Privacy policy
Processing of personal data and special-category health data.
1. Who we are
Sole Proprietor Oleksandr Viktorovych Berezovskyi (ФОП Березовський Олександр Вікторович, Ukraine), Ukrainian taxpayer ID 3114619894, registered on 16 September 2025, state register entry no. 2010350000000877534, activity code 86.22 (Specialised medical practice), licensed by the Ukrainian Ministry of Health for medical practice in the specialty of Radiology (“рентгенологія”; licence granted by MOH order no. 973 dated 16 July 2026).
2. Data we collect
- Identifying data: full name, date of birth, contact details (phone number, email).
- Technical data: IP address, user-agent, Telegram user_id.
- Medical data (special category under GDPR art. 9): radiology reports, DICOM images, complaints, medical history.
- Payment data: tokenised transaction identifiers only — we do not store card numbers, that data sits with the payment processor.
3. Purposes of processing
- Delivering the advisory medical service.
- Meeting tax and bookkeeping obligations.
- Sending transactional notifications (order status).
- Service improvement (aggregated, anonymised analytics).
4. Legal bases for processing
- Processing of health data by a medical professional bound by medical secrecy, in the course of providing medical services (art. 7(2)(6) of Ukrainian Law no. 2297-VI / GDPR art. 9(2)(h)).
- Your explicit consent (art. 11 of Ukrainian Law no. 2297-VI / GDPR art. 9(2)(a)).
- Performance of a contract — see the public offer agreement.
- Legal obligations (Ukrainian tax and medical-records legislation).
- Protection of vital interests (GDPR art. 9(2)(c) — exceptional cases only).
5. Who we share data with
- Telegram — the messages and files you send through the bot (communication channel).
- Hetzner (EU, Finland / Germany) — secure storage of files and data, encrypted at rest.
- Plata by mono / monobank (JSC Universal Bank) — payment processing; receives payment identifiers only, never medical data.
- Checkbox — fiscal receipt registration; receives the amount and the service name.
- Postmark (EU) — email notifications (only if you provide an email address).
- Google (Gmail) — if you choose to send your study materials to the contact email address yourself: the email body and attachments are processed by Google’s mail service.
- AI tools (speech-to-text and similar) are used only within the Provider’s protected environment; medical data is not shared with third-party AI services without your separate consent.
6. Cross-border transfers
- Data is stored in the EU (Hetzner).
- If a transfer to a third country is required, we rely on Standard Contractual Clauses plus supplementary measures.
7. Retention
- Reports and accompanying medical records: 5 years, unless the law requires a longer period.
- Raw DICOM files: deleted once you confirm receipt of the report, and no later than 30 days after it is issued.
- Accounting records: 5 years (Ukrainian Tax Code).
- Access logs: 1 year.
- Cookies: the website uses no third-party tracking cookies or analytics.
8. Your rights
- Access to your data.
- Rectification.
- Erasure (subject to mandatory retention periods).
- Restriction of processing.
- Data portability.
- Objection to processing.
- Withdrawal of consent.
- Not to be subject to decisions based solely on automated processing: every report is prepared personally by the physician.
- Lodging a complaint with the Ukrainian Parliament Commissioner for Human Rights or with your EU Data Protection Authority.
Send requests for access, rectification, portability, restriction or objection to berezovskiy.a@gmail.com. We respond within 30 days.
To erase your data, use the /forgetme command in the Telegram bot: it automatically deletes your study files, cancels any active orders and anonymises your profile. Medical reports and accounting records are kept for the mandatory periods (section 7), no longer linked to your contact details. You can also request erasure by email.
9. Security
- Encryption of data at rest and in transit (TLS).
- Audit logging of access to medical files.
- Only the physician has access to medical data; service components run with least privilege.
- Pseudonymisation where feasible.
- Daily encrypted backups, with a copy kept off the primary server.
- Periodic security reviews and component updates.
10. Breach notification
- Within 72 hours — notify the Ukrainian Commissioner / the relevant EU Data Protection Authority.
- If the breach poses a high risk to the patient — notify the patient without undue delay.
11. Data protection responsibility
- Person responsible for personal data protection (art. 24 of Ukrainian Law no. 2297-VI): Oleksandr Berezovskyi (the sole proprietor personally).
- A separate DPO under the GDPR has not been designated: the processing is not large-scale within the meaning of GDPR art. 37.
- Email: berezovskiy.a@gmail.com.
12. Changes to this Policy
The current version is published on the website. For material changes, we notify users through the bot and/or by email.
13. Contact
- Email: berezovskiy.a@gmail.com
14. Language
This Policy is published in Ukrainian and English. In the event of any discrepancy, the Ukrainian version prevails.