Privacy
Privacy Policy
The categories of data used by RomDoc, processing purposes and user rights.
Last updated: 05 August 2026
Introduction
# ROMDOC PRIVACY POLICY **Last update:** [27 06 2026] **Version:** [1.0]
1. About this policy
This Privacy Policy explains how personal data is collected, used, disclosed, stored and protected when you use the RomDoc platform, available through the website **[www.romdoc.fit](http://www.romdoc.fit)**, hereinafter referred to as "RomDoc" or the "Platform". The policy applies, as appropriate: * visitors to the Platform; * patients; * doctors; * clinic representatives; * to personnel authorized by doctors; * people who contact the support service; * persons requesting the exercise of rights regarding personal data; * other persons whose data is processed through the Platform. This policy should be read together with the RomDoc Terms and Conditions and any specific information displayed when using a particular functionality.
2. Who operates RomDoc?
The RomDoc platform is operated by: **Legal name:** COZUMEL SRL **Legal form:** [ SRL ] **Unique registration code:** [RO16813867] **Registration number at the Trade Register:** [J05/1783/2204] **Head office:** [Str. Dr. Louis Pasteur 38, ap. 31, 410154, Oradea, Bihor county , Romania ] **General email:** [support@romdoc.fit](mailto:support@romdoc.fit) **Data protection email:** [privacy@romdoc.fit](mailto:privacy@romdoc.fit) **Data Protection Officer, if appointed:** [ Farkas Csaba ] In this policy, the entity operating the Platform is referred to as "RomDoc", the "Operator" or "we".
3. Data protection roles
The role of RomDoc may vary depending on the processing operation. ### 3.1. RomDoc as data controller RomDoc generally acts as a data controller for processing related to: * creating and managing accounts; * Platform security; * identity and email address verification; * managing scheduling requests; * operational notifications; * doctors' subscriptions; * professional verification of doctors; * moderation of reviews; * prevention of fraud and abuse; * support service; * resolving complaints; * exercise of rights regarding personal data; * compliance with RomDoc's legal obligations. ### 3.2. Doctors and clinics The doctor or clinic may act as an independent controller for the data processed for the purpose of: * provision of consultation and medical service; * establishing the diagnosis; * recommending or providing treatment; * preparing and maintaining medical documentation; * fulfilling the professional and legal obligations of the medical provider; * billing of medical services; * managing the direct relationship with the patient. RomDoc does not establish the purposes and content of the medical document. ### 3.3. Hosting medical data When a doctor or clinic uses RomDoc to upload or manage medical documents, RoDoc can provide the technical infrastructure on behalf of the medical provider. The exact roles, responsibilities and applicable instructions will be established through agreements concluded between RomDoc and the respective doctor or clinic. In certain situations, RomDoc and the medical provider may have distinct or complementary responsibilities. For information about processing carried out directly by a doctor or clinic, we recommend that you also consult the respective provider's own privacy policy.
4. The principles we adhere to
RomDoc aims for personal data to be: * processed lawfully, fairly and transparently; * collected for specified, explicit and legitimate purposes; * adequate, relevant and limited to what is necessary; * correct and up-to-date; * kept only for as long as necessary; * protected by appropriate technical and organizational measures; * accessible only to authorized persons; * used in a way that respects the rights of data subjects.
5. Data we may collect
Depending on how you use the Platform, we may process the following categories of data. ### 5.1. Identification and account data These may include: * name and surname; * email address; * phone number; * the internal account identifier; * account role; * preferred language; * account creation date; * email address verification status; * account status; * history of authentications and important changes; * profile picture, if uploaded; * account preferences. RomDoc does not have access to your password in readable format. Passwords and authentication mechanisms are managed through specialized authentication systems. ### 5.2. Appointment data We can process: * patient's name; * his/her contact details; * selected doctor and clinic; * specialty; * requested date and time; * confirmed or rescheduled date and time; * scheduling status; * reason for cancellation, if provided; * observations entered by the patient, doctor or authorized personnel; * programming source; * change history; * the identity of the person who made a change; * notifications associated with the schedule. We recommend that you do not enter more medical information in the general fields than is necessary to administer the appointment. ### 5.3. Health data Depending on the activated functionalities, the Platform may process health data, such as: * the medical reason for presentation; * information communicated in connection with an appointment; * consultation notes; * diagnostics; * recommendations; * prescriptions; * referrals; * laboratory results; * imaging results; * medical reports; * uploaded medical documents; * information on previous consultations; * information shared by the patient with a doctor. Health data is considered sensitive data and benefits from additional protection. RomDoc does not require users to publish medical data in public sections, reviews, or profiles. ### 5.4. Data about doctors To create and manage a professional profile we may process: * name and contact details; * professional photography; * title and specialty; * biography; * languages spoken; * professional experience; * services and rates; * clinics and activity locations; * availability; * professional registration number; * issuing authority; * supporting professional documents; * professional verification status; * the expiration date of some documents; * subscription information; * billing data; * information about authorized personnel; * profile management history. Certain professional information is publicly displayed to allow patients to find and evaluate available providers. Supporting documents used for professional verification are not publicly displayed. ### 5.5. Data on authorized personnel For people added by a doctor or clinic, we can process: * name; * email address; * role; * the doctor or clinic with which the person is associated; * permissions granted; * invitation status; * activity carried out through the account; * access and modification history. ### 5.6. Payment and billing details For doctors' subscriptions we can process: * the name or designation of the payer; * billing address; * tax code, if necessary; * selected plan; * value and currency; * billing period; * payment status; * transaction and subscription identifiers; * subscription start and end date; * information about invoices and refunds; * last digits and card type, if provided by the payment processor. Complete card data is entered and processed by the specialized payment provider and is not stored directly by RomDoc. ### 5.7. Reviews and published content We can process: * the text of the review; * the grade awarded; * the doctor or clinic in question; * associated programming; * publication date; * moderation status; * reasons for reporting or moderation; * responses or appeals; * the author's internal identity. The patient's full name may not be displayed publicly, even though RomDoc retains it to verify the authenticity of the review. Do not include detailed medical data, personal identification numbers, addresses, document numbers, or information about other people in your reviews. ### 5.8. Technical and usage data When you use the Platform we may automatically collect: * IP address; * device type; * operating system; * browser type and version; * browser language; * pages accessed; * date and time of access; * session identifiers; * technical errors; * security events; * logs of requests to the server; * information necessary to detect fraud or misuse; * general data about the Platform's performance. This data is not used to establish a diagnosis or make medical decisions. ### 5.9. Location data If you use map-based functionalities, we may process: * chosen city; * the area searched; * approximate coordinates of medical locations; * approximate location determined from IP address; * device location, only if you grant the appropriate permission. You can deny access to precise location and manually search by city or address. ### 5.10. Communications and support When you contact us, we may process: * name; * email address; * phone number; * message content; * attached files; * request category; * answer history; * information necessary to verify identity; * data on the resolution of the request. Do not email medical or identity documents unless we request this through an appropriate and secure channel. ### 5.11. Data regarding privacy requests and account closure We can process: * type of request; * date of transmission; * the identity of the applicant; * information used for identity verification; * request status; * date of account restriction or closure; * associated correspondence; * actions taken; * the reasons why certain data was retained; * notifications sent.
6. How we get the data
We can obtain the data: * directly from you; * from the doctor, clinic or authorized personnel with whom you interact; * from the person making an appointment on your behalf; * from the payment provider; * from authentication and infrastructure providers; * from legitimate professional registers or sources, for the purpose of verifying a doctor; * from the technical activity of the device and browser; * from communications and complaints from other users; * from authorities or professional bodies, when the law allows or requires this. If another person provides us with your data, they must have a legitimate reason and inform you accordingly.
7. Purposes and grounds of processing
RomDoc processes data only when there is an applicable legal basis. ### 7.1. Account creation and management **Goals:** * user registration; * authentication; * email address verification; * providing account functionalities; * preferences management; * account closure. **Subject:** execution of the contract or carrying out the steps requested before its conclusion. ### 7.2. Managing appointments **Goals:** * sending the request to the doctor or clinic; * availability check; * confirmation, rescheduling or cancellation; * displaying history in the account; * sending notifications; * solving problems associated with programming. **Grounds:** execution of the service requested by the patient and, where applicable, legitimate interest in the operation and documentation of the service. If the request contains health data, an appropriate condition for the processing of special categories of data will also be applied, depending on the context and the role of each party. ### 7.3. Provision of medical services Processing carried out for diagnosis, treatment, medical documentation or other clinical purposes is carried out mainly under the responsibility of the doctor or clinic. The grounds and conditions applicable to this processing are established by the medical provider in accordance with its legal and professional obligations. ### 7.4. Professional verification of doctors **Goals:** * identity verification; * verification of professional information; * checking the validity of certain documents; * granting, withdrawal or expiry of the verification mark; * prevention of fake professional profiles. **Grounds:** execution of the contractual relationship with the doctor, legitimate interest regarding the safety and trust in the Platform and, when necessary, compliance with legal obligations. ### 7.5. Subscriptions, payments and billing **Goals:** * payment initiation; * subscription management; * issuing or keeping financial and accounting documents; * fraud prevention; * resolving disputed payments. **Grounds:** execution of the contract, legal financial-accounting obligations and legitimate interest in preventing fraud. ### 7.6. Operational communications **Goals:** * account confirmation; * security alerts; * notifications about appointments; * subscription notifications; * notifications about account closure; * informing about important changes to the service. **Grounds:** execution of the contract, compliance with legal obligations and legitimate interest in the operation of the Platform. These messages are not marketing communications. ### 7.7. Marketing We may only send communications about products, features or offers when there is an appropriate legal basis. When necessary, we request separate consent. Consent may be withdrawn at any time, without affecting the lawfulness of the processing prior to withdrawal. Opting out of marketing does not affect necessary account messages, appointments, security, or requested services. ### 7.8. Security and abuse prevention **Goals:** * protecting accounts; * prevention of unauthorized access; * detection of attacks and fraud attempts; * investigating suspicious activity; * ensuring system integrity; * making and testing safety copies; * incident documentation. **Grounds:** legitimate interest in the security of the Platform, protecting users and complying with legal security obligations. ### 7.9. Review and Content Moderation **Goals:** * checking eligibility for publishing a review; * detection of illegal or abusive content; * investigating complaints; * hiding or removing content; * prevention of fake reviews. **Grounds:** execution of the service, legitimate interest in the integrity of the Platform and compliance with legal obligations. ### 7.10. Complaints, disputes and legal claims **Goals:** * resolving complaints; * exercise of rights; * ascertaining, exercising or defending rights; * response to requests from authorities; * compliance with legal obligations. **Grounds:** legal obligation and legitimate interest in defending rights.
8. Health data and other sensitive data
Health data are special categories of data. They are only processed when: * processing is necessary for the provision or administration of medical services; * the processing is carried out under the responsibility of a professional subject to the obligation of confidentiality; * processing is necessary for the defense of a right; * there is a legal obligation or authorization; * the data subject has given his or her explicit consent, where consent is the appropriate basis; * another condition provided by law is applicable. Requesting an appointment does not authorize the use of medical data for marketing. RomDoc does not sell health data and does not use it for personalized advertising.
9. Necessity of providing data
Certain data is necessary for: * account creation; * identity verification; * sending an appointment; * managing a subscription; * compliance with a legal obligation; * providing access to protected documents or functionalities. If you do not provide this data, we may not be able to create your account, submit your appointment, process your payment, or provide the requested functionality. Data marked as optional can be omitted without generally hindering the use of basic functionalities.
10. Who can we disclose data to?
Data is disclosed only to the extent necessary and according to applicable roles and permissions. ### 10.1. Doctors, clinics and authorized personnel The dates of an appointment can be accessed: * the selected doctor; * the clinic where the appointment takes place; * to the staff authorized to manage that doctor's appointments; * other persons legitimately involved in the provision of medical services. Staff do not automatically receive access to medical records. Their access is limited by roles and permissions. ### 10.2. Technical suppliers We may use suppliers to: * databases; * authentication; * hosting; * file storage; * backup copies; * sending emails; * payment processing; * maps and geolocation; * error monitoring; * security; * technical assistance. These providers process data based on contracts and only for the necessary services. As of the last update, providers may include: * **Supabase**, for database, authentication and file storage; * **Vercel**, for hosting and delivering the application; * **Resend**, for sending operational emails; * **Stripe**, for payment processing and subscription management; * **Google Workspace**, for support communications; * **Google Maps Platform**, for maps, addresses and location; * **Google Cloud**, for infrastructure, storage or backups, if these services are enabled; * [OTHER SUPPLIERS]. The list of providers may be updated when the Platform infrastructure changes. ### 10.3. Consultants and professional providers The data may be disclosed, within the necessary limits, to: * lawyers; * accountants; * auditors; * security consultants; * insurance providers; * specialists contracted to investigate incidents. ### 10.4. Authorities and other persons We may disclose data: * if the law requires it; * at the legal request of a competent authority; * to protect the life, health or safety of a person; * to investigate fraud or an incident; * for the establishment, exercise or defense of a right; * in the context of a reorganization, merger, sale or transfer of activity, in compliance with applicable guarantees.
11. Public data
Certain data about doctors and clinics is publicly displayed, such as: * name; * professional photography; * specialty; * biography; * services and rates; * clinics; * cities and professional addresses; * availability; * languages spoken; * reviews; * professional verification status. Doctors must avoid publishing personal data that is not necessary for their professional profile. Patient data, physician verification documents, and medical records are not publicly displayed.
12. Maps and location services
The platform can integrate map services provided by Google. When loading the map, the provider may receive information such as: * IP address; * browser type; * device information; * approximate location; * interactions with the map. Your device's precise location is only used if you grant permission in your browser or device. You can use manual search without granting access to the exact location.
13. Payments
Subscription payments are processed by a specialized provider. Full card information is entered directly into the payment provider's system. RomDoc can receive: * payment confirmation; * subscription status; * value; * currency; * transaction identifiers; * last digits and card type; * the payment method expiration date, in the form provided by the processor; * information about failed payments, refunds or appeals.
The payment provider processes certain data as an independent controller, in accordance with its own privacy policy.
14. International transfers
Some providers may store or access data from countries outside Romania or the European Economic Area. When an international transfer takes place, RomDoc aims to use an appropriate legal mechanism, such as: * an adequacy decision; * approved standard contractual clauses; * mandatory corporate rules; * a derogation permitted by law; * other guarantees recognized by applicable law. When necessary, we analyze the risks of the transfer and apply additional technical, contractual or organizational measures. You can request additional information about the safeguards used at [privacy@romdoc.fit](mailto:privacy@romdoc.fit).
15. Retention periods
Data is kept only as long as necessary for the purposes for which it was collected, legal obligations and the defense of rights. Final periods must be established and documented by RomDoc prior to commercial launch. The main criteria and proposed periods are: ### 15.1. Accounts Account data is retained for the duration of the account and for a period of **[X YEARS/MONTHS]** after its closure, if necessary for security, complaints or defense of rights. ### 15.2. Appointments Administrative data about appointments is kept for **[X YEARS]** from the date of the appointment or from the last relevant action. Data that is part of the medical documentation may be retained by the doctor or clinic for the periods imposed on the medical provider by applicable legislation. ### 15.3. Medical documents Medical documents are retained according to the purpose for which they were created, the medical provider's instructions, the patient's rights, and legal archiving obligations. Closing the RomDoc account does not automatically result in the deletion of documents that the doctor or clinic is legally obligated to keep. ### 15.4. Professional verification documents Verification documents are retained for the duration of the verification and for **[X YEARS]** after its expiration, rejection or withdrawal, to the extent necessary for auditing, complaints and fraud prevention. ### 15.5. Financial and accounting data Invoices and other financial and accounting documents are kept for the period provided for by applicable tax and accounting legislation. ### 15.6. Reviews Reviews are retained for as long as they are published and for **[X YEARS/MONTHS]** after deletion, if retention is necessary to resolve a complaint or defend rights. ### 15.7. Technical and security logs Regular diaries are typically kept for **[X MONTHS]**. Logs associated with an incident, fraud, or dispute may be retained longer, until the investigation is completed and applicable deadlines have expired. ### 15.8. Requests regarding rights and account closure Records of requests and responses are kept for **[X YEARS]**, to demonstrate compliance with legal obligations. ### 15.9. Backup copies Data deleted from active systems may remain temporarily in backups until overwritten or the backup cycle expires. Access to these copies is restricted, and data is not restored to current use unless recovery is necessary following an incident.
16. Data security
We apply technical and organizational measures proportionate to the risks, which may include: * encryption of communications; * role-based access control; * database and file access policies; * secure authentication; * multifactor authentication for privileged roles; * journaling of important operations; * temporary access to files via signed links; * limiting personnel access; * backup copies; * incident monitoring; * security updates and fixes; * separation of development and production environments; * training of persons with access; * confidentiality agreements; * supplier evaluation. No method of transmission or storage can guarantee absolute security. If you suspect that an account or document has been accessed without authorization, contact us immediately at [support@romdoc.fit](mailto:support@romdoc.fit).
17. Security incidents
In the event of an incident affecting personal data, RomDoc will: * investigate the situation; * limit the effects of the incident; * document the measures taken; * inform the supervisory authority when the law requires it; * inform affected persons when the incident may pose a high risk to their rights and freedoms; * take measures to prevent the incident from recurring.
18. Your rights
Under the conditions provided by law, you may have the following rights. ### 18.1. Right to information You have the right to receive clear information about how your data is processed. ### 18.2. Right of access You can request confirmation that we are processing your data and a copy of the eligible data. ### 18.3. Right to rectification You can request the correction of inaccurate data and the completion of incomplete data. Certain information can be updated directly from your account. ### 18.4. Right to erasure You can request the deletion of data when the legal conditions are met. The right to erasure is not absolute. We may retain certain data if this is necessary for: * compliance with a legal obligation; * mandatory medical documentation; * establishing, exercising or defending a right; * fraud prevention; * Platform security; * resolving a complaint; * other situations provided for by law. ### 18.5. Right to restriction of processing You can request that the use of data be limited in certain situations. ### 18.6. Right to portability For certain data provided directly by you and processed automatically based on consent or contract, you can request to receive them in a structured, commonly used and machine-readable format. ### 18.7. Right to object You may object to processing based on legitimate interest for reasons related to your particular situation. You can object to direct marketing at any time. ### 18.8. Withdrawal of consent If processing is based on consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. ### 18.9. Rights regarding automated decisions At the date of the last update, RomDoc does not use decisions based exclusively on automated processing that produce legal effects on the user or similarly significantly affect him/her. Search filters, results ordering, technical abuse prevention, and general recommendations do not constitute medical decisions. If we introduce such a system in the future, we will provide specific information and the guarantees provided by law. ### 18.10. Right to file a complaint You have the right to file a complaint with: **National Supervisory Authority for Personal Data Processing – ANSPDCP** We encourage you to first contact us at [privacy@romdoc.fit](mailto:privacy@romdoc.fit), to attempt to resolve the issue directly. This does not limit your right to contact the authority.
19. How you can exercise your rights
You can submit a request to: **[privacy@romdoc.fit](mailto:privacy@romdoc.fit)** The request must specify: * name; * the email address associated with the account; * the right you wish to exercise; * information necessary to identify the data; * any detail that helps us understand the request. To protect your data, we may request additional information to verify your identity. We will not ask for your account password. We will respond within the time limit provided by law. If the request is complex or there are multiple requests, the time limit may be extended according to law, with the applicant being informed. The exercise of rights is usually free of charge. For manifestly unfounded, excessive or repetitive requests, we may apply the measures permitted by law. If the data is processed under the responsibility of a doctor or clinic, we may forward the request to the competent provider or indicate how you can contact them.
20. Account closure
You can request account closure through the functionality available on the Platform or by contacting RomDoc. Closure may involve: * access restriction; * cancellation of future functionalities; * termination of the subscription, according to the applicable conditions; * deletion or anonymization of eligible data; * retaining information that must be maintained legally; * separating the account from certain records that cannot be deleted; * keeping a minimum log of the request and the measures taken. RomDoc may apply a waiting period during which the request can be canceled. Medical documents and professional records are not automatically deleted if the doctor, clinic or RomDoc has the legal obligation or right to keep them.
21. Children and minors
The accounts are intended primarily for people who have reached the age of 18. Appointments for a minor must be made by the parent, guardian or legal representative, if the functionality is available. The person entering the minor's data confirms that they have the right to act on their behalf. RomDoc and medical providers may request additional documents or confirmations regarding legal representation. Independent accounts for children should not be created without complying with applicable legal requirements.
23. External links and services
The Platform may contain links to websites of doctors, clinics, payment processors or other third parties. RomDoc does not control the processing carried out by these third parties outside the Platform. We recommend that you consult the privacy policy of each external service before providing it with personal data.
24. Modification of this policy
We may update the Privacy Policy to reflect: * legislative changes; * new functionalities; * changes in suppliers; * changes in the purposes of processing; * additional security measures; * recommendations of the authorities; * organizational changes. The updated version will be published on the Platform and will indicate the date of the last update. In the event of a significant change, we may inform users by: * email; * notification in account; * message displayed on the Platform; * other appropriate means. If new processing requires consent, it will be requested separately.
25. Contact
For general questions: **[support@romdoc.fit](mailto:support@romdoc.fit)** For questions, requests and complaints regarding personal data: **[privacy@romdoc.fit](mailto:privacy@romdoc.fit)** Operator Data: **COZUMEL SRL** **[ Str. Dr. Louis Pasteur 38, ap. 31, 410154, Oradea, Bihor county, Romania ] ** **[CUI: RO16813867 REGISTER J05/1783/2004]** We will review data protection requests carefully and respond in accordance with applicable law.