1. Preamble
Protecting your personal data – in particular your health data – is important to us. We process your data exclusively within the framework of the applicable data protection laws, in particular the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications-Telemedia Data Protection Act (TTDSG).
This privacy policy informs you about:
- which data we process,
- for what purposes this is done,
- on what legal basis this takes place,
- to which recipients data is disclosed,
- and which rights you have as a data subject.
NeoClariox Ltd. is not a medical facility and does not itself provide any medical or pharmaceutical services. Doctors and pharmacies are independent controllers with respect to their own data processing.
2. Controller
NeoClariox Ltd.
Georgiou A 125, Narcissos Complex, Office 26–27
4048 Limassol, Cyprus
Email: [email protected]
Represented by the management.
3. Data Protection Officer
Name: Anna Oravcova
Email: [email protected]
4. Definitions
This policy uses terms as defined in Art. 4 GDPR, in particular:
- personal data
- special categories of personal data (health data)
- processing
- controller
- processor
- consent
5. Purposes of the Platform & Role Model
NeoClariox operates a platform that connects users with independent service providers (doctors, pharmacies, other healthcare professionals).
Medical service providers are independent controllers pursuant to Art. 4 No. 7 GDPR.
NeoClariox processes health data exclusively:
- to arrange medical services,
- for appointment management,
- for the transmission of documents,
- for communication,
- for billing platform services.
Providing certain personal data is necessary in order to use the platform and to arrange medical services. Without this information, mediation and the use of certain platform functions cannot take place.
6. Data Processing When Visiting the Platform
6.1 Server Log Files
When the platform is accessed, we process:
- partially anonymized IP address
- date/time
- pages/files accessed
- browser & operating system
- referrer URL
Legal basis: Art. 6 (1) (f) GDPR (operation & security).
Retention period: max. 14 days.
Recipient: hosting provider netcup GmbH.
6.2 Cookies & Consent Management
Our platform uses cookies and similar technologies.
Categories:
- technically necessary (e.g. login, security)
- statistics (e.g. Matomo, optional)
- marketing/tracking (only with consent)
For the use of technically necessary cookies, we rely on § 25 (2) TTDSG as well as Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (f) GDPR (legitimate interest in a secure and functional operation of the platform).
Legal basis (non-necessary cookies): Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TTDSG.
Your consent is managed via a consent management tool and can be withdrawn at any time.
6.3 Matomo (self-hosted)
- Used only with consent.
- IP address is anonymized.
- Legal basis: Art. 6 (1) (a) GDPR.
- Withdrawal: via cookie settings.
6.4 Google Analytics
- Used only with consent.
- Transfer to the USA – with Standard Contractual Clauses (SCC).
- We do not transmit any health data or medical content to Google.
- Legal basis: Art. 6 (1) (a) GDPR.
7. Data Processing During Registration / User Account
Registration is required to use certain platform functions.
We process:
- name, address
- email address
- password (hashed; your password is stored exclusively as a cryptographic hash value and is never readable by us in plain text.)
- IP address
- health-related information that you voluntarily provide
- uploaded documents
- usage data
Legal bases:
- Art. 6 (1) (b) GDPR (usage contract)
- Art. 9 (2) (a) GDPR (consent to health data)
Consent is given actively by ticking a checkbox and can be withdrawn at any time.
8. Data Processing for Arranging Medical Services
For mediation we process:
- name
- contact details
- relevant health data
- details of the request
- required documents
- appointment preferences
- technical connection data for video appointments
Legal basis: Art. 6 (1) (b) GDPR and Art. 9 (2) (a) GDPR (consent).
8.1 Transmission to Doctors and Pharmacies
The transmission of the above data to service providers takes place exclusively:
- to prepare/perform the treatment contract
- with your explicit consent
Doctors and pharmacies are independent controllers pursuant to Art. 4 No. 7 GDPR. Their data processing is governed by their own privacy policies.
8.2 Video Communication (MiroTalk C2C)
We use "MiroTalk C2C" as a WebRTC-based video solution.
- end-to-end encrypted transmission
- no permanent storage of audio/video
- servers in the EU (configuration-dependent)
Legal basis: Art. 6 (1) (b) GDPR & Art. 9 (2) (a) GDPR.
Role: processor pursuant to Art. 28 GDPR.
9. Payment & Transaction Processing
We work with various payment service providers, including: medicflow, Adyen, Mollie, DIMOCO, micropayment (as well as other providers that we integrate technically for redundancy).
In particular, the following are processed:
- name
- contact details
- invoice data
- payment method
- transaction data
- technical data (IP, browser)
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) as well as Art. 6 (1) (c) GDPR (compliance with legal retention obligations, in particular under the German Commercial Code (HGB) and Fiscal Code (AO)).
Payment service providers are generally independent controllers. Data transfers to third countries take place on the basis of SCC. Transaction data is stored for up to 10 years in accordance with commercial and tax law requirements.
10. Contact & Communication
When you contact us by email or contact form, we process:
- name
- email address
- content of the request
Legal basis: Art. 6 (1) (a) GDPR (consent) or (b) (contract).
11. Newsletter
If you subscribe to our newsletter, we use your email address to regularly send you information about our offers, platform features or relevant health topics.
For this we use the service SendGrid (Twilio Inc., USA). To ensure your data is protected even when transferred to the USA, the processing is based on the Standard Contractual Clauses (SCC) approved by the EU Commission as well as additional technical security measures of the provider.
To ensure that your registration actually originates from you, we use the double opt-in procedure: after registering, you receive a confirmation email. Your newsletter subscription is only activated after you click the confirmation link.
We store:
- your email address
- the time of registration and confirmation
- technical log data to document your consent
In addition, for technical reasons we may statistically evaluate whether and when newsletters are opened and which links are clicked. We use this information exclusively to improve our content and better tailor it to the interests of our recipients.
You can unsubscribe from the newsletter at any time via the unsubscribe link at the end of each email or by messaging us. The withdrawal takes effect only for the future.
Legal basis: Art. 6 (1) (a) GDPR (consent).
12. Third-Party Content
When embedding videos/graphics, your IP address may be transmitted to the third-party provider.
Legal basis: Art. 6 (1) (a) GDPR (consent in the consent banner).
13. Recipients of Personal Data
| Recipient | Role | Purpose |
|---|---|---|
| Hosting / netcup | Processor | Operation of the platform |
| Doctors | Independent controller | Treatment |
| Pharmacies | Independent controller | Prescription/medication dispensing |
| Payment service providers | Independent controller | Payment processing |
| MiroTalk | Processor | Video consultations |
| SendGrid | Processor | Newsletter |
| Internal IT service providers | Processor | Support |
14. Retention Period
As a rule, we store personal data only for as long as is necessary to fulfil the respective purposes or as required by law.
The most important periods at a glance:
- Server log files: automatic deletion after max. 14 days
- Registration and account data: until your user account is deleted
- Health data: until you withdraw your consent or until the mediation process is fully completed
- Communication data (e.g. emails): until your request has been finally processed
- Billing, payment and tax-relevant data: up to 10 years (statutory retention periods under HGB and AO)
- Newsletter data: until you withdraw your consent
When the respective storage purposes cease to apply or statutory retention obligations have expired, we delete the relevant data automatically and securely.
15. Your Rights Under the GDPR
You have the following rights at any time with regard to your personal data:
Access (Art. 15 GDPR)
You can request information about which data we have stored about you and for what purposes it is processed.
Rectification (Art. 16 GDPR)
If data is incorrect or incomplete, you can request its correction.
Erasure (Art. 17 GDPR)
You can request the deletion of your data, provided no statutory retention obligations conflict with this.
Restriction of Processing (Art. 18 GDPR)
Under certain conditions, you can request that your data only be processed to a restricted extent.
Data Portability (Art. 20 GDPR)
You can request that we provide your data to you or another controller in a common, machine-readable format.
Objection (Art. 21 GDPR)
If we process data on the basis of legitimate interests, you can object to this processing. In the case of direct advertising, you can object at any time without giving reasons.
Withdrawal of Your Consent (Art. 7 (3) GDPR)
You can withdraw consent you have given at any time with effect for the future – without giving reasons.
Right to Complain (Art. 77 GDPR)
You can complain to a data protection supervisory authority if you believe that your data is being processed unlawfully.
16. Security
We take extensive technical and organizational measures to protect your personal data against loss, misuse, unauthorized access or unauthorized disclosure.
These measures include, among others:
- SSL/TLS encryption for all data transmissions
- storage exclusively in certified EU data centers
- access restrictions for employees and service providers
- confidentiality agreements
- regular security audits and updates
- secured backups
- encryption of sensitive data
- processing by service providers exclusively on the basis of Art. 28 GDPR data processing agreements and documented security standards
We only pass on your data if there is a legal basis for doing so or if you have expressly consented. Disclosure for commercial purposes (e.g. sale of user data) does not take place.
17. Changes to This Privacy Policy
We reserve the right to amend this policy. The current version is always available on our platform.