1. Summary
- We use only strictly necessary cookies: the session, protection against forged requests, "remember me" and the trusted device for two-factor authentication.
- Display preferences (theme, menu, columns) are kept in the browser's local storage, are not sent to the server and do not identify you.
- We do not use advertising cookies, cross-site tracking cookies or third-party analytics tools (Google Analytics, Meta Pixel, etc.). Our usage statistics use no cookies.
- That is why we do not display a consent banner: strictly necessary cookies do not require one (Article 4(5) of Law 506/2004 on electronic communications; reg. 6(4) PECR).
2. What cookies and local storage are
Cookies are small files that a website saves in the browser and that the browser sends back with every request. Local storage (localStorage and sessionStorage) is an area of the browser in which the page keeps information without automatically sending it to the server; sessionStorage is cleared when the tab is closed.
3. Where this policy applies
This policy applies to the medadmin.ro website, the practices' platform (each practice's subdomain), the practices' public pages (online booking, confirmations, questionnaires), the patient portal pacient.medadmin.ro and the window of the MedAdmin desktop application, which displays the platform. Cookies are bound to the domain visited ("host-only") and are not shared between subdomains.
4. Cookies used
| Name | Purpose | Type | Duration |
|---|---|---|---|
medadmin_lite_session |
maintains the session (sign-in, forms, sign-up steps, visit source) | strictly necessary; HttpOnly, Secure, SameSite=Lax | 8 hours from the last activity |
XSRF-TOKEN |
protection against cross-site request forgery (CSRF) | strictly necessary; Secure, SameSite=Lax; read by the page in order to send it back | same as the session |
remember_web_… |
keeps you signed in only if you tick „Ține-mă minte” (Remember me) | strictly necessary, enabled by you; HttpOnly | until sign-out, at most 400 days |
ma_2fa_… |
remembers, at your request, that this browser is trusted, so that you are not asked for the two-factor authentication code at every sign-in; the value is signed and bound to your account | strictly necessary, enabled by you; HttpOnly, Secure, SameSite=Lax | 30 days |
The name of the session cookie derives from the application name; if it changes, we update the table.
5. Browser local storage
| Key | Where | Purpose | Duration |
|---|---|---|---|
appearance |
platform, portal | the chosen theme (light, dark, system) | until you delete it |
medadmin.sidebar.collapsed |
platform | side menu collapsed or expanded | until you delete it |
medadmin.panou.deschise |
platform | the open sections of the main dashboard | until you delete it |
medadmin.patients.columns |
platform | the columns shown in the patient list | until you delete it |
medadmin:demo-tour:… |
demo practices | progress of the guided tour | until you delete it |
medadmin.pwa.dismissed |
platform | the date on which you closed the prompt to install the app | until you delete it |
medadmin.2fa.banner.dismissed.… (sessionStorage) |
platform | you closed the banner recommending two-factor authentication | until you close the tab |
medadmin.q.… (sessionStorage) |
the questionnaire sent to the patient by link | the answers filled in, so that they are not lost if the page reloads; deleted on submission | until submission or until you close the tab |
The platform also uses a "service worker", which keeps on the device only the application's static files (scripts, logos, fonts) and the "Fără conexiune" (No connection) page. Pages containing data, server responses and patient files are not cached.
6. Third-party cookies
6.1. No third-party scripts or cookies are loaded on MedAdmin pages.
6.2. When you pay for the subscription or make a payment to a practice, you are redirected to the Stripe page (checkout.stripe.com). There Stripe uses its own cookies, necessary for the payment and for fraud prevention, in accordance with Stripe's policy (stripe.com/cookie-settings). They belong to the Stripe domain, not to MedAdmin.
7. Usage statistics
We measure use of the platform with our own tool, without cookies and without persistent identifiers: the browser sends events (for example "page viewed" with the address pattern, without parameters), each with its own random identifier. Events contain no name, phone, email, personal identification number (CNP) or free text. Details in the Privacy Policy, section 4.
8. Mobile apps
The MedAdmin Doctor and MedAdmin Pacient apps do not use tracking cookies. The data saved on the phone is described in their policies: MedAdmin Pacient, MedAdmin Doctor.
9. How to control them
You can delete or block cookies and local storage from the browser settings. If you block strictly necessary cookies, you will not be able to sign in. Clearing local storage only resets display preferences.
10. Changes and contact
If we ever introduce cookies that are not strictly necessary, we will use them only after obtaining your consent through a banner, and we will update this policy. The website, the platform and the portal are operated by Sysqo Limited, Company number 14417339, 18 Old Field Road, Pencoed, Bridgend, Wales, CF35 5LJ, United Kingdom. Questions: gdpr@medadmin.ro.