Skip to main content
Datenschutz

Datenschutzerklärung

Zuletzt aktualisiert:

Dokument auf Englisch

Dieses Dokument liegt in der von Ihnen gewählten Sprache nicht vor, daher zeigen wir die englische Fassung. Es ist der aktuelle Text, gültig ab dem oben genannten Datum. Rechtsverbindlich bleibt die polnische Fassung.

In short

Medova is a platform operated by EPKO sp. z o.o. This policy describes what we do with the personal data of people who visit medova.health and use an account with us.

  • We do not sell your data and we do not share it with advertisers beyond what you consent to.
  • Analytics and marketing are off by default until you switch them on in the consent banner.
  • We do not keep a health record of our own. Health data about you, where it exists at all, lives in a clinic's records, not ours. See „When the clinic is the controller, not us”.
  • You can download your data, correct it, delete your account and withdraw consent at any time.

The full text is below. If anything is unclear, write to our Data Protection Officer at dpo@medova.health.

Medical disclaimer

Medova does not provide medical services, does not diagnose and does not give medical advice. Information about diseases and vaccines is educational and does not replace a consultation with a doctor. In an emergency call your local emergency number (112 in Poland and the EU).

1. Who controls your data

The controller of personal data is:

EPKO sp. z o.o.
ul. Podleśna 2, 05-270 Marki, Poland
Company register (KRS): 0000908693, Tax ID (NIP): 1251720637, Statistical ID (REGON): 389307530

General contact: office@medova.health
Data protection matters: dpo@medova.health

This policy covers medova.health and its subpages, the user account, contact forms, and the panel used by healthcare providers working with Medova.

2. When the clinic is the controller, not us

This is the most important distinction in this document, because it decides who you address your requests to.

We are the controller when you browse the site, create a patient account, subscribe to our newsletter, fill in a contact form or use the provider search. Everything described in this policy applies.

The healthcare provider is the controller when your data goes into its panel: an appointment booking with a specific provider, the patient record, notes from a visit, a pre-visit form, correspondence with the front desk. In those cases Medova is only a processor, acting on the provider's documented instructions under a data processing agreement concluded pursuant to Article 28 GDPR.

In practice:

  • Questions about the content of medical records, how long they are kept and who may see them go to the provider. We have no right to change or disclose them on our own initiative.
  • If you send us a request that concerns the provider's data, we pass it on without undue delay and tell you where it went.
  • The processing agreement we conclude with providers, including the list of sub-processors, is available in the service as a separate document.

Medova does not maintain a patient health profile of its own. The feature that collected such declarations (pregnancy, immunosuppression, chronic conditions, allergies, blood type) was switched off on 27 July 2026, and the data was irreversibly deleted on 31 July 2026 along with the table that held it. We record this here because the previous version of this policy described that processing as ongoing.

3. What data we collect

  • Account data: email address, first name, password (stored only as a cryptographic hash), profile picture, role in the system, interface language.
  • Provider and staff data: name, address, registration details (tax and statistical identifiers, healthcare register entry), contact details of the people operating the account.
  • Booking data: name, phone, email, chosen service, date and provider. The controller of this data is the provider (see section 2).
  • Technical data: IP address, browser and device type, pages visited, time on site, referral source.
  • Communication data: the content of messages, support tickets and feedback you send us.
  • Billing data: payment history and subscription status where a provider uses a paid plan. We never see or store card numbers; the payment provider handles them.
  • Vaccination enquiries: email address and the disease or vaccine the enquiry concerns. The vaccine you are interested in is health data, so we collect it only on the basis of explicit consent and delete it automatically after 90 days.

We do not collect data we have no purpose for, and we never require health information just to let you browse.

4. Why we process data and on what basis

Every purpose has its own legal basis under Article 6 GDPR (and Article 9 where health data is involved). Where the basis is consent, you can withdraw it at any time, and withdrawal does not affect the lawfulness of what we did before.

PurposeLegal basisExplanation
Running your account and providing the serviceArt. 6(1)(b) GDPR (performance of a contract)Without it there is no login and no account features
Handling an appointment bookingArt. 6(1)(b) GDPR for the provider; Art. 28 GDPR for usWe process on the instructions of the provider, who is the controller
Vaccination or availability enquiryArt. 6(1)(a) and Art. 9(2)(a) GDPR (explicit consent)The vaccine you ask about is health data
Site analyticsArt. 6(1)(a) GDPR (consent)Off by default, switched on only by the consent banner
Marketing and campaign measurementArt. 6(1)(a) GDPR (consent)Off by default; includes the Meta conversion pixel
Newsletter and product updatesArt. 6(1)(a) GDPR (consent)Every message carries an unsubscribe link
Security, abuse prevention, rate limitingArt. 6(1)(f) GDPR (legitimate interest)Protecting the service, accounts and data from attack and misuse
Billing, accounting, taxArt. 6(1)(c) GDPR (legal obligation)Accounting and tax legislation
Establishing, exercising or defending claimsArt. 6(1)(f) GDPR (legitimate interest)For the limitation period of the claim

5. Who we entrust data to (Article 28 GDPR)

We use providers who process data on our behalf, only under data processing agreements and only to the extent needed to run the service. The table below is generated from the supplier register kept in the service's source code, so it cannot describe a provider we no longer use.

ProcessorWhat they process for usWhere the data sitsTransfer basis
Supabase Inc.Database, authentication, file storageAWS eu-central-1 (Frankfurt, Germany)Data stays in the EU; standard contractual clauses for technical support
Hetzner Online GmbHApplication hosting (dedicated server)GermanyNo transfer outside the EEA
Cloudflare, Inc.CDN, attack protection, TLS terminationGlobal network, EU points of presenceStandard contractual clauses
Stripe Payments Europe, Ltd.Payments and settlementIrelandStandard contractual clauses; EU-US Data Privacy Framework
Resend, Inc.Transactional email (confirmations, reminders)United StatesStandard contractual clauses
Upstash, Inc.Rate limiting (stores a hashed IP address only)European UnionStandard contractual clauses
SMSAPI Sp. z o.o.SMS delivery to patients in Poland (confirmations, reminders)PolandNo transfer outside the EEA
Twilio Inc.SMS delivery to patients outside Poland (confirmations, reminders)United StatesStandard contractual clauses; EU-US Data Privacy Framework
Anthropic PBCLanguage-model features (translations, support handling)United StatesStandard contractual clauses; zero-retention mode, no training on the data
Google LLCAnalytics (GA4, with consent), maps and geocoding, fonts, Tag ManagerUnited StatesStandard contractual clauses; EU-US Data Privacy Framework
Meta Platforms Ireland LimitedConversion pixel (Meta Pixel) for paid Meta/Instagram campaigns, with marketing consentIreland / global networkStandard contractual clauses; EU-US Data Privacy Framework
ElevenLabs Inc.AI receptionist demo widget on the clinics landing pageUnited StatesStandard contractual clauses; EU-US Data Privacy Framework

6. Transfers outside the European Economic Area

The application runs on a server in Germany and the database sits in the European Union (Frankfurt). Account data and provider data therefore do not leave the EEA in normal operation.

Some supporting providers are established outside the EEA, mostly in the United States. In every such case the transfer relies on standard contractual clauses approved by the European Commission and, where the provider is certified, additionally on the EU-US Data Privacy Framework. The basis for each provider is shown in the table in section 5.

We also apply supplementary measures: encryption in transit and at rest, minimising what we send to providers, and disabling third-party scripts on paths where the URL itself would say something about health (the booking wizard, a provider profile).

You can obtain a copy of the safeguards in place by writing to dpo@medova.health.

7. How long we keep data

We delete data once the purpose we collected it for has passed, unless the law requires us to keep it longer.

CategoryRetentionWhy this period
User accountWhile the account exists, then up to 5 yearsDefence against claims and record-keeping duties
Vaccination enquiries90 days, deleted automaticallyMinimisation; we keep health data as briefly as we can
Accounting and billing records5 full years from the end of the tax yearPolish accounting and tax law
Analytics data (with consent)26 monthsGoogle Analytics 4 configuration
Correspondence and support tickets3 years from the last contactHandling complaints and evidence
Security and server logsUp to 90 daysAbuse detection and diagnostics
Consent recordsWhile the consent applies and 3 years after withdrawalDemonstrating compliance, Art. 7(1) GDPR
Booking data and visit recordsSet by the provider as controllerMedical records legislation, typically 20 years
BackupsUp to 35 days after deletion from the live systemBackup rotation; deletion propagates with the cycle

8. Your rights and how to use them

Under Articles 15-22 GDPR you have the right to access your data and receive a copy, to rectification of inaccurate data, to erasure (the „right to be forgotten”), to restriction of processing, to portability in a machine-readable format, to object to processing based on legitimate interest, and not to be subject to a decision based solely on automated processing. You may withdraw consent at any time.

How to do it:

  1. Sign in and go to Settings → Privacy. Downloading a copy of your data and deleting your account work immediately, without waiting for us.
  2. Analytics and marketing consent can be changed at any time in the cookie settings in the site footer.
  3. Anything that cannot be handled from the account goes to dpo@medova.health.

We respond without undue delay and within one month at the latest. For particularly complex requests we may extend that by two further months, telling you why within the first month. Exercising your rights is free; we only allow a fee or refusal for manifestly unfounded or excessive requests, and we must justify it.

If your request concerns data for which a provider is the controller (section 2), we forward it to that provider and tell you where it went.

9. Cookies, analytics and campaign measurement

Cookies and browser storage are described in detail in our Cookies Policy. The essentials:

  • Analytics and marketing are off by default. Until you click consent, Google consent mode stays at „denied” and the Meta conversion pixel does not load at all.
  • You can withdraw consent at any time in the cookie settings. Withdrawal takes effect immediately and the scripts stop loading.
  • On health-related paths (the booking wizard, provider profiles, the provider search) we do not load third-party marketing or analytics scripts regardless of consent, because the URL itself would reveal health information.
  • Our own visit statistics run without cookies, without cross-site identifiers, on our server in Germany.

10. Automation and artificial intelligence

We do not make decisions about you that produce legal or similarly significant effects solely by automated means within the meaning of Article 22 GDPR. We do not profile you to refuse service, set a price or assess your reliability.

The automation we do use is:

  • Searching and ordering providers by query relevance, distance, ratings and profile completeness. These are rules, not profiling of you as a person.
  • Machine translation of the service into 15 languages, with editorial review for legal content.
  • Country health summaries generated by a language model from public WHO data. They are educational and labelled as AI-generated.
  • A demonstration voice assistant you can talk to on the page for healthcare providers. It is clearly identified as a machine before the conversation begins.

The full register of AI systems, their role, labelling and human oversight is described in AI Transparency. You may request human review of any automated output by writing to dpo@medova.health.

11. Data security

  • Encryption in transit (TLS 1.3) and at rest (AES-256).
  • Data separated between providers at the database level, so one provider's query cannot reach another's data.
  • Role-based access on a least-privilege basis, with two-factor authentication available for every account.
  • Logging of administrative actions and access to sensitive data.
  • Backups with regularly tested restores.
  • Security reviews and testing on significant system changes.

Report vulnerabilities to security@medova.health or office@medova.health. We follow responsible disclosure and do not pursue good-faith researchers.

12. Personal data breaches

  • Supervisory authority: we notify the President of the Personal Data Protection Office within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to people's rights and freedoms.
  • You are notified without undue delay where the breach is likely to result in a high risk to your rights and freedoms. We say what happened, what the likely consequences are, what we have already done and what you can do yourself.
  • The provider is notified immediately where the breach concerns data we process on its behalf, because as controller it decides whether to notify patients.
  • Register: we keep an internal record of every personal data breach, including those not subject to notification, with the effects and remedial action.

13. People under 16

You must be at least 16 to create a Medova account. We apply this age uniformly in every country we operate in, even though the GDPR allows Member States to lower it to 13.

We do not knowingly collect data from younger people. If we learn that an account was created by someone under 16 without a guardian's consent, we delete the data without undue delay. If you suspect this, write to dpo@medova.health.

A guardian books appointments on a child's behalf; the child's data then goes to the provider, which is its controller.

14. Data Protection Officer

We have appointed a Data Protection Officer. You can contact them about anything concerning the processing of your data and the exercise of your rights:

Medova Data Protection Officer
Email: dpo@medova.health
Address: EPKO sp. z o.o., ul. Podleśna 2, 05-270 Marki, Poland

Contacting the Officer is free of charge and your correspondence is confidential.

15. Complaint to a supervisory authority

If you believe we process your data unlawfully, you have the right to lodge a complaint with a supervisory authority (Article 77 GDPR). The competent authority for Medova is:

President of the Personal Data Protection Office (UODO)
ul. Stawki 2, 00-193 Warsaw, Poland
Phone: +48 22 531 03 00
Web: www.uodo.gov.pl
Email: kancelaria@uodo.gov.pl

If you live in another EEA country, you may also complain to the authority for your place of residence or work.