Privacy Policy

Last updated: 1 August 2026.

Who processes your data

Your data is processed by the clinic where you book your appointment — it decides which data is collected and why. This platform is a technical service the clinic uses, and it processes data solely on the clinic's instructions, for no purpose of its own. For anything concerning your data, contact the clinic.

Data you enter when booking

Your first and last name, phone number, email address and, optionally, a note. We also store the appointment details (date, time, selected doctor and service) and the time you gave consent. The note is free text — do not enter health information there unless the clinic explicitly asks for it.

Health data

Clinics that also keep patient charts through the platform record health data: medical history, findings and measurements, diagnoses, treatments, images and billing. This is medical documentation the clinic keeps under applicable regulations, exactly as it would on paper. Clinics that use the platform only for scheduling cannot enter such data at all — the system prevents it, rather than relying on staff discipline.

Account for viewing appointments

If you create an account to view your appointments, we store your email address and your password in encrypted form. Through the account you can see your appointments and treatment plan, but not the doctor's working notes — access to those is arranged through the clinic. You can also create the account by signing in with Google: in that case Google gives us your email address and basic profile details (name and picture), we store no password, but Google learns that you signed in to this application. If you would rather avoid that, sign in with an email address and password — everything else works the same. An account is optional: you can book an appointment without one.

Technical data and abuse protection

To prevent automated booking of fake appointments, we temporarily record the IP address the request came from and the phone number in the request. These records are deleted automatically after two days and are not used for anything else. We use only cookies necessary for operation — so the system remembers that you are signed in. There are no tracking or advertising cookies.

Why we collect data

Solely to book and maintain your appointment: the clinic needs to know who is coming and how to reach you, and we email you a confirmation, reminders and a cancellation link. We do not use the data for anything else and we neither sell nor share it with third parties. We use only the technical services required to operate: the database, email delivery, technical error monitoring and — only if you choose it yourself — signing in with Google.

Who has access

Only the clinic where you booked can see your data. Data belonging to different clinics is technically separated and is never publicly accessible. Within a clinic, staff see only what their work requires — reception, for example, does not see the medical part of the chart. Every change to a chart is logged: who changed what, and when.

Where data is stored

On servers in the European Union (Frankfurt, Germany), and it is not transferred outside it. Our error monitoring service tells us when something in the application stops working; it is configured NOT to receive your personal or health data — no names, no page addresses containing your data, no form contents and no cookies. The one exception is signing in with Google, if you choose it: the sign-in itself then happens at Google, under Google's own privacy policy, and only your email address and basic profile details are returned to us. Your appointment and health data are never sent to Google.

How long we keep data

Appointment data is kept while the clinic maintains its appointment records, and is deleted at your request or when the clinic stops using the platform. Medical documentation is kept by the clinic for the periods required by healthcare documentation law — the clinic must retain it even if you request deletion. The log of chart changes (who changed what, and when) and the access log (who opened, printed or exported the chart, and when) are kept for twelve months and then deleted automatically. Technical abuse-protection records are deleted after two days.

Legal basis and your rights

We process booking data on the basis of your consent (Serbian Personal Data Protection Act), given by ticking the consent box when booking. Medical documentation is kept by the clinic on the basis of healthcare regulations. You have the right to access, correct, delete and port your data, and to withdraw consent — simply contact the clinic where you booked, by phone or in person. If you believe your rights have been violated, you may contact the Commissioner for Information of Public Importance and Personal Data Protection.

← Back to home

Clinic login