Model information notice that the practice displays to patients (arts. 13 and 14 GDPR). The practice's fields are filled in automatically from the company details in MedAdmin. The practice adapts the notice to its activity (for example the laboratories or collaborators it works with) and signs it with the patient through the "Notă de informare" (Information notice) document in the record.
1. Summary
- The controller of your data is [name of the practice]. The practice uses the MedAdmin software, provided by Sysqo Limited, which processes the data only on behalf of the practice.
- We process your data to provide you with medical care, to manage your appointments and payments and to comply with the law.
- We do not use the data for advertising without your separate consent, which you may refuse without any consequence for your treatment.
- You have the right to see, correct and receive copies of your data and to complain to ANSPDCP (the Romanian supervisory authority).
2. Who we are
[name of the practice], tax identification number (CUI) [tax ID of the practice], with its registered office at [registered office of the practice], telephone [phone of the practice], email [email of the practice] (the "practice", "we"). Data protection contact: [contact details of the data protection officer, if appointed, or the email of the practice].
3. What data we process
- Identification and contact: surname, first name, personal numeric code (CNP), date of birth, sex, address, telephone, email; for minors and represented persons, also the data of the parent or legal representative.
- Data concerning health: medical history, allergies, chronic conditions, medication, diagnoses, investigations, images and X-rays, results, treatment plans, procedures performed, answers to pre-visit questionnaires, signed consents and, depending on the specialty, other sensitive data (for example from psychological counselling or from gynaecology and urology consultations).
- Insurance data: insured status, the health insurance fund and the data on the national health insurance card, if we have a contract with the health insurance fund.
- Administrative and financial data: appointments, attendance, estimates, payments, invoices and receipts.
- Communications: the SMS messages and emails sent, your responses to confirmation links.
4. Why we process it and on what basis
| Purpose | Basis |
|---|---|
| providing medical care, preparing and keeping the mandatory medical documents | art. 9(2)(h) GDPR; Law 95/2006 on healthcare reform; Law 46/2003 on patients' rights |
| appointments, confirmations and reminders for your appointments, recall for check-ups | art. 6(1)(b) GDPR (the relationship with the patient) and the consent to SMS messages about appointments, which you may withdraw at any time by replying STOP |
| estimates, receipts, invoices, fiscal receipts, e-Factura (Romanian e-invoicing) | art. 6(1)(b) and (c) GDPR; tax and accounting legislation |
| verifying insured status and reporting to the health insurance fund | arts. 6(1)(c) and 9(2)(h) GDPR; Law 95/2006 and the framework contract |
| clinical photographs, recordings | your separate consent (art. 9(2)(a) GDPR), requested through the "Acord pentru fotografii clinice" (Consent to clinical photographs) document |
| commercial messages (offers, campaigns) | only with your separate consent (art. 6(1)(a) GDPR; Law 506/2004 on electronic communications), which you may refuse or withdraw at any time |
| defending the practice's rights in the event of a dispute | arts. 6(1)(f) and 9(2)(f) GDPR |
Providing identification data and relevant medical data is necessary for medical care and for the documents required by law; without them we cannot treat you safely. The other consents are optional.
5. Who we share it with
- the practice's doctors, nurses and administrative staff, each only as much as they need for their role;
- other doctors, laboratories or clinics involved in your treatment, only the necessary data, or the persons you have named in the declaration on the communication of medical data;
- the health insurance fund, ANAF (the Romanian tax authority) and other authorities, when required by law;
- our providers acting as processors, under contract (art. 28 GDPR): Sysqo Limited, the provider of the MedAdmin software, with its sub-processors (Hetzner hosting in Germany, SMS through SMSLink in Romania, email through Google Workspace, notifications through Firebase); the payment processor Stripe, for online payments; our accountant.
The data is hosted in the European Union. Some providers (Google, Stripe) may access technical data from outside the EU, with the safeguards required by the GDPR (the EU–US Data Privacy Framework or standard contractual clauses). The software provider has its registered office in the United Kingdom, a country recognised by the European Commission as providing an adequate level of protection.
6. The patient portal and the MedAdmin Pacient application
If you use the pacient.medadmin.ro portal or the MedAdmin Pacient application, you see there the appointments, documents and payments we publish. The portal account is administered by Sysqo Limited, in accordance with the portal policy; your record remains with us.
7. How long we keep the data
- Medical documents: for the period provided by health regulations and by the practice's archival nomenclature: [retention period applied by the practice].
- Financial and accounting documents: in accordance with Accounting Law 82/1991 (5 years for supporting documents, 10 years for registers).
- Data used only for appointments and communications: for as long as you are our patient and at most 3 years after your last visit.
- Consents to commercial messages and photographs: until you withdraw them; clinical photographs form part of the medical file.
[TO BE CONFIRMED (DE CONFIRMAT) by the lawyer: the retention period for medical documents in outpatient care, by specialty (there is no single period in Law 46/2003; the archiving rules and the unit's archival nomenclature apply). Recommendation: a standard period proposed by the lawyer for each MedAdmin edition, filled in automatically in the field above.]
8. Security and data on devices
Data is kept encrypted in transit and, for sensitive fields, at rest; access is personal, with roles and an access log. On the practice's phones, tablets and computers there may be temporary, encrypted copies of the schedule and the records of the day, for continuity of consultations; they are deleted when the device is disconnected.
9. Automated analyses
Some investigations (for example a dental CT scan) may be analysed automatically by the software, on servers in the EU, as an aid for the doctor. The result is a suggestion checked by the doctor; no decision about you is taken solely by automated means.
10. Your rights
You have the right of access to your data and to copies of medical documents (in accordance with Law 46/2003), to rectification, to erasure (within the limits of the legal retention obligations), to restriction, to portability, to object and to withdraw consent, without affecting the processing carried out before the withdrawal. Contact us at [email of the practice] or at reception. We respond within one month at most.
You have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, sector 1, Bucharest, www.dataprotection.ro.
11. Confirmation
I have received and read this information notice. Patient (or legal representative): ____________________ · Date: ____________