns, with marketing consentIreland / global networkStandard contractual clauses; EU-US Data Privacy Framework
ElevenLabs Inc.AI receptionist demo widget on the clinics landing pageUnited StatesStandard contractual clauses; EU-US Data Privacy Framework

Your rights

You have the right to access your data and receive a copy, to have it corrected, erased or its processing restricted, to data portability, to object to processing based on our legitimate interest, and to withdraw consent at any time.

The fastest route: sign in and go to Settings → Privacy. Downloading a copy of your data and deleting your account work immediately, without waiting for us. Cookie consent is changed in the site footer.

Anything more complex goes to dpo@medova.health. We answer within one month at the latest, and for complex matters we may extend that by two months, telling you in advance.

How we secure data

  • The application runs on a server in Germany, the database in the European Union.
  • Encryption in transit (TLS 1.3) and at rest (AES-256).
  • Data separated between providers at the database level.
  • Two-factor sign-in available for every account.
  • Logging of access to sensitive data and of administrative actions.
  • Backups with regularly tested restores.

Found a vulnerability? Write to security@medova.health. We do not pursue good-faith researchers.

Data Protection Officer

You can write directly to our Data Protection Officer about anything concerning your data. It costs nothing and the correspondence is confidential.

Email: dpo@medova.health
EPKO sp. z o.o., ul. Podleśna 2, 05-270 Marki, Poland

Complaint to a supervisory authority

If you believe we process your data unlawfully, you may lodge a complaint:

President of the Personal Data Protection Office (UODO)
ul. Stawki 2, 00-193 Warsaw, Poland
Phone: +48 22 531 03 00
Web: www.uodo.gov.pl
Email: kancelaria@uodo.gov.pl

Living in another European Economic Area country? You may also complain to the authority for your place of residence or work.